prev controla
Napsal: 30 led 2017 19:16
Zdravím,
nic závažnýho, krom občasnýho seknutí kurzoru myšky.
Posílám log z FRST.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by Virgill (administrator) on VIRGILL-PC (30-01-2017 19:07:44)
Running from C:\Users\Virgill\Downloads
Loaded Profiles: Virgill (Available Profiles: Virgill)
Platform: Windows 10 Pro Version 1511 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\WINDOWS\System32\atiesrxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\WINDOWS\System32\wimserv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\INS_894b6c07.TMP
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(AMD) C:\WINDOWS\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\WINDOWS\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe
(Akamai Technologies, Inc.) C:\Users\Virgill\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Virgill\AppData\Local\Akamai\netsession_win.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696832 2016-11-24] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe [18923008 2015-06-16] ()
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1046064 2017-01-23] ()
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [MurGee.com Auto Keyboard] => C:\Users\Virgill\Documents\Auto Keyboard\AutoKeyboard.exe [83440 2015-03-27] (MurGee.com)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Virgill\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\MountPoints2: {25f03466-b0ed-11e5-8ece-000e2e640877} - "I:\Lenovo_Suite.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 185.147.250.13 185.147.250.14 192.168.1.1
Tcpip\..\Interfaces\{2cbd68be-aa6a-4cb1-aa11-c6266c4cebdc}: [DhcpNameServer] 185.147.250.13 185.147.250.14 192.168.1.1
Tcpip\..\Interfaces\{30877717-9a83-4c96-a7ba-9b10675a8260}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{949d9305-ddc3-4f35-807f-a176e512e079}: [DhcpNameServer] 213.180.36.130 213.180.36.131
Internet Explorer:
==================
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131011372525856110&GUID=1BFBEC75-BC8E-4BF1-A4CE-F3C39D704A26
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> DefaultScope {583E6183-82B5-4071-8CE0-21A1D36C9B9C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> {3C46B73F-0D56-4415-9541-862D61CAFC41} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11467
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> {583E6183-82B5-4071-8CE0-21A1D36C9B9C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> {58478693-1F8E-49e3-A598-38C048094EB0} URL = hxxp://www.google.com/custom?client=pub-379428 ... earchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-09-23] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\rulez\startrek\Arc\Plugins\ArcPluginIE.dll [2016-12-08] (Perfect World Entertainment Inc)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> No Name - {A3834AE7-CA97-48EA-80E9-70F6E1ADD4DB} - No File
FireFox:
========
FF ProfilePath: C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878 [2017-01-30]
FF Extension: (Firebug) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\firebug@software.joehewitt.com.xpi [2016-10-11]
FF Extension: (MEGA) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\firefox@mega.co.nz.xpi [2017-01-30]
FF Extension: (Pin It button) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi [2016-09-29]
FF Extension: (Adblock Plus) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-11] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\rulez\startrek\Arc\Plugins\npArcPluginFF.dll [2016-12-08] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2573572955-775236183-1901679569-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Virgill\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-01-20] (Citrix Online)
Chrome:
=======
CHR Profile: C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default [2017-01-28]
CHR Extension: (Prezentace Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-18]
CHR Extension: (Dokumenty Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-20]
CHR Extension: (Disk Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-20]
CHR Extension: (YouTube) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-20]
CHR Extension: (Tabulky Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-22]
CHR Extension: (Gmail) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-20]
CHR Extension: (Chrome Media Router) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-18]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ArcService; C:\rulez\startrek\Arc\ArcService.exe [87064 2016-12-08] (Perfect World Entertainment Inc)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
S2 gupdate1d2463ee6998e6f; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-11-24] (Google Inc.)
S3 gupdatem1d2463ee6a2ddb1; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-11-24] (Google Inc.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-01-06] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-01-06] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-10-25] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [427064 2017-01-06] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1318128 2017-01-23] (Overwolf LTD)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation)
R2 NVIDIA Wireless Controller Service; "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
S3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63al.sys [5170176 2015-10-30] (Broadcom Corporation)
S3 clwvd6; C:\WINDOWS\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
S3 clwvd7; C:\WINDOWS\system32\DRIVERS\clwvd7.sys [49944 2016-06-02] (CyberLink Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [254528 2016-09-22] (DT Soft Ltd)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-09-29] (REALiX(tm))
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2017-01-06] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47672 2017-01-06] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-01-06] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [943112 2016-10-30] (Realtek )
S3 RTL8023x64; C:\WINDOWS\System32\drivers\Rtnic64.sys [51712 2015-10-30] (Realtek Semiconductor Corporation )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [418784 2016-11-24] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42600 2016-09-29] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 wmbclass; C:\WINDOWS\System32\drivers\wmbclass.sys [303104 2015-10-30] (Microsoft Corporation)
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-30 19:07 - 2017-01-30 19:08 - 00016817 _____ C:\Users\Virgill\Downloads\FRST.txt
2017-01-30 19:07 - 2017-01-30 19:07 - 00000000 ____D C:\FRST
2017-01-30 19:06 - 2017-01-30 19:07 - 02420736 _____ (Farbar) C:\Users\Virgill\Downloads\FRST64.exe
2017-01-25 07:14 - 2017-01-25 07:14 - 00000000 ____D C:\Users\Virgill\AppData\Local\Chromium
2017-01-25 07:12 - 2017-01-25 07:12 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2017-01-25 07:12 - 00000000 ____D C:\WINDOWS\LastGood
2017-01-25 07:12 - 2017-01-06 02:10 - 00158264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-01-25 07:12 - 2017-01-06 02:10 - 00126008 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-01-25 07:12 - 2017-01-06 02:10 - 00059448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-01-25 07:12 - 2017-01-06 01:09 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-01-18 22:44 - 2017-01-18 22:45 - 07586584 _____ (Christian Kaiser ) C:\Users\Virgill\Downloads\LightscreenSetup-2.4.exe
2017-01-17 14:11 - 2017-01-17 14:11 - 17628560 _____ (IObit ) C:\Users\Virgill\Downloads\driver_booster_setup.exe
2017-01-17 07:08 - 2017-01-17 07:08 - 00000000 ____D C:\Users\Virgill\Downloads\backups
2017-01-17 07:05 - 2017-01-17 07:05 - 00388608 _____ (Trend Micro Inc.) C:\Users\Virgill\Downloads\hijackthis.exe
2017-01-11 23:52 - 2017-01-11 23:52 - 00000042 _____ C:\Users\Virgill\Desktop\CPA action.txt
2017-01-11 08:33 - 2016-12-21 10:01 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-01-11 08:33 - 2016-12-21 10:01 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-01-11 08:33 - 2016-12-21 09:25 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2017-01-11 08:33 - 2016-12-21 08:18 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-01-11 08:33 - 2016-12-21 07:56 - 01502208 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-01-11 08:33 - 2016-12-21 06:41 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-01-11 08:33 - 2016-12-21 06:39 - 22373376 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-01-11 08:33 - 2016-12-21 06:15 - 07839232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-01-11 08:33 - 2016-12-21 06:06 - 03663872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-01-11 08:33 - 2016-12-21 06:03 - 18671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-01-11 08:33 - 2016-12-21 05:48 - 05658624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-01-11 08:33 - 2016-10-25 07:55 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-30 19:08 - 2016-01-20 16:52 - 00000692 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2573572955-775236183-1901679569-1000.job
2017-01-30 18:54 - 2015-12-21 20:01 - 00000000 ____D C:\Users\Virgill\AppData\Roaming\TS3Client
2017-01-30 18:44 - 2016-07-04 10:13 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-01-30 18:43 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-30 18:39 - 2016-11-18 17:33 - 00000000 ____D C:\Users\Virgill\AppData\LocalLow\Mozilla
2017-01-30 18:37 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-30 18:36 - 2016-07-03 08:47 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-30 18:35 - 2015-12-20 20:30 - 00004204 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{033FCC92-586D-449F-8D21-4887FE3C1747}
2017-01-30 18:34 - 2016-09-29 03:19 - 00003036 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Virgill)
2017-01-30 18:31 - 2016-10-27 18:23 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-01-30 00:21 - 2016-01-20 16:52 - 00000596 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2573572955-775236183-1901679569-1000.job
2017-01-28 19:07 - 2016-11-10 07:04 - 00003960 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1478757887
2017-01-28 19:07 - 2016-11-10 07:04 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2017-01-28 19:07 - 2016-11-10 07:04 - 00000000 ____D C:\Program Files (x86)\Opera
2017-01-28 01:30 - 2016-10-26 23:43 - 00000000 ____D C:\Program Files (x86)\BSGO
2017-01-27 23:53 - 2016-07-17 15:59 - 00000000 ____D C:\Users\Virgill\AppData\Local\CrashDumps
2017-01-27 22:54 - 2016-02-11 01:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-01-27 22:54 - 2016-02-11 01:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-27 22:43 - 2015-12-23 09:50 - 00000000 ____D C:\Users\Virgill\Documents\bsgo
2017-01-26 15:02 - 2016-01-15 09:02 - 00000000 ____D C:\Program Files (x86)\Overwolf
2017-01-25 07:28 - 2016-01-20 16:52 - 00003854 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-2573572955-775236183-1901679569-1000
2017-01-25 07:28 - 2016-01-20 16:52 - 00003758 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-2573572955-775236183-1901679569-1000
2017-01-25 07:16 - 2015-12-19 05:27 - 01771468 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-01-25 07:16 - 2015-10-30 19:31 - 00750030 _____ C:\WINDOWS\system32\perfh005.dat
2017-01-25 07:16 - 2015-10-30 19:31 - 00150654 _____ C:\WINDOWS\system32\perfc005.dat
2017-01-25 07:16 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2017-01-25 07:14 - 2016-10-05 18:36 - 00001485 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-01-25 07:14 - 2016-10-05 18:35 - 00003884 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:14 - 2016-07-03 08:20 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-25 07:13 - 2016-07-03 08:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-25 07:12 - 2016-10-05 18:35 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-07-04 10:05 - 00000000 ____D C:\Users\Virgill\AppData\Local\NVIDIA Corporation
2017-01-25 07:12 - 2016-07-03 09:28 - 00000000 ____D C:\Users\Virgill\AppData\Local\NVIDIA
2017-01-25 07:12 - 2016-07-03 08:20 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-23 11:42 - 2016-09-03 11:35 - 00000000 ____D C:\Users\Virgill\AppData\Local\Akamai
2017-01-22 21:05 - 2016-10-31 21:12 - 00000000 ____D C:\WINDOWS\Panther
2017-01-22 20:58 - 2016-12-02 23:14 - 00000000 ___HD C:\$WINDOWS.~BT
2017-01-22 20:38 - 2016-11-12 14:00 - 00000000 ____D C:\Users\Virgill\AppData\Local\TeamSpeak 3 Client
2017-01-21 04:41 - 2015-12-19 05:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-21 00:37 - 2015-10-30 07:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2017-01-20 05:18 - 2016-12-14 05:21 - 00000276 _____ C:\Users\Virgill\Desktop\VypinacPC.ini
2017-01-18 16:25 - 2015-12-20 20:01 - 00000000 ____D C:\Users\Virgill\AppData\Local\GHISLER
2017-01-17 15:07 - 2016-12-30 01:46 - 00000000 ____D C:\Users\Virgill\Documents\startrek
2017-01-17 07:05 - 2015-12-19 00:38 - 00000000 ____D C:\Users\Virgill\AppData\Local\VirtualStore
2017-01-17 06:53 - 2015-12-19 00:46 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-01-17 06:52 - 2016-07-24 17:31 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-17 06:50 - 2016-01-02 02:07 - 00000000 ____D C:\WINDOWS\Minidump
2017-01-17 06:48 - 2015-12-19 05:18 - 00000000 ____D C:\Users\Virgill
2017-01-14 08:22 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2017-01-13 12:32 - 2016-11-09 12:36 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-01-12 05:05 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-01-11 08:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-01-11 08:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-11 08:42 - 2015-12-19 01:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-11 08:39 - 2015-12-19 01:31 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-01-11 08:39 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-11 07:57 - 2016-11-10 04:01 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-01-10 01:34 - 2015-12-20 20:36 - 00000000 ____D C:\Users\Virgill\AppData\Roaming\vlc
2017-01-06 02:10 - 2016-10-05 18:35 - 01855544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 01756728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 01454136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 01318968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 00121912 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 00047672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-01-06 00:42 - 2016-10-05 18:35 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-01-03 19:12 - 2015-12-30 01:05 - 00000000 ____D C:\Program Files\Miranda NG
2017-01-02 21:05 - 2016-11-03 03:03 - 00000002 _____ C:\END
2016-12-31 06:45 - 2015-12-19 05:18 - 00524288 ___SH C:\Users\Virgill\NTUSER.DAT{dbf448c2-a606-11e5-8ec4-f6e736bdca8a}.TMContainer00000000000000000001.regtrans-ms
2016-12-31 06:45 - 2015-12-19 05:18 - 00065536 ___SH C:\Users\Virgill\NTUSER.DAT{dbf448c2-a606-11e5-8ec4-f6e736bdca8a}.TM.blf
2016-12-31 01:27 - 2015-10-30 07:28 - 00000000 ___RD C:\Program Files (x86)
==================== Files in the root of some directories =======
2016-07-23 13:08 - 2016-07-23 13:08 - 0003584 _____ () C:\Users\Virgill\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-02-04 12:17 - 2016-02-04 12:17 - 0000858 _____ () C:\Users\Virgill\AppData\Local\recently-used.xbel
2015-12-22 01:30 - 2015-12-22 01:30 - 0000017 _____ () C:\Users\Virgill\AppData\Local\resmon.resmoncfg
2016-10-30 14:10 - 2016-10-30 14:10 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\Virgill\dht.dat
C:\Users\Virgill\resume.20160923.124007.dat
C:\Users\Virgill\resume.dat
C:\Users\Virgill\rss.dat
C:\Users\Virgill\settings.dat
C:\Users\Virgill\uninstall.exe
C:\Users\Virgill\utorrent.exe
Some files in TEMP:
====================
2016-10-05 18:35 - 2016-10-25 21:21 - 1137208 _____ (NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\NvTelemetry.dll
2016-10-05 18:35 - 2016-10-25 21:21 - 0218680 _____ (NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\NvTelemetryAPI32.dll
2016-10-05 18:35 - 2016-10-25 21:21 - 0270392 _____ (NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\NvTelemetryAPI64.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-28 10:40
==================== End of FRST.txt ============================
nic závažnýho, krom občasnýho seknutí kurzoru myšky.
Posílám log z FRST.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by Virgill (administrator) on VIRGILL-PC (30-01-2017 19:07:44)
Running from C:\Users\Virgill\Downloads
Loaded Profiles: Virgill (Available Profiles: Virgill)
Platform: Windows 10 Pro Version 1511 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\WINDOWS\System32\atiesrxx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\WINDOWS\System32\wimserv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\INS_894b6c07.TMP
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(AMD) C:\WINDOWS\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\WINDOWS\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe
(Akamai Technologies, Inc.) C:\Users\Virgill\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Virgill\AppData\Local\Akamai\netsession_win.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16696832 2016-11-24] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe [18923008 2015-06-16] ()
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1046064 2017-01-23] ()
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [MurGee.com Auto Keyboard] => C:\Users\Virgill\Documents\Auto Keyboard\AutoKeyboard.exe [83440 2015-03-27] (MurGee.com)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Virgill\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\RunOnce: [Uninstall C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Virgill\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\...\MountPoints2: {25f03466-b0ed-11e5-8ece-000e2e640877} - "I:\Lenovo_Suite.exe"
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 185.147.250.13 185.147.250.14 192.168.1.1
Tcpip\..\Interfaces\{2cbd68be-aa6a-4cb1-aa11-c6266c4cebdc}: [DhcpNameServer] 185.147.250.13 185.147.250.14 192.168.1.1
Tcpip\..\Interfaces\{30877717-9a83-4c96-a7ba-9b10675a8260}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{949d9305-ddc3-4f35-807f-a176e512e079}: [DhcpNameServer] 213.180.36.130 213.180.36.131
Internet Explorer:
==================
HKU\S-1-5-21-2573572955-775236183-1901679569-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131011372525856110&GUID=1BFBEC75-BC8E-4BF1-A4CE-F3C39D704A26
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> DefaultScope {583E6183-82B5-4071-8CE0-21A1D36C9B9C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> {3C46B73F-0D56-4415-9541-862D61CAFC41} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11467
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> {583E6183-82B5-4071-8CE0-21A1D36C9B9C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> {58478693-1F8E-49e3-A598-38C048094EB0} URL = hxxp://www.google.com/custom?client=pub-379428 ... earchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-09-23] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\rulez\startrek\Arc\Plugins\ArcPluginIE.dll [2016-12-08] (Perfect World Entertainment Inc)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-23] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2573572955-775236183-1901679569-1000 -> No Name - {A3834AE7-CA97-48EA-80E9-70F6E1ADD4DB} - No File
FireFox:
========
FF ProfilePath: C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878 [2017-01-30]
FF Extension: (Firebug) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\firebug@software.joehewitt.com.xpi [2016-10-11]
FF Extension: (MEGA) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\firefox@mega.co.nz.xpi [2017-01-30]
FF Extension: (Pin It button) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi [2016-09-29]
FF Extension: (Adblock Plus) - C:\Users\Virgill\AppData\Roaming\Mozilla\Firefox\Profiles\0l70a99x.default-1454323038878\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-11] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-25] (NVIDIA Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\rulez\startrek\Arc\Plugins\npArcPluginFF.dll [2016-12-08] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2573572955-775236183-1901679569-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Virgill\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-01-20] (Citrix Online)
Chrome:
=======
CHR Profile: C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default [2017-01-28]
CHR Extension: (Prezentace Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-18]
CHR Extension: (Dokumenty Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-20]
CHR Extension: (Disk Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-20]
CHR Extension: (YouTube) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-20]
CHR Extension: (Tabulky Google) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-22]
CHR Extension: (Gmail) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-20]
CHR Extension: (Chrome Media Router) - C:\Users\Virgill\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-18]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ArcService; C:\rulez\startrek\Arc\ArcService.exe [87064 2016-12-08] (Perfect World Entertainment Inc)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
S2 gupdate1d2463ee6998e6f; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-11-24] (Google Inc.)
S3 gupdatem1d2463ee6a2ddb1; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2016-11-24] (Google Inc.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-01-06] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-01-06] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-10-25] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [427064 2017-01-06] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1318128 2017-01-23] (Overwolf LTD)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation)
R2 NVIDIA Wireless Controller Service; "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
S3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63al.sys [5170176 2015-10-30] (Broadcom Corporation)
S3 clwvd6; C:\WINDOWS\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
S3 clwvd7; C:\WINDOWS\system32\DRIVERS\clwvd7.sys [49944 2016-06-02] (CyberLink Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [254528 2016-09-22] (DT Soft Ltd)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-09-29] (REALiX(tm))
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2017-01-06] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47672 2017-01-06] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59448 2017-01-06] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [943112 2016-10-30] (Realtek )
S3 RTL8023x64; C:\WINDOWS\System32\drivers\Rtnic64.sys [51712 2015-10-30] (Realtek Semiconductor Corporation )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [418784 2016-11-24] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42600 2016-09-29] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 wmbclass; C:\WINDOWS\System32\drivers\wmbclass.sys [303104 2015-10-30] (Microsoft Corporation)
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-30 19:07 - 2017-01-30 19:08 - 00016817 _____ C:\Users\Virgill\Downloads\FRST.txt
2017-01-30 19:07 - 2017-01-30 19:07 - 00000000 ____D C:\FRST
2017-01-30 19:06 - 2017-01-30 19:07 - 02420736 _____ (Farbar) C:\Users\Virgill\Downloads\FRST64.exe
2017-01-25 07:14 - 2017-01-25 07:14 - 00000000 ____D C:\Users\Virgill\AppData\Local\Chromium
2017-01-25 07:12 - 2017-01-25 07:12 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2017-01-25 07:12 - 00000000 ____D C:\WINDOWS\LastGood
2017-01-25 07:12 - 2017-01-06 02:10 - 00158264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-01-25 07:12 - 2017-01-06 02:10 - 00126008 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-01-25 07:12 - 2017-01-06 02:10 - 00059448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-01-25 07:12 - 2017-01-06 01:09 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-01-18 22:44 - 2017-01-18 22:45 - 07586584 _____ (Christian Kaiser ) C:\Users\Virgill\Downloads\LightscreenSetup-2.4.exe
2017-01-17 14:11 - 2017-01-17 14:11 - 17628560 _____ (IObit ) C:\Users\Virgill\Downloads\driver_booster_setup.exe
2017-01-17 07:08 - 2017-01-17 07:08 - 00000000 ____D C:\Users\Virgill\Downloads\backups
2017-01-17 07:05 - 2017-01-17 07:05 - 00388608 _____ (Trend Micro Inc.) C:\Users\Virgill\Downloads\hijackthis.exe
2017-01-11 23:52 - 2017-01-11 23:52 - 00000042 _____ C:\Users\Virgill\Desktop\CPA action.txt
2017-01-11 08:33 - 2016-12-21 10:01 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-01-11 08:33 - 2016-12-21 10:01 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-01-11 08:33 - 2016-12-21 09:25 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2017-01-11 08:33 - 2016-12-21 08:18 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-01-11 08:33 - 2016-12-21 07:56 - 01502208 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-01-11 08:33 - 2016-12-21 06:41 - 04895744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-01-11 08:33 - 2016-12-21 06:39 - 22373376 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-01-11 08:33 - 2016-12-21 06:15 - 07839232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-01-11 08:33 - 2016-12-21 06:06 - 03663872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-01-11 08:33 - 2016-12-21 06:03 - 18671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-01-11 08:33 - 2016-12-21 05:48 - 05658624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-01-11 08:33 - 2016-10-25 07:55 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-30 19:08 - 2016-01-20 16:52 - 00000692 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2573572955-775236183-1901679569-1000.job
2017-01-30 18:54 - 2015-12-21 20:01 - 00000000 ____D C:\Users\Virgill\AppData\Roaming\TS3Client
2017-01-30 18:44 - 2016-07-04 10:13 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-01-30 18:43 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-30 18:39 - 2016-11-18 17:33 - 00000000 ____D C:\Users\Virgill\AppData\LocalLow\Mozilla
2017-01-30 18:37 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-30 18:36 - 2016-07-03 08:47 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-30 18:35 - 2015-12-20 20:30 - 00004204 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{033FCC92-586D-449F-8D21-4887FE3C1747}
2017-01-30 18:34 - 2016-09-29 03:19 - 00003036 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Virgill)
2017-01-30 18:31 - 2016-10-27 18:23 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-01-30 00:21 - 2016-01-20 16:52 - 00000596 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2573572955-775236183-1901679569-1000.job
2017-01-28 19:07 - 2016-11-10 07:04 - 00003960 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1478757887
2017-01-28 19:07 - 2016-11-10 07:04 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2017-01-28 19:07 - 2016-11-10 07:04 - 00000000 ____D C:\Program Files (x86)\Opera
2017-01-28 01:30 - 2016-10-26 23:43 - 00000000 ____D C:\Program Files (x86)\BSGO
2017-01-27 23:53 - 2016-07-17 15:59 - 00000000 ____D C:\Users\Virgill\AppData\Local\CrashDumps
2017-01-27 22:54 - 2016-02-11 01:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-01-27 22:54 - 2016-02-11 01:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-27 22:43 - 2015-12-23 09:50 - 00000000 ____D C:\Users\Virgill\Documents\bsgo
2017-01-26 15:02 - 2016-01-15 09:02 - 00000000 ____D C:\Program Files (x86)\Overwolf
2017-01-25 07:28 - 2016-01-20 16:52 - 00003854 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-2573572955-775236183-1901679569-1000
2017-01-25 07:28 - 2016-01-20 16:52 - 00003758 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-2573572955-775236183-1901679569-1000
2017-01-25 07:16 - 2015-12-19 05:27 - 01771468 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-01-25 07:16 - 2015-10-30 19:31 - 00750030 _____ C:\WINDOWS\system32\perfh005.dat
2017-01-25 07:16 - 2015-10-30 19:31 - 00150654 _____ C:\WINDOWS\system32\perfc005.dat
2017-01-25 07:16 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2017-01-25 07:14 - 2016-10-05 18:36 - 00001485 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-01-25 07:14 - 2016-10-05 18:35 - 00003884 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:14 - 2016-07-03 08:20 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-01-25 07:13 - 2016-07-03 08:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-01-25 07:12 - 2016-10-05 18:35 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-10-05 18:35 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-01-25 07:12 - 2016-07-04 10:05 - 00000000 ____D C:\Users\Virgill\AppData\Local\NVIDIA Corporation
2017-01-25 07:12 - 2016-07-03 09:28 - 00000000 ____D C:\Users\Virgill\AppData\Local\NVIDIA
2017-01-25 07:12 - 2016-07-03 08:20 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-01-23 11:42 - 2016-09-03 11:35 - 00000000 ____D C:\Users\Virgill\AppData\Local\Akamai
2017-01-22 21:05 - 2016-10-31 21:12 - 00000000 ____D C:\WINDOWS\Panther
2017-01-22 20:58 - 2016-12-02 23:14 - 00000000 ___HD C:\$WINDOWS.~BT
2017-01-22 20:38 - 2016-11-12 14:00 - 00000000 ____D C:\Users\Virgill\AppData\Local\TeamSpeak 3 Client
2017-01-21 04:41 - 2015-12-19 05:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-21 00:37 - 2015-10-30 07:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2017-01-20 05:18 - 2016-12-14 05:21 - 00000276 _____ C:\Users\Virgill\Desktop\VypinacPC.ini
2017-01-18 16:25 - 2015-12-20 20:01 - 00000000 ____D C:\Users\Virgill\AppData\Local\GHISLER
2017-01-17 15:07 - 2016-12-30 01:46 - 00000000 ____D C:\Users\Virgill\Documents\startrek
2017-01-17 07:05 - 2015-12-19 00:38 - 00000000 ____D C:\Users\Virgill\AppData\Local\VirtualStore
2017-01-17 06:53 - 2015-12-19 00:46 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-01-17 06:52 - 2016-07-24 17:31 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-01-17 06:50 - 2016-01-02 02:07 - 00000000 ____D C:\WINDOWS\Minidump
2017-01-17 06:48 - 2015-12-19 05:18 - 00000000 ____D C:\Users\Virgill
2017-01-14 08:22 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2017-01-13 12:32 - 2016-11-09 12:36 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-01-12 05:05 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-01-11 08:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-01-11 08:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-11 08:42 - 2015-12-19 01:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-11 08:39 - 2015-12-19 01:31 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-01-11 08:39 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-11 07:57 - 2016-11-10 04:01 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-01-10 01:34 - 2015-12-20 20:36 - 00000000 ____D C:\Users\Virgill\AppData\Roaming\vlc
2017-01-06 02:10 - 2016-10-05 18:35 - 01855544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 01756728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 01454136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 01318968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 00121912 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-01-06 02:10 - 2016-10-05 18:35 - 00047672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-01-06 00:42 - 2016-10-05 18:35 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-01-03 19:12 - 2015-12-30 01:05 - 00000000 ____D C:\Program Files\Miranda NG
2017-01-02 21:05 - 2016-11-03 03:03 - 00000002 _____ C:\END
2016-12-31 06:45 - 2015-12-19 05:18 - 00524288 ___SH C:\Users\Virgill\NTUSER.DAT{dbf448c2-a606-11e5-8ec4-f6e736bdca8a}.TMContainer00000000000000000001.regtrans-ms
2016-12-31 06:45 - 2015-12-19 05:18 - 00065536 ___SH C:\Users\Virgill\NTUSER.DAT{dbf448c2-a606-11e5-8ec4-f6e736bdca8a}.TM.blf
2016-12-31 01:27 - 2015-10-30 07:28 - 00000000 ___RD C:\Program Files (x86)
==================== Files in the root of some directories =======
2016-07-23 13:08 - 2016-07-23 13:08 - 0003584 _____ () C:\Users\Virgill\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-02-04 12:17 - 2016-02-04 12:17 - 0000858 _____ () C:\Users\Virgill\AppData\Local\recently-used.xbel
2015-12-22 01:30 - 2015-12-22 01:30 - 0000017 _____ () C:\Users\Virgill\AppData\Local\resmon.resmoncfg
2016-10-30 14:10 - 2016-10-30 14:10 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\Virgill\dht.dat
C:\Users\Virgill\resume.20160923.124007.dat
C:\Users\Virgill\resume.dat
C:\Users\Virgill\rss.dat
C:\Users\Virgill\settings.dat
C:\Users\Virgill\uninstall.exe
C:\Users\Virgill\utorrent.exe
Some files in TEMP:
====================
2016-10-05 18:35 - 2016-10-25 21:21 - 1137208 _____ (NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\NvTelemetry.dll
2016-10-05 18:35 - 2016-10-25 21:21 - 0218680 _____ (NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\NvTelemetryAPI32.dll
2016-10-05 18:35 - 2016-10-25 21:21 - 0270392 _____ (NVIDIA Corporation) C:\Users\Virgill\AppData\Local\Temp\NvTelemetryAPI64.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-28 10:40
==================== End of FRST.txt ============================