ukrdl mi vyhledávač DĚKUJI http://www.startpageing123.com
Napsal: 14 bře 2017 18:29
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2017
Ran by Gerard (administrator) on GERARD-OSOBNÍ (14-03-2017 18:00:28)
Running from C:\Users\Gerard\Desktop
Loaded Profiles: Gerard (Available Profiles: Gerard)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files (x86)\ASUSTek Computer Inc\ASUS U3100MINI PLUS V2 Utilities\RTLRCtl.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(hxxp://www.amuleall.org/) C:\Config.Msi\19937a.rbf
() C:\Program Files (x86)\Explorer\iedvutils.exe
() C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Program Files (x86)\Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files (x86)\Explorer\iexplore.exe
(forum.viry.cz) C:\Users\Gerard\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-10-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Driver Genius] => [X]
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\RunOnce: [RealtekHDAUpgrade] => RealtekHDAUpgrade
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\...\MountPoints2: {6ca2659c-6527-11e5-9b2e-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2015-10-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Remote Control.lnk [2015-09-27]
ShortcutTarget: Remote Control.lnk -> C:\Program Files (x86)\ASUSTek Computer Inc\ASUS U3100MINI PLUS V2 Utilities\RTLRCtl.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk [2016-01-09]
ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-03-14]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0ED6F968-6050-48DF-B7B8-4092160D0869}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://seznam.cz/
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-4194783695-2281227778-3063890349-1001 -> {2313AC38-BA14-4797-8175-B74E8B13C266} URL =
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Gerard\AppData\Roaming\Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227 [2017-03-14]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227 -> startpageing123
FF Homepage: Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227 -> hxxps://www.seznam.cz/
FF SearchPlugin: C:\Users\Gerard\AppData\Roaming\Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227\searchplugins\startpageing123.xml [2017-03-14]
FF ProfilePath: C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227 [2017-03-14]
FF Homepage: Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227 -> hxxps://www.seznam.cz/
FF Extension: (SimilarWeb) - C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-03-14] [not signed]
FF Extension: (FF Adr) - C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-03-14] [not signed]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\Extensions\langpack-cs@firefox.mozilla.org.xpi [2017-03-14] [not signed]
FF SearchPlugin: C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\searchplugins\startsearch.xml [2017-03-14]
FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Gerard\AppData\Roaming\Mozilla\Firefox\Profiles\7r0jcc5e.default\extensions\deskCutv2@gmail.com => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-27] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-27] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-13] (NVIDIA Corporation)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [104624 2017-03-10] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-10-13] (NVIDIA Corporation)
R2 iedvutils; C:\Program Files (x86)\Explorer\iedvutils.exe [89272 2017-03-14] ()
S2 Kyubey; C:\Users\Gerard\AppData\Roaming\Kyubey\Kyubey.exe [113664 2017-03-14] () [File not signed]
S2 MustangService_2015_10_10; C:\ProgramData\TempMoudleSet\MustangSer336.exe [235776 2015-12-15] (MustangService)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-10-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-10-13] (NVIDIA Corporation)
S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [24576 2017-03-14] (Realtek Semiconductor.) [File not signed]
R2 wimApSrv; C:\ProgramData\VMware\VMware Service\vmAutoStart.dll [105984 2017-03-14] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Gerard\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-03-14] (Windows) [File not signed]
R2 WinSnare; C:\Users\Gerard\AppData\Roaming\WinSnare\WinSnare.dll [776704 2017-03-14] (InterSect Alliance Pty Ltd) [File not signed] <==== ATTENTION
R2 ed2kidle; "C:\Program Files (x86)\amulell\ed2k.exe" -downloadwhenidle [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 ASUSVRC64; C:\Windows\System32\DRIVERS\AsusVRC64.sys [23424 2008-10-13] (ASUSTeK COMPUTER INC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-01-03] ()
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-10-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-10-13] (NVIDIA Corporation)
S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [521944 2013-09-12] (Realtek Semiconductor Corporation )
R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16056 2017-03-14] (SlimWare Utilities, Inc.)
S3 AIDA64Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [X]
S3 ATICDSDr; \??\C:\Users\Gerard\AppData\Local\Temp\ATICDSDr.sys [X] <==== ATTENTION
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S1 iSafeKrnlMon; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 18:00 - 2017-03-14 18:00 - 00015327 _____ C:\Users\Gerard\Desktop\LM.bat
2017-03-14 18:00 - 2017-03-14 18:00 - 00015055 _____ C:\Users\Gerard\Desktop\FRST.txt
2017-03-14 17:59 - 2017-03-14 18:00 - 00029696 _____ C:\Users\Gerard\AppData\Local\MSGBOX.EXE
2017-03-14 17:59 - 2017-03-14 18:00 - 00000000 ____D C:\FRST
2017-03-14 17:57 - 2017-03-14 17:57 - 02424832 _____ (Farbar) C:\Users\Gerard\Desktop\FRST64.exe
2017-03-14 17:57 - 2017-03-14 17:57 - 00112640 _____ (forum.viry.cz) C:\Users\Gerard\Desktop\FRSTLauncher.exe
2017-03-14 17:44 - 2017-03-14 17:44 - 00000000 ____D C:\Windows\SysWOW64\WinFast
2017-03-14 17:31 - 2017-03-14 17:31 - 00002142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-14 17:31 - 2017-03-14 17:31 - 00002072 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\Users\Gerard\AppData\Local\Noflat
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\Users\Gerard\AppData\Local\Google
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\ProgramData\VMware
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\Program Files (x86)\Noflat
2017-03-14 17:29 - 2017-03-14 17:31 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-03-14 17:29 - 2017-03-14 17:29 - 00000000 ____D C:\Windows\system32\log
2017-03-14 17:29 - 2016-05-23 03:41 - 00055056 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
2017-03-14 17:29 - 2016-05-19 07:42 - 00052392 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
2017-03-14 17:27 - 2017-03-14 17:51 - 00000000 ____D C:\Users\Gerard\AppData\LocalLow\Mozilla
2017-03-14 17:26 - 2017-03-14 17:26 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\Firefox
2017-03-14 17:26 - 2017-03-14 17:26 - 00000000 ____D C:\Users\Gerard\AppData\Local\Firefox
2017-03-14 17:26 - 2017-03-14 17:26 - 00000000 ____D C:\Program Files (x86)\Firefox
2017-03-14 17:25 - 2017-03-14 17:47 - 00000000 ____D C:\Windows\system32\appmgmt
2017-03-14 17:23 - 2017-03-14 17:36 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-03-14 17:23 - 2017-03-14 17:23 - 00001873 _____ C:\Users\Public\Desktop\Internet Explorer.lnk
2017-03-14 17:23 - 2017-03-14 17:23 - 00000000 ____D C:\Program Files (x86)\Explorer
2017-03-14 17:20 - 2017-03-14 17:20 - 00000000 ____D C:\Program Files (x86)\n1
2017-03-14 17:19 - 2017-03-14 17:43 - 00000000 ____D C:\Program Files (x86)\BikaQRss
2017-03-14 17:19 - 2017-03-14 17:20 - 00003576 _____ C:\Windows\System32\Tasks\Milimili
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\WinSnare
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\WinSAPSvc
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\Kyubey
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Program Files (x86)\MIO
2017-03-14 16:57 - 2000-01-01 01:00 - 01028352 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2017-03-14 16:57 - 2000-01-01 01:00 - 00082544 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2017-03-14 16:18 - 2017-03-14 16:22 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\TP-LINK
2017-03-14 16:18 - 2017-03-14 16:18 - 00002271 _____ C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk
2017-03-14 16:18 - 2017-03-14 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
2017-03-14 16:17 - 2017-03-14 16:17 - 00000000 ____D C:\Program Files (x86)\TP-LINK
2017-03-14 16:16 - 2015-06-19 02:54 - 03741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys
2017-03-14 16:16 - 2015-06-19 02:54 - 03741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys
2017-03-14 16:16 - 2015-06-19 02:54 - 00030472 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll
2017-03-14 16:16 - 2015-06-19 02:53 - 00028467 _____ C:\Windows\system32\netrtwlanu.cat
2017-03-14 16:16 - 2015-02-16 15:19 - 00008320 _____ C:\Windows\system32\rtlCoInst.dat
2017-03-14 16:15 - 2017-03-14 16:16 - 00000000 ____D C:\ProgramData\TP-LINK
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 17:58 - 2016-01-03 15:03 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2017-03-14 17:58 - 2016-01-03 15:03 - 00000000 ____D C:\Windows\system32\DAX2
2017-03-14 17:58 - 2015-09-27 16:04 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-03-14 17:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2017-03-14 17:47 - 2009-07-14 05:45 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-03-14 17:47 - 2009-07-14 05:45 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-03-14 17:44 - 2015-09-27 16:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-03-14 17:29 - 2015-09-27 16:01 - 00001713 _____ C:\Users\Gerard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2017-03-14 17:27 - 2009-07-14 16:18 - 00668866 _____ C:\Windows\system32\perfh005.dat
2017-03-14 17:27 - 2009-07-14 16:18 - 00141526 _____ C:\Windows\system32\perfc005.dat
2017-03-14 17:27 - 2009-07-14 06:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-14 17:26 - 2015-09-27 16:52 - 00002291 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-03-14 17:26 - 2015-09-27 16:52 - 00002221 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-03-14 17:24 - 2015-09-27 17:21 - 00000000 ____D C:\Program Files (x86)\RayDld
2017-03-14 17:23 - 2015-09-27 16:01 - 00002664 _____ C:\Users\Gerard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-14 17:16 - 2015-10-01 20:04 - 00002840 _____ C:\Windows\System32\Tasks\SlimDrivers Startup
2017-03-14 17:16 - 2015-10-01 20:04 - 00000412 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2017-03-14 17:16 - 2015-10-01 20:03 - 00016056 _____ (SlimWare Utilities, Inc.) C:\Windows\system32\Drivers\SWDUMon.sys
2017-03-14 17:15 - 2015-09-27 17:00 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-14 17:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-14 16:57 - 2015-09-27 16:05 - 00000000 ____D C:\Program Files (x86)\Realtek
==================== Files in the root of some directories =======
2017-03-14 17:59 - 2017-03-14 18:00 - 0029696 _____ () C:\Users\Gerard\AppData\Local\MSGBOX.EXE
2015-10-02 09:34 - 2015-10-02 09:34 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2015-09-27 17:48 - 2015-09-27 17:48 - 0983320 _____ (Soft Installer ) C:\Users\Gerard\AppData\Local\Temp\ICReinstall_realtek-high-definition-audio-driver.exe
2015-09-27 17:00 - 2014-07-02 18:44 - 1214048 _____ (NVIDIA Corporation) C:\Users\Gerard\AppData\Local\Temp\nvSCPAPI.dll
2015-09-27 17:00 - 2014-07-02 18:44 - 0411936 _____ (NVIDIA Corporation) C:\Users\Gerard\AppData\Local\Temp\nvSCPAPISvr.exe
2016-01-03 14:43 - 2014-07-02 18:44 - 0826712 _____ (NVIDIA Corporation) C:\Users\Gerard\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-19 11:13
==================== End of FRST.txt ============================
Ran by Gerard (administrator) on GERARD-OSOBNÍ (14-03-2017 18:00:28)
Running from C:\Users\Gerard\Desktop
Loaded Profiles: Gerard (Available Profiles: Gerard)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files (x86)\ASUSTek Computer Inc\ASUS U3100MINI PLUS V2 Utilities\RTLRCtl.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(hxxp://www.amuleall.org/) C:\Config.Msi\19937a.rbf
() C:\Program Files (x86)\Explorer\iedvutils.exe
() C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Program Files (x86)\Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files (x86)\Explorer\iexplore.exe
(forum.viry.cz) C:\Users\Gerard\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-10-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Driver Genius] => [X]
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\RunOnce: [RealtekHDAUpgrade] => RealtekHDAUpgrade
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\...\MountPoints2: {6ca2659c-6527-11e5-9b2e-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2015-10-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Remote Control.lnk [2015-09-27]
ShortcutTarget: Remote Control.lnk -> C:\Program Files (x86)\ASUSTek Computer Inc\ASUS U3100MINI PLUS V2 Utilities\RTLRCtl.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk [2016-01-09]
ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-03-14]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0ED6F968-6050-48DF-B7B8-4092160D0869}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1443 ... earchTerms}
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://seznam.cz/
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=148 ... J90Z105457
HKU\S-1-5-21-4194783695-2281227778-3063890349-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds ... earchTerms}
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-4194783695-2281227778-3063890349-1001 -> {2313AC38-BA14-4797-8175-B74E8B13C266} URL =
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Gerard\AppData\Roaming\Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227 [2017-03-14]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227 -> startpageing123
FF Homepage: Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227 -> hxxps://www.seznam.cz/
FF SearchPlugin: C:\Users\Gerard\AppData\Roaming\Mozilla\Firefox\Profiles\na8rv4k9.default-1452362835227\searchplugins\startpageing123.xml [2017-03-14]
FF ProfilePath: C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227 [2017-03-14]
FF Homepage: Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227 -> hxxps://www.seznam.cz/
FF Extension: (SimilarWeb) - C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\Extensions\@DA3566E2-F709-11E5-8E87-A604BC8E7F8B.xpi [2017-03-14] [not signed]
FF Extension: (FF Adr) - C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2017-03-14] [not signed]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\Extensions\langpack-cs@firefox.mozilla.org.xpi [2017-03-14] [not signed]
FF SearchPlugin: C:\Users\Gerard\AppData\Roaming\Firefox\Firefox\Profiles\na8rv4k9.default-1452362835227\searchplugins\startsearch.xml [2017-03-14]
FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Gerard\AppData\Roaming\Mozilla\Firefox\Profiles\7r0jcc5e.default\extensions\deskCutv2@gmail.com => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-27] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-27] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-13] (NVIDIA Corporation)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [104624 2017-03-10] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-10-13] (NVIDIA Corporation)
R2 iedvutils; C:\Program Files (x86)\Explorer\iedvutils.exe [89272 2017-03-14] ()
S2 Kyubey; C:\Users\Gerard\AppData\Roaming\Kyubey\Kyubey.exe [113664 2017-03-14] () [File not signed]
S2 MustangService_2015_10_10; C:\ProgramData\TempMoudleSet\MustangSer336.exe [235776 2015-12-15] (MustangService)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-10-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-10-13] (NVIDIA Corporation)
S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [24576 2017-03-14] (Realtek Semiconductor.) [File not signed]
R2 wimApSrv; C:\ProgramData\VMware\VMware Service\vmAutoStart.dll [105984 2017-03-14] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Gerard\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-03-14] (Windows) [File not signed]
R2 WinSnare; C:\Users\Gerard\AppData\Roaming\WinSnare\WinSnare.dll [776704 2017-03-14] (InterSect Alliance Pty Ltd) [File not signed] <==== ATTENTION
R2 ed2kidle; "C:\Program Files (x86)\amulell\ed2k.exe" -downloadwhenidle [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 ASUSVRC64; C:\Windows\System32\DRIVERS\AsusVRC64.sys [23424 2008-10-13] (ASUSTeK COMPUTER INC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-01-03] ()
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-10-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-10-13] (NVIDIA Corporation)
S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [521944 2013-09-12] (Realtek Semiconductor Corporation )
R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16056 2017-03-14] (SlimWare Utilities, Inc.)
S3 AIDA64Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [X]
S3 ATICDSDr; \??\C:\Users\Gerard\AppData\Local\Temp\ATICDSDr.sys [X] <==== ATTENTION
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S1 iSafeKrnlMon; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 18:00 - 2017-03-14 18:00 - 00015327 _____ C:\Users\Gerard\Desktop\LM.bat
2017-03-14 18:00 - 2017-03-14 18:00 - 00015055 _____ C:\Users\Gerard\Desktop\FRST.txt
2017-03-14 17:59 - 2017-03-14 18:00 - 00029696 _____ C:\Users\Gerard\AppData\Local\MSGBOX.EXE
2017-03-14 17:59 - 2017-03-14 18:00 - 00000000 ____D C:\FRST
2017-03-14 17:57 - 2017-03-14 17:57 - 02424832 _____ (Farbar) C:\Users\Gerard\Desktop\FRST64.exe
2017-03-14 17:57 - 2017-03-14 17:57 - 00112640 _____ (forum.viry.cz) C:\Users\Gerard\Desktop\FRSTLauncher.exe
2017-03-14 17:44 - 2017-03-14 17:44 - 00000000 ____D C:\Windows\SysWOW64\WinFast
2017-03-14 17:31 - 2017-03-14 17:31 - 00002142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-14 17:31 - 2017-03-14 17:31 - 00002072 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\Users\Gerard\AppData\Local\Noflat
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\Users\Gerard\AppData\Local\Google
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\ProgramData\VMware
2017-03-14 17:31 - 2017-03-14 17:31 - 00000000 ____D C:\Program Files (x86)\Noflat
2017-03-14 17:29 - 2017-03-14 17:31 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-03-14 17:29 - 2017-03-14 17:29 - 00000000 ____D C:\Windows\system32\log
2017-03-14 17:29 - 2016-05-23 03:41 - 00055056 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
2017-03-14 17:29 - 2016-05-19 07:42 - 00052392 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
2017-03-14 17:27 - 2017-03-14 17:51 - 00000000 ____D C:\Users\Gerard\AppData\LocalLow\Mozilla
2017-03-14 17:26 - 2017-03-14 17:26 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\Firefox
2017-03-14 17:26 - 2017-03-14 17:26 - 00000000 ____D C:\Users\Gerard\AppData\Local\Firefox
2017-03-14 17:26 - 2017-03-14 17:26 - 00000000 ____D C:\Program Files (x86)\Firefox
2017-03-14 17:25 - 2017-03-14 17:47 - 00000000 ____D C:\Windows\system32\appmgmt
2017-03-14 17:23 - 2017-03-14 17:36 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-03-14 17:23 - 2017-03-14 17:23 - 00001873 _____ C:\Users\Public\Desktop\Internet Explorer.lnk
2017-03-14 17:23 - 2017-03-14 17:23 - 00000000 ____D C:\Program Files (x86)\Explorer
2017-03-14 17:20 - 2017-03-14 17:20 - 00000000 ____D C:\Program Files (x86)\n1
2017-03-14 17:19 - 2017-03-14 17:43 - 00000000 ____D C:\Program Files (x86)\BikaQRss
2017-03-14 17:19 - 2017-03-14 17:20 - 00003576 _____ C:\Windows\System32\Tasks\Milimili
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\WinSnare
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\WinSAPSvc
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\Kyubey
2017-03-14 17:19 - 2017-03-14 17:19 - 00000000 ____D C:\Program Files (x86)\MIO
2017-03-14 16:57 - 2000-01-01 01:00 - 01028352 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2017-03-14 16:57 - 2000-01-01 01:00 - 00082544 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2017-03-14 16:18 - 2017-03-14 16:22 - 00000000 ____D C:\Users\Gerard\AppData\Roaming\TP-LINK
2017-03-14 16:18 - 2017-03-14 16:18 - 00002271 _____ C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk
2017-03-14 16:18 - 2017-03-14 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
2017-03-14 16:17 - 2017-03-14 16:17 - 00000000 ____D C:\Program Files (x86)\TP-LINK
2017-03-14 16:16 - 2015-06-19 02:54 - 03741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys
2017-03-14 16:16 - 2015-06-19 02:54 - 03741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys
2017-03-14 16:16 - 2015-06-19 02:54 - 00030472 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll
2017-03-14 16:16 - 2015-06-19 02:53 - 00028467 _____ C:\Windows\system32\netrtwlanu.cat
2017-03-14 16:16 - 2015-02-16 15:19 - 00008320 _____ C:\Windows\system32\rtlCoInst.dat
2017-03-14 16:15 - 2017-03-14 16:16 - 00000000 ____D C:\ProgramData\TP-LINK
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 17:58 - 2016-01-03 15:03 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2017-03-14 17:58 - 2016-01-03 15:03 - 00000000 ____D C:\Windows\system32\DAX2
2017-03-14 17:58 - 2015-09-27 16:04 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-03-14 17:58 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2017-03-14 17:47 - 2009-07-14 05:45 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-03-14 17:47 - 2009-07-14 05:45 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-03-14 17:44 - 2015-09-27 16:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-03-14 17:29 - 2015-09-27 16:01 - 00001713 _____ C:\Users\Gerard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2017-03-14 17:27 - 2009-07-14 16:18 - 00668866 _____ C:\Windows\system32\perfh005.dat
2017-03-14 17:27 - 2009-07-14 16:18 - 00141526 _____ C:\Windows\system32\perfc005.dat
2017-03-14 17:27 - 2009-07-14 06:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-14 17:26 - 2015-09-27 16:52 - 00002291 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-03-14 17:26 - 2015-09-27 16:52 - 00002221 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-03-14 17:24 - 2015-09-27 17:21 - 00000000 ____D C:\Program Files (x86)\RayDld
2017-03-14 17:23 - 2015-09-27 16:01 - 00002664 _____ C:\Users\Gerard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-14 17:16 - 2015-10-01 20:04 - 00002840 _____ C:\Windows\System32\Tasks\SlimDrivers Startup
2017-03-14 17:16 - 2015-10-01 20:04 - 00000412 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2017-03-14 17:16 - 2015-10-01 20:03 - 00016056 _____ (SlimWare Utilities, Inc.) C:\Windows\system32\Drivers\SWDUMon.sys
2017-03-14 17:15 - 2015-09-27 17:00 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-14 17:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-14 16:57 - 2015-09-27 16:05 - 00000000 ____D C:\Program Files (x86)\Realtek
==================== Files in the root of some directories =======
2017-03-14 17:59 - 2017-03-14 18:00 - 0029696 _____ () C:\Users\Gerard\AppData\Local\MSGBOX.EXE
2015-10-02 09:34 - 2015-10-02 09:34 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2015-09-27 17:48 - 2015-09-27 17:48 - 0983320 _____ (Soft Installer ) C:\Users\Gerard\AppData\Local\Temp\ICReinstall_realtek-high-definition-audio-driver.exe
2015-09-27 17:00 - 2014-07-02 18:44 - 1214048 _____ (NVIDIA Corporation) C:\Users\Gerard\AppData\Local\Temp\nvSCPAPI.dll
2015-09-27 17:00 - 2014-07-02 18:44 - 0411936 _____ (NVIDIA Corporation) C:\Users\Gerard\AppData\Local\Temp\nvSCPAPISvr.exe
2016-01-03 14:43 - 2014-07-02 18:44 - 0826712 _____ (NVIDIA Corporation) C:\Users\Gerard\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-19 11:13
==================== End of FRST.txt ============================