NTB pomalý, zahřívá se a pořád vyskakují varovné hlášky
Napsal: 04 bře 2017 10:23
Zdravím,
prosím o kontrolu logu a rady s řešením vyskytlých problémů.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-03-2017
Ran by uživatel (administrator) on TEREZKA (04-03-2017 09:55:32)
Running from C:\Users\uživatel\Desktop
Loaded Profiles: uživatel (Available Profiles: uživatel & DefaultAppPool)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IEC) C:\Program Files (x86)\BikaQRss\BikaQ.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Microsoft Corporation) C:\Windows\System32\LockAppHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Kephyr) C:\Program Files\FreeFixer\freefixer.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1424896 2011-09-08] (IDT, Inc.)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [43320 2011-09-30] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\WINDOWS\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-04-27] (Synaptics Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2011-10-08] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [574008 2011-07-11] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation)
HKLM-x32\...\Run: [CorelDRAW Graphics Suite 11b] => C:\Program Files (x86)\Corel\Corel Graphics 12\Languages\CZ\Programs\Registration.exe [729088 2004-06-22] (Corel Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-03] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [BackgroundContainerV2] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\uživatel\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation)
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [OfficeSyncProcess] => "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4701888 2017-02-07] (Disc Soft Ltd)
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\MountPoints2: {7c971688-facc-11e6-8d96-a0b3cc6bae6e} - "I:\SETUP.EXE"
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [806400 2016-07-16] (Microsoft Corporation)
HKLM\...\Providers\5u3iln5i: C:\Program Files (x86)\Aqering Launcher\local64spl.dll [306176 2017-02-28] ()
ShellExecuteHooks: No Name - {40B28EE4-FCD3-11E6-B8D8-64006A5CFC23} - C:\Program Files (x86)\Reosetherprutaent\Zopuck.dll [145920 2017-02-28] ()
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2013-02-15]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-01-19]
ShortcutTarget: Dropbox.lnk -> C:\Users\uživatel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2013-03-09]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5afb70c8-cdb5-40fa-9bbf-740a23511bc6}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8a9e1336-47b2-4a9e-9ca2-a29c3d9bbd3d}: [DhcpNameServer] 10.0.0.1 10.0.0.2 10.0.0.3 8.8.8.8
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
URLSearchHook: HKLM-x32 - (No Name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No File
URLSearchHook: HKU\S-1-5-21-2171009598-501426374-144545434-1000 - (No Name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No File
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM -> {4C0FC07B-4777-4901-9592-88F34131FCD9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM-x32 -> {4C0FC07B-4777-4901-9592-88F34131FCD9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=G3A0B1 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {28793F6D-8A28-4058-B57F-F8DE69FFC5D1} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559&CUI=UN30423236243086517&UM=1
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {4C0FC07B-4777-4901-9592-88F34131FCD9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2013-01-09] (pdfforge GbR)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-03] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-03] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: No Name -> {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} -> No File
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll [2013-01-09] (pdfforge GbR)
Toolbar: HKLM-x32 - No Name - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No File
Toolbar: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> No Name - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... BBAKLHBBAX
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
FireFox:
========
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-28]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-28]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: (PDF Architect Converter For Firefox) - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-02-17] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1227197.dll [2017-02-20] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-03] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2013-10-02] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
CHR StartupUrls: Profile 1 -> "hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX"
CHR DefaultSearchURL: Profile 1 -> hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
CHR DefaultSearchKeyword: Profile 1 -> startpageing123
CHR Plugin: (Shockwave Flash) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll => No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\pdf.dll => No File
CHR Plugin: (Norton Confidential) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\npcoplgn.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => No File
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-03] <==== ATTENTION
CHR Extension: (Prezentace Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-11]
CHR Extension: (Dokumenty Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-11]
CHR Extension: (Disk Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-02]
CHR Extension: (YouTube) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-11]
CHR Extension: (Vyhledávání Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-11]
CHR Extension: (Tabulky Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-02]
CHR Extension: (AdBlock) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-28]
CHR Extension: (Avast Online Security) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-01-02]
CHR Extension: (FormApps Chrome Extension) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2017-01-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-28]
CHR Extension: (Citace PRO VUT) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pdhchaeklpanlniilpbkjddfiikjadih [2017-01-02]
CHR Extension: (Gmail) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-11]
CHR Extension: (Chrome Media Router) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-28]
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-02-28]
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-04]
CHR Extension: (Dokumenty Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Disk Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-26]
CHR Extension: (YouTube) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-31]
CHR Extension: (Avast Passwords) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2017-03-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19]
CHR Extension: (AdBlock) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-25]
CHR Extension: (Avast Online Security) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-05]
CHR Extension: (Gmail) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-11]
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\System Profile [2017-02-28]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... BBAKLHBBAX
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-03] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-03] (AVAST Software)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36936 2014-09-18] (Just Develop It) [File not signed] <==== ATTENTION
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-02-07] (Disc Soft Ltd)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 ssinstall; C:\WINDOWS\SysWoW64\ssins.exe [4696960 2016-12-27] (PS Media s.r.o.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-04-27] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\uživatel\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-03-03] (TODO: <Company name>) [File not signed]
R2 WinSnare; C:\Users\uživatel\AppData\Roaming\WinSnare\WinSnare.dll [776192 2017-03-03] (InterSect Alliance Pty Ltd) [File not signed]
S2 ed2kidle; "C:\Program Files (x86)\amuleCexx\ed2k.exe" -downloadwhenidle [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [309272 2017-03-03] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [189768 2017-03-03] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334600 2017-03-03] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [48528 2017-03-03] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-03-03] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32088 2017-03-03] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [126600 2017-03-03] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [100640 2017-03-03] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-03-03] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [993608 2017-03-03] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [547904 2017-03-03] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [162528 2017-03-03] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [337592 2017-03-03] (AVAST Software)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-02-28] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-02-28] (Disc Soft Ltd)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283064 2014-10-16] (Disc Soft Ltd)
S3 iSafeKrnlBoot; C:\WINDOWS\System32\DRIVERS\iSafeKrnlBoot.sys [45224 2015-03-19] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\WINDOWS\System32\DRIVERS\iSafeNetFilter.sys [52392 2015-02-15] (Elex do Brasil Participações Ltda)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 netr28x; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52904 2016-04-27] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30544 2016-02-17] (HP)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-04 09:55 - 2017-03-04 09:56 - 00037764 _____ C:\Users\uživatel\Desktop\FRST.txt
2017-03-04 09:55 - 2017-03-04 09:55 - 00000000 ____D C:\FRST
2017-03-04 09:50 - 2017-03-04 09:55 - 02423808 _____ (Farbar) C:\Users\uživatel\Desktop\FRST64.exe
2017-03-04 09:41 - 2017-03-04 09:41 - 02704615 _____ (Kephyr) C:\Users\uživatel\Downloads\freefixersetup.exe
2017-03-04 09:41 - 2017-03-04 09:41 - 00003066 _____ C:\WINDOWS\System32\Tasks\FreeFixer background scan
2017-03-04 09:41 - 2017-03-04 09:41 - 00000330 _____ C:\WINDOWS\Tasks\FreeFixer background scan.job
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeFixer
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\FreeFixer
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Users\uživatel\AppData\Local\FreeFixer
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Program Files\FreeFixer
2017-03-04 09:33 - 2017-03-04 09:33 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-03-03 22:23 - 2017-03-04 09:53 - 00000000 ____D C:\Program Files (x86)\amuleCexx
2017-03-03 22:23 - 2017-03-03 22:23 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-03-03 22:23 - 2017-03-03 22:23 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\aMule
2017-03-03 22:22 - 2017-03-03 22:22 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.2.3)
2017-03-03 22:18 - 2017-03-03 22:18 - 00398408 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-03-03 17:58 - 2017-03-03 17:58 - 00000000 ____D C:\Users\uživatel\AppData\Local\AVAST Software
2017-03-03 16:03 - 2017-03-03 16:03 - 00000000 ___HD C:\$AV_ASW
2017-03-03 16:03 - 2017-03-03 16:03 - 00000000 ____D C:\Program Files (x86)\MK
2017-03-01 17:02 - 2017-03-04 09:39 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Kyubey
2017-03-01 17:02 - 2017-03-03 22:23 - 00003640 _____ C:\WINDOWS\System32\Tasks\Milimili
2017-03-01 17:02 - 2017-03-03 22:22 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\WinSnare
2017-03-01 17:02 - 2017-03-03 22:22 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\WinSAPSvc
2017-03-01 17:02 - 2017-03-01 17:02 - 00003326 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-03-01 17:02 - 2017-03-01 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-03-01 17:02 - 2017-03-01 17:02 - 00000000 ____D C:\Program Files (x86)\MIO
2017-03-01 17:02 - 2017-03-01 17:02 - 00000000 ____D C:\Program Files (x86)\BikaQRss
2017-03-01 17:01 - 2017-03-01 17:01 - 00000000 ____D C:\Program Files (x86)\5u3iln5i
2017-02-28 15:10 - 2017-02-28 15:10 - 00004110 _____ C:\Users\uživatel\Downloads\Aktivacni_klice_MS_Campus_2010 (1).txt
2017-02-28 14:03 - 2017-02-28 14:03 - 00002766 _____ C:\Users\uživatel\Desktop\Microsoft Outlook 2010.lnk
2017-02-28 14:02 - 2017-02-28 14:02 - 00002798 _____ C:\Users\uživatel\Desktop\Microsoft Word 2010.lnk
2017-02-28 14:02 - 2017-02-28 14:02 - 00002718 _____ C:\Users\uživatel\Desktop\Microsoft Excel 2010.lnk
2017-02-28 14:02 - 2017-02-28 14:02 - 00002702 _____ C:\Users\uživatel\Desktop\Microsoft PowerPoint 2010.lnk
2017-02-28 13:57 - 2017-02-28 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2017-02-28 13:57 - 2017-02-28 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-02-28 13:57 - 2017-02-28 13:57 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-02-28 13:56 - 2017-02-28 13:56 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2017-02-28 13:55 - 2017-02-28 13:55 - 00000000 ____D C:\WINDOWS\PCHEALTH
2017-02-28 13:55 - 2017-02-28 13:55 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
2017-02-28 13:55 - 2017-02-28 13:55 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2017-02-28 13:52 - 2017-02-28 13:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2017-02-28 13:51 - 2017-02-28 13:57 - 00000000 ____D C:\WINDOWS\SHELLNEW
2017-02-28 13:51 - 2017-02-28 13:55 - 00000000 ____D C:\Program Files\Microsoft Office
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 __RHD C:\MSOCache
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2017-02-28 13:22 - 2017-02-28 13:22 - 00000000 ____D C:\Users\uživatel\AppData\Local\Disc_Soft_Ltd
2017-02-28 13:19 - 2017-02-28 13:22 - 00000000 ____D C:\Users\u゙ivatel\AppData\Local\Shihese
2017-02-28 13:19 - 2017-02-28 13:19 - 00006170 _____ C:\WINDOWS\System32\Tasks\Aqering Launcher
2017-02-28 13:19 - 2017-02-28 13:19 - 00000000 ____D C:\Users\u゙ivatel
2017-02-28 13:19 - 2017-02-28 13:19 - 00000000 ____D C:\Program Files (x86)\Aqering Launcher
2017-02-28 13:18 - 2017-03-01 17:02 - 00000000 ____D C:\Program Files (x86)\Reosetherprutaent
2017-02-28 13:18 - 2017-02-28 13:50 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\DAEMON Tools Lite
2017-02-28 13:18 - 2017-02-28 13:21 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2017-02-28 13:18 - 2017-02-28 13:18 - 00047672 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtliteusbbus.sys
2017-02-28 13:18 - 2017-02-28 13:18 - 00030264 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtlitescsibus.sys
2017-02-28 13:18 - 2017-02-28 13:18 - 00005122 _____ C:\WINDOWS\System32\Tasks\Jehity
2017-02-28 13:18 - 2017-02-28 13:18 - 00000000 ____D C:\Users\uživatel\AppData\Local\Shihese
2017-02-28 13:18 - 2017-02-28 13:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2017-02-28 13:17 - 2017-02-28 13:17 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-02-28 13:16 - 2017-02-28 13:16 - 00692072 _____ (Disc Soft Ltd.) C:\Users\uživatel\DTLiteInstaller.exe
2017-02-28 13:11 - 2017-02-28 13:13 - 00000000 ____D C:\Users\uživatel\Desktop\MAMKA
2017-02-28 13:06 - 2017-02-28 13:11 - 00000000 ____D C:\Users\uživatel\Desktop\různé dokumenty
2017-02-28 13:03 - 2017-02-28 13:12 - 00000000 ____D C:\Users\uživatel\Desktop\různé fotky
2017-02-28 13:03 - 2017-02-28 13:11 - 00000000 ____D C:\Users\uživatel\Desktop\ruční práce
2017-02-28 13:02 - 2017-02-28 13:09 - 00000000 ____D C:\Users\uživatel\Desktop\recepty
2017-02-28 12:55 - 2017-02-28 12:55 - 00004110 _____ C:\Users\uživatel\Downloads\Aktivacni_klice_MS_Campus_2010.txt
2017-02-28 12:54 - 2017-02-28 13:09 - 806311936 _____ C:\Users\uživatel\Downloads\SW_DVD5_Office_Professional_Plus_2010_64Bit_Czech_MLF_X16-52577.ISO
2017-02-28 12:54 - 2017-02-28 12:54 - 00004186 _____ C:\Users\uživatel\Downloads\Aktivacni_klice_Win7 a Office 2010.txt
2017-02-28 12:50 - 2017-02-28 12:56 - 238758432 _____ C:\Users\uživatel\Downloads\setup_av_eps.exe
2017-02-09 19:40 - 2017-03-03 22:19 - 00003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-02-09 19:40 - 2017-03-03 22:16 - 00334600 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-02-09 19:40 - 2017-03-03 22:16 - 00309272 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-02-09 19:40 - 2017-03-03 22:16 - 00189768 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-02-09 19:40 - 2017-03-03 22:16 - 00048528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-02-05 09:52 - 2017-02-05 09:52 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-02-05 09:52 - 2017-02-05 09:52 - 00000000 ____D C:\Program Files\Common Files\AV
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-04 09:31 - 2016-01-30 19:24 - 00002584 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-04 09:30 - 2016-01-30 19:24 - 00002596 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-04 09:29 - 2016-10-29 19:58 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-03 22:22 - 2016-10-29 20:39 - 00004006 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1468519780
2017-03-03 22:22 - 2016-07-14 19:09 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-03-03 22:21 - 2016-10-29 20:39 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-03 22:21 - 2013-02-17 10:01 - 00000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForuživatel.job
2017-03-03 22:20 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-03-03 22:18 - 2015-03-19 21:30 - 00547904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00337592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00162528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00126600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00100640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-03-03 22:17 - 2016-07-11 18:58 - 00032088 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-03-03 22:17 - 2015-03-19 21:30 - 00993608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-03-03 22:16 - 2015-03-29 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-03-03 22:15 - 2015-03-29 09:18 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-03-03 22:15 - 2015-03-29 09:18 - 00000000 ____D C:\Program Files (x86)\Java
2017-03-03 22:12 - 2016-10-29 20:06 - 00000000 ____D C:\Users\uživatel
2017-03-03 19:39 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-03 18:01 - 2013-07-24 19:50 - 00002096 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2017-03-03 18:01 - 2011-10-22 01:33 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2017-03-03 15:56 - 2016-10-29 20:39 - 00003264 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForuživatel
2017-03-02 17:55 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-01 19:05 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-01 18:09 - 2013-02-12 20:26 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-28 18:44 - 2016-12-13 21:42 - 00003280 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-28 18:44 - 2015-10-11 11:09 - 00002433 _____ C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-28 18:44 - 2015-10-11 11:09 - 00000000 ___RD C:\Users\uživatel\OneDrive
2017-02-28 15:33 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\System
2017-02-28 15:33 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini
2017-02-28 14:04 - 2016-10-29 19:58 - 00356512 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-28 13:57 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-28 13:55 - 2016-10-29 20:26 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-02-28 13:42 - 2015-10-11 11:02 - 00000000 ____D C:\Users\uživatel\AppData\Local\Packages
2017-02-28 13:41 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-28 13:35 - 2011-10-22 01:30 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2017-02-28 13:24 - 2013-10-06 07:06 - 00000000 ____D C:\Users\uživatel\Downloads\FILMY A SERIÁLY
2017-02-28 13:00 - 2015-03-19 21:27 - 00000000 ____D C:\Program Files\AVAST Software
2017-02-25 09:30 - 2013-07-23 06:29 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-25 09:18 - 2013-02-15 14:10 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-24 21:04 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-18 16:40 - 2013-07-25 18:39 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\uTorrent
2017-02-06 20:48 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 20:48 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2013-02-12 20:22 - 2013-02-12 20:25 - 97565024 _____ () C:\Program Files (x86)\avast_free_antivirus_setup.exe
2014-10-16 18:05 - 2014-03-10 14:43 - 1488486400 _____ () C:\Program Files (x86)\Corel-Draw-12-CZ-(plna-verze-CD1,CD2,CD3)-+-key.iso
2014-10-16 18:06 - 2014-10-16 18:07 - 19862734 _____ () C:\Program Files (x86)\DTLite-setup.exe
2015-06-19 17:43 - 2015-06-19 17:43 - 6402936 _____ (EXP Systems LLC) C:\Program Files (x86)\Install_PDFR_v226.exe
2014-10-25 09:31 - 2014-08-15 11:05 - 151255864 _____ (Malvern Instruments Ltd. ) C:\Program Files (x86)\Malvern-Zetasizer-Software-v703-PSS0012-34-EN-JP.exe
2013-02-17 18:14 - 2013-02-17 18:15 - 25321251 _____ () C:\Program Files (x86)\pdfcreator-setup.exe
2013-02-15 09:40 - 2013-02-15 10:02 - 806311936 _____ () C:\Program Files (x86)\SW_DVD5_Office_Professional_Plus_2010_64Bit_Czech_MLF_X16-52577.ISO
2013-07-25 18:38 - 2013-07-25 18:39 - 1158585 _____ (emc) C:\Program Files (x86)\utorrent-setup.exe
2015-03-18 21:02 - 2015-05-23 08:43 - 0000020 _____ () C:\Users\uživatel\AppData\Roaming\appdataFr3.bin
Files to move or delete:
====================
C:\Users\uživatel\dro_setup.exe
C:\Users\uživatel\DTLiteInstaller.exe
C:\Users\uživatel\HPSupportSolutionsFramework-12.0.30.81.exe
C:\Users\uživatel\sp59155.exe
C:\Users\uživatel\uTorrent221.exe
Some files in TEMP:
====================
2017-01-03 22:26 - 2016-12-01 09:31 - 0050720 _____ (HP Inc.) C:\Users\uživatel\AppData\Local\Temp\ACLMInstaller.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-01 06:49
==================== End of FRST.txt ============================
prosím o kontrolu logu a rady s řešením vyskytlých problémů.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-03-2017
Ran by uživatel (administrator) on TEREZKA (04-03-2017 09:55:32)
Running from C:\Users\uživatel\Desktop
Loaded Profiles: uživatel (Available Profiles: uživatel & DefaultAppPool)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IEC) C:\Program Files (x86)\BikaQRss\BikaQ.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Microsoft Corporation) C:\Windows\System32\LockAppHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Kephyr) C:\Program Files\FreeFixer\freefixer.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1424896 2011-09-08] (IDT, Inc.)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [43320 2011-09-30] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Windows Mobile Device Center] => C:\WINDOWS\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-04-27] (Synaptics Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2011-10-08] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [574008 2011-07-11] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-16] (InstallShield Software Corporation)
HKLM-x32\...\Run: [CorelDRAW Graphics Suite 11b] => C:\Program Files (x86)\Corel\Corel Graphics 12\Languages\CZ\Programs\Registration.exe [729088 2004-06-22] (Corel Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-03] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [BackgroundContainerV2] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\uživatel\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation)
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [OfficeSyncProcess] => "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4701888 2017-02-07] (Disc Soft Ltd)
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-2171009598-501426374-144545434-1000\...\MountPoints2: {7c971688-facc-11e6-8d96-a0b3cc6bae6e} - "I:\SETUP.EXE"
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [806400 2016-07-16] (Microsoft Corporation)
HKLM\...\Providers\5u3iln5i: C:\Program Files (x86)\Aqering Launcher\local64spl.dll [306176 2017-02-28] ()
ShellExecuteHooks: No Name - {40B28EE4-FCD3-11E6-B8D8-64006A5CFC23} - C:\Program Files (x86)\Reosetherprutaent\Zopuck.dll [145920 2017-02-28] ()
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-03] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\uživatel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2013-02-15]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-01-19]
ShortcutTarget: Dropbox.lnk -> C:\Users\uživatel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2013-03-09]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5afb70c8-cdb5-40fa-9bbf-740a23511bc6}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8a9e1336-47b2-4a9e-9ca2-a29c3d9bbd3d}: [DhcpNameServer] 10.0.0.1 10.0.0.2 10.0.0.3 8.8.8.8
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-2171009598-501426374-144545434-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
URLSearchHook: HKLM-x32 - (No Name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No File
URLSearchHook: HKU\S-1-5-21-2171009598-501426374-144545434-1000 - (No Name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No File
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM -> {4C0FC07B-4777-4901-9592-88F34131FCD9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM-x32 -> {4C0FC07B-4777-4901-9592-88F34131FCD9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=G3A0B1 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {28793F6D-8A28-4058-B57F-F8DE69FFC5D1} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1750559&CUI=UN30423236243086517&UM=1
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {4C0FC07B-4777-4901-9592-88F34131FCD9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/710-111095-2958-3/4?mpre=hxxp://www.ebay.co.uk/sch/i.html?_nkw={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2013-01-09] (pdfforge GbR)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-03] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-03] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: No Name -> {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} -> No File
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll [2013-01-09] (pdfforge GbR)
Toolbar: HKLM-x32 - No Name - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - No File
Toolbar: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> No Name - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... BBAKLHBBAX
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2171009598-501426374-144545434-1000 -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
FireFox:
========
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-28]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-28]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: (PDF Architect Converter For Firefox) - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-02-17] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1227197.dll [2017-02-20] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-03] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2013-10-02] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX
CHR StartupUrls: Profile 1 -> "hxxp://www.startpageing123.com/?type=hp&ts=148 ... BBAKLHBBAX"
CHR DefaultSearchURL: Profile 1 -> hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
CHR DefaultSearchKeyword: Profile 1 -> startpageing123
CHR Plugin: (Shockwave Flash) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll => No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\pdf.dll => No File
CHR Plugin: (Norton Confidential) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\npcoplgn.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => No File
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-03] <==== ATTENTION
CHR Extension: (Prezentace Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-11]
CHR Extension: (Dokumenty Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-11]
CHR Extension: (Disk Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-02]
CHR Extension: (YouTube) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-11]
CHR Extension: (Vyhledávání Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-11]
CHR Extension: (Tabulky Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-02]
CHR Extension: (AdBlock) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-28]
CHR Extension: (Avast Online Security) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-01-02]
CHR Extension: (FormApps Chrome Extension) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2017-01-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-28]
CHR Extension: (Citace PRO VUT) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pdhchaeklpanlniilpbkjddfiikjadih [2017-01-02]
CHR Extension: (Gmail) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-11]
CHR Extension: (Chrome Media Router) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-28]
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-02-28]
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-04]
CHR Extension: (Dokumenty Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Disk Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-26]
CHR Extension: (YouTube) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-31]
CHR Extension: (Avast Passwords) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2017-03-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19]
CHR Extension: (AdBlock) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-25]
CHR Extension: (Avast Online Security) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-05]
CHR Extension: (Gmail) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-11]
CHR Profile: C:\Users\uživatel\AppData\Local\Google\Chrome\User Data\System Profile [2017-02-28]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... BBAKLHBBAX
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7147320 2017-03-03] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-03] (AVAST Software)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36936 2014-09-18] (Just Develop It) [File not signed] <==== ATTENTION
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-02-07] (Disc Soft Ltd)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 ssinstall; C:\WINDOWS\SysWoW64\ssins.exe [4696960 2016-12-27] (PS Media s.r.o.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-04-27] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\uživatel\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-03-03] (TODO: <Company name>) [File not signed]
R2 WinSnare; C:\Users\uživatel\AppData\Roaming\WinSnare\WinSnare.dll [776192 2017-03-03] (InterSect Alliance Pty Ltd) [File not signed]
S2 ed2kidle; "C:\Program Files (x86)\amuleCexx\ed2k.exe" -downloadwhenidle [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [309272 2017-03-03] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [189768 2017-03-03] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334600 2017-03-03] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [48528 2017-03-03] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-03-03] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32088 2017-03-03] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [126600 2017-03-03] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [100640 2017-03-03] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [75704 2017-03-03] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [993608 2017-03-03] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [547904 2017-03-03] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [162528 2017-03-03] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [337592 2017-03-03] (AVAST Software)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-02-28] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-02-28] (Disc Soft Ltd)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283064 2014-10-16] (Disc Soft Ltd)
S3 iSafeKrnlBoot; C:\WINDOWS\System32\DRIVERS\iSafeKrnlBoot.sys [45224 2015-03-19] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\WINDOWS\System32\DRIVERS\iSafeNetFilter.sys [52392 2015-02-15] (Elex do Brasil Participações Ltda)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 netr28x; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52904 2016-04-27] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30544 2016-02-17] (HP)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-04 09:55 - 2017-03-04 09:56 - 00037764 _____ C:\Users\uživatel\Desktop\FRST.txt
2017-03-04 09:55 - 2017-03-04 09:55 - 00000000 ____D C:\FRST
2017-03-04 09:50 - 2017-03-04 09:55 - 02423808 _____ (Farbar) C:\Users\uživatel\Desktop\FRST64.exe
2017-03-04 09:41 - 2017-03-04 09:41 - 02704615 _____ (Kephyr) C:\Users\uživatel\Downloads\freefixersetup.exe
2017-03-04 09:41 - 2017-03-04 09:41 - 00003066 _____ C:\WINDOWS\System32\Tasks\FreeFixer background scan
2017-03-04 09:41 - 2017-03-04 09:41 - 00000330 _____ C:\WINDOWS\Tasks\FreeFixer background scan.job
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeFixer
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\FreeFixer
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Users\uživatel\AppData\Local\FreeFixer
2017-03-04 09:41 - 2017-03-04 09:41 - 00000000 ____D C:\Program Files\FreeFixer
2017-03-04 09:33 - 2017-03-04 09:33 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-03-03 22:23 - 2017-03-04 09:53 - 00000000 ____D C:\Program Files (x86)\amuleCexx
2017-03-03 22:23 - 2017-03-03 22:23 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-03-03 22:23 - 2017-03-03 22:23 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\aMule
2017-03-03 22:22 - 2017-03-03 22:22 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.2.3)
2017-03-03 22:18 - 2017-03-03 22:18 - 00398408 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-03-03 17:58 - 2017-03-03 17:58 - 00000000 ____D C:\Users\uživatel\AppData\Local\AVAST Software
2017-03-03 16:03 - 2017-03-03 16:03 - 00000000 ___HD C:\$AV_ASW
2017-03-03 16:03 - 2017-03-03 16:03 - 00000000 ____D C:\Program Files (x86)\MK
2017-03-01 17:02 - 2017-03-04 09:39 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Kyubey
2017-03-01 17:02 - 2017-03-03 22:23 - 00003640 _____ C:\WINDOWS\System32\Tasks\Milimili
2017-03-01 17:02 - 2017-03-03 22:22 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\WinSnare
2017-03-01 17:02 - 2017-03-03 22:22 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\WinSAPSvc
2017-03-01 17:02 - 2017-03-01 17:02 - 00003326 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-03-01 17:02 - 2017-03-01 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-03-01 17:02 - 2017-03-01 17:02 - 00000000 ____D C:\Program Files (x86)\MIO
2017-03-01 17:02 - 2017-03-01 17:02 - 00000000 ____D C:\Program Files (x86)\BikaQRss
2017-03-01 17:01 - 2017-03-01 17:01 - 00000000 ____D C:\Program Files (x86)\5u3iln5i
2017-02-28 15:10 - 2017-02-28 15:10 - 00004110 _____ C:\Users\uživatel\Downloads\Aktivacni_klice_MS_Campus_2010 (1).txt
2017-02-28 14:03 - 2017-02-28 14:03 - 00002766 _____ C:\Users\uživatel\Desktop\Microsoft Outlook 2010.lnk
2017-02-28 14:02 - 2017-02-28 14:02 - 00002798 _____ C:\Users\uživatel\Desktop\Microsoft Word 2010.lnk
2017-02-28 14:02 - 2017-02-28 14:02 - 00002718 _____ C:\Users\uživatel\Desktop\Microsoft Excel 2010.lnk
2017-02-28 14:02 - 2017-02-28 14:02 - 00002702 _____ C:\Users\uživatel\Desktop\Microsoft PowerPoint 2010.lnk
2017-02-28 13:57 - 2017-02-28 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2017-02-28 13:57 - 2017-02-28 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-02-28 13:57 - 2017-02-28 13:57 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-02-28 13:56 - 2017-02-28 13:56 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2017-02-28 13:55 - 2017-02-28 13:55 - 00000000 ____D C:\WINDOWS\PCHEALTH
2017-02-28 13:55 - 2017-02-28 13:55 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
2017-02-28 13:55 - 2017-02-28 13:55 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2017-02-28 13:52 - 2017-02-28 13:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2017-02-28 13:51 - 2017-02-28 13:57 - 00000000 ____D C:\WINDOWS\SHELLNEW
2017-02-28 13:51 - 2017-02-28 13:55 - 00000000 ____D C:\Program Files\Microsoft Office
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 __RHD C:\MSOCache
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-02-28 13:51 - 2017-02-28 13:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2017-02-28 13:22 - 2017-02-28 13:22 - 00000000 ____D C:\Users\uživatel\AppData\Local\Disc_Soft_Ltd
2017-02-28 13:19 - 2017-02-28 13:22 - 00000000 ____D C:\Users\u゙ivatel\AppData\Local\Shihese
2017-02-28 13:19 - 2017-02-28 13:19 - 00006170 _____ C:\WINDOWS\System32\Tasks\Aqering Launcher
2017-02-28 13:19 - 2017-02-28 13:19 - 00000000 ____D C:\Users\u゙ivatel
2017-02-28 13:19 - 2017-02-28 13:19 - 00000000 ____D C:\Program Files (x86)\Aqering Launcher
2017-02-28 13:18 - 2017-03-01 17:02 - 00000000 ____D C:\Program Files (x86)\Reosetherprutaent
2017-02-28 13:18 - 2017-02-28 13:50 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\DAEMON Tools Lite
2017-02-28 13:18 - 2017-02-28 13:21 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2017-02-28 13:18 - 2017-02-28 13:18 - 00047672 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtliteusbbus.sys
2017-02-28 13:18 - 2017-02-28 13:18 - 00030264 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtlitescsibus.sys
2017-02-28 13:18 - 2017-02-28 13:18 - 00005122 _____ C:\WINDOWS\System32\Tasks\Jehity
2017-02-28 13:18 - 2017-02-28 13:18 - 00000000 ____D C:\Users\uživatel\AppData\Local\Shihese
2017-02-28 13:18 - 2017-02-28 13:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2017-02-28 13:17 - 2017-02-28 13:17 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-02-28 13:16 - 2017-02-28 13:16 - 00692072 _____ (Disc Soft Ltd.) C:\Users\uživatel\DTLiteInstaller.exe
2017-02-28 13:11 - 2017-02-28 13:13 - 00000000 ____D C:\Users\uživatel\Desktop\MAMKA
2017-02-28 13:06 - 2017-02-28 13:11 - 00000000 ____D C:\Users\uživatel\Desktop\různé dokumenty
2017-02-28 13:03 - 2017-02-28 13:12 - 00000000 ____D C:\Users\uživatel\Desktop\různé fotky
2017-02-28 13:03 - 2017-02-28 13:11 - 00000000 ____D C:\Users\uživatel\Desktop\ruční práce
2017-02-28 13:02 - 2017-02-28 13:09 - 00000000 ____D C:\Users\uživatel\Desktop\recepty
2017-02-28 12:55 - 2017-02-28 12:55 - 00004110 _____ C:\Users\uživatel\Downloads\Aktivacni_klice_MS_Campus_2010.txt
2017-02-28 12:54 - 2017-02-28 13:09 - 806311936 _____ C:\Users\uživatel\Downloads\SW_DVD5_Office_Professional_Plus_2010_64Bit_Czech_MLF_X16-52577.ISO
2017-02-28 12:54 - 2017-02-28 12:54 - 00004186 _____ C:\Users\uživatel\Downloads\Aktivacni_klice_Win7 a Office 2010.txt
2017-02-28 12:50 - 2017-02-28 12:56 - 238758432 _____ C:\Users\uživatel\Downloads\setup_av_eps.exe
2017-02-09 19:40 - 2017-03-03 22:19 - 00003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-02-09 19:40 - 2017-03-03 22:16 - 00334600 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-02-09 19:40 - 2017-03-03 22:16 - 00309272 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-02-09 19:40 - 2017-03-03 22:16 - 00189768 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-02-09 19:40 - 2017-03-03 22:16 - 00048528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-02-05 09:52 - 2017-02-05 09:52 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-02-05 09:52 - 2017-02-05 09:52 - 00000000 ____D C:\Program Files\Common Files\AV
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-04 09:31 - 2016-01-30 19:24 - 00002584 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-04 09:30 - 2016-01-30 19:24 - 00002596 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-04 09:29 - 2016-10-29 19:58 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-03 22:22 - 2016-10-29 20:39 - 00004006 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1468519780
2017-03-03 22:22 - 2016-07-14 19:09 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-03-03 22:21 - 2016-10-29 20:39 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-03 22:21 - 2013-02-17 10:01 - 00000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForuživatel.job
2017-03-03 22:20 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-03-03 22:18 - 2015-03-19 21:30 - 00547904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00337592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00162528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00126600 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00100640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00075704 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-03-03 22:18 - 2015-03-19 21:30 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-03-03 22:17 - 2016-07-11 18:58 - 00032088 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-03-03 22:17 - 2015-03-19 21:30 - 00993608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-03-03 22:16 - 2015-03-29 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-03-03 22:15 - 2015-03-29 09:18 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-03-03 22:15 - 2015-03-29 09:18 - 00000000 ____D C:\Program Files (x86)\Java
2017-03-03 22:12 - 2016-10-29 20:06 - 00000000 ____D C:\Users\uživatel
2017-03-03 19:39 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-03 18:01 - 2013-07-24 19:50 - 00002096 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2017-03-03 18:01 - 2011-10-22 01:33 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2017-03-03 15:56 - 2016-10-29 20:39 - 00003264 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForuživatel
2017-03-02 17:55 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-01 19:05 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-01 18:09 - 2013-02-12 20:26 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-28 18:44 - 2016-12-13 21:42 - 00003280 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-28 18:44 - 2015-10-11 11:09 - 00002433 _____ C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-28 18:44 - 2015-10-11 11:09 - 00000000 ___RD C:\Users\uživatel\OneDrive
2017-02-28 15:33 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\System
2017-02-28 15:33 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini
2017-02-28 14:04 - 2016-10-29 19:58 - 00356512 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-28 13:57 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-28 13:55 - 2016-10-29 20:26 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-02-28 13:42 - 2015-10-11 11:02 - 00000000 ____D C:\Users\uživatel\AppData\Local\Packages
2017-02-28 13:41 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-28 13:35 - 2011-10-22 01:30 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2017-02-28 13:24 - 2013-10-06 07:06 - 00000000 ____D C:\Users\uživatel\Downloads\FILMY A SERIÁLY
2017-02-28 13:00 - 2015-03-19 21:27 - 00000000 ____D C:\Program Files\AVAST Software
2017-02-25 09:30 - 2013-07-23 06:29 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-25 09:18 - 2013-02-15 14:10 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-24 21:04 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-18 16:40 - 2013-07-25 18:39 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\uTorrent
2017-02-06 20:48 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 20:48 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2013-02-12 20:22 - 2013-02-12 20:25 - 97565024 _____ () C:\Program Files (x86)\avast_free_antivirus_setup.exe
2014-10-16 18:05 - 2014-03-10 14:43 - 1488486400 _____ () C:\Program Files (x86)\Corel-Draw-12-CZ-(plna-verze-CD1,CD2,CD3)-+-key.iso
2014-10-16 18:06 - 2014-10-16 18:07 - 19862734 _____ () C:\Program Files (x86)\DTLite-setup.exe
2015-06-19 17:43 - 2015-06-19 17:43 - 6402936 _____ (EXP Systems LLC) C:\Program Files (x86)\Install_PDFR_v226.exe
2014-10-25 09:31 - 2014-08-15 11:05 - 151255864 _____ (Malvern Instruments Ltd. ) C:\Program Files (x86)\Malvern-Zetasizer-Software-v703-PSS0012-34-EN-JP.exe
2013-02-17 18:14 - 2013-02-17 18:15 - 25321251 _____ () C:\Program Files (x86)\pdfcreator-setup.exe
2013-02-15 09:40 - 2013-02-15 10:02 - 806311936 _____ () C:\Program Files (x86)\SW_DVD5_Office_Professional_Plus_2010_64Bit_Czech_MLF_X16-52577.ISO
2013-07-25 18:38 - 2013-07-25 18:39 - 1158585 _____ (emc) C:\Program Files (x86)\utorrent-setup.exe
2015-03-18 21:02 - 2015-05-23 08:43 - 0000020 _____ () C:\Users\uživatel\AppData\Roaming\appdataFr3.bin
Files to move or delete:
====================
C:\Users\uživatel\dro_setup.exe
C:\Users\uživatel\DTLiteInstaller.exe
C:\Users\uživatel\HPSupportSolutionsFramework-12.0.30.81.exe
C:\Users\uživatel\sp59155.exe
C:\Users\uživatel\uTorrent221.exe
Some files in TEMP:
====================
2017-01-03 22:26 - 2016-12-01 09:31 - 0050720 _____ (HP Inc.) C:\Users\uživatel\AppData\Local\Temp\ACLMInstaller.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-01 06:49
==================== End of FRST.txt ============================