Prosím o Kontrolu
Napsal: 30 led 2017 12:16
Dobrý den,prosím o kontrolu 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by Dominik (administrator) on DOMINIK-PC (30-01-2017 12:07:51)
Running from C:\Users\Dominik\Documents
Loaded Profiles: Dominik (Available Profiles: Dominik)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [406664 2016-05-25] (Power Software Ltd)
HKU\S-1-5-21-707951698-1732677806-592134114-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-20] (Piriform Ltd)
HKU\S-1-5-21-707951698-1732677806-592134114-1000\...\MountPoints2: I - I:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0AA83DC0-B66F-43FD-9DAD-56EA86565672}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-707951698-1732677806-592134114-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-707951698-1732677806-592134114-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-12] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-12] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: k63582xc.default
FF ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\k63582xc.default [2017-01-30]
FF NewTab: Mozilla\Firefox\Profiles\k63582xc.default -> about:newtab
FF Homepage: Mozilla\Firefox\Profiles\k63582xc.default -> about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-12] ()
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-12] ()
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-12] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-12] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default [2017-01-30]
CHR Extension: (Prezentace Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-16]
CHR Extension: (Dokumenty Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-16]
CHR Extension: (Disk Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-16]
CHR Extension: (YouTube) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-16]
CHR Extension: (Tabulky Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-16]
CHR Extension: (AdBlock) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-01-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19]
CHR Extension: (Gmail) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-16]
CHR Extension: (Chrome Media Router) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-15]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [389392 2016-11-13] (EasyAntiCheat Ltd)
R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [79552 2016-03-02] (Bitdefender)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [458296 2016-10-25] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [458296 2016-10-25] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-10-25] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1165368 2016-10-25] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2017-01-04] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2017-01-04] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-04-02] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-10-14] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [718840 2016-08-12] (BitDefender)
U5 avchv; C:\Windows\System32\Drivers\avchv.sys [261056 2012-11-02] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [593144 2013-04-17] (BitDefender)
R1 bdfwfpf; C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [121928 2013-07-02] (Bitdefender SRL)
R1 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [148696 2013-04-22] (BitDefender LLC)
S3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus64.sys [261120 2005-09-23] (Pinnacle Systems GmbH) [File not signed]
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2016-10-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47672 2016-10-25] (NVIDIA Corporation)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [382536 2013-05-28] (BitDefender S.R.L.)
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-26 19:52 - 2017-01-26 21:35 - 1822603277 _____ C:\Users\Dominik\Downloads\Vikings.S04E19.1080p.WEB-DL.DD5.1.H264-RARBG.mkv
2017-01-26 19:48 - 2017-01-26 19:48 - 00023930 _____ C:\Users\Dominik\Downloads\Vikings.S04E19.1080p.WEB-DL.DD5.1.H264-RARBG.srt
2017-01-24 00:24 - 2017-01-24 00:24 - 00000222 _____ C:\Users\Dominik\Desktop\Resident Evil 7 Biohazard 7 Teaser Beginning Hour.url
2017-01-22 20:02 - 2017-01-22 20:02 - 01673544 _____ ( ) C:\Users\Dominik\Downloads\cpu-z_1.78-en.exe
2017-01-22 20:02 - 2017-01-22 20:02 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2017-01-22 20:02 - 2017-01-22 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-01-22 20:02 - 2017-01-22 20:02 - 00000000 ____D C:\Program Files\CPUID
2017-01-20 01:09 - 2017-01-26 00:06 - 00000238 _____ C:\Users\Dominik\Desktop\Nový textový dokument.txt
2017-01-19 21:34 - 2017-01-19 21:34 - 00022537 _____ C:\Users\Dominik\Downloads\Vikings.S04E18.1080p.WEB-DL.DD5.1.H264-RARBG.srt
2017-01-19 19:50 - 2017-01-19 21:33 - 1847391237 _____ C:\Users\Dominik\Downloads\Vikings.S04E18.1080p.WEB-DL.DD5.1.H264-RARBG.mkv
2017-01-15 01:03 - 2017-01-15 23:11 - 00000000 ____D C:\V-H-S (2012)
2017-01-15 00:56 - 2017-01-15 00:56 - 00014496 _____ C:\Users\Dominik\Downloads\[CzT]V_H_S_2012_.torrent
2017-01-13 23:29 - 2017-01-13 23:53 - 00000000 ____D C:\Blair Witch
2017-01-13 23:28 - 2017-01-13 23:28 - 00022995 _____ C:\Users\Dominik\Downloads\[CzT]Blair_Witch_2016_720pHD_.torrent
2017-01-12 16:33 - 2017-01-12 17:26 - 930514937 _____ C:\Users\Dominik\Downloads\Vikings.S04E17.720p.HDTV.x264-FLEET.mkv
2017-01-12 16:32 - 2017-01-12 16:32 - 00029063 _____ C:\Users\Dominik\Downloads\Vikings.S04E17.720p.HDTV.x264-FLEET (+SVA).srt
2017-01-09 21:01 - 2017-01-09 21:03 - 00000000 ____D C:\stalkerhh
2017-01-09 20:59 - 2017-01-09 21:03 - 00000000 ____D C:\stalůker
2017-01-09 19:18 - 2017-01-09 19:19 - 08733953 _____ C:\Users\Dominik\Downloads\Stalker-Shadow-of-Chernobyl-Patch-a-Crack-1.0006.zip
2017-01-09 18:08 - 2017-01-09 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autumnal Wanderers
2017-01-09 14:51 - 2017-01-09 14:53 - 74472808 _____ (THQ ) C:\Users\Dominik\Downloads\stk-cz-10005.exe
2017-01-09 14:46 - 2017-01-09 14:47 - 58935312 _____ C:\Users\Dominik\Downloads\stalker_shadow_of_chernobyl_cz_patch_10000_10004.zip
2017-01-09 14:45 - 2017-01-09 14:45 - 12163888 _____ (THQ ) C:\Users\Dominik\Downloads\stk-ww-0-3.exe
2017-01-09 14:45 - 2017-01-09 14:45 - 08275798 _____ C:\Users\Dominik\Downloads\stalker_shadow_of_chernobyl_cz_patch_10001.zip
2017-01-09 14:45 - 2017-01-09 14:45 - 00002315 _____ C:\Users\Public\Desktop\S.T.A.L.K.E.R. - Shadow of Chernobyl.lnk
2017-01-09 14:45 - 2017-01-09 14:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
2017-01-09 14:39 - 2017-01-09 20:19 - 00000000 ____D C:\Users\Public\Documents\STALKER-SHOC
2017-01-09 14:39 - 2017-01-09 14:39 - 00000000 ____D C:\Program Files (x86)\THQ
2017-01-09 14:34 - 2017-01-09 14:35 - 82456210 _____ C:\Users\Dominik\Downloads\S.T.A.L.K.E.R_SoC_All_Patches_1.0001-_1.0006.rar
2017-01-09 14:33 - 2017-01-09 14:33 - 08057608 _____ (THQ ) C:\Users\Dominik\Downloads\official_patch_soc-win-10005_10006.exe
2017-01-09 12:18 - 2017-01-09 12:19 - 17959538 _____ C:\Users\Dominik\Downloads\lidsky_vztah_jako_soucast_profese.pdf
2017-01-08 23:08 - 2017-01-08 23:08 - 03988944 _____ C:\Users\Dominik\Downloads\adwcleaner_6.042.exe
2017-01-08 22:28 - 2017-01-08 22:28 - 04060064 _____ (GSC Game World ) C:\Users\Dominik\Downloads\stk-multi-patch.exe
2017-01-08 22:18 - 2017-01-08 22:22 - 00000000 ____D C:\Autumn Aurora 2.1 by Autumnal Wanderers (30.09.2015)
2017-01-08 16:01 - 2017-01-08 16:18 - 00000000 ____D C:\Program Files (x86)\PowerISO
2017-01-08 16:01 - 2017-01-08 16:01 - 02977032 _____ (Power Software Ltd) C:\Users\Dominik\Downloads\PowerISO6.exe
2017-01-08 16:01 - 2017-01-08 16:01 - 00001007 _____ C:\Users\Public\Desktop\PowerISO.lnk
2017-01-08 16:01 - 2017-01-08 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
2017-01-08 16:01 - 2016-05-25 00:06 - 00137280 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2017-01-07 21:42 - 2017-01-09 14:57 - 00000000 ____D C:\Users\Dominik\Downloads\StalkerSoCH[CZ]
2017-01-07 21:36 - 2017-01-07 21:36 - 00016160 _____ C:\Users\Dominik\Downloads\[CzT]STALKER_Shadow_of_Chernobyl_CZ_.torrent
2017-01-07 20:45 - 2017-01-08 22:13 - 1669478745 _____ C:\Users\Dominik\Downloads\Autumn_Aurora_2.1_by_Autumnal_Wanderers_30.09.2015.7z
2017-01-05 16:54 - 2017-01-05 17:47 - 948771680 _____ C:\Users\Dominik\Downloads\Vikings.S04E16.PROPER.720p.HDTV.x264-FLEET.mkv
2017-01-05 16:51 - 2017-01-05 16:51 - 00020150 _____ C:\Users\Dominik\Downloads\Vikings.S04E16.PROPER.720p.HDTV.x264-FLEET.srt
2017-01-05 16:51 - 2017-01-05 16:51 - 00020150 _____ C:\Users\Dominik\Downloads\Vikings.S04E16.PROPER.720p.HDTV.x264-FLEET (1).srt
2017-01-04 18:05 - 2017-01-04 18:05 - 00007975 _____ C:\Users\Dominik\Downloads\Potvrzení-o-absolvované-exkurzi (2).odt
2017-01-04 17:54 - 2017-01-04 17:54 - 00007975 _____ C:\Users\Dominik\Downloads\Potvrzení-o-absolvované-exkurzi (1).odt
2017-01-04 14:16 - 2017-01-04 14:38 - 00000000 ____D C:\Users\Dominik\Documents\Survarium-Steam
2017-01-03 18:00 - 2017-01-03 18:17 - 587467523 _____ C:\Users\Dominik\Downloads\Darkest Hour Ultimate Age of Empires.rar
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-30 12:08 - 2016-09-29 11:45 - 00013115 _____ C:\Users\Dominik\Documents\FRST.txt
2017-01-30 12:07 - 2016-11-07 08:39 - 00000000 ____D C:\Users\Dominik\Documents\FRST-OlderVersion
2017-01-30 12:07 - 2016-07-11 10:16 - 02420736 _____ (Farbar) C:\Users\Dominik\Documents\FRST64.exe
2017-01-30 12:07 - 2015-10-26 17:34 - 00000000 ____D C:\FRST
2017-01-30 11:10 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-30 11:10 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-30 11:05 - 2015-10-29 18:45 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-30 10:30 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-30 01:23 - 2016-11-19 13:32 - 00000000 ____D C:\Users\Dominik\AppData\LocalLow\Mozilla
2017-01-29 10:01 - 2016-11-18 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-29 10:01 - 2015-09-27 21:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-27 10:17 - 2016-08-04 19:40 - 00000000 ____D C:\Users\Dominik\AppData\Local\CrashDumps
2017-01-26 23:00 - 2015-09-19 19:01 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\vlc
2017-01-25 23:11 - 2015-09-21 16:27 - 00000000 ____D C:\AdwCleaner
2017-01-25 22:15 - 2016-04-25 14:43 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-24 19:54 - 2015-09-27 19:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2017-01-24 19:54 - 2015-09-18 17:24 - 00000000 ____D C:\Program Files (x86)\Steam
2017-01-24 07:21 - 2009-07-14 06:08 - 00032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-01-24 00:16 - 2015-09-18 17:25 - 00000000 ____D C:\Users\Dominik\AppData\Local\Steam
2017-01-22 12:09 - 2016-08-31 13:08 - 00000000 ____D C:\Users\Dominik\AppData\Local\ElevatedDiagnostics
2017-01-19 17:43 - 2015-09-27 12:49 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-19 01:05 - 2016-03-28 18:08 - 00000000 ____D C:\Users\Dominik\Documents\TopStyle 5
2017-01-16 01:08 - 2016-10-16 15:02 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\uTorrent
2017-01-12 21:43 - 2015-11-13 14:41 - 00000000 ____D C:\Fraps
2017-01-12 14:37 - 2015-11-19 21:53 - 00000000 ____D C:\Darkest Hour
2017-01-10 13:43 - 2015-09-27 12:50 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-06 01:04 - 2015-09-25 14:39 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Origin
2017-01-05 16:24 - 2015-09-25 14:37 - 00000000 ____D C:\ProgramData\Origin
2017-01-04 15:50 - 2016-10-14 16:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2017-01-04 15:50 - 2015-09-25 16:42 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2017-01-04 15:12 - 2015-09-25 14:37 - 00000000 ____D C:\Program Files (x86)\Origin
2017-01-04 00:51 - 2015-09-15 21:08 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Skype
==================== Files in the root of some directories =======
2016-09-04 21:01 - 2016-09-04 21:07 - 0000000 _____ () C:\Program Files (x86)\ToDownloadBase.db
2016-08-25 20:52 - 2016-09-21 17:29 - 0029696 _____ () C:\Users\Dominik\AppData\Local\MSGBOX.EXE
2016-02-23 17:32 - 2016-02-23 17:32 - 0000913 _____ () C:\Users\Dominik\AppData\Local\recently-used.xbel
2015-10-21 19:28 - 2016-09-28 09:12 - 0007602 _____ () C:\Users\Dominik\AppData\Local\Resmon.ResmonCfg
2016-10-14 16:37 - 2016-10-14 16:37 - 0000000 ___SH () C:\ProgramData\.rdata
2016-08-11 18:14 - 2016-08-11 18:15 - 0101114 _____ () C:\ProgramData\1470935671.bdinstall.bin
2016-08-11 18:18 - 2016-08-11 18:18 - 0198197 _____ () C:\ProgramData\1470935869.bdinstall.bin
Some files in TEMP:
====================
2017-01-09 18:11 - 2017-01-09 18:11 - 0065536 _____ (Sony DADC Austria AG) C:\Users\Dominik\AppData\Local\Temp\drm_dialogs.dll
2016-04-15 17:29 - 2016-08-25 21:50 - 0746088 _____ (NVIDIA Corporation) C:\Users\Dominik\AppData\Local\Temp\nvSCPAPI.dll
2016-04-15 17:29 - 2016-08-25 21:50 - 0860776 _____ (NVIDIA Corporation) C:\Users\Dominik\AppData\Local\Temp\nvSCPAPI64.dll
2016-08-30 11:59 - 2016-08-25 21:49 - 0345024 _____ (NVIDIA Corporation) C:\Users\Dominik\AppData\Local\Temp\nvStInst.exe
2016-08-04 20:23 - 2017-01-24 19:54 - 0192512 _____ () C:\Users\Dominik\AppData\Local\Temp\sfamcc00001.dll
2016-08-06 16:04 - 2016-12-06 21:34 - 0192512 _____ () C:\Users\Dominik\AppData\Local\Temp\sfamcc00002.dll
2016-09-26 20:26 - 2017-01-03 22:16 - 43872728 _____ (Skype Technologies S.A.) C:\Users\Dominik\AppData\Local\Temp\SkypeSetup.exe
2016-08-15 17:31 - 2016-08-15 17:31 - 0945691 _____ () C:\Users\Dominik\AppData\Local\Temp\ubi90F8.tmp.exe
2016-09-25 17:48 - 2016-09-25 17:48 - 22895331 _____ (Ubisoft) C:\Users\Dominik\AppData\Local\Temp\ubi9CA5.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-23 09:57
==================== End of FRST.txt ============================

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by Dominik (administrator) on DOMINIK-PC (30-01-2017 12:07:51)
Running from C:\Users\Dominik\Documents
Loaded Profiles: Dominik (Available Profiles: Dominik)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [406664 2016-05-25] (Power Software Ltd)
HKU\S-1-5-21-707951698-1732677806-592134114-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-20] (Piriform Ltd)
HKU\S-1-5-21-707951698-1732677806-592134114-1000\...\MountPoints2: I - I:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0AA83DC0-B66F-43FD-9DAD-56EA86565672}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-707951698-1732677806-592134114-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-707951698-1732677806-592134114-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-12] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-12] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: k63582xc.default
FF ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\k63582xc.default [2017-01-30]
FF NewTab: Mozilla\Firefox\Profiles\k63582xc.default -> about:newtab
FF Homepage: Mozilla\Firefox\Profiles\k63582xc.default -> about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-12] ()
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-12] ()
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-12] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-12] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default [2017-01-30]
CHR Extension: (Prezentace Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-16]
CHR Extension: (Dokumenty Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-16]
CHR Extension: (Disk Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-16]
CHR Extension: (YouTube) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-16]
CHR Extension: (Tabulky Google) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-16]
CHR Extension: (AdBlock) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-01-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19]
CHR Extension: (Gmail) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-16]
CHR Extension: (Chrome Media Router) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-15]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [389392 2016-11-13] (EasyAntiCheat Ltd)
R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [79552 2016-03-02] (Bitdefender)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [458296 2016-10-25] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [458296 2016-10-25] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-10-25] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1165368 2016-10-25] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2017-01-04] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2017-01-04] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2016-04-02] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-10-14] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [718840 2016-08-12] (BitDefender)
U5 avchv; C:\Windows\System32\Drivers\avchv.sys [261056 2012-11-02] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [593144 2013-04-17] (BitDefender)
R1 bdfwfpf; C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [121928 2013-07-02] (Bitdefender SRL)
R1 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [148696 2013-04-22] (BitDefender LLC)
S3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus64.sys [261120 2005-09-23] (Pinnacle Systems GmbH) [File not signed]
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2016-10-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47672 2016-10-25] (NVIDIA Corporation)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [382536 2013-05-28] (BitDefender S.R.L.)
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-26 19:52 - 2017-01-26 21:35 - 1822603277 _____ C:\Users\Dominik\Downloads\Vikings.S04E19.1080p.WEB-DL.DD5.1.H264-RARBG.mkv
2017-01-26 19:48 - 2017-01-26 19:48 - 00023930 _____ C:\Users\Dominik\Downloads\Vikings.S04E19.1080p.WEB-DL.DD5.1.H264-RARBG.srt
2017-01-24 00:24 - 2017-01-24 00:24 - 00000222 _____ C:\Users\Dominik\Desktop\Resident Evil 7 Biohazard 7 Teaser Beginning Hour.url
2017-01-22 20:02 - 2017-01-22 20:02 - 01673544 _____ ( ) C:\Users\Dominik\Downloads\cpu-z_1.78-en.exe
2017-01-22 20:02 - 2017-01-22 20:02 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2017-01-22 20:02 - 2017-01-22 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-01-22 20:02 - 2017-01-22 20:02 - 00000000 ____D C:\Program Files\CPUID
2017-01-20 01:09 - 2017-01-26 00:06 - 00000238 _____ C:\Users\Dominik\Desktop\Nový textový dokument.txt
2017-01-19 21:34 - 2017-01-19 21:34 - 00022537 _____ C:\Users\Dominik\Downloads\Vikings.S04E18.1080p.WEB-DL.DD5.1.H264-RARBG.srt
2017-01-19 19:50 - 2017-01-19 21:33 - 1847391237 _____ C:\Users\Dominik\Downloads\Vikings.S04E18.1080p.WEB-DL.DD5.1.H264-RARBG.mkv
2017-01-15 01:03 - 2017-01-15 23:11 - 00000000 ____D C:\V-H-S (2012)
2017-01-15 00:56 - 2017-01-15 00:56 - 00014496 _____ C:\Users\Dominik\Downloads\[CzT]V_H_S_2012_.torrent
2017-01-13 23:29 - 2017-01-13 23:53 - 00000000 ____D C:\Blair Witch
2017-01-13 23:28 - 2017-01-13 23:28 - 00022995 _____ C:\Users\Dominik\Downloads\[CzT]Blair_Witch_2016_720pHD_.torrent
2017-01-12 16:33 - 2017-01-12 17:26 - 930514937 _____ C:\Users\Dominik\Downloads\Vikings.S04E17.720p.HDTV.x264-FLEET.mkv
2017-01-12 16:32 - 2017-01-12 16:32 - 00029063 _____ C:\Users\Dominik\Downloads\Vikings.S04E17.720p.HDTV.x264-FLEET (+SVA).srt
2017-01-09 21:01 - 2017-01-09 21:03 - 00000000 ____D C:\stalkerhh
2017-01-09 20:59 - 2017-01-09 21:03 - 00000000 ____D C:\stalůker
2017-01-09 19:18 - 2017-01-09 19:19 - 08733953 _____ C:\Users\Dominik\Downloads\Stalker-Shadow-of-Chernobyl-Patch-a-Crack-1.0006.zip
2017-01-09 18:08 - 2017-01-09 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autumnal Wanderers
2017-01-09 14:51 - 2017-01-09 14:53 - 74472808 _____ (THQ ) C:\Users\Dominik\Downloads\stk-cz-10005.exe
2017-01-09 14:46 - 2017-01-09 14:47 - 58935312 _____ C:\Users\Dominik\Downloads\stalker_shadow_of_chernobyl_cz_patch_10000_10004.zip
2017-01-09 14:45 - 2017-01-09 14:45 - 12163888 _____ (THQ ) C:\Users\Dominik\Downloads\stk-ww-0-3.exe
2017-01-09 14:45 - 2017-01-09 14:45 - 08275798 _____ C:\Users\Dominik\Downloads\stalker_shadow_of_chernobyl_cz_patch_10001.zip
2017-01-09 14:45 - 2017-01-09 14:45 - 00002315 _____ C:\Users\Public\Desktop\S.T.A.L.K.E.R. - Shadow of Chernobyl.lnk
2017-01-09 14:45 - 2017-01-09 14:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
2017-01-09 14:39 - 2017-01-09 20:19 - 00000000 ____D C:\Users\Public\Documents\STALKER-SHOC
2017-01-09 14:39 - 2017-01-09 14:39 - 00000000 ____D C:\Program Files (x86)\THQ
2017-01-09 14:34 - 2017-01-09 14:35 - 82456210 _____ C:\Users\Dominik\Downloads\S.T.A.L.K.E.R_SoC_All_Patches_1.0001-_1.0006.rar
2017-01-09 14:33 - 2017-01-09 14:33 - 08057608 _____ (THQ ) C:\Users\Dominik\Downloads\official_patch_soc-win-10005_10006.exe
2017-01-09 12:18 - 2017-01-09 12:19 - 17959538 _____ C:\Users\Dominik\Downloads\lidsky_vztah_jako_soucast_profese.pdf
2017-01-08 23:08 - 2017-01-08 23:08 - 03988944 _____ C:\Users\Dominik\Downloads\adwcleaner_6.042.exe
2017-01-08 22:28 - 2017-01-08 22:28 - 04060064 _____ (GSC Game World ) C:\Users\Dominik\Downloads\stk-multi-patch.exe
2017-01-08 22:18 - 2017-01-08 22:22 - 00000000 ____D C:\Autumn Aurora 2.1 by Autumnal Wanderers (30.09.2015)
2017-01-08 16:01 - 2017-01-08 16:18 - 00000000 ____D C:\Program Files (x86)\PowerISO
2017-01-08 16:01 - 2017-01-08 16:01 - 02977032 _____ (Power Software Ltd) C:\Users\Dominik\Downloads\PowerISO6.exe
2017-01-08 16:01 - 2017-01-08 16:01 - 00001007 _____ C:\Users\Public\Desktop\PowerISO.lnk
2017-01-08 16:01 - 2017-01-08 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
2017-01-08 16:01 - 2016-05-25 00:06 - 00137280 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2017-01-07 21:42 - 2017-01-09 14:57 - 00000000 ____D C:\Users\Dominik\Downloads\StalkerSoCH[CZ]
2017-01-07 21:36 - 2017-01-07 21:36 - 00016160 _____ C:\Users\Dominik\Downloads\[CzT]STALKER_Shadow_of_Chernobyl_CZ_.torrent
2017-01-07 20:45 - 2017-01-08 22:13 - 1669478745 _____ C:\Users\Dominik\Downloads\Autumn_Aurora_2.1_by_Autumnal_Wanderers_30.09.2015.7z
2017-01-05 16:54 - 2017-01-05 17:47 - 948771680 _____ C:\Users\Dominik\Downloads\Vikings.S04E16.PROPER.720p.HDTV.x264-FLEET.mkv
2017-01-05 16:51 - 2017-01-05 16:51 - 00020150 _____ C:\Users\Dominik\Downloads\Vikings.S04E16.PROPER.720p.HDTV.x264-FLEET.srt
2017-01-05 16:51 - 2017-01-05 16:51 - 00020150 _____ C:\Users\Dominik\Downloads\Vikings.S04E16.PROPER.720p.HDTV.x264-FLEET (1).srt
2017-01-04 18:05 - 2017-01-04 18:05 - 00007975 _____ C:\Users\Dominik\Downloads\Potvrzení-o-absolvované-exkurzi (2).odt
2017-01-04 17:54 - 2017-01-04 17:54 - 00007975 _____ C:\Users\Dominik\Downloads\Potvrzení-o-absolvované-exkurzi (1).odt
2017-01-04 14:16 - 2017-01-04 14:38 - 00000000 ____D C:\Users\Dominik\Documents\Survarium-Steam
2017-01-03 18:00 - 2017-01-03 18:17 - 587467523 _____ C:\Users\Dominik\Downloads\Darkest Hour Ultimate Age of Empires.rar
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-30 12:08 - 2016-09-29 11:45 - 00013115 _____ C:\Users\Dominik\Documents\FRST.txt
2017-01-30 12:07 - 2016-11-07 08:39 - 00000000 ____D C:\Users\Dominik\Documents\FRST-OlderVersion
2017-01-30 12:07 - 2016-07-11 10:16 - 02420736 _____ (Farbar) C:\Users\Dominik\Documents\FRST64.exe
2017-01-30 12:07 - 2015-10-26 17:34 - 00000000 ____D C:\FRST
2017-01-30 11:10 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-30 11:10 - 2009-07-14 05:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-30 11:05 - 2015-10-29 18:45 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-30 10:30 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-30 01:23 - 2016-11-19 13:32 - 00000000 ____D C:\Users\Dominik\AppData\LocalLow\Mozilla
2017-01-29 10:01 - 2016-11-18 11:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-29 10:01 - 2015-09-27 21:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-27 10:17 - 2016-08-04 19:40 - 00000000 ____D C:\Users\Dominik\AppData\Local\CrashDumps
2017-01-26 23:00 - 2015-09-19 19:01 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\vlc
2017-01-25 23:11 - 2015-09-21 16:27 - 00000000 ____D C:\AdwCleaner
2017-01-25 22:15 - 2016-04-25 14:43 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-24 19:54 - 2015-09-27 19:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2017-01-24 19:54 - 2015-09-18 17:24 - 00000000 ____D C:\Program Files (x86)\Steam
2017-01-24 07:21 - 2009-07-14 06:08 - 00032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-01-24 00:16 - 2015-09-18 17:25 - 00000000 ____D C:\Users\Dominik\AppData\Local\Steam
2017-01-22 12:09 - 2016-08-31 13:08 - 00000000 ____D C:\Users\Dominik\AppData\Local\ElevatedDiagnostics
2017-01-19 17:43 - 2015-09-27 12:49 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-19 01:05 - 2016-03-28 18:08 - 00000000 ____D C:\Users\Dominik\Documents\TopStyle 5
2017-01-16 01:08 - 2016-10-16 15:02 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\uTorrent
2017-01-12 21:43 - 2015-11-13 14:41 - 00000000 ____D C:\Fraps
2017-01-12 14:37 - 2015-11-19 21:53 - 00000000 ____D C:\Darkest Hour
2017-01-10 13:43 - 2015-09-27 12:50 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-06 01:04 - 2015-09-25 14:39 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Origin
2017-01-05 16:24 - 2015-09-25 14:37 - 00000000 ____D C:\ProgramData\Origin
2017-01-04 15:50 - 2016-10-14 16:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2017-01-04 15:50 - 2015-09-25 16:42 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2017-01-04 15:12 - 2015-09-25 14:37 - 00000000 ____D C:\Program Files (x86)\Origin
2017-01-04 00:51 - 2015-09-15 21:08 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Skype
==================== Files in the root of some directories =======
2016-09-04 21:01 - 2016-09-04 21:07 - 0000000 _____ () C:\Program Files (x86)\ToDownloadBase.db
2016-08-25 20:52 - 2016-09-21 17:29 - 0029696 _____ () C:\Users\Dominik\AppData\Local\MSGBOX.EXE
2016-02-23 17:32 - 2016-02-23 17:32 - 0000913 _____ () C:\Users\Dominik\AppData\Local\recently-used.xbel
2015-10-21 19:28 - 2016-09-28 09:12 - 0007602 _____ () C:\Users\Dominik\AppData\Local\Resmon.ResmonCfg
2016-10-14 16:37 - 2016-10-14 16:37 - 0000000 ___SH () C:\ProgramData\.rdata
2016-08-11 18:14 - 2016-08-11 18:15 - 0101114 _____ () C:\ProgramData\1470935671.bdinstall.bin
2016-08-11 18:18 - 2016-08-11 18:18 - 0198197 _____ () C:\ProgramData\1470935869.bdinstall.bin
Some files in TEMP:
====================
2017-01-09 18:11 - 2017-01-09 18:11 - 0065536 _____ (Sony DADC Austria AG) C:\Users\Dominik\AppData\Local\Temp\drm_dialogs.dll
2016-04-15 17:29 - 2016-08-25 21:50 - 0746088 _____ (NVIDIA Corporation) C:\Users\Dominik\AppData\Local\Temp\nvSCPAPI.dll
2016-04-15 17:29 - 2016-08-25 21:50 - 0860776 _____ (NVIDIA Corporation) C:\Users\Dominik\AppData\Local\Temp\nvSCPAPI64.dll
2016-08-30 11:59 - 2016-08-25 21:49 - 0345024 _____ (NVIDIA Corporation) C:\Users\Dominik\AppData\Local\Temp\nvStInst.exe
2016-08-04 20:23 - 2017-01-24 19:54 - 0192512 _____ () C:\Users\Dominik\AppData\Local\Temp\sfamcc00001.dll
2016-08-06 16:04 - 2016-12-06 21:34 - 0192512 _____ () C:\Users\Dominik\AppData\Local\Temp\sfamcc00002.dll
2016-09-26 20:26 - 2017-01-03 22:16 - 43872728 _____ (Skype Technologies S.A.) C:\Users\Dominik\AppData\Local\Temp\SkypeSetup.exe
2016-08-15 17:31 - 2016-08-15 17:31 - 0945691 _____ () C:\Users\Dominik\AppData\Local\Temp\ubi90F8.tmp.exe
2016-09-25 17:48 - 2016-09-25 17:48 - 22895331 _____ (Ubisoft) C:\Users\Dominik\AppData\Local\Temp\ubi9CA5.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-23 09:57
==================== End of FRST.txt ============================