pomaly ntb
Napsal: 06 čer 2017 19:11
dobry Den prosim o pomoc s Ntb je desne pomaly ,a prevazne prohlizec seka se a je pomaly(pripojeni internetu je dobre jinej stroj a tam to bezi suprove)
FRST scan
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-06-2017
Ran by p.Martina (administrator) on PMARTINA-PC (06-06-2017 20:04:25)
Running from C:\Users\p.Martina\Desktop
Loaded Profiles: p.Martina (Available Profiles: p.Martina & DefaultAppPool)
Platform: Microsoft Windows 10 Pro Version 1511 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_65\bin\javaw.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\WINDOWS\System32\browser_broker.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM\...\Run: [RzWizard] => C:\Program Files\Razer\RzWizard\RzWizard.exe [263112 2016-03-23] (Razer Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKU\S-1-5-21-528259500-889367275-2168026962-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-528259500-889367275-2168026962-1000\...\MountPoints2: {1bbb54a0-e920-11e6-86dc-001eec538b51} - "E:\HiSuiteDownLoader.exe"
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6f01c5af-451c-42a1-a5c3-b2882a965a38}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{934d0345-7222-42ef-84a7-7cb90703b68c}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-18] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-18] (Oracle Corporation)
DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234}
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default [2017-06-06]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\iwjz5abn.default -> My Way
FF Homepage: Mozilla\Firefox\Profiles\iwjz5abn.default -> seznam.cz
FF Extension: (Forecastfox) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2015-12-15]
FF Extension: (Oskar) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{5b175400-2368-11de-8c30-0800200c9a66} [2011-02-02] [not signed]
FF Extension: (DownloadHelper) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2015-06-10]
FF Extension: (AmbientFox) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9} [2011-02-08] [not signed]
FF SearchPlugin: C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\searchplugins\Retrogamer_2z.xml [2011-07-04]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml [2011-04-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-11] ()
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-05] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxps://www.seznam.cz/
CHR StartupUrls: Profile 1 -> "hxxps://www.seznam.cz/"
CHR Profile: C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default [2017-06-04]
CHR Extension: (Prezentace Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-29]
CHR Extension: (Dokumenty Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-29]
CHR Extension: (Disk Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-29]
CHR Extension: (YouTube) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-29]
CHR Extension: (Vyhledávání Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-29]
CHR Extension: (Tabulky Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-29]
CHR Extension: (Gmail) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-29]
CHR Profile: C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-06-06]
CHR Extension: (Prezentace Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-29]
CHR Extension: (Dokumenty Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-29]
CHR Extension: (Disk Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-29]
CHR Extension: (YouTube) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-29]
CHR Extension: (Vyhledávání Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-29]
CHR Extension: (Tabulky Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (AdBlock) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-04-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-15]
CHR Extension: (Gmail) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-29]
CHR Extension: (Chrome Media Router) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-26]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3398608 2017-05-09] (Malwarebytes)
S2 RzWizardService; C:\Program Files\Razer\RzWizard\RzWizardService.exe [376272 2016-03-23] (Razer Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [280376 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23264 2016-09-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63l.sys [4715008 2015-10-30] (Broadcom Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [59936 2017-06-06] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [162208 2017-06-05] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [97208 2017-06-06] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [39840 2017-06-06] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [220576 2017-06-06] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [74656 2017-06-06] (Malwarebytes)
R1 MpKsl347aafb3; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{02E59C75-718B-4BB6-8CD4-2491752E89AA}\MpKsl347aafb3.sys [39168 2017-06-05] (Microsoft Corporation)
R1 MpKsl6646ed31; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59F601AF-3FD3-44E7-92B4-D297F835EDED}\MpKsl6646ed31.sys [39168 2017-02-05] (Microsoft Corporation)
R2 SecDrv; C:\WINDOWS\system32\drivers\SECDRV.SYS [12400 2016-02-22] (Macrovision Europe Ltd) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37400 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [246104 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [98648 2015-10-30] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [163328 2015-10-30] (Microsoft Corporation)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-06 20:04 - 2017-06-06 20:05 - 00013254 _____ C:\Users\p.Martina\Desktop\FRST.txt
2017-06-06 20:03 - 2017-06-06 20:04 - 01774080 _____ (Farbar) C:\Users\p.Martina\Desktop\FRST.exe
2017-06-06 20:01 - 2017-06-06 20:01 - 00000721 _____ C:\Users\p.Martina\Desktop\OSType.txt
2017-06-06 20:00 - 2017-06-06 20:02 - 00015327 _____ C:\Users\p.Martina\Desktop\LM.bat
2017-06-06 19:46 - 2017-06-06 19:46 - 00000000 ____D C:\Users\p.Martina\AppData\Roaming\VitySoft
2017-06-06 19:46 - 2017-06-06 19:46 - 00000000 ____D C:\Users\p.Martina\.objectdb
2017-06-06 19:44 - 2017-03-22 21:54 - 00000000 ____D C:\Users\p.Martina\Desktop\FreeRapid
2017-06-06 19:43 - 2017-06-06 19:47 - 16723996 _____ C:\Users\p.Martina\Desktop\FreeRapid.rar
2017-06-05 17:04 - 2017-06-05 17:04 - 00162208 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-06-05 17:03 - 2017-06-06 05:02 - 00074656 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-06-05 17:03 - 2017-06-06 03:54 - 00220576 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-06-05 17:03 - 2017-06-06 03:54 - 00097208 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-06-05 17:03 - 2017-06-06 03:54 - 00039840 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-06-05 17:03 - 2017-06-06 00:25 - 00059936 _____ C:\WINDOWS\system32\Drivers\mbae.sys
2017-06-05 17:03 - 2017-06-05 17:03 - 00002093 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-06-05 17:03 - 2017-06-05 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-06-05 17:02 - 2017-06-05 17:02 - 00000000 ____D C:\Program Files\Malwarebytes
2017-06-05 16:58 - 2017-06-05 17:02 - 64025992 _____ (Malwarebytes ) C:\Users\p.Martina\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.139-1.0.2060.exe
2017-06-05 16:51 - 2017-06-05 16:59 - 04110280 _____ C:\Users\p.Martina\Desktop\adwcleaner_6.047.exe
2017-05-30 10:18 - 2017-05-30 10:18 - 00678382 _____ C:\Users\p.Martina\Desktop\smlouva.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-06 20:04 - 2014-03-21 17:13 - 00000000 ____D C:\FRST
2017-06-06 20:02 - 2014-03-21 17:03 - 00029696 _____ C:\Users\p.Martina\AppData\Local\MSGBOX.EXE
2017-06-06 19:46 - 2016-01-29 14:25 - 00000000 ____D C:\Users\p.Martina
2017-06-06 05:41 - 2011-02-02 12:15 - 00000000 ____D C:\Users\p.Martina\AppData\Roaming\vlc
2017-06-06 03:58 - 2016-01-29 14:24 - 01996112 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-06 03:58 - 2015-10-30 17:08 - 00830550 _____ C:\WINDOWS\system32\perfh005.dat
2017-06-06 03:58 - 2015-10-30 17:08 - 00185322 _____ C:\WINDOWS\system32\perfc005.dat
2017-06-06 03:58 - 2015-10-30 07:47 - 00000000 ____D C:\WINDOWS\INF
2017-06-06 03:56 - 2015-10-30 07:48 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-06 03:53 - 2016-01-29 14:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-05 17:02 - 2015-08-20 16:26 - 00000000 ____D C:\AdwCleaner
2017-06-05 17:02 - 2014-06-13 10:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-04 21:00 - 2015-10-30 07:48 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-30 22:45 - 2011-02-02 12:04 - 00456360 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-25 09:07 - 2016-01-29 15:14 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-25 09:07 - 2016-01-29 15:14 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-11 09:04 - 2017-04-13 11:06 - 05821944 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2017-05-11 09:04 - 2015-10-30 07:48 - 00000000 ____D C:\WINDOWS\system32\Macromed
==================== Files in the root of some directories =======
2012-12-17 11:25 - 2017-05-05 08:35 - 0001291 _____ () C:\Users\p.Martina\AppData\Roaming\mainhst.zgh
2014-03-21 17:03 - 2017-06-06 20:02 - 0029696 _____ () C:\Users\p.Martina\AppData\Local\MSGBOX.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-02 09:16
==================== End of FRST.txt ============================
FRST scan
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 05-06-2017
Ran by p.Martina (administrator) on PMARTINA-PC (06-06-2017 20:04:25)
Running from C:\Users\p.Martina\Desktop
Loaded Profiles: p.Martina (Available Profiles: p.Martina & DefaultAppPool)
Platform: Microsoft Windows 10 Pro Version 1511 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_65\bin\javaw.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\WINDOWS\System32\browser_broker.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM\...\Run: [RzWizard] => C:\Program Files\Razer\RzWizard\RzWizard.exe [263112 2016-03-23] (Razer Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKU\S-1-5-21-528259500-889367275-2168026962-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-528259500-889367275-2168026962-1000\...\MountPoints2: {1bbb54a0-e920-11e6-86dc-001eec538b51} - "E:\HiSuiteDownLoader.exe"
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6f01c5af-451c-42a1-a5c3-b2882a965a38}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{934d0345-7222-42ef-84a7-7cb90703b68c}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-11-18] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-18] (Oracle Corporation)
DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234}
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default [2017-06-06]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\iwjz5abn.default -> My Way
FF Homepage: Mozilla\Firefox\Profiles\iwjz5abn.default -> seznam.cz
FF Extension: (Forecastfox) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2015-12-15]
FF Extension: (Oskar) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{5b175400-2368-11de-8c30-0800200c9a66} [2011-02-02] [not signed]
FF Extension: (DownloadHelper) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2015-06-10]
FF Extension: (AmbientFox) - C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\Extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9} [2011-02-08] [not signed]
FF SearchPlugin: C:\Users\p.Martina\AppData\Roaming\Mozilla\Firefox\Profiles\iwjz5abn.default\searchplugins\Retrogamer_2z.xml [2011-07-04]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml [2011-04-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-11] ()
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-05] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxps://www.seznam.cz/
CHR StartupUrls: Profile 1 -> "hxxps://www.seznam.cz/"
CHR Profile: C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default [2017-06-04]
CHR Extension: (Prezentace Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-29]
CHR Extension: (Dokumenty Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-29]
CHR Extension: (Disk Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-29]
CHR Extension: (YouTube) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-29]
CHR Extension: (Vyhledávání Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-29]
CHR Extension: (Tabulky Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-29]
CHR Extension: (Gmail) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-29]
CHR Profile: C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-06-06]
CHR Extension: (Prezentace Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-29]
CHR Extension: (Dokumenty Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-29]
CHR Extension: (Disk Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-29]
CHR Extension: (YouTube) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-29]
CHR Extension: (Vyhledávání Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-29]
CHR Extension: (Tabulky Google) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (AdBlock) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-04-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-15]
CHR Extension: (Gmail) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-29]
CHR Extension: (Chrome Media Router) - C:\Users\p.Martina\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-26]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3398608 2017-05-09] (Malwarebytes)
S2 RzWizardService; C:\Program Files\Razer\RzWizard\RzWizardService.exe [376272 2016-03-23] (Razer Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [280376 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23264 2016-09-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63l.sys [4715008 2015-10-30] (Broadcom Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae.sys [59936 2017-06-06] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [162208 2017-06-05] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [97208 2017-06-06] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [39840 2017-06-06] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [220576 2017-06-06] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [74656 2017-06-06] (Malwarebytes)
R1 MpKsl347aafb3; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{02E59C75-718B-4BB6-8CD4-2491752E89AA}\MpKsl347aafb3.sys [39168 2017-06-05] (Microsoft Corporation)
R1 MpKsl6646ed31; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59F601AF-3FD3-44E7-92B4-D297F835EDED}\MpKsl6646ed31.sys [39168 2017-02-05] (Microsoft Corporation)
R2 SecDrv; C:\WINDOWS\system32\drivers\SECDRV.SYS [12400 2016-02-22] (Macrovision Europe Ltd) [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37400 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [246104 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [98648 2015-10-30] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [163328 2015-10-30] (Microsoft Corporation)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-06 20:04 - 2017-06-06 20:05 - 00013254 _____ C:\Users\p.Martina\Desktop\FRST.txt
2017-06-06 20:03 - 2017-06-06 20:04 - 01774080 _____ (Farbar) C:\Users\p.Martina\Desktop\FRST.exe
2017-06-06 20:01 - 2017-06-06 20:01 - 00000721 _____ C:\Users\p.Martina\Desktop\OSType.txt
2017-06-06 20:00 - 2017-06-06 20:02 - 00015327 _____ C:\Users\p.Martina\Desktop\LM.bat
2017-06-06 19:46 - 2017-06-06 19:46 - 00000000 ____D C:\Users\p.Martina\AppData\Roaming\VitySoft
2017-06-06 19:46 - 2017-06-06 19:46 - 00000000 ____D C:\Users\p.Martina\.objectdb
2017-06-06 19:44 - 2017-03-22 21:54 - 00000000 ____D C:\Users\p.Martina\Desktop\FreeRapid
2017-06-06 19:43 - 2017-06-06 19:47 - 16723996 _____ C:\Users\p.Martina\Desktop\FreeRapid.rar
2017-06-05 17:04 - 2017-06-05 17:04 - 00162208 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-06-05 17:03 - 2017-06-06 05:02 - 00074656 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-06-05 17:03 - 2017-06-06 03:54 - 00220576 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-06-05 17:03 - 2017-06-06 03:54 - 00097208 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-06-05 17:03 - 2017-06-06 03:54 - 00039840 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-06-05 17:03 - 2017-06-06 00:25 - 00059936 _____ C:\WINDOWS\system32\Drivers\mbae.sys
2017-06-05 17:03 - 2017-06-05 17:03 - 00002093 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-06-05 17:03 - 2017-06-05 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-06-05 17:02 - 2017-06-05 17:02 - 00000000 ____D C:\Program Files\Malwarebytes
2017-06-05 16:58 - 2017-06-05 17:02 - 64025992 _____ (Malwarebytes ) C:\Users\p.Martina\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.139-1.0.2060.exe
2017-06-05 16:51 - 2017-06-05 16:59 - 04110280 _____ C:\Users\p.Martina\Desktop\adwcleaner_6.047.exe
2017-05-30 10:18 - 2017-05-30 10:18 - 00678382 _____ C:\Users\p.Martina\Desktop\smlouva.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-06 20:04 - 2014-03-21 17:13 - 00000000 ____D C:\FRST
2017-06-06 20:02 - 2014-03-21 17:03 - 00029696 _____ C:\Users\p.Martina\AppData\Local\MSGBOX.EXE
2017-06-06 19:46 - 2016-01-29 14:25 - 00000000 ____D C:\Users\p.Martina
2017-06-06 05:41 - 2011-02-02 12:15 - 00000000 ____D C:\Users\p.Martina\AppData\Roaming\vlc
2017-06-06 03:58 - 2016-01-29 14:24 - 01996112 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-06 03:58 - 2015-10-30 17:08 - 00830550 _____ C:\WINDOWS\system32\perfh005.dat
2017-06-06 03:58 - 2015-10-30 17:08 - 00185322 _____ C:\WINDOWS\system32\perfc005.dat
2017-06-06 03:58 - 2015-10-30 07:47 - 00000000 ____D C:\WINDOWS\INF
2017-06-06 03:56 - 2015-10-30 07:48 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-06 03:53 - 2016-01-29 14:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-05 17:02 - 2015-08-20 16:26 - 00000000 ____D C:\AdwCleaner
2017-06-05 17:02 - 2014-06-13 10:09 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-04 21:00 - 2015-10-30 07:48 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-30 22:45 - 2011-02-02 12:04 - 00456360 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-25 09:07 - 2016-01-29 15:14 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-25 09:07 - 2016-01-29 15:14 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-11 09:04 - 2017-04-13 11:06 - 05821944 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2017-05-11 09:04 - 2015-10-30 07:48 - 00000000 ____D C:\WINDOWS\system32\Macromed
==================== Files in the root of some directories =======
2012-12-17 11:25 - 2017-05-05 08:35 - 0001291 _____ () C:\Users\p.Martina\AppData\Roaming\mainhst.zgh
2014-03-21 17:03 - 2017-06-06 20:02 - 0029696 _____ () C:\Users\p.Martina\AppData\Local\MSGBOX.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-02 09:16
==================== End of FRST.txt ============================