Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-02-2017
Ran by woya (administrator) on WOYTA (23-02-2017 11:25:20)
Running from C:\Users\woya\Downloads
Loaded Profiles: woya (Available Profiles: woya & Administrator)
Platform: Windows 8.1 Connected (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
() C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Users\woya\AppData\Roaming\Seznam.cz\szninstall.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
() C:\Users\woya\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\woya\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmui.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672664 2014-06-30] (Realtek Semiconductor)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1284680 2014-01-17] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-04-29] (Qualcomm®Atheros®)
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1475344 2016-03-24] (Lavasoft)
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\Run: [Steam] => "C:\Users\woya\Desktop\Nová složka\steam.exe" -silent
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\Run: [GSplay.exe] => C:\Users\woya\Desktop\GSplay.exe
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\woya\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\woya\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\MountPoints2: {34852885-5583-11e5-8263-acd1b85b8ca0} - "E:\Autorun.exe"
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\...\MountPoints2: {5deba2d2-560f-11e5-8265-acd1b85b8ca0} - "G:\Install.exe"
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-09-09] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-09-09] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-09-09] (Acer Incorporated)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [2016-09-09] (Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [2016-09-09] (Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [2016-09-09] (Acer Incorporated)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [345360 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [345360 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [345360 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [345360 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9 16 C:\WINDOWS\SysWOW64\LavasoftTcpService.dll [345360 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9-x64 01 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9-x64 02 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9-x64 03 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9-x64 04 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-09-07] (Lavasoft Limited)
Winsock: Catalog9-x64 16 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-09-07] (Lavasoft Limited)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{9D8B0457-CB80-45F2-93FC-226FF32ED990}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.seznam.cz/?clid=12454
HKU\S-1-5-21-3354066490-3795016998-3616670782-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {07DABBBB-7C71-43CD-9A0B-38218CEB43CD} URL = hxxp://
www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {20A794BE-539A-4ABE-905E-BF7262C67DA1} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {35F1F2F5-6E9B-4FA5-9365-06DE685EC9F6} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {4676566E-8E36-47B1-AC52-289DD87C7642} URL = hxxp://
www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {7FF58829-AE7D-4698-88BB-44079369A2F9} URL = hxxp://
www.mapy.cz/?query={searchTerms}&source ... arch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {8BBC4653-7911-4317-8A75-C5E56D3170AC} URL = hxxp://
www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {9814D5FA-946F-4F51-80CC-417F8AE0ABD5} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/search?fr=vmn&type=vmn__webcompa__1_0__ya__ch_WCYID10196_swoc_campaign_150907__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {C7F25AC1-915D-414D-B4E2-19DE7550F76E} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> {F0473FF6-D974-430F-843B-597BE706BBA0} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll => No File
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-3354066490-3795016998-3616670782-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [{8B1E27AE-119E-456b-B22E-08C61FACB097}] - C:\Program Files (x86)\Tomabo\MP4 Downloader\MP4D_FF.xpi => not found
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default [2017-02-23]
CHR Extension: (Prezentace Google) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-29]
CHR Extension: (Dokumenty Google) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-29]
CHR Extension: (Disk Google) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-29]
CHR Extension: (Seznam Lištička - Email) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2017-02-22]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2017-02-22]
CHR Extension: (YouTube) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-29]
CHR Extension: (Tabulky Google) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-19]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2017-02-22]
CHR Extension: (Gmail) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\woya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-05]
CHR HKLM-x32\...\Chrome\Extension: [glhecpdglaanfgdgcefipbokcmenleaf] - C:\Program Files (x86)\Tomabo\MP4 Downloader\MP4D_GC.crx <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-04-29] (Windows (R) Win 7 DDK provider) [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2267352 2016-08-30] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [315376 2014-06-09] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-02] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-02] (Intel(R) Corporation)
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760 2016-03-24] (Lavasoft Limited)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625632 2015-07-22] (Lenovo)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [455912 2014-12-30] (Acer Incorporate)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [17168 2016-03-24] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
S4 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\WINDOWS\system32\DRIVERS\athwbx.sys [3893248 2014-04-03] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_LWFLT; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [77464 2014-04-29] (Qualcomm Atheros)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
S3 dtultrascsibus; C:\WINDOWS\System32\drivers\dtultrascsibus.sys [30264 2015-09-08] (Disc Soft Ltd)
S3 dtultrausbbus; C:\WINDOWS\System32\drivers\dtultrausbbus.sys [47160 2015-09-08] (Disc Soft Ltd)
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [31232 2014-06-09] (Intel Corporation)
R3 iaioi2c; C:\WINDOWS\System32\drivers\iaioi2ce.sys [69632 2014-06-09] (Intel Corporation)
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [21360 2013-07-18] (Acer Incorporated)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [14680 2013-07-18] (Acer Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [35856 2014-03-24] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [257880 2014-03-24] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
U0 aswVmm; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-23 11:25 - 2017-02-23 11:26 - 00020011 _____ C:\Users\woya\Downloads\FRST.txt
2017-02-23 11:25 - 2017-02-23 11:25 - 00000000 ____D C:\FRST
2017-02-23 11:23 - 2017-02-23 11:23 - 02423296 _____ (Farbar) C:\Users\woya\Downloads\FRST64.exe
2017-02-22 18:20 - 2017-02-22 18:20 - 01107968 _____ C:\Users\woya\Downloads\RSIT.exe
2017-02-22 18:20 - 2017-02-22 18:20 - 00000000 ____D C:\Program Files (x86)\trend micro
2017-02-22 18:18 - 2017-02-22 18:18 - 01324032 _____ C:\Users\woya\Downloads\RSITx64 (1).exe
2017-02-22 18:13 - 2017-02-22 18:13 - 01222144 _____ C:\Users\woya\Downloads\RSITx64.exe
2017-02-22 18:13 - 2017-02-22 18:13 - 00000000 ____D C:\rsit
2017-02-22 18:13 - 2017-02-22 18:13 - 00000000 ____D C:\Program Files\trend micro
2017-02-22 17:12 - 2017-02-22 17:12 - 00023032 _____ (Wiper Software) C:\WINDOWS\system32\wiperrm.exe
2017-02-22 17:12 - 2017-02-22 17:12 - 00003278 _____ C:\WINDOWS\System32\Tasks\WiperSoft Startup
2017-02-22 17:12 - 2017-02-22 17:12 - 00000786 _____ C:\Users\woya\Desktop\WiperSoft.lnk
2017-02-22 17:12 - 2017-02-22 17:12 - 00000000 ____D C:\Users\woya\AppData\Roaming\WiperSoft
2017-02-22 17:12 - 2017-02-22 17:12 - 00000000 ____D C:\Users\woya\AppData\Local\CrashRpt
2017-02-22 17:12 - 2017-02-22 17:12 - 00000000 ____D C:\Program Files\WiperSoft
2017-02-22 17:11 - 2017-02-22 17:11 - 01944616 _____ (WiperSoft) C:\Users\woya\Downloads\WiperSoft-installer.exe
2017-02-22 16:31 - 2017-02-22 17:32 - 00000000 ____D C:\WINDOWS\pss
2017-02-19 21:08 - 2017-02-19 21:08 - 00000791 _____ C:\Users\woya\Desktop\Start Tor Browser.lnk
2017-02-19 21:07 - 2017-02-19 21:08 - 00000000 ____D C:\Users\woya\Desktop\Tor Browser
2017-02-16 19:09 - 2017-02-20 20:09 - 00000000 ____D C:\Users\woya\Documents\18 WoS Extreme Trucker
2017-02-16 18:49 - 2017-02-16 18:49 - 00001373 _____ C:\Users\Public\Desktop\18 WoS Extreme Trucker.lnk
2017-02-16 18:49 - 2017-02-16 18:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\18 WoS Extreme Trucker
2017-02-16 18:49 - 2017-02-16 18:49 - 00000000 ____D C:\Program Files (x86)\18 WoS Extreme Trucker
2017-02-10 17:35 - 2017-02-10 17:51 - 00000000 ____D C:\ProgramData\Nero
2017-02-10 17:28 - 2017-02-10 17:41 - 00000000 ____D C:\Users\woya\AppData\Roaming\Nero
2017-02-09 16:34 - 2017-02-10 17:40 - 00000000 ____D C:\Users\woya\Desktop\2017 cd
2017-02-05 20:22 - 2017-02-12 20:06 - 00000000 ____D C:\Users\woya\Desktop\garáž inspirace
2017-02-03 21:31 - 2017-02-03 21:31 - 00003366 _____ C:\WINDOWS\System32\Tasks\avastBCLS-1-5-21-3354066490-3795016998-3616670782-1001
2017-02-03 21:30 - 2017-02-03 21:30 - 00004214 _____ C:\WINDOWS\System32\Tasks\avast! BCU UpdateS-1-5-21-3354066490-3795016998-3616670782-1001
2017-02-03 21:30 - 2017-02-03 21:30 - 00001153 _____ C:\Users\woya\Desktop\Avast Browser Cleanup.lnk
2017-02-03 21:30 - 2017-02-03 21:30 - 00000000 ____D C:\Users\woya\AppData\Roaming\Microsoft\Windows\Start Menu\Avast Browser Cleanup
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-23 11:26 - 2016-04-07 20:26 - 00000000 ____D C:\Users\woya\AppData\Roaming\Seznam.cz
2017-02-23 11:26 - 2016-01-31 09:11 - 00000000 ____D C:\ProgramData\CanonIJPLM
2017-02-23 11:25 - 2015-07-29 18:21 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3354066490-3795016998-3616670782-1001
2017-02-23 11:24 - 2015-07-29 18:21 - 00000000 ____D C:\Users\woya\AppData\Local\CrashDumps
2017-02-23 11:22 - 2015-01-17 04:40 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-23 11:22 - 2015-01-17 04:40 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-23 11:22 - 2014-03-18 10:47 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-23 11:22 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2017-02-22 18:02 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-22 16:19 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-21 17:09 - 2015-06-14 18:55 - 00000000 ____D C:\Users\woya\Desktop\psani
2017-02-20 17:48 - 2015-08-20 19:18 - 00000000 ____D C:\Users\woya\AppData\Roaming\vlc
2017-02-20 17:37 - 2016-10-26 19:19 - 00000000 ____D C:\Users\woya\Desktop\ok obrázky
2017-02-19 21:08 - 2016-06-21 07:44 - 00000839 _____ C:\Users\woya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2017-02-19 20:43 - 2015-05-31 18:47 - 00000000 ____D C:\Users\woya\Desktop\obrázky
2017-02-15 14:43 - 2013-08-22 16:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-10 17:34 - 2014-07-25 10:32 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-04 00:00 - 2015-07-29 18:04 - 00000000 ____D C:\Users\woya
2017-02-03 22:00 - 2016-03-29 17:25 - 00002179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-03 21:38 - 2016-03-29 17:18 - 00000000 ____D C:\Users\woya\AppData\Roaming\AVAST Software
2017-02-03 21:38 - 2016-03-29 17:15 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-02 17:10 - 2013-08-22 15:44 - 00381936 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-01-27 21:30 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-27 21:30 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
==================== Files in the root of some directories =======
2016-03-29 13:42 - 2016-03-29 14:19 - 0038334 _____ () C:\Users\woya\AppData\Roaming\+REcovER+axnmj+.png
2016-03-29 13:42 - 2016-03-29 14:19 - 0001041 _____ () C:\Users\woya\AppData\Roaming\+REcovER+axnmj+.txt
2016-03-29 17:25 - 2016-03-29 18:50 - 0038334 _____ () C:\Users\woya\AppData\Roaming\+REcovER+gbsft+.png
2016-03-29 17:25 - 2016-03-29 18:50 - 0001041 _____ () C:\Users\woya\AppData\Roaming\+REcovER+gbsft+.txt
2016-03-28 18:02 - 2016-03-28 18:02 - 0038334 _____ () C:\Users\woya\AppData\Roaming\+REcovER+ppoad+.png
2016-03-28 18:02 - 2016-03-28 18:02 - 0001041 _____ () C:\Users\woya\AppData\Roaming\+REcovER+ppoad+.txt
2016-03-29 13:22 - 2016-03-29 13:22 - 0038334 _____ () C:\Users\woya\AppData\Roaming\+REcovER+qsdah+.png
2016-03-29 13:22 - 2016-03-29 13:22 - 0001041 _____ () C:\Users\woya\AppData\Roaming\+REcovER+qsdah+.txt
2016-03-29 13:42 - 2016-03-29 14:19 - 0038334 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+axnmj+.png
2016-03-29 13:42 - 2016-03-29 14:19 - 0001041 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+axnmj+.txt
2016-03-29 17:23 - 2016-03-29 18:50 - 0038334 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+gbsft+.png
2016-03-29 17:24 - 2016-03-29 18:50 - 0001041 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+gbsft+.txt
2016-03-28 18:02 - 2016-03-28 18:02 - 0038334 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+ppoad+.png
2016-03-28 18:02 - 2016-03-28 18:02 - 0001041 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+ppoad+.txt
2016-03-29 13:22 - 2016-03-29 13:22 - 0038334 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+qsdah+.png
2016-03-29 13:22 - 2016-03-29 13:22 - 0001041 _____ () C:\Users\woya\AppData\Roaming\Microsoft\+REcovER+qsdah+.txt
2016-03-29 13:31 - 2016-03-29 14:17 - 0038334 _____ () C:\Users\woya\AppData\Local\+REcovER+axnmj+.png
2016-03-29 13:31 - 2016-03-29 14:17 - 0001041 _____ () C:\Users\woya\AppData\Local\+REcovER+axnmj+.txt
2016-03-29 17:05 - 2016-03-29 18:48 - 0038334 _____ () C:\Users\woya\AppData\Local\+REcovER+gbsft+.png
2016-03-29 17:05 - 2016-03-29 18:48 - 0001041 _____ () C:\Users\woya\AppData\Local\+REcovER+gbsft+.txt
2016-03-28 17:32 - 2016-03-28 18:01 - 0038334 _____ () C:\Users\woya\AppData\Local\+REcovER+ppoad+.png
2016-03-28 17:32 - 2016-03-28 18:01 - 0001041 _____ () C:\Users\woya\AppData\Local\+REcovER+ppoad+.txt
2016-03-29 13:13 - 2016-03-29 13:21 - 0038334 _____ () C:\Users\woya\AppData\Local\+REcovER+qsdah+.png
2016-03-29 13:13 - 2016-03-29 13:21 - 0001041 _____ () C:\Users\woya\AppData\Local\+REcovER+qsdah+.txt
2015-01-17 04:48 - 2015-01-17 04:48 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2016-04-07 20:48 - 2015-11-23 18:51 - 4964056 _____ (Acer Incorporated) C:\Users\woya\AppData\Local\Temp\AcerDocsSetup.exe
2015-09-09 10:22 - 2015-09-09 10:22 - 7850088 _____ (Microsoft Corporation) C:\Users\woya\AppData\Local\Temp\BingBarSetup-Partner.exe
2015-09-08 09:16 - 2015-09-08 09:16 - 0102912 _____ () C:\Users\woya\AppData\Local\Temp\bitool.dll
2016-04-01 21:54 - 2016-04-01 21:54 - 0467968 _____ (Realtek Semiconductor Corp.) C:\Users\woya\AppData\Local\Temp\COMAP.EXE
2015-05-15 14:57 - 2015-05-15 14:57 - 0027448 _____ (AVG Technologies) C:\Users\woya\AppData\Local\Temp\DseShExt-x64.dll
2015-05-15 14:57 - 2015-05-15 14:57 - 0030008 _____ (AVG Technologies) C:\Users\woya\AppData\Local\Temp\DseShExt-x86.dll
2015-11-12 15:30 - 2014-06-19 17:42 - 7031360 _____ (Foxit Corporation) C:\Users\woya\AppData\Local\Temp\Foxit PhantomPDF Updater.exe
2016-04-07 21:02 - 2014-06-19 17:42 - 7031360 _____ (Foxit Corporation) C:\Users\woya\AppData\Local\Temp\FoxitUpdater.exe
2015-09-22 18:06 - 2015-09-22 18:06 - 2382216 _____ (Mooii) C:\Users\woya\AppData\Local\Temp\GoogleSetup.exe
2017-02-10 17:32 - 2014-03-20 00:55 - 1036288 _____ (Microsoft Corporation) C:\Users\woya\AppData\Local\Temp\kernel32.dll
2015-09-01 12:11 - 2015-09-01 12:11 - 0120336 _____ (McAfee, Inc.) C:\Users\woya\AppData\Local\Temp\McCSPInstall.dll
2016-03-29 18:23 - 2015-09-01 12:11 - 0162120 _____ (McAfee Inc.) C:\Users\woya\AppData\Local\Temp\mccspuninstall.exe
2016-01-31 08:56 - 2015-01-19 19:48 - 1126480 ____N (CANON INC.) C:\Users\woya\AppData\Local\Temp\MSETUP4.EXE
2015-12-11 18:02 - 2015-12-11 18:03 - 62903592 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\oct3A0.tmp.exe
2016-02-17 11:05 - 2016-02-17 11:06 - 63078856 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octA9B3.tmp.exe
2015-08-06 18:10 - 2015-08-06 18:20 - 67114248 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octAF19.tmp.exe
2015-10-16 20:01 - 2015-10-16 20:03 - 67197784 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octB4FF.tmp.exe
2015-12-19 05:16 - 2015-12-19 05:17 - 63066872 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octB55E.tmp.exe
2015-09-02 21:56 - 2015-09-02 21:58 - 67202952 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octBB15.tmp.exe
2016-03-12 23:06 - 2016-03-12 23:06 - 63142648 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octC5AF.tmp.exe
2015-12-04 20:11 - 2015-12-04 20:18 - 62760704 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octCDC7.tmp.exe
2016-03-09 09:13 - 2016-03-09 09:14 - 63143840 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octD498.tmp.exe
2015-10-30 21:49 - 2015-10-30 21:51 - 64809432 _____ (SweetLabs,Inc.) C:\Users\woya\AppData\Local\Temp\octF860.tmp.exe
2015-05-15 14:57 - 2015-05-15 14:57 - 0033080 _____ (AVG Technologies) C:\Users\woya\AppData\Local\Temp\SDShelEx-win32.dll
2015-05-15 14:57 - 2015-05-15 14:57 - 0032056 _____ (AVG Technologies) C:\Users\woya\AppData\Local\Temp\SDShelEx-x64.dll
2016-03-26 21:10 - 2016-03-26 21:10 - 0685568 _____ () C:\Users\woya\AppData\Local\Temp\sqlite-3.8.2-x86-sqlitejdbc.dll
2016-07-03 15:11 - 2016-07-03 15:12 - 30533688 _____ () C:\Users\woya\AppData\Local\Temp\vlc-2.2.4-win32.exe
2016-09-25 06:00 - 2016-09-25 06:00 - 1246584 _____ (Google Inc.) C:\Users\woya\AppData\Local\Temp\{E3206134-7530-4F06-B7CC-238CD47B99DC}-53.0.2785.143_53.0.2785.116_chrome_updater.exe
2017-02-09 16:36 - 2017-02-09 16:36 - 0534528 _____ () C:\Users\woya\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-02-17 17:15
==================== End of FRST.txt ============================