Prosím o preventivku
Napsal: 02 dub 2017 10:26
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Slávek (administrator) on SLAVEK-NB (02-04-2017 11:21:42)
Running from C:\Users\Slávek\Desktop
Loaded Profiles: Slávek (Available Profiles: Slávek)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(SODATSW spol. s .r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Service.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozC17E.tmp
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartW8Button] => C:\Program Files (x86)\StartW8\bin\StartW8Button.exe [59784 2014-06-05] (SODATSW spol. s r.o.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [909744 2017-03-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [63432 2017-03-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [{845380e2-f0b5-4584-bc40-cc54345b3c06}] => C:\ProgramData\Package Cache\{845380e2-f0b5-4584-bc40-cc54345b3c06}\Avira.OE.Setup.Bundle.exe [980136 2017-02-02] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [{0b46d918-af4f-4612-8076-5c0ae67cb2aa}] => C:\ProgramData\Package Cache\{0b46d918-af4f-4612-8076-5c0ae67cb2aa}\Avira.OE.Setup.Bundle.exe [978808 2017-03-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] (Qualcomm®Atheros®)
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\...\MountPoints2: {3c4cc656-1204-11e6-829a-201a0652b269} - "G:\autorun.exe"
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\...\MountPoints2: {e326139c-e454-11e4-827d-201a06443156} - "G:\autorun.exe"
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> none
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-08-09]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 82.163.142.7 95.211.158.134
Tcpip\..\Interfaces\{2B237A2D-F696-4F3B-B7EE-8BA63C93B393}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A5CB9438-24F2-4CFD-A9EB-371DF8F114BE}: [DhcpNameServer] 82.163.142.7
Tcpip\..\Interfaces\{F8766E43-DC37-4F2E-9878-AF9D69A3E833}: [DhcpNameServer] 82.163.142.7
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
SearchScopes: HKU\S-1-5-21-4242946692-605027899-2297166520-1001 -> DefaultScope {3902C2DF-EE2B-482E-A0F7-9CB95039D089} URL =
SearchScopes: HKU\S-1-5-21-4242946692-605027899-2297166520-1001 -> {3902C2DF-EE2B-482E-A0F7-9CB95039D089} URL =
SearchScopes: HKU\S-1-5-21-4242946692-605027899-2297166520-1001 -> {6E0E1BDD-C4B2-4282-B586-E7DFAD3171D3} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11433
FireFox:
========
FF ProfilePath: C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733 [2017-04-02]
FF user.js: detected! => C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\user.js [2016-03-15]
FF Homepage: Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733 -> hxxp://www.eurofotbal.cz/
FF Extension: (Český slovník pro kontrolu pravopisu) - C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\Extensions\cs@dictionaries.addons.mozilla.org [2017-01-28]
FF Extension: (S3.Google Translator) - C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\Extensions\s3google@translator.xpi [2016-10-19]
FF Extension: (Site Deployment Checker) - C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\features\{043469c8-8a1c-427a-ae68-79b317f5bda7}\deployment-checker@mozilla.org.xpi [2017-03-25]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4242946692-605027899-2297166520-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Slávek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-22] (Unity Technologies ApS)
Chrome:
=======
CHR Profile: C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default [2017-03-27]
CHR Extension: (Dokumenty Google) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-18]
CHR Extension: (YouTube) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-18]
CHR Extension: (Avira Browser Safety) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-10-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-09]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1115552 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [487432 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [487432 2017-03-22] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1519136 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) [File not signed]
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [349560 2017-03-09] (Avira Operations GmbH & Co. KG)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-08] (Broadcom Corporation.)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-06] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.)
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [192304 2016-02-16] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
R2 StartW8Service; C:\Program Files (x86)\StartW8\bin\StartW8Service.exe [620424 2014-06-05] (SODATSW spol. s .r.o.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [161824 2017-03-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [163976 2017-03-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [44488 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [88488 2017-03-22] (Avira Operations GmbH & Co. KG)
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-08-08] (Broadcom Corporation.)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-02-16] (Huawei Technologies Co., Ltd.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-08-20] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-08-20] ()
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 usbser; C:\Windows\system32\DRIVERS\USBSER.sys [33280 2016-02-16] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44024 2015-02-04] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [264000 2015-02-04] (Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 AIDA64Driver; \??\D:\_Programy, nastaveni, data\_PC testy, čističe\Finalwire Aida64 Extreme v4.00.2700 portable cracked\kerneld.x64 [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2095-03-10 23:33 - 2095-03-10 23:33 - 00000000 ____D C:\Users\Slávek\Desktop\Původní data aplikace Firefox
2095-03-10 23:26 - 2095-03-10 23:26 - 00001135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2095-03-10 23:26 - 2095-03-10 23:26 - 00001123 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2095-03-10 23:24 - 2017-01-30 10:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-02 11:21 - 2017-04-02 11:22 - 00016456 _____ C:\Users\Slávek\Desktop\FRST.txt
2017-04-02 11:21 - 2017-04-02 11:21 - 00000000 ____D C:\Users\Slávek\Desktop\FRST-OlderVersion
2017-04-02 11:02 - 2017-04-02 11:02 - 193122802 _____ C:\Users\Slávek\Downloads\Prokletý-ostrov---2010,-drama,-thriller,-mysteriózní,-CZ-dabing,-(Angel).avi.part
2017-04-02 11:02 - 2017-04-02 11:02 - 00000000 _____ C:\Users\Slávek\Downloads\Prokletý-ostrov---2010,-drama,-thriller,-mysteriózní,-CZ-dabing,-(Angel).avi
2017-03-27 18:41 - 2017-03-27 18:42 - 09274608 _____ (Piriform Ltd) C:\Users\Slávek\Downloads\ccsetup528.exe
2017-03-20 20:20 - 2017-03-20 20:20 - 00089414 _____ C:\Users\Slávek\Downloads\2418-0891441947-131515940-131515940.pdf
2017-03-19 07:54 - 2017-03-19 07:54 - 00001112 _____ C:\Users\Public\Desktop\Avira Connect.lnk
2017-03-18 19:57 - 2017-03-18 20:42 - 733781862 _____ C:\Users\Slávek\Downloads\Zlodeji_zelenych_koni_Cesky_film_Cz-Avi_Drama_2016.avi
2017-03-15 18:23 - 2017-03-15 18:23 - 00089278 _____ C:\Users\Slávek\Downloads\484903353.PDF
2017-03-12 19:54 - 2017-03-12 19:54 - 00017920 _____ C:\Users\Slávek\Downloads\T-17030-Ořechov-Hladůvkovi-KUT dopojení.xls
2017-03-11 10:43 - 2017-03-11 12:32 - 1965895680 _____ C:\Users\Slávek\Downloads\Jak-porodit-a-nezbláznit-se-(2012)-CZ-dabing-(martincz75).avi
2017-03-10 16:35 - 2017-03-10 17:40 - 1168603136 _____ C:\Users\Slávek\Downloads\Dovolena-za-trest-(2014).avi
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2095-03-06 17:32 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\apppatch
2095-03-06 17:30 - 2013-08-22 16:44 - 00482256 _____ C:\Windows\system32\FNTCACHE.DAT
2095-03-06 17:25 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\CodeIntegrity
2095-03-06 17:25 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Internet Explorer
2095-03-06 17:25 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files (x86)\Internet Explorer
2021-10-21 15:36 - 2014-08-06 19:42 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC.dat
2021-10-04 09:34 - 2014-08-06 19:42 - 00000712 _____ C:\Windows\system32\Drivers\RTMICEQ0.dat
2017-04-02 11:21 - 2016-06-21 18:31 - 00000000 ____D C:\FRST
2017-04-02 11:21 - 2016-06-21 18:29 - 02424832 _____ (Farbar) C:\Users\Slávek\Desktop\FRST64.exe
2017-03-31 06:21 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf
2017-03-30 06:45 - 2014-08-10 09:42 - 00000000 ____D C:\Users\Slávek\AppData\Local\Deployment
2017-03-27 18:58 - 2014-08-09 06:12 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4242946692-605027899-2297166520-1001
2017-03-27 18:43 - 2014-10-15 17:24 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-03-22 18:05 - 2016-05-11 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-22 18:03 - 2016-10-09 13:01 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2017-03-21 21:24 - 2014-08-06 18:53 - 00739924 _____ C:\Windows\system32\perfh005.dat
2017-03-21 21:24 - 2014-08-06 18:53 - 00151610 _____ C:\Windows\system32\perfc005.dat
2017-03-21 21:24 - 2014-01-17 21:40 - 01745984 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-21 11:34 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2017-03-19 09:00 - 2016-11-15 20:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-19 08:01 - 2016-11-17 11:20 - 00000000 ____D C:\Users\Slávek\AppData\LocalLow\Mozilla
2017-03-19 07:53 - 2014-08-09 13:15 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-14 19:24 - 2016-01-08 17:11 - 00004372 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-03-14 19:24 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-03-14 19:24 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\Macromed
==================== Files in the root of some directories =======
2016-10-06 22:09 - 2016-12-06 06:41 - 0004608 _____ () C:\Users\Slávek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-06 19:42 - 2014-08-06 19:42 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-28 21:05
==================== End of FRST.txt ============================
Ran by Slávek (administrator) on SLAVEK-NB (02-04-2017 11:21:42)
Running from C:\Users\Slávek\Desktop
Loaded Profiles: Slávek (Available Profiles: Slávek)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(SODATSW spol. s .r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Service.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\tobedeleted\mozC17E.tmp
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-09-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartW8Button] => C:\Program Files (x86)\StartW8\bin\StartW8Button.exe [59784 2014-06-05] (SODATSW spol. s r.o.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [909744 2017-03-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [63432 2017-03-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [{845380e2-f0b5-4584-bc40-cc54345b3c06}] => C:\ProgramData\Package Cache\{845380e2-f0b5-4584-bc40-cc54345b3c06}\Avira.OE.Setup.Bundle.exe [980136 2017-02-02] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\RunOnce: [{0b46d918-af4f-4612-8076-5c0ae67cb2aa}] => C:\ProgramData\Package Cache\{0b46d918-af4f-4612-8076-5c0ae67cb2aa}\Avira.OE.Setup.Bundle.exe [978808 2017-03-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] (Qualcomm®Atheros®)
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\...\MountPoints2: {3c4cc656-1204-11e6-829a-201a0652b269} - "G:\autorun.exe"
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\...\MountPoints2: {e326139c-e454-11e4-827d-201a06443156} - "G:\autorun.exe"
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> none
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-08-09]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 82.163.142.7 95.211.158.134
Tcpip\..\Interfaces\{2B237A2D-F696-4F3B-B7EE-8BA63C93B393}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A5CB9438-24F2-4CFD-A9EB-371DF8F114BE}: [DhcpNameServer] 82.163.142.7
Tcpip\..\Interfaces\{F8766E43-DC37-4F2E-9878-AF9D69A3E833}: [DhcpNameServer] 82.163.142.7
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-4242946692-605027899-2297166520-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
SearchScopes: HKU\S-1-5-21-4242946692-605027899-2297166520-1001 -> DefaultScope {3902C2DF-EE2B-482E-A0F7-9CB95039D089} URL =
SearchScopes: HKU\S-1-5-21-4242946692-605027899-2297166520-1001 -> {3902C2DF-EE2B-482E-A0F7-9CB95039D089} URL =
SearchScopes: HKU\S-1-5-21-4242946692-605027899-2297166520-1001 -> {6E0E1BDD-C4B2-4282-B586-E7DFAD3171D3} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11433
FireFox:
========
FF ProfilePath: C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733 [2017-04-02]
FF user.js: detected! => C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\user.js [2016-03-15]
FF Homepage: Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733 -> hxxp://www.eurofotbal.cz/
FF Extension: (Český slovník pro kontrolu pravopisu) - C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\Extensions\cs@dictionaries.addons.mozilla.org [2017-01-28]
FF Extension: (S3.Google Translator) - C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\Extensions\s3google@translator.xpi [2016-10-19]
FF Extension: (Site Deployment Checker) - C:\Users\Slávek\AppData\Roaming\Mozilla\Firefox\Profiles\wjp8wklo.default-3950631209733\features\{043469c8-8a1c-427a-ae68-79b317f5bda7}\deployment-checker@mozilla.org.xpi [2017-03-25]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4242946692-605027899-2297166520-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Slávek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-22] (Unity Technologies ApS)
Chrome:
=======
CHR Profile: C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default [2017-03-27]
CHR Extension: (Dokumenty Google) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-18]
CHR Extension: (YouTube) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-18]
CHR Extension: (Avira Browser Safety) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-10-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Slávek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-09]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1115552 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [487432 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [487432 2017-03-22] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1519136 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) [File not signed]
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [349560 2017-03-09] (Avira Operations GmbH & Co. KG)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-08] (Broadcom Corporation.)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-06] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-09-06] (ELAN Microelectronics Corp.)
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [192304 2016-02-16] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
R2 StartW8Service; C:\Program Files (x86)\StartW8\bin\StartW8Service.exe [620424 2014-06-05] (SODATSW spol. s .r.o.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [161824 2017-03-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [163976 2017-03-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [44488 2017-03-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [88488 2017-03-22] (Avira Operations GmbH & Co. KG)
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-08-08] (Broadcom Corporation.)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-02-16] (Huawei Technologies Co., Ltd.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-08-20] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-08-20] ()
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 usbser; C:\Windows\system32\DRIVERS\USBSER.sys [33280 2016-02-16] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44024 2015-02-04] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [264000 2015-02-04] (Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 AIDA64Driver; \??\D:\_Programy, nastaveni, data\_PC testy, čističe\Finalwire Aida64 Extreme v4.00.2700 portable cracked\kerneld.x64 [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2095-03-10 23:33 - 2095-03-10 23:33 - 00000000 ____D C:\Users\Slávek\Desktop\Původní data aplikace Firefox
2095-03-10 23:26 - 2095-03-10 23:26 - 00001135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2095-03-10 23:26 - 2095-03-10 23:26 - 00001123 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2095-03-10 23:24 - 2017-01-30 10:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-02 11:21 - 2017-04-02 11:22 - 00016456 _____ C:\Users\Slávek\Desktop\FRST.txt
2017-04-02 11:21 - 2017-04-02 11:21 - 00000000 ____D C:\Users\Slávek\Desktop\FRST-OlderVersion
2017-04-02 11:02 - 2017-04-02 11:02 - 193122802 _____ C:\Users\Slávek\Downloads\Prokletý-ostrov---2010,-drama,-thriller,-mysteriózní,-CZ-dabing,-(Angel).avi.part
2017-04-02 11:02 - 2017-04-02 11:02 - 00000000 _____ C:\Users\Slávek\Downloads\Prokletý-ostrov---2010,-drama,-thriller,-mysteriózní,-CZ-dabing,-(Angel).avi
2017-03-27 18:41 - 2017-03-27 18:42 - 09274608 _____ (Piriform Ltd) C:\Users\Slávek\Downloads\ccsetup528.exe
2017-03-20 20:20 - 2017-03-20 20:20 - 00089414 _____ C:\Users\Slávek\Downloads\2418-0891441947-131515940-131515940.pdf
2017-03-19 07:54 - 2017-03-19 07:54 - 00001112 _____ C:\Users\Public\Desktop\Avira Connect.lnk
2017-03-18 19:57 - 2017-03-18 20:42 - 733781862 _____ C:\Users\Slávek\Downloads\Zlodeji_zelenych_koni_Cesky_film_Cz-Avi_Drama_2016.avi
2017-03-15 18:23 - 2017-03-15 18:23 - 00089278 _____ C:\Users\Slávek\Downloads\484903353.PDF
2017-03-12 19:54 - 2017-03-12 19:54 - 00017920 _____ C:\Users\Slávek\Downloads\T-17030-Ořechov-Hladůvkovi-KUT dopojení.xls
2017-03-11 10:43 - 2017-03-11 12:32 - 1965895680 _____ C:\Users\Slávek\Downloads\Jak-porodit-a-nezbláznit-se-(2012)-CZ-dabing-(martincz75).avi
2017-03-10 16:35 - 2017-03-10 17:40 - 1168603136 _____ C:\Users\Slávek\Downloads\Dovolena-za-trest-(2014).avi
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2095-03-06 17:32 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\apppatch
2095-03-06 17:30 - 2013-08-22 16:44 - 00482256 _____ C:\Windows\system32\FNTCACHE.DAT
2095-03-06 17:25 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\CodeIntegrity
2095-03-06 17:25 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Internet Explorer
2095-03-06 17:25 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files (x86)\Internet Explorer
2021-10-21 15:36 - 2014-08-06 19:42 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC.dat
2021-10-04 09:34 - 2014-08-06 19:42 - 00000712 _____ C:\Windows\system32\Drivers\RTMICEQ0.dat
2017-04-02 11:21 - 2016-06-21 18:31 - 00000000 ____D C:\FRST
2017-04-02 11:21 - 2016-06-21 18:29 - 02424832 _____ (Farbar) C:\Users\Slávek\Desktop\FRST64.exe
2017-03-31 06:21 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf
2017-03-30 06:45 - 2014-08-10 09:42 - 00000000 ____D C:\Users\Slávek\AppData\Local\Deployment
2017-03-27 18:58 - 2014-08-09 06:12 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4242946692-605027899-2297166520-1001
2017-03-27 18:43 - 2014-10-15 17:24 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-03-22 18:05 - 2016-05-11 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-22 18:03 - 2016-10-09 13:01 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2017-03-22 18:03 - 2016-02-21 10:53 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2017-03-21 21:24 - 2014-08-06 18:53 - 00739924 _____ C:\Windows\system32\perfh005.dat
2017-03-21 21:24 - 2014-08-06 18:53 - 00151610 _____ C:\Windows\system32\perfc005.dat
2017-03-21 21:24 - 2014-01-17 21:40 - 01745984 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-21 11:34 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2017-03-19 09:00 - 2016-11-15 20:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-19 08:01 - 2016-11-17 11:20 - 00000000 ____D C:\Users\Slávek\AppData\LocalLow\Mozilla
2017-03-19 07:53 - 2014-08-09 13:15 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-14 19:24 - 2016-01-08 17:11 - 00004372 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-03-14 19:24 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-03-14 19:24 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\Macromed
==================== Files in the root of some directories =======
2016-10-06 22:09 - 2016-12-06 06:41 - 0004608 _____ () C:\Users\Slávek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-06 19:42 - 2014-08-06 19:42 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-28 21:05
==================== End of FRST.txt ============================