Problem s starem Windows 8.1 ... preparing repair
Napsal: 19 bře 2017 23:19
Dobry vecer, poprosim vas o kontrolu logu. Notebook ma problemy s nabootovnim windows.
Spustil sa az po xy pokusoch. Pred spustenim som nahradil v system32/config SAM,SECURITY,SYSTEM,software,default z datumu 3.3.2017
Pri starte vyhodi 2x chybu Rundll .... zasuvny modul sa nepodarilo najst.
Posielam log pre kontrolu na viry
Vopred dakujem
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Mato (administrator) on MATO (19-03-2017 23:04:39)
Running from C:\Users\Mato\Downloads
Loaded Profiles: Mato (Available Profiles: Mato)
Platform: Windows 8.1 (Update) (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
() C:\Windows\SysWOW64\SecUPDUtilSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Pokki) C:\Users\Mato\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.18384_none_fa1d93c39b41b41a\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\GenValObj.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\ByteCodeGenerator.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13261456 2012-12-10] (Realtek Semiconductor)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA Corporation)
HKLM\...\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [63432 2017-03-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-18] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [Steam] => D:\Hry\Skyrim\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [uTorrent] => C:\Users\Mato\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-27] (BitTorrent Inc.)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [Facebook Update] => C:\Users\Mato\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-15] (Facebook Inc.)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\RunOnce: [Application Restart #1] => C:\Users\Mato\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [7875640 2015-10-30] (Pokki)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\RunOnce: [Application Restart #0] => C:\Users\Mato\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [7875640 2015-10-30] (Pokki)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 77.48.221.10 10.0.0.1
Tcpip\..\Interfaces\{30F310FD-3790-491C-BE59-01522AFED992}: [DhcpNameServer] 77.48.221.10 10.0.0.1
Tcpip\..\Interfaces\{F8F8D734-DADE-4225-9508-26EA3C586CF3}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={F7975B19-B5B8-11E2-BE81-6036DDB09CE8}
SearchScopes: HKU\S-1-5-21-4204622686-3959268731-1216914738-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-25] (Oracle Corporation)
BHO-x32: Rich Media Downloader -> {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} -> C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll => No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-25] (Oracle Corporation)
BHO-x32: No Name -> {FEB703F7-E7B2-4AB0-9566-87658AC70095} -> No File
FireFox:
========
FF ProfilePath: C:\Users\Mato\AppData\Roaming\Mozilla\Firefox\Profiles\7wFYJ7DL.default [not found]
FF HKLM-x32\...\Firefox\Extensions: [{3DF4B26D-DB19-45DF-962A-6719D071245B}] - C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B} => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [No File]
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-25] (Oracle Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-31] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin-x32: @richmediaplayer.com/nppluginrichmediaplayer -> C:\Program Files (x86)\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-05-08] ()
FF Plugin HKU\S-1-5-21-4204622686-3959268731-1216914738-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mato\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-4204622686-3959268731-1216914738-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default [2017-03-19]
CHR Extension: (Adblock Plus) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-19]
CHR Extension: (Avast Online Security) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-03-19]
CHR Extension: (IE Tab) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2017-03-19]
CHR Extension: (Avira SafeSearch Plus) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2017-01-25]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-19]
CHR Extension: (Chrome Media Router) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-19]
CHR Extension: (Camera Video) - C:\Users\Mato\AppData\Local\Camera Video\Component [2015-12-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [doagiokpgboiomffjfhaiimafndmmpni] - C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\richmediadownloader.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Mato\AppData\Roaming\BabSolution\CR\Delta.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [fkcdbkhjcaljlfolhllfneigeepmjfim] - C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\playerextension.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files (x86)\Movie2KDownloader.com\m2kDownloader10.crx <not found>
Opera:
=======
OPR Session Restore: -> is enabled.
OPR Extension: (Adblock Plus) - C:\Users\Mato\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2017-03-19]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-18] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-18] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [349560 2017-03-09] (Avira Operations GmbH & Co. KG)
R2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [25232 2016-12-09] (Avira Operations GmbH & Co. KG)
S3 DAUpdaterSvc; D:\Hry\Dragon\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-07-26] (BioWare)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-04-06] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-04-06] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-04-06] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-04-06] (NVIDIA Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [118576 2014-11-26] ()
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [114656 2012-09-25] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [X]
S2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [37656 2016-11-11] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [108816 2016-11-11] (AVAST Software)
S3 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [103064 2016-11-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-11-11] (AVAST Software)
S3 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [969184 2016-11-11] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [513632 2016-11-11] (AVAST Software)
S3 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [163416 2016-11-11] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-11-11] (AVAST Software)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [151352 2016-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [153904 2016-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [35488 2016-02-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [78208 2016-05-13] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2013-03-27] (DT Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [263528 2015-11-20] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [14976 2015-11-20] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [186784 2015-11-20] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [142976 2015-11-20] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [206312 2015-11-20] (ESET)
R1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [52872 2015-12-19] (ESET)
R0 epfwwfp; C:\WINDOWS\System32\DRIVERS\epfwwfp.sys [69840 2015-11-20] (ESET)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-11-01] (REALiX(tm))
R3 NETwNe64; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [3349984 2014-04-17] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-04-06] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-03-21] (NVIDIA Corporation)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-08-06] (Synaptics Incorporated)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S4 IMFFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [X]
S3 RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-19 23:04 - 2017-03-19 23:04 - 00021695 _____ C:\Users\Mato\Downloads\FRST.txt
2017-03-19 23:04 - 2017-03-19 23:04 - 00000000 ____D C:\FRST
2017-03-19 23:03 - 2017-03-19 23:04 - 02424832 _____ (Farbar) C:\Users\Mato\Downloads\FRST64.exe
2017-03-19 23:03 - 2017-03-19 23:04 - 02424832 _____ (Farbar) C:\Users\Mato\Downloads\FRST64 (1).exe
2017-03-19 22:59 - 2017-03-19 22:59 - 00688992 _____ (Swearware) C:\Users\Mato\Downloads\dds.exe
2017-03-19 22:54 - 2017-03-19 22:56 - 00000000 ____D C:\rsit
2017-03-19 22:54 - 2017-03-19 22:54 - 00000000 ____D C:\Program Files\trend micro
2017-03-19 22:39 - 2017-03-19 22:39 - 00000000 ____D C:\ProgramData\ProductData
2017-03-19 19:39 - 2017-03-19 19:41 - 00267152 _____ C:\WINDOWS\ntbtlog.txt
2017-03-19 19:06 - 2017-03-19 19:06 - 00000000 _____ C:\Recovery.txt
2017-03-19 19:03 - 2017-03-19 20:35 - 647989563 _____ C:\WINDOWS\MEMORY.DMP
2017-03-19 18:54 - 2017-03-19 18:54 - 00000000 __SHD C:\found.000
2017-03-19 18:46 - 2017-03-19 18:46 - 00004027 _____ C:\Users\Mato\Desktop\JRT.txt
2017-03-19 18:42 - 2017-03-19 18:43 - 00625979 _____ C:\Users\Mato\Documents\pinfect.zip
2017-03-19 18:42 - 2017-03-19 18:43 - 00000027 _____ C:\WINDOWS\Lic.xxx
2017-03-19 18:42 - 2017-03-19 18:43 - 00000000 ____D C:\ProgramData\Kaspersky SDK
2017-03-19 18:41 - 2017-03-19 18:41 - 00000000 ____D C:\ProgramData\MicroWorld
2017-03-19 15:37 - 2017-03-19 15:37 - 00001159 _____ C:\Users\Public\Desktop\Avira Connect.lnk
2017-03-12 22:00 - 2017-03-12 22:00 - 00091324 _____ C:\Users\Mato\Desktop\13.3. - 17.3. 2017 Jedálny lístok Pamlska.pdf
2017-03-12 21:59 - 2017-03-12 21:59 - 00044065 _____ C:\Users\Mato\Desktop\13.3. - 17.3. 2017 Jedálny lístok Pamlska.odt
2017-03-05 23:01 - 2017-03-12 21:59 - 00044065 _____ C:\Users\Mato\Desktop\6.3. - 10.3. 2017 Jedálny lístok Pamlska.odt
2017-02-25 11:05 - 2017-02-25 11:05 - 00010615 _____ C:\Users\Mato\Downloads\Príloha_bez_názvu_00082 (1).htm
2017-02-25 10:21 - 2017-02-25 10:21 - 00000297 _____ C:\Users\Mato\Downloads\_Certification_.htm
2017-02-25 09:49 - 2017-02-25 09:49 - 00010615 _____ C:\Users\Mato\Downloads\Príloha_bez_názvu_00082.htm
2017-02-22 17:46 - 2017-02-22 17:46 - 00000000 ____D C:\Users\Mato\AppData\Local\ElevatedDiagnostics
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-19 23:03 - 2014-11-08 14:50 - 00000000 ___DO C:\Users\Mato\OneDrive
2017-03-19 23:00 - 2016-09-15 22:22 - 00000000 ____D C:\Users\Mato\AppData\Local\IE Tab
2017-03-19 23:00 - 2012-07-26 08:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-19 22:58 - 2015-10-19 21:20 - 00003806 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EC17E433-736A-415F-B462-6F4495E34941}
2017-03-19 22:58 - 2013-03-27 21:29 - 00000000 ____D C:\Program Files (x86)\Opera
2017-03-19 22:56 - 2016-11-01 22:14 - 00647040 _____ C:\WINDOWS\system32\perfh01B.dat
2017-03-19 22:56 - 2016-11-01 22:14 - 00122548 _____ C:\WINDOWS\system32\perfc01B.dat
2017-03-19 22:56 - 2014-09-24 06:35 - 01521674 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-19 22:56 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2017-03-19 22:56 - 2013-03-27 19:24 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4204622686-3959268731-1216914738-1001
2017-03-19 22:53 - 2013-03-27 19:15 - 00000000 ____D C:\Users\Mato\AppData\Local\VirtualStore
2017-03-19 22:47 - 2013-05-08 10:31 - 00000954 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2017-03-19 22:35 - 2014-11-07 22:08 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-19 22:35 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-19 18:48 - 2014-11-07 22:16 - 00000000 ____D C:\Users\Mato
2017-03-19 18:48 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2017-03-19 18:45 - 2016-11-01 19:26 - 00000000 ____D C:\Users\Mato\AppData\Roaming\IObit
2017-03-19 18:45 - 2016-11-01 19:26 - 00000000 ____D C:\ProgramData\IObit
2017-03-19 18:44 - 2013-09-16 01:08 - 00000000 ____D C:\Users\Mato\AppData\Local\SweetLabs App Platform
2017-03-19 18:40 - 2013-11-21 23:38 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-19 15:41 - 2013-07-20 19:34 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-19 15:37 - 2016-03-09 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-19 15:37 - 2013-03-28 19:36 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-15 22:10 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-15 22:10 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-15 22:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-03-15 22:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-03-15 22:01 - 2013-03-28 12:37 - 00004288 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-03-13 19:16 - 2015-12-02 10:10 - 00000000 ____D C:\Users\Mato\AppData\Local\CrashDumps
2017-03-13 19:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-10 05:34 - 2016-12-18 16:46 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-10 05:34 - 2016-12-18 16:46 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-06 18:59 - 2013-08-13 09:43 - 00000000 ____D C:\Users\Mato\Desktop\Pamska
2017-03-01 17:40 - 2017-02-10 11:31 - 00001074 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 43.lnk
2017-03-01 17:40 - 2016-07-07 17:29 - 00003850 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1400699424
2017-02-28 18:49 - 2015-05-25 07:30 - 00000000 ____D C:\Users\Mato\Documents\The Witcher 3
2017-02-17 14:50 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\ModemLogs
==================== Files in the root of some directories =======
2015-08-17 16:39 - 2015-08-17 16:40 - 0017408 _____ () C:\Users\Mato\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-02 10:17 - 2015-12-02 10:17 - 0000098 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Some files in TEMP:
====================
2012-07-09 00:40 - 2012-07-09 00:40 - 1299920 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\PresentationCore.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 2040296 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\PresentationFramework.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0232904 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\ReachFramework.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0031200 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationProvider.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0039376 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationTypes.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0650168 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\WindowsBase.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0035816 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\WindowsFormsIntegration.dll
2017-03-19 18:41 - 2008-08-29 18:51 - 0188928 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\DOWNLOAD.EXE
2017-03-19 18:41 - 2008-09-06 01:56 - 0210944 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\esupdate.exe
2017-03-19 18:41 - 2007-03-20 13:50 - 0038400 _____ (Kaspersky Lab) C:\Users\Mato\AppData\Local\Temp\FSSync.dll
2017-03-19 18:41 - 2008-09-06 00:11 - 0056384 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\Getvlist.exe
2017-03-19 18:41 - 2008-07-21 18:57 - 0065536 _____ () C:\Users\Mato\AppData\Local\Temp\ikave.dll
2017-03-19 18:41 - 2002-07-11 14:34 - 0036928 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\ipc.dll
2017-03-19 18:41 - 2008-07-21 18:56 - 0278528 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kave.dll
2017-03-19 18:41 - 2003-10-07 16:58 - 0098304 _____ () C:\Users\Mato\AppData\Local\Temp\kavsign.exe
2017-03-19 18:41 - 2004-11-11 13:36 - 0143416 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavss.dll
2017-03-19 18:41 - 2004-08-17 17:24 - 0020536 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavss.exe
2017-03-19 18:41 - 2004-11-05 16:38 - 0159865 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavssd.dll
2017-03-19 18:41 - 2004-08-17 18:26 - 0053306 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavssdi.dll
2017-03-19 18:41 - 2004-11-05 16:20 - 0036921 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavssi.dll
2017-03-19 18:41 - 2004-08-18 12:05 - 0102481 _____ () C:\Users\Mato\AppData\Local\Temp\kavvlg.dll
2017-03-19 18:42 - 2017-03-19 18:42 - 0548864 _____ (Microsoft Corporation) C:\Users\Mato\AppData\Local\Temp\msvcp80.dll
2017-03-19 18:42 - 2017-03-19 18:42 - 0626688 _____ (Microsoft Corporation) C:\Users\Mato\AppData\Local\Temp\msvcr80.dll
2017-03-19 18:41 - 2008-09-06 00:38 - 2007040 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\msvl64.dll
2017-03-19 18:41 - 2008-09-06 00:20 - 0192512 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\msvlclnt.dll
2017-03-19 18:41 - 2008-04-29 15:00 - 0099328 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\MWAVL.EXE
2017-03-19 18:41 - 2008-08-29 12:45 - 0745472 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\MWAVREG.EXE
2017-03-19 18:41 - 2008-09-06 00:09 - 0204800 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\MWUnZip.dll
2017-03-19 18:42 - 2017-03-19 18:42 - 0241664 _____ () C:\Users\Mato\AppData\Local\Temp\MYDB.DLL
2017-03-19 18:41 - 2007-03-20 17:04 - 0184320 _____ (Kaspersky Lab) C:\Users\Mato\AppData\Local\Temp\prLoader.dll
2017-03-19 18:41 - 1996-10-14 07:08 - 0173328 _____ (Microsoft Corporation) C:\Users\Mato\AppData\Local\Temp\red32.dll
2017-03-19 18:41 - 2008-09-06 01:39 - 0093696 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\Reload.exe
2017-03-19 18:41 - 2008-07-21 18:58 - 0139264 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\ScanningProcess.exe
2017-03-19 18:41 - 2008-09-06 00:27 - 0054784 _____ (MicroWorld Technologies Inc) C:\Users\Mato\AppData\Local\Temp\setpriv.exe
2017-03-19 18:41 - 2008-09-06 00:44 - 0043520 _____ (MicroWorld Technologies Inc) C:\Users\Mato\AppData\Local\Temp\unregx.exe
2017-03-19 18:41 - 2008-02-22 11:35 - 0413696 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\VIEWTCP.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-03 18:30
==================== End of FRST.txt ============================
Spustil sa az po xy pokusoch. Pred spustenim som nahradil v system32/config SAM,SECURITY,SYSTEM,software,default z datumu 3.3.2017
Pri starte vyhodi 2x chybu Rundll .... zasuvny modul sa nepodarilo najst.
Posielam log pre kontrolu na viry
Vopred dakujem
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Mato (administrator) on MATO (19-03-2017 23:04:39)
Running from C:\Users\Mato\Downloads
Loaded Profiles: Mato (Available Profiles: Mato)
Platform: Windows 8.1 (Update) (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
() C:\Windows\SysWOW64\SecUPDUtilSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Pokki) C:\Users\Mato\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.18384_none_fa1d93c39b41b41a\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\GenValObj.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\ByteCodeGenerator.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13261456 2012-12-10] (Realtek Semiconductor)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA Corporation)
HKLM\...\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [63432 2017-03-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-18] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [Steam] => D:\Hry\Skyrim\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [uTorrent] => C:\Users\Mato\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-27] (BitTorrent Inc.)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [Facebook Update] => C:\Users\Mato\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-15] (Facebook Inc.)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\RunOnce: [Application Restart #1] => C:\Users\Mato\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [7875640 2015-10-30] (Pokki)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\RunOnce: [Application Restart #0] => C:\Users\Mato\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [7875640 2015-10-30] (Pokki)
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 77.48.221.10 10.0.0.1
Tcpip\..\Interfaces\{30F310FD-3790-491C-BE59-01522AFED992}: [DhcpNameServer] 77.48.221.10 10.0.0.1
Tcpip\..\Interfaces\{F8F8D734-DADE-4225-9508-26EA3C586CF3}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-4204622686-3959268731-1216914738-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={F7975B19-B5B8-11E2-BE81-6036DDB09CE8}
SearchScopes: HKU\S-1-5-21-4204622686-3959268731-1216914738-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-25] (Oracle Corporation)
BHO-x32: Rich Media Downloader -> {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} -> C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll => No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-25] (Oracle Corporation)
BHO-x32: No Name -> {FEB703F7-E7B2-4AB0-9566-87658AC70095} -> No File
FireFox:
========
FF ProfilePath: C:\Users\Mato\AppData\Roaming\Mozilla\Firefox\Profiles\7wFYJ7DL.default [not found]
FF HKLM-x32\...\Firefox\Extensions: [{3DF4B26D-DB19-45DF-962A-6719D071245B}] - C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B} => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [No File]
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-25] (Oracle Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-31] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin-x32: @richmediaplayer.com/nppluginrichmediaplayer -> C:\Program Files (x86)\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-05-08] ()
FF Plugin HKU\S-1-5-21-4204622686-3959268731-1216914738-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mato\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-4204622686-3959268731-1216914738-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default [2017-03-19]
CHR Extension: (Adblock Plus) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-19]
CHR Extension: (Avast Online Security) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-03-19]
CHR Extension: (IE Tab) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2017-03-19]
CHR Extension: (Avira SafeSearch Plus) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2017-01-25]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-19]
CHR Extension: (Chrome Media Router) - C:\Users\Mato\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-19]
CHR Extension: (Camera Video) - C:\Users\Mato\AppData\Local\Camera Video\Component [2015-12-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [doagiokpgboiomffjfhaiimafndmmpni] - C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\richmediadownloader.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Mato\AppData\Roaming\BabSolution\CR\Delta.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [fkcdbkhjcaljlfolhllfneigeepmjfim] - C:\Users\Mato\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\playerextension.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files (x86)\Movie2KDownloader.com\m2kDownloader10.crx <not found>
Opera:
=======
OPR Session Restore: -> is enabled.
OPR Extension: (Adblock Plus) - C:\Users\Mato\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2017-03-19]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-18] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-18] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [349560 2017-03-09] (Avira Operations GmbH & Co. KG)
R2 AviraUpdaterService; C:\Program Files (x86)\Avira\SoftwareUpdater\Avira.SoftwareUpdater.ServiceHost.exe [25232 2016-12-09] (Avira Operations GmbH & Co. KG)
S3 DAUpdaterSvc; D:\Hry\Dragon\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-07-26] (BioWare)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-04-06] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-04-06] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-04-06] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-04-06] (NVIDIA Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [118576 2014-11-26] ()
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [114656 2012-09-25] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [X]
S2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [37656 2016-11-11] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [108816 2016-11-11] (AVAST Software)
S3 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [103064 2016-11-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-11-11] (AVAST Software)
S3 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [969184 2016-11-11] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [513632 2016-11-11] (AVAST Software)
S3 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [163416 2016-11-11] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-11-11] (AVAST Software)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [151352 2016-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [153904 2016-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [35488 2016-02-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [78208 2016-05-13] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2013-03-27] (DT Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [263528 2015-11-20] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [14976 2015-11-20] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [186784 2015-11-20] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [142976 2015-11-20] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [206312 2015-11-20] (ESET)
R1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [52872 2015-12-19] (ESET)
R0 epfwwfp; C:\WINDOWS\System32\DRIVERS\epfwwfp.sys [69840 2015-11-20] (ESET)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-11-01] (REALiX(tm))
R3 NETwNe64; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [3349984 2014-04-17] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-04-06] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-03-21] (NVIDIA Corporation)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-08-06] (Synaptics Incorporated)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S4 IMFFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [X]
S3 RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-19 23:04 - 2017-03-19 23:04 - 00021695 _____ C:\Users\Mato\Downloads\FRST.txt
2017-03-19 23:04 - 2017-03-19 23:04 - 00000000 ____D C:\FRST
2017-03-19 23:03 - 2017-03-19 23:04 - 02424832 _____ (Farbar) C:\Users\Mato\Downloads\FRST64.exe
2017-03-19 23:03 - 2017-03-19 23:04 - 02424832 _____ (Farbar) C:\Users\Mato\Downloads\FRST64 (1).exe
2017-03-19 22:59 - 2017-03-19 22:59 - 00688992 _____ (Swearware) C:\Users\Mato\Downloads\dds.exe
2017-03-19 22:54 - 2017-03-19 22:56 - 00000000 ____D C:\rsit
2017-03-19 22:54 - 2017-03-19 22:54 - 00000000 ____D C:\Program Files\trend micro
2017-03-19 22:39 - 2017-03-19 22:39 - 00000000 ____D C:\ProgramData\ProductData
2017-03-19 19:39 - 2017-03-19 19:41 - 00267152 _____ C:\WINDOWS\ntbtlog.txt
2017-03-19 19:06 - 2017-03-19 19:06 - 00000000 _____ C:\Recovery.txt
2017-03-19 19:03 - 2017-03-19 20:35 - 647989563 _____ C:\WINDOWS\MEMORY.DMP
2017-03-19 18:54 - 2017-03-19 18:54 - 00000000 __SHD C:\found.000
2017-03-19 18:46 - 2017-03-19 18:46 - 00004027 _____ C:\Users\Mato\Desktop\JRT.txt
2017-03-19 18:42 - 2017-03-19 18:43 - 00625979 _____ C:\Users\Mato\Documents\pinfect.zip
2017-03-19 18:42 - 2017-03-19 18:43 - 00000027 _____ C:\WINDOWS\Lic.xxx
2017-03-19 18:42 - 2017-03-19 18:43 - 00000000 ____D C:\ProgramData\Kaspersky SDK
2017-03-19 18:41 - 2017-03-19 18:41 - 00000000 ____D C:\ProgramData\MicroWorld
2017-03-19 15:37 - 2017-03-19 15:37 - 00001159 _____ C:\Users\Public\Desktop\Avira Connect.lnk
2017-03-12 22:00 - 2017-03-12 22:00 - 00091324 _____ C:\Users\Mato\Desktop\13.3. - 17.3. 2017 Jedálny lístok Pamlska.pdf
2017-03-12 21:59 - 2017-03-12 21:59 - 00044065 _____ C:\Users\Mato\Desktop\13.3. - 17.3. 2017 Jedálny lístok Pamlska.odt
2017-03-05 23:01 - 2017-03-12 21:59 - 00044065 _____ C:\Users\Mato\Desktop\6.3. - 10.3. 2017 Jedálny lístok Pamlska.odt
2017-02-25 11:05 - 2017-02-25 11:05 - 00010615 _____ C:\Users\Mato\Downloads\Príloha_bez_názvu_00082 (1).htm
2017-02-25 10:21 - 2017-02-25 10:21 - 00000297 _____ C:\Users\Mato\Downloads\_Certification_.htm
2017-02-25 09:49 - 2017-02-25 09:49 - 00010615 _____ C:\Users\Mato\Downloads\Príloha_bez_názvu_00082.htm
2017-02-22 17:46 - 2017-02-22 17:46 - 00000000 ____D C:\Users\Mato\AppData\Local\ElevatedDiagnostics
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-19 23:03 - 2014-11-08 14:50 - 00000000 ___DO C:\Users\Mato\OneDrive
2017-03-19 23:00 - 2016-09-15 22:22 - 00000000 ____D C:\Users\Mato\AppData\Local\IE Tab
2017-03-19 23:00 - 2012-07-26 08:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-19 22:58 - 2015-10-19 21:20 - 00003806 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EC17E433-736A-415F-B462-6F4495E34941}
2017-03-19 22:58 - 2013-03-27 21:29 - 00000000 ____D C:\Program Files (x86)\Opera
2017-03-19 22:56 - 2016-11-01 22:14 - 00647040 _____ C:\WINDOWS\system32\perfh01B.dat
2017-03-19 22:56 - 2016-11-01 22:14 - 00122548 _____ C:\WINDOWS\system32\perfc01B.dat
2017-03-19 22:56 - 2014-09-24 06:35 - 01521674 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-19 22:56 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2017-03-19 22:56 - 2013-03-27 19:24 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4204622686-3959268731-1216914738-1001
2017-03-19 22:53 - 2013-03-27 19:15 - 00000000 ____D C:\Users\Mato\AppData\Local\VirtualStore
2017-03-19 22:47 - 2013-05-08 10:31 - 00000954 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2017-03-19 22:35 - 2014-11-07 22:08 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-19 22:35 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-19 18:48 - 2014-11-07 22:16 - 00000000 ____D C:\Users\Mato
2017-03-19 18:48 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2017-03-19 18:45 - 2016-11-01 19:26 - 00000000 ____D C:\Users\Mato\AppData\Roaming\IObit
2017-03-19 18:45 - 2016-11-01 19:26 - 00000000 ____D C:\ProgramData\IObit
2017-03-19 18:44 - 2013-09-16 01:08 - 00000000 ____D C:\Users\Mato\AppData\Local\SweetLabs App Platform
2017-03-19 18:40 - 2013-11-21 23:38 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-19 15:41 - 2013-07-20 19:34 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-19 15:37 - 2016-03-09 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-19 15:37 - 2013-03-28 19:36 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-15 22:10 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-15 22:10 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-15 22:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-03-15 22:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-03-15 22:01 - 2013-03-28 12:37 - 00004288 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-03-13 19:16 - 2015-12-02 10:10 - 00000000 ____D C:\Users\Mato\AppData\Local\CrashDumps
2017-03-13 19:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-10 05:34 - 2016-12-18 16:46 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-10 05:34 - 2016-12-18 16:46 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-06 18:59 - 2013-08-13 09:43 - 00000000 ____D C:\Users\Mato\Desktop\Pamska
2017-03-01 17:40 - 2017-02-10 11:31 - 00001074 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 43.lnk
2017-03-01 17:40 - 2016-07-07 17:29 - 00003850 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1400699424
2017-02-28 18:49 - 2015-05-25 07:30 - 00000000 ____D C:\Users\Mato\Documents\The Witcher 3
2017-02-17 14:50 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\ModemLogs
==================== Files in the root of some directories =======
2015-08-17 16:39 - 2015-08-17 16:40 - 0017408 _____ () C:\Users\Mato\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-02 10:17 - 2015-12-02 10:17 - 0000098 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Some files in TEMP:
====================
2012-07-09 00:40 - 2012-07-09 00:40 - 1299920 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\PresentationCore.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 2040296 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\PresentationFramework.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0232904 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\ReachFramework.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0031200 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationProvider.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0039376 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\UIAutomationTypes.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0650168 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\WindowsBase.dll
2012-07-09 00:40 - 2012-07-09 00:40 - 0035816 _____ (Microsoft Corporation) C:\Users\ADMINI~1\AppData\Local\Temp\WindowsFormsIntegration.dll
2017-03-19 18:41 - 2008-08-29 18:51 - 0188928 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\DOWNLOAD.EXE
2017-03-19 18:41 - 2008-09-06 01:56 - 0210944 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\esupdate.exe
2017-03-19 18:41 - 2007-03-20 13:50 - 0038400 _____ (Kaspersky Lab) C:\Users\Mato\AppData\Local\Temp\FSSync.dll
2017-03-19 18:41 - 2008-09-06 00:11 - 0056384 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\Getvlist.exe
2017-03-19 18:41 - 2008-07-21 18:57 - 0065536 _____ () C:\Users\Mato\AppData\Local\Temp\ikave.dll
2017-03-19 18:41 - 2002-07-11 14:34 - 0036928 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\ipc.dll
2017-03-19 18:41 - 2008-07-21 18:56 - 0278528 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kave.dll
2017-03-19 18:41 - 2003-10-07 16:58 - 0098304 _____ () C:\Users\Mato\AppData\Local\Temp\kavsign.exe
2017-03-19 18:41 - 2004-11-11 13:36 - 0143416 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavss.dll
2017-03-19 18:41 - 2004-08-17 17:24 - 0020536 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavss.exe
2017-03-19 18:41 - 2004-11-05 16:38 - 0159865 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavssd.dll
2017-03-19 18:41 - 2004-08-17 18:26 - 0053306 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavssdi.dll
2017-03-19 18:41 - 2004-11-05 16:20 - 0036921 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\kavssi.dll
2017-03-19 18:41 - 2004-08-18 12:05 - 0102481 _____ () C:\Users\Mato\AppData\Local\Temp\kavvlg.dll
2017-03-19 18:42 - 2017-03-19 18:42 - 0548864 _____ (Microsoft Corporation) C:\Users\Mato\AppData\Local\Temp\msvcp80.dll
2017-03-19 18:42 - 2017-03-19 18:42 - 0626688 _____ (Microsoft Corporation) C:\Users\Mato\AppData\Local\Temp\msvcr80.dll
2017-03-19 18:41 - 2008-09-06 00:38 - 2007040 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\msvl64.dll
2017-03-19 18:41 - 2008-09-06 00:20 - 0192512 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\msvlclnt.dll
2017-03-19 18:41 - 2008-04-29 15:00 - 0099328 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\MWAVL.EXE
2017-03-19 18:41 - 2008-08-29 12:45 - 0745472 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\MWAVREG.EXE
2017-03-19 18:41 - 2008-09-06 00:09 - 0204800 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\MWUnZip.dll
2017-03-19 18:42 - 2017-03-19 18:42 - 0241664 _____ () C:\Users\Mato\AppData\Local\Temp\MYDB.DLL
2017-03-19 18:41 - 2007-03-20 17:04 - 0184320 _____ (Kaspersky Lab) C:\Users\Mato\AppData\Local\Temp\prLoader.dll
2017-03-19 18:41 - 1996-10-14 07:08 - 0173328 _____ (Microsoft Corporation) C:\Users\Mato\AppData\Local\Temp\red32.dll
2017-03-19 18:41 - 2008-09-06 01:39 - 0093696 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\Reload.exe
2017-03-19 18:41 - 2008-07-21 18:58 - 0139264 _____ (Kaspersky Lab.) C:\Users\Mato\AppData\Local\Temp\ScanningProcess.exe
2017-03-19 18:41 - 2008-09-06 00:27 - 0054784 _____ (MicroWorld Technologies Inc) C:\Users\Mato\AppData\Local\Temp\setpriv.exe
2017-03-19 18:41 - 2008-09-06 00:44 - 0043520 _____ (MicroWorld Technologies Inc) C:\Users\Mato\AppData\Local\Temp\unregx.exe
2017-03-19 18:41 - 2008-02-22 11:35 - 0413696 _____ (MicroWorld Technologies Inc.) C:\Users\Mato\AppData\Local\Temp\VIEWTCP.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-03 18:30
==================== End of FRST.txt ============================