Virus reklamy
Napsal: 18 led 2017 14:06
Ahojte,
mal som zavireny pc, same reklamy ... uz to vyzerá, byt v pohode no myslim si, ze tam este nieco ostalo.
PC sa zapina strasne dlho, oproti obdobiu pred virusom ...
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017
Ran by p4too (administrator) on DESKTOP-FSNBGS5 (18-01-2017 14:04:17)
Running from C:\Users\p4too\Desktop
Loaded Profiles: p4too (Available Profiles: defaultuser0 & p4too)
Platform: Windows 10 Pro N Version 1607 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(JetBrains s.r.o) C:\Program Files (x86)\JetBrains\ETW Host\JetBrains.ETW.Collector.Host.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(ExpanDrive, Inc.) C:\Program Files (x86)\ExpanDrive\ExpanDrive.exe
() C:\Program Files (x86)\ExpanDrive\expandrive\expandrivedw.exe
(Spotify Ltd) C:\Users\p4too\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\p4too\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3947704 2015-08-29] (Synaptics Incorporated)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [gplyra] => C:\Users\p4too\AppData\Roaming\gplyra\gplyra\start.cmd [216 2016-01-19] ()
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] wscript C:\Windows\run.vbs,
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\Run: [Google Update] => C:\Users\p4too\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\Run: [ExpanDrive] => C:\Program Files (x86)\ExpanDrive\ExpanDrive.exe [1471072 2015-02-04] (ExpanDrive, Inc.)
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\Run: [Spotify Web Helper] => C:\Users\p4too\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2017-01-02] (Spotify Ltd)
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\MountPoints2: {3c2cd3d1-7cec-11e6-a050-f0761c6c6ff4} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-18\...\Run: [] => 0
HKLM\...\Providers\vlitza5s: C:\Program Files (x86)\Jerjatstervele Server\local64spl.dll [292352 2017-01-18] ()
SSODL: EldosMountNotificator-cbfs4 - {E4B9D98A-19E4-4A2F-B080-BBF8AF8BCF51} - C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs4 - {E4B9D98A-19E4-4A2F-B080-BBF8AF8BCF51} - C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellExecuteHooks: No Name - {2B291F10-DB96-11E6-B994-64006A5CFC23} - -> No File
ShellIconOverlayIdentifiers: [00ExpanDriveExt1] -> {C955792B-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers: [00ExpanDriveExt2] -> {C955792C-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs4] -> {9CF93BCF-F6A8-4625-A75C-2F8F67BA0D39} => C:\Windows\system32\cbfsMntNtf4.dll [2013-11-15] (EldoS Corporation)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File
ShellIconOverlayIdentifiers-x32: [00ExpanDriveExt1] -> {C955792B-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers-x32: [00ExpanDriveExt2] -> {C955792C-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs4] -> {9CF93BCF-F6A8-4625-A75C-2F8F67BA0D39} => C:\Windows\SysWOW64\cbfsMntNtf4.dll [2013-11-15] (EldoS Corporation)
Startup: C:\Users\p4too\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\thunderbird.exe – odkaz.lnk [2016-09-20]
ShortcutTarget: thunderbird.exe – odkaz.lnk -> E:\SoftWare\Thunderbird\thunderbird.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 8.8.4.4 8.8.8.8
Tcpip\..\Interfaces\{450fc5d8-0ece-4669-ae3b-2a1cd2e0fa44}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{88ebffb6-5b12-4da6-9153-1d057df9a8f9}: [DhcpNameServer] 8.8.4.4 8.8.8.8
Internet Explorer:
==================
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
FireFox:
========
FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-01-18]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin HKU\S-1-5-21-3402369080-3581635727-2017991681-1001: @tools.google.com/Google Update;version=3 -> C:\Users\p4too\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3402369080-3581635727-2017991681-1001: @tools.google.com/Google Update;version=9 -> C:\Users\p4too\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://google.com/
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.youndoo.com/?z=9227f5a8015421805b78 ... 5A&type=hp"
CHR Profile: C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-01-18] <==== ATTENTION
CHR Extension: (Prekladač Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2016-09-17]
CHR Extension: (Prezentácie Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-17]
CHR Extension: (Dokumenty Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-17]
CHR Extension: (Disk Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-17]
CHR Extension: (YouTube) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-17]
CHR Extension: (Adblock Plus) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-26]
CHR Extension: (AdBlocker - Blokovač reklám pre YouTube™) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-12-23]
CHR Extension: (Tabuľky Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-17]
CHR Extension: (Kaspersky Protection) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-01-18]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-17]
CHR Extension: (AdBlock) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-17]
CHR Extension: (Gmail) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-17]
CHR Extension: (Chrome Media Router) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-16]
CHR Profile: C:\Users\p4too\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-01-18]
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2297104 2015-10-12] (Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation)
R2 jetbrainsetw.106.0.20160913.92350; C:\Program Files (x86)\JetBrains\ETW Host\JetBrains.ETW.Collector.Host.exe [1474624 2016-09-13] (JetBrains s.r.o)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S2 KuaizipUpdateChecker; C:\Program Files\żěŃą\X86\kuaizipUpdateChecker.dll [X]
S4 OracleJobSchedulerXE; e:\software\oracledatabase\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [X]
S3 OracleMTSRecoveryService; E:\oracle\app\pato\product\11.1.0\client_1\bin\omtsreco.exe "OracleMTSRecoveryService" [X]
S2 OracleServiceXE; e:\software\oracledatabase\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [X]
S3 OracleXEClrAgent; E:\SoftWare\OracleDatabase\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS="EXTPROC_DLLS=ONLY:E:\SoftWare\OracleDatabase\app\oracle\product\11.2.0\server\bin\oraclr11.dll" <==== ATTENTION
S2 OracleXETNSListener; E:\SoftWare\OracleDatabase\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [X]
S2 Prijik; C:\Program Files (x86)\Habing\Srhcloud.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [227144 2015-10-12] (Broadcom Corporation.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7585280 2016-07-16] (Broadcom Corporation)
R1 cbfs4; C:\Windows\system32\drivers\cbfs4.sys [387776 2013-11-15] (EldoS Corporation)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [191312 2016-06-26] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\drivers\klhk.sys [435032 2017-01-18] (AO Kaspersky Lab)
S3 klids; C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys [182360 2017-01-18] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1019616 2017-01-18] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [57424 2017-01-18] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [218920 2017-01-18] (AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [85984 2017-01-18] ()
R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [245512 2017-01-18] (AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [104720 2017-01-18] (AO Kaspersky Lab)
R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [164888 2017-01-18] (AO Kaspersky Lab)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [134880 2017-01-18] (AO Kaspersky Lab)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [194480 2016-06-14] (AO Kaspersky Lab)
R2 KuaiZipDrive; C:\Windows\system32\drivers\KuaiZipDrive.sys [92832 2017-01-18] (WinMount International Inc)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-10-15] (Malwarebytes)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_03205ffa8fdea79d\nvlddmkm.sys [14200880 2016-12-12] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [759552 2015-08-12] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
S3 SensorsSimulatorDriver; C:\Windows\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-08-29] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S1 cbfs6-0; \??\E:\SoftWare\NetDrive\cbfs6.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-18 14:04 - 2017-01-18 14:04 - 00024107 _____ C:\Users\p4too\Desktop\FRST.txt
2017-01-18 13:57 - 2017-01-18 13:57 - 00049522 _____ C:\Users\p4too\Desktop\FRST1 (2).txt
2017-01-18 13:52 - 2017-01-18 13:57 - 03146014 _____ C:\Users\p4too\Desktop\FRST1 (1).txt
2017-01-18 13:51 - 2017-01-18 14:04 - 00000000 ____D C:\FRST
2017-01-18 13:50 - 2017-01-18 13:50 - 00112640 _____ (forum.viry.cz) C:\Users\p4too\Desktop\FRSTLauncher.exe
2017-01-18 13:49 - 2017-01-18 13:49 - 02419200 _____ (Farbar) C:\Users\p4too\Desktop\FRST64.exe
2017-01-18 12:00 - 2017-01-18 12:00 - 00000000 ____D C:\Users\p4too\AppData\Roaming\NVIDIA
2017-01-18 11:41 - 2017-01-18 12:12 - 00000000 ____D C:\Users\p4too\AppData\Local\AdvinstAnalytics
2017-01-18 11:25 - 2017-01-18 11:25 - 00245512 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00218920 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00164888 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_mark.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00104720 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klbg.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00085984 _____ C:\Windows\system32\Drivers\klupd_klif_kimul.sys
2017-01-18 11:20 - 2017-01-18 11:51 - 00003392 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2017-01-18 11:20 - 2017-01-18 11:36 - 00001447 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
2017-01-18 11:20 - 2017-01-18 11:22 - 00000000 ____D C:\Program Files\Common Files\AV
2017-01-18 11:20 - 2017-01-18 11:20 - 00002208 _____ C:\Users\Public\Desktop\Safe Money.lnk
2017-01-18 11:20 - 2017-01-18 11:20 - 00002184 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2017-01-18 11:20 - 2017-01-18 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2017-01-18 11:20 - 2017-01-18 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2017-01-18 11:20 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2017-01-18 11:19 - 2017-01-18 13:48 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-01-18 11:19 - 2017-01-18 11:25 - 01019616 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys
2017-01-18 11:19 - 2017-01-18 11:24 - 00435032 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys
2017-01-18 11:19 - 2017-01-18 11:20 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2017-01-18 11:19 - 2016-06-26 15:14 - 00191312 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys
2017-01-18 11:13 - 2017-01-18 12:01 - 00000000 ____D C:\Users\p4too\AppData\Local\app
2017-01-18 11:13 - 2017-01-18 11:27 - 00000000 ____D C:\Program Files\Q7F8DGH862
2017-01-18 11:13 - 2017-01-18 11:13 - 00092832 _____ (WinMount International Inc) C:\Windows\system32\Drivers\KuaiZipDrive.sys
2017-01-18 11:13 - 2017-01-18 11:13 - 00003558 _____ C:\Windows\System32\Tasks\KuaiZip_Update
2017-01-18 11:13 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Softlink
2017-01-18 11:13 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Roaming\KuaiZip
2017-01-18 11:13 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Local\tuto_monetize_120170117
2017-01-18 11:12 - 2017-01-18 13:41 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Phejutiontgersp
2017-01-18 11:12 - 2017-01-18 12:25 - 00000000 ____D C:\Program Files (x86)\Jerjatstervele Server
2017-01-18 11:12 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Roaming\UCChannel
2017-01-18 11:12 - 2017-01-18 11:12 - 00006100 _____ C:\Windows\System32\Tasks\Jerjatstervele Server
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Microleaves
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Roaming\gplyra
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Local\Mepock
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\ProgramData\Avira
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\ProgramData\Avg
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\ProgramData\AVAST Software
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 _____ C:\TOSTACK
2017-01-14 15:52 - 2017-01-14 15:52 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-01-02 21:21 - 2017-01-18 11:22 - 00000000 ____D C:\Users\p4too\AppData\Local\Spotify
2017-01-02 21:21 - 2017-01-02 21:21 - 00001836 _____ C:\Users\p4too\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2017-01-02 21:20 - 2017-01-18 10:44 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Spotify
2017-01-01 22:22 - 2017-01-01 22:22 - 00000000 ____D C:\Users\p4too\AppData\Local\VS Revo Group
2017-01-01 22:22 - 2017-01-01 22:22 - 00000000 ____D C:\ProgramData\VS Revo Group
2017-01-01 22:22 - 2017-01-01 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2017-01-01 22:22 - 2016-12-16 08:53 - 00040984 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2016-12-31 21:29 - 2016-12-31 21:29 - 00000000 ____D C:\ProgramData\{08439167-4CA5-48E9-A810-A3A7C0B80B06}
2016-12-31 21:20 - 2016-12-31 21:20 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Quest Software
2016-12-25 16:52 - 2016-12-25 16:52 - 00004002 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003974 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003938 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003912 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003750 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003708 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-12-25 16:52 - 2016-12-12 04:03 - 01854400 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 01452480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-12-25 16:51 - 2016-12-25 16:51 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-12-25 16:51 - 2016-12-12 04:03 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2016-12-25 16:51 - 2016-12-11 19:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-12-25 16:51 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-12-25 16:51 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2016-12-25 16:51 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-12-25 16:51 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2016-12-25 16:50 - 2016-12-25 16:51 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-12-25 16:49 - 2016-12-12 04:03 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 34710584 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 28201408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 10803880 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 10353960 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 09158616 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 08761560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 02950200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 02587704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 01038392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00974784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00942528 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00894400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00802768 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00643928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00394888 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00327408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00101824 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00091584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-12-25 16:49 - 2016-12-12 04:03 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-12-25 16:49 - 2016-12-12 04:03 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2016-12-25 16:31 - 2016-12-25 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2016-12-24 22:05 - 2016-12-24 22:05 - 00000000 ____D C:\Users\p4too\AppData\Local\2K Games
2016-12-24 22:04 - 2016-12-24 22:04 - 00000000 ____D C:\ProgramData\Steam
2016-12-24 21:48 - 2016-12-24 22:06 - 00000000 ____D C:\MAFIA 3 CZ
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-18 13:50 - 2016-09-17 12:44 - 00000000 ____D C:\Users\p4too\AppData\Local\ClassicShell
2017-01-18 13:47 - 2016-09-17 15:38 - 02148802 _____ C:\Windows\system32\perfh01B.dat
2017-01-18 13:47 - 2016-09-17 15:38 - 00645398 _____ C:\Windows\system32\perfc01B.dat
2017-01-18 13:47 - 2016-09-17 12:25 - 05087438 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-18 13:41 - 2016-10-03 16:28 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-18 13:41 - 2016-09-17 12:26 - 00000000 __SHD C:\Users\p4too\IntelGraphicsProfiles
2017-01-18 13:41 - 2016-09-17 12:24 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-18 13:41 - 2016-09-17 12:18 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-18 13:37 - 2016-07-16 07:04 - 00786432 _____ C:\Windows\system32\config\BBI
2017-01-18 13:34 - 2016-09-17 13:38 - 00000000 ____D C:\Users\p4too\AppData\Local\CrashDumps
2017-01-18 13:34 - 2016-07-16 12:44 - 00000000 ____D C:\Windows\INF
2017-01-18 13:32 - 2016-09-17 12:17 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-01-18 12:25 - 2016-09-17 13:37 - 00000000 ____D C:\Users\p4too\AppData\Roaming\uTorrent
2017-01-18 12:04 - 2016-12-12 20:09 - 00000000 ____D C:\Projects
2017-01-18 11:36 - 2016-07-16 07:04 - 00032768 _____ C:\Windows\system32\config\ELAM
2017-01-18 11:24 - 2016-06-20 23:41 - 00057424 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klim6.sys
2017-01-18 11:24 - 2016-06-02 22:39 - 00134880 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys
2017-01-18 11:19 - 2016-07-16 12:45 - 00000000 ___HD C:\Windows\ELAMBKUP
2017-01-18 11:14 - 2016-11-26 21:25 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Skype
2017-01-18 11:12 - 2016-09-18 21:06 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-01-18 11:12 - 2016-09-17 15:57 - 00000000 ____D C:\Program Files (x86)\JetBrains
2017-01-18 06:15 - 2016-09-17 12:31 - 00000000 ____D C:\Users\p4too\AppData\Roaming\AIMP
2017-01-17 19:10 - 2016-09-17 15:49 - 00000000 ____D C:\Users\p4too\Documents\Visual Studio 2015
2017-01-14 15:52 - 2016-07-16 12:45 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-14 15:52 - 2016-07-16 12:45 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-01-14 15:51 - 2016-09-17 13:52 - 00000000 ____D C:\Program Files\Microsoft Office
2017-01-10 18:23 - 2016-09-17 13:17 - 00000000 ____D C:\Windows\Panther
2017-01-10 18:23 - 2016-07-16 12:45 - 00000000 ____D C:\Windows\LiveKernelReports
2017-01-09 20:29 - 2016-09-17 12:22 - 00000000 ____D C:\Users\p4too\AppData\Local\Packages
2017-01-05 00:15 - 2016-10-01 18:32 - 00000600 _____ C:\Users\p4too\AppData\Roaming\winscp.rnd
2017-01-01 22:53 - 2016-09-17 12:21 - 00000000 ____D C:\Users\p4too
2016-12-31 21:48 - 2016-09-17 14:12 - 00000000 ____D C:\Users\p4too\AppData\Local\PokerStars.EU
2016-12-31 21:44 - 2016-10-06 18:24 - 00000000 ____D C:\Users\p4too\Documents\Toad Data Modeler
2016-12-31 21:44 - 2016-10-06 18:24 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Dell
2016-12-31 21:29 - 2016-09-17 15:40 - 00000000 ____D C:\ProgramData\PreEmptive Solutions
2016-12-31 17:34 - 2016-07-16 07:04 - 00000000 ____D C:\Windows\system32\config
2016-12-30 13:00 - 2016-09-17 12:18 - 00524288 ___SH C:\Windows\system32\config\COMPONENTS{f5b135ec-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000002.regtrans-ms
2016-12-30 13:00 - 2016-09-17 12:18 - 00065536 ___SH C:\Windows\system32\config\COMPONENTS{f5b135ec-4b48-11e6-80cb-e41d2d012050}.TM.blf
2016-12-30 13:00 - 2016-07-16 07:04 - 42205184 _____ C:\Windows\system32\config\COMPONENTS
2016-12-27 12:45 - 2016-09-17 13:56 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Nitro
2016-12-26 10:22 - 2016-09-17 12:18 - 00524288 ___SH C:\Windows\system32\config\COMPONENTS{f5b135ec-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000001.regtrans-ms
2016-12-26 10:20 - 2016-09-17 12:46 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-26 10:20 - 2016-07-16 07:04 - 00000000 ____D C:\Windows\WinSxS
2016-12-26 10:19 - 2016-07-16 07:04 - 00000000 ____D C:\Windows\SysWOW64
2016-12-25 17:07 - 2016-09-17 12:49 - 00000000 ____D C:\Users\p4too\AppData\Local\NVIDIA Corporation
2016-12-25 16:52 - 2016-09-17 12:48 - 00000000 ____D C:\Users\p4too\AppData\Local\NVIDIA
2016-12-25 16:52 - 2016-09-17 12:24 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-12-25 16:52 - 2016-09-17 12:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-12-25 16:52 - 2016-09-17 12:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-12-24 13:37 - 2016-11-22 19:36 - 00000000 ____D C:\Users\p4too\AppData\Local\Diagnostics
==================== Files in the root of some directories =======
2017-01-18 11:13 - 2017-01-18 11:13 - 0023622 _____ () C:\Users\p4too\AppData\Roaming\aliexpress.ico
2017-01-18 11:13 - 2017-01-18 11:13 - 0099678 _____ () C:\Users\p4too\AppData\Roaming\booking.ico
2016-10-01 18:32 - 2017-01-05 00:15 - 0000600 _____ () C:\Users\p4too\AppData\Roaming\winscp.rnd
2016-09-20 18:12 - 2016-10-16 15:10 - 0000600 _____ () C:\Users\p4too\AppData\Local\PUTTY.RND
2016-09-17 12:22 - 2016-09-17 12:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-17 18:02
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:222.91 GB) (Free:140.37 GB) NTFS
Available physical RAM: 7232.23 MB
Total physical RAM: 10152.27 MB
Percentage of memory in use: 28%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 00000000)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows\system32\drivers:ucdrv-x64.sys [23652]
AlternateDataStreams: C:\Windows\system32\drivers:x64 [1479458]
AlternateDataStreams: C:\Windows\system32\drivers:x86 [1205026]
==================== Security Center ==================
AV: Kaspersky Total Security (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Total Security (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\p4too\Desktop" je 5 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lync
"c:\program files\microsoft office\root\office16\lync.exe" /fromrunkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneDrive
"c:\program files (x86)\skype\phone\skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsDefender
ECHO is off.
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================
mal som zavireny pc, same reklamy ... uz to vyzerá, byt v pohode no myslim si, ze tam este nieco ostalo.
PC sa zapina strasne dlho, oproti obdobiu pred virusom ...
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2017
Ran by p4too (administrator) on DESKTOP-FSNBGS5 (18-01-2017 14:04:17)
Running from C:\Users\p4too\Desktop
Loaded Profiles: p4too (Available Profiles: defaultuser0 & p4too)
Platform: Windows 10 Pro N Version 1607 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(JetBrains s.r.o) C:\Program Files (x86)\JetBrains\ETW Host\JetBrains.ETW.Collector.Host.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(ExpanDrive, Inc.) C:\Program Files (x86)\ExpanDrive\ExpanDrive.exe
() C:\Program Files (x86)\ExpanDrive\expandrive\expandrivedw.exe
(Spotify Ltd) C:\Users\p4too\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Users\p4too\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\p4too\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3947704 2015-08-29] (Synaptics Incorporated)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [gplyra] => C:\Users\p4too\AppData\Roaming\gplyra\gplyra\start.cmd [216 2016-01-19] ()
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] wscript C:\Windows\run.vbs,
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\Run: [Google Update] => C:\Users\p4too\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\Run: [ExpanDrive] => C:\Program Files (x86)\ExpanDrive\ExpanDrive.exe [1471072 2015-02-04] (ExpanDrive, Inc.)
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\Run: [Spotify Web Helper] => C:\Users\p4too\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2017-01-02] (Spotify Ltd)
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\...\MountPoints2: {3c2cd3d1-7cec-11e6-a050-f0761c6c6ff4} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-18\...\Run: [] => 0
HKLM\...\Providers\vlitza5s: C:\Program Files (x86)\Jerjatstervele Server\local64spl.dll [292352 2017-01-18] ()
SSODL: EldosMountNotificator-cbfs4 - {E4B9D98A-19E4-4A2F-B080-BBF8AF8BCF51} - C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs4 - {E4B9D98A-19E4-4A2F-B080-BBF8AF8BCF51} - C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellExecuteHooks: No Name - {2B291F10-DB96-11E6-B994-64006A5CFC23} - -> No File
ShellIconOverlayIdentifiers: [00ExpanDriveExt1] -> {C955792B-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers: [00ExpanDriveExt2] -> {C955792C-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs4] -> {9CF93BCF-F6A8-4625-A75C-2F8F67BA0D39} => C:\Windows\system32\cbfsMntNtf4.dll [2013-11-15] (EldoS Corporation)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File
ShellIconOverlayIdentifiers-x32: [00ExpanDriveExt1] -> {C955792B-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers-x32: [00ExpanDriveExt2] -> {C955792C-31A0-4791-9DDE-0A9A57411C16} => C:\Program Files (x86)\ExpanDrive\ExpanDriveOverlays.x64.dll [2015-02-04] ()
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs4] -> {9CF93BCF-F6A8-4625-A75C-2F8F67BA0D39} => C:\Windows\SysWOW64\cbfsMntNtf4.dll [2013-11-15] (EldoS Corporation)
Startup: C:\Users\p4too\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\thunderbird.exe – odkaz.lnk [2016-09-20]
ShortcutTarget: thunderbird.exe – odkaz.lnk -> E:\SoftWare\Thunderbird\thunderbird.exe (No File)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 8.8.4.4 8.8.8.8
Tcpip\..\Interfaces\{450fc5d8-0ece-4669-ae3b-2a1cd2e0fa44}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{88ebffb6-5b12-4da6-9153-1d057df9a8f9}: [DhcpNameServer] 8.8.4.4 8.8.8.8
Internet Explorer:
==================
HKU\S-1-5-21-3402369080-3581635727-2017991681-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-01-18] (AO Kaspersky Lab)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
FireFox:
========
FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-01-18]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-11] (NVIDIA Corporation)
FF Plugin HKU\S-1-5-21-3402369080-3581635727-2017991681-1001: @tools.google.com/Google Update;version=3 -> C:\Users\p4too\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3402369080-3581635727-2017991681-1001: @tools.google.com/Google Update;version=9 -> C:\Users\p4too\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://google.com/
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.youndoo.com/?z=9227f5a8015421805b78 ... 5A&type=hp"
CHR Profile: C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-01-18] <==== ATTENTION
CHR Extension: (Prekladač Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2016-09-17]
CHR Extension: (Prezentácie Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-17]
CHR Extension: (Dokumenty Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-17]
CHR Extension: (Disk Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-17]
CHR Extension: (YouTube) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-17]
CHR Extension: (Adblock Plus) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-26]
CHR Extension: (AdBlocker - Blokovač reklám pre YouTube™) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-12-23]
CHR Extension: (Tabuľky Google) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-17]
CHR Extension: (Kaspersky Protection) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-01-18]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-17]
CHR Extension: (AdBlock) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-17]
CHR Extension: (Gmail) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-17]
CHR Extension: (Chrome Media Router) - C:\Users\p4too\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-16]
CHR Profile: C:\Users\p4too\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-01-18]
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2297104 2015-10-12] (Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [359848 2015-09-09] (Intel Corporation)
R2 jetbrainsetw.106.0.20160913.92350; C:\Program Files (x86)\JetBrains\ETW Host\JetBrains.ETW.Collector.Host.exe [1474624 2016-09-13] (JetBrains s.r.o)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S2 KuaizipUpdateChecker; C:\Program Files\żěŃą\X86\kuaizipUpdateChecker.dll [X]
S4 OracleJobSchedulerXE; e:\software\oracledatabase\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [X]
S3 OracleMTSRecoveryService; E:\oracle\app\pato\product\11.1.0\client_1\bin\omtsreco.exe "OracleMTSRecoveryService" [X]
S2 OracleServiceXE; e:\software\oracledatabase\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [X]
S3 OracleXEClrAgent; E:\SoftWare\OracleDatabase\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe agent_sid=CLRExtProc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25 ENVS="EXTPROC_DLLS=ONLY:E:\SoftWare\OracleDatabase\app\oracle\product\11.2.0\server\bin\oraclr11.dll" <==== ATTENTION
S2 OracleXETNSListener; E:\SoftWare\OracleDatabase\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [X]
S2 Prijik; C:\Program Files (x86)\Habing\Srhcloud.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [227144 2015-10-12] (Broadcom Corporation.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7585280 2016-07-16] (Broadcom Corporation)
R1 cbfs4; C:\Windows\system32\drivers\cbfs4.sys [387776 2013-11-15] (EldoS Corporation)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [191312 2016-06-26] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\drivers\klhk.sys [435032 2017-01-18] (AO Kaspersky Lab)
S3 klids; C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys [182360 2017-01-18] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1019616 2017-01-18] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [57424 2017-01-18] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [218920 2017-01-18] (AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [85984 2017-01-18] ()
R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [245512 2017-01-18] (AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [104720 2017-01-18] (AO Kaspersky Lab)
R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [164888 2017-01-18] (AO Kaspersky Lab)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [134880 2017-01-18] (AO Kaspersky Lab)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [194480 2016-06-14] (AO Kaspersky Lab)
R2 KuaiZipDrive; C:\Windows\system32\drivers\KuaiZipDrive.sys [92832 2017-01-18] (WinMount International Inc)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-10-15] (Malwarebytes)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_03205ffa8fdea79d\nvlddmkm.sys [14200880 2016-12-12] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [759552 2015-08-12] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
S3 SensorsSimulatorDriver; C:\Windows\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-08-29] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S1 cbfs6-0; \??\E:\SoftWare\NetDrive\cbfs6.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-18 14:04 - 2017-01-18 14:04 - 00024107 _____ C:\Users\p4too\Desktop\FRST.txt
2017-01-18 13:57 - 2017-01-18 13:57 - 00049522 _____ C:\Users\p4too\Desktop\FRST1 (2).txt
2017-01-18 13:52 - 2017-01-18 13:57 - 03146014 _____ C:\Users\p4too\Desktop\FRST1 (1).txt
2017-01-18 13:51 - 2017-01-18 14:04 - 00000000 ____D C:\FRST
2017-01-18 13:50 - 2017-01-18 13:50 - 00112640 _____ (forum.viry.cz) C:\Users\p4too\Desktop\FRSTLauncher.exe
2017-01-18 13:49 - 2017-01-18 13:49 - 02419200 _____ (Farbar) C:\Users\p4too\Desktop\FRST64.exe
2017-01-18 12:00 - 2017-01-18 12:00 - 00000000 ____D C:\Users\p4too\AppData\Roaming\NVIDIA
2017-01-18 11:41 - 2017-01-18 12:12 - 00000000 ____D C:\Users\p4too\AppData\Local\AdvinstAnalytics
2017-01-18 11:25 - 2017-01-18 11:25 - 00245512 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00218920 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00164888 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_mark.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00104720 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klbg.sys
2017-01-18 11:25 - 2017-01-18 11:25 - 00085984 _____ C:\Windows\system32\Drivers\klupd_klif_kimul.sys
2017-01-18 11:20 - 2017-01-18 11:51 - 00003392 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2017-01-18 11:20 - 2017-01-18 11:36 - 00001447 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
2017-01-18 11:20 - 2017-01-18 11:22 - 00000000 ____D C:\Program Files\Common Files\AV
2017-01-18 11:20 - 2017-01-18 11:20 - 00002208 _____ C:\Users\Public\Desktop\Safe Money.lnk
2017-01-18 11:20 - 2017-01-18 11:20 - 00002184 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2017-01-18 11:20 - 2017-01-18 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2017-01-18 11:20 - 2017-01-18 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2017-01-18 11:20 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2017-01-18 11:19 - 2017-01-18 13:48 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-01-18 11:19 - 2017-01-18 11:25 - 01019616 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys
2017-01-18 11:19 - 2017-01-18 11:24 - 00435032 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys
2017-01-18 11:19 - 2017-01-18 11:20 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2017-01-18 11:19 - 2016-06-26 15:14 - 00191312 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys
2017-01-18 11:13 - 2017-01-18 12:01 - 00000000 ____D C:\Users\p4too\AppData\Local\app
2017-01-18 11:13 - 2017-01-18 11:27 - 00000000 ____D C:\Program Files\Q7F8DGH862
2017-01-18 11:13 - 2017-01-18 11:13 - 00092832 _____ (WinMount International Inc) C:\Windows\system32\Drivers\KuaiZipDrive.sys
2017-01-18 11:13 - 2017-01-18 11:13 - 00003558 _____ C:\Windows\System32\Tasks\KuaiZip_Update
2017-01-18 11:13 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Softlink
2017-01-18 11:13 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Roaming\KuaiZip
2017-01-18 11:13 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Local\tuto_monetize_120170117
2017-01-18 11:12 - 2017-01-18 13:41 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Phejutiontgersp
2017-01-18 11:12 - 2017-01-18 12:25 - 00000000 ____D C:\Program Files (x86)\Jerjatstervele Server
2017-01-18 11:12 - 2017-01-18 11:13 - 00000000 ____D C:\Users\p4too\AppData\Roaming\UCChannel
2017-01-18 11:12 - 2017-01-18 11:12 - 00006100 _____ C:\Windows\System32\Tasks\Jerjatstervele Server
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Microleaves
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Roaming\gplyra
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Local\Mepock
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\p4too\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\ProgramData\Avira
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\ProgramData\Avg
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 ____D C:\ProgramData\AVAST Software
2017-01-18 11:12 - 2017-01-18 11:12 - 00000000 _____ C:\TOSTACK
2017-01-14 15:52 - 2017-01-14 15:52 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-01-02 21:21 - 2017-01-18 11:22 - 00000000 ____D C:\Users\p4too\AppData\Local\Spotify
2017-01-02 21:21 - 2017-01-02 21:21 - 00001836 _____ C:\Users\p4too\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2017-01-02 21:20 - 2017-01-18 10:44 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Spotify
2017-01-01 22:22 - 2017-01-01 22:22 - 00000000 ____D C:\Users\p4too\AppData\Local\VS Revo Group
2017-01-01 22:22 - 2017-01-01 22:22 - 00000000 ____D C:\ProgramData\VS Revo Group
2017-01-01 22:22 - 2017-01-01 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2017-01-01 22:22 - 2016-12-16 08:53 - 00040984 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2016-12-31 21:29 - 2016-12-31 21:29 - 00000000 ____D C:\ProgramData\{08439167-4CA5-48E9-A810-A3A7C0B80B06}
2016-12-31 21:20 - 2016-12-31 21:20 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Quest Software
2016-12-25 16:52 - 2016-12-25 16:52 - 00004002 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003974 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003938 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003912 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003750 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00003708 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2016-12-25 16:52 - 2016-12-25 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-12-25 16:52 - 2016-12-12 04:03 - 01854400 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 01452480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-12-25 16:52 - 2016-12-12 04:03 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-12-25 16:51 - 2016-12-25 16:51 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-12-25 16:51 - 2016-12-12 04:03 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2016-12-25 16:51 - 2016-12-11 19:23 - 00134712 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-12-25 16:51 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-12-25 16:51 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2016-12-25 16:51 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-12-25 16:51 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2016-12-25 16:50 - 2016-12-25 16:51 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-12-25 16:49 - 2016-12-12 04:03 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 34710584 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 28201408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 10803880 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 10353960 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 09158616 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 08761560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 02950200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 02587704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 01038392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00974784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00942528 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00894400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00802768 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00643928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00394888 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00327408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00101824 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00091584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-12-25 16:49 - 2016-12-12 04:03 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-12-25 16:49 - 2016-12-12 04:03 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-12-25 16:49 - 2016-12-12 04:03 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2016-12-25 16:31 - 2016-12-25 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2016-12-24 22:05 - 2016-12-24 22:05 - 00000000 ____D C:\Users\p4too\AppData\Local\2K Games
2016-12-24 22:04 - 2016-12-24 22:04 - 00000000 ____D C:\ProgramData\Steam
2016-12-24 21:48 - 2016-12-24 22:06 - 00000000 ____D C:\MAFIA 3 CZ
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-18 13:50 - 2016-09-17 12:44 - 00000000 ____D C:\Users\p4too\AppData\Local\ClassicShell
2017-01-18 13:47 - 2016-09-17 15:38 - 02148802 _____ C:\Windows\system32\perfh01B.dat
2017-01-18 13:47 - 2016-09-17 15:38 - 00645398 _____ C:\Windows\system32\perfc01B.dat
2017-01-18 13:47 - 2016-09-17 12:25 - 05087438 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-18 13:41 - 2016-10-03 16:28 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-18 13:41 - 2016-09-17 12:26 - 00000000 __SHD C:\Users\p4too\IntelGraphicsProfiles
2017-01-18 13:41 - 2016-09-17 12:24 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-18 13:41 - 2016-09-17 12:18 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-18 13:37 - 2016-07-16 07:04 - 00786432 _____ C:\Windows\system32\config\BBI
2017-01-18 13:34 - 2016-09-17 13:38 - 00000000 ____D C:\Users\p4too\AppData\Local\CrashDumps
2017-01-18 13:34 - 2016-07-16 12:44 - 00000000 ____D C:\Windows\INF
2017-01-18 13:32 - 2016-09-17 12:17 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-01-18 12:25 - 2016-09-17 13:37 - 00000000 ____D C:\Users\p4too\AppData\Roaming\uTorrent
2017-01-18 12:04 - 2016-12-12 20:09 - 00000000 ____D C:\Projects
2017-01-18 11:36 - 2016-07-16 07:04 - 00032768 _____ C:\Windows\system32\config\ELAM
2017-01-18 11:24 - 2016-06-20 23:41 - 00057424 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klim6.sys
2017-01-18 11:24 - 2016-06-02 22:39 - 00134880 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys
2017-01-18 11:19 - 2016-07-16 12:45 - 00000000 ___HD C:\Windows\ELAMBKUP
2017-01-18 11:14 - 2016-11-26 21:25 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Skype
2017-01-18 11:12 - 2016-09-18 21:06 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-01-18 11:12 - 2016-09-17 15:57 - 00000000 ____D C:\Program Files (x86)\JetBrains
2017-01-18 06:15 - 2016-09-17 12:31 - 00000000 ____D C:\Users\p4too\AppData\Roaming\AIMP
2017-01-17 19:10 - 2016-09-17 15:49 - 00000000 ____D C:\Users\p4too\Documents\Visual Studio 2015
2017-01-14 15:52 - 2016-07-16 12:45 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-14 15:52 - 2016-07-16 12:45 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-01-14 15:51 - 2016-09-17 13:52 - 00000000 ____D C:\Program Files\Microsoft Office
2017-01-10 18:23 - 2016-09-17 13:17 - 00000000 ____D C:\Windows\Panther
2017-01-10 18:23 - 2016-07-16 12:45 - 00000000 ____D C:\Windows\LiveKernelReports
2017-01-09 20:29 - 2016-09-17 12:22 - 00000000 ____D C:\Users\p4too\AppData\Local\Packages
2017-01-05 00:15 - 2016-10-01 18:32 - 00000600 _____ C:\Users\p4too\AppData\Roaming\winscp.rnd
2017-01-01 22:53 - 2016-09-17 12:21 - 00000000 ____D C:\Users\p4too
2016-12-31 21:48 - 2016-09-17 14:12 - 00000000 ____D C:\Users\p4too\AppData\Local\PokerStars.EU
2016-12-31 21:44 - 2016-10-06 18:24 - 00000000 ____D C:\Users\p4too\Documents\Toad Data Modeler
2016-12-31 21:44 - 2016-10-06 18:24 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Dell
2016-12-31 21:29 - 2016-09-17 15:40 - 00000000 ____D C:\ProgramData\PreEmptive Solutions
2016-12-31 17:34 - 2016-07-16 07:04 - 00000000 ____D C:\Windows\system32\config
2016-12-30 13:00 - 2016-09-17 12:18 - 00524288 ___SH C:\Windows\system32\config\COMPONENTS{f5b135ec-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000002.regtrans-ms
2016-12-30 13:00 - 2016-09-17 12:18 - 00065536 ___SH C:\Windows\system32\config\COMPONENTS{f5b135ec-4b48-11e6-80cb-e41d2d012050}.TM.blf
2016-12-30 13:00 - 2016-07-16 07:04 - 42205184 _____ C:\Windows\system32\config\COMPONENTS
2016-12-27 12:45 - 2016-09-17 13:56 - 00000000 ____D C:\Users\p4too\AppData\Roaming\Nitro
2016-12-26 10:22 - 2016-09-17 12:18 - 00524288 ___SH C:\Windows\system32\config\COMPONENTS{f5b135ec-4b48-11e6-80cb-e41d2d012050}.TMContainer00000000000000000001.regtrans-ms
2016-12-26 10:20 - 2016-09-17 12:46 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-26 10:20 - 2016-07-16 07:04 - 00000000 ____D C:\Windows\WinSxS
2016-12-26 10:19 - 2016-07-16 07:04 - 00000000 ____D C:\Windows\SysWOW64
2016-12-25 17:07 - 2016-09-17 12:49 - 00000000 ____D C:\Users\p4too\AppData\Local\NVIDIA Corporation
2016-12-25 16:52 - 2016-09-17 12:48 - 00000000 ____D C:\Users\p4too\AppData\Local\NVIDIA
2016-12-25 16:52 - 2016-09-17 12:24 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-12-25 16:52 - 2016-09-17 12:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-12-25 16:52 - 2016-09-17 12:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-12-24 13:37 - 2016-11-22 19:36 - 00000000 ____D C:\Users\p4too\AppData\Local\Diagnostics
==================== Files in the root of some directories =======
2017-01-18 11:13 - 2017-01-18 11:13 - 0023622 _____ () C:\Users\p4too\AppData\Roaming\aliexpress.ico
2017-01-18 11:13 - 2017-01-18 11:13 - 0099678 _____ () C:\Users\p4too\AppData\Roaming\booking.ico
2016-10-01 18:32 - 2017-01-05 00:15 - 0000600 _____ () C:\Users\p4too\AppData\Roaming\winscp.rnd
2016-09-20 18:12 - 2016-10-16 15:10 - 0000600 _____ () C:\Users\p4too\AppData\Local\PUTTY.RND
2016-09-17 12:22 - 2016-09-17 12:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-17 18:02
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:222.91 GB) (Free:140.37 GB) NTFS
Available physical RAM: 7232.23 MB
Total physical RAM: 10152.27 MB
Percentage of memory in use: 28%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 00000000)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows\system32\drivers:ucdrv-x64.sys [23652]
AlternateDataStreams: C:\Windows\system32\drivers:x64 [1479458]
AlternateDataStreams: C:\Windows\system32\drivers:x86 [1205026]
==================== Security Center ==================
AV: Kaspersky Total Security (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Total Security (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\p4too\Desktop" je 5 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lync
"c:\program files\microsoft office\root\office16\lync.exe" /fromrunkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneDrive
"c:\program files (x86)\skype\phone\skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
ECHO is off.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsDefender
ECHO is off.
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================