Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-06-2017 01
Ran by Monika 1 (administrator) on MONIKA1-PC (09-06-2017 22:47:15)
Running from C:\Users\Monika 1\Desktop
Loaded Profiles: UpdatusUser & Monika 1 (Available Profiles: UpdatusUser & Monika 1)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Samsung) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BitTorrent Inc.) C:\Users\Monika 1\AppData\Roaming\uTorrent\uTorrent.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
() C:\Program Files (x86)\Polar\Daemon\polard.exe
(Hammer & Chisel, Inc.) C:\Users\Monika 1\AppData\Local\Discord\app-0.0.297\Discord.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(MyHeritage) C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(BitTorrent Inc.) C:\Users\Monika 1\AppData\Roaming\uTorrent\updates\3.5.0_43804\utorrentie.exe
(BitTorrent Inc.) C:\Users\Monika 1\AppData\Roaming\uTorrent\updates\3.5.0_43804\utorrentie.exe
(BitTorrent Inc.) C:\Users\Monika 1\AppData\Roaming\uTorrent\updates\3.5.0_43804\utorrentie.exe
(Hammer & Chisel, Inc.) C:\Users\Monika 1\AppData\Local\Discord\app-0.0.297\Discord.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Hammer & Chisel, Inc.) C:\Users\Monika 1\AppData\Local\Discord\app-0.0.297\Discord.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Monika 1\Downloads\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12558440 2011-07-12] (Realtek Semiconductor)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2721576 2011-06-17] (ELAN Microelectronics Corp.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-12] (AVAST Software)
HKLM-x32\...\Run: [Family Tree Builder Update] => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [14829232 2016-09-05] (MyHeritage)
HKLM-x32\...\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [105120 2012-08-21] (PC Tools)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2015-04-10] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\...\Run: [uTorrent] => C:\Users\Monika 1\AppData\Roaming\uTorrent\uTorrent.exe [1980608 2017-05-31] (BitTorrent Inc.)
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\...\Run: [Discord] => C:\Users\Monika 1\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [226920 2011-06-05] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [193128 2011-06-05] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-12] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-12] (AVAST Software)
GroupPolicy\User: Restriction <======= ATTENTION
GroupPolicyUsers\S-1-5-21-2234519877-4043553204-3602242062-1000\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{3834D084-56B4-47C4-9DAE-FAB240C7FD84}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{B236B5F9-65E2-493C-BC77-966EC4867725}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2234519877-4043553204-3602242062-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2234519877-4043553204-3602242062-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://
www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2234519877-4043553204-3602242062-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://
www.google.com/search?q={searchTerms}&r ... {startPage}
SearchScopes: HKU\S-1-5-21-2234519877-4043553204-3602242062-1001 -> {F470F530-4FF5-494A-BF97-95DB92CC5578} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-10-17] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-16] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-10-17] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2015-05-20] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-16] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2015-05-20] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: 3ref42cx.default-1415191334322
FF ProfilePath: C:\Users\Monika 1\AppData\Roaming\Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 [2017-06-09]
FF NewTab: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> hxxp://
www.google.com/
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> Seznam
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> hxxp://
www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> Google
FF Homepage: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> hxxps://
www.seznam.cz/
FF Keyword.URL: Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322 -> hxxp://
www.google.com/search?btnG=Google+Search&q=
FF Extension: (Avast SafePrice) - C:\Users\Monika 1\AppData\Roaming\Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322\Extensions\
sp@avast.com.xpi [2017-06-09]
FF Extension: (Avast Online Security) - C:\Users\Monika 1\AppData\Roaming\Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322\Extensions\
wrc@avast.com.xpi [2017-06-09]
FF Extension: (Disable TLS Certificate Transparency) - C:\Users\Monika 1\AppData\Roaming\Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322\features\{ba91e302-7d52-47c2-9c05-a3c533a2d2a2}\
disable-cert-transparency@mozilla.org.xpi [2017-05-12]
FF Extension: (Disable Prefetch) - C:\Users\Monika 1\AppData\Roaming\Mozilla\Firefox\Profiles\3ref42cx.default-1415191334322\features\{ba91e302-7d52-47c2-9c05-a3c533a2d2a2}\
disable-prefetch@mozilla.org.xpi [2017-05-12]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-14] ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-10-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-10-17] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-14] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll [2013-02-18] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-08-13] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-08-26] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-05-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2015-05-20] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-09] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-03-30] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Monika 1\AppData\Local\Google\Chrome\User Data\Default [2017-06-08]
CHR Extension: (Avast SafePrice) - C:\Users\Monika 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-08]
CHR Extension: (AdBlock) - C:\Users\Monika 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-05-16]
CHR Extension: (Avast Online Security) - C:\Users\Monika 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-05-31]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Monika 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-12]
CHR Extension: (Chrome Media Router) - C:\Users\Monika 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-31]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7346208 2017-05-12] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-12] (AVAST Software)
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [794272 2012-08-21] (PC Tools)
R2 Polar Daemon; C:\Program Files (x86)\Polar\Daemon\polard.exe [413184 2012-08-17] () [File not signed]
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R1 aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [311808 2017-05-12] (AVAST Software s.r.o.)
R0 aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [190256 2017-05-12] (AVAST Software s.r.o.)
R0 aswblog; C:\windows\system32\drivers\aswbloga.sys [334576 2017-05-12] (AVAST Software s.r.o.)
R0 aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [49016 2017-05-12] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\windows\system32\drivers\aswHdsKe.sys [82936 2017-01-21] (AVAST Software)
S3 aswHwid; C:\windows\system32\drivers\aswHwid.sys [38296 2017-05-12] (AVAST Software)
R1 aswKbd; C:\windows\system32\drivers\aswKbd.sys [32600 2017-05-12] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [128648 2017-05-12] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [101152 2017-05-12] (AVAST Software)
R0 aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [75704 2017-05-12] (AVAST Software)
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1007160 2017-05-12] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [569192 2017-05-12] (AVAST Software)
S2 aswStm; C:\windows\system32\drivers\aswStm.sys [158880 2017-05-12] (AVAST Software)
R0 aswVmm; C:\windows\system32\drivers\aswVmm.sys [339696 2017-05-12] (AVAST Software)
S3 MosIrUsb; C:\windows\System32\DRIVERS\MosIrUsb.sys [27648 2007-10-11] ()
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2011-10-25] (Windows (R) 2003 DDK 3790 provider)
R2 SGDrv; C:\windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-09 22:47 - 2017-06-09 22:48 - 00020814 _____ C:\Users\Monika 1\Desktop\FRST.txt
2017-06-09 15:56 - 2017-06-09 22:45 - 00112640 _____ (forum.viry.cz) C:\Users\Monika 1\Downloads\FRSTLauncher.exe
2017-06-08 19:08 - 2017-06-08 19:08 - 02435072 _____ (Farbar) C:\Users\Monika 1\Desktop\FRST64.exe
2017-06-08 16:23 - 2017-06-08 16:23 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-06-08 16:20 - 2017-06-08 16:21 - 00000000 ____D C:\Users\Monika 1\AppData\LocalLow\uTorrent
2017-05-14 23:36 - 2017-05-14 23:36 - 00081083 _____ C:\Users\Monika 1\Desktop\evropskaunie.pptx
2017-05-14 22:19 - 2017-05-14 22:19 - 00334336 _____ C:\Users\Monika 1\Downloads\european_union_cs.ppt
2017-05-14 22:16 - 2017-05-14 22:16 - 01401856 _____ C:\Users\Monika 1\Downloads\1_historie_eu.ppt
2017-05-12 20:57 - 2017-05-12 20:57 - 00400456 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2017-05-12 20:39 - 2017-05-12 20:39 - 07649280 _____ C:\Program Files (x86)\GUTF285.tmp
2017-05-12 20:39 - 2017-05-12 20:39 - 00000000 ____D C:\Program Files (x86)\GUMF284.tmp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-09 22:47 - 2015-12-16 11:58 - 00000000 ____D C:\FRST
2017-06-09 22:45 - 2013-04-21 12:52 - 00000000 ____D C:\Users\Monika 1\AppData\Roaming\uTorrent
2017-06-09 15:50 - 2016-11-27 09:33 - 00000000 ____D C:\Users\Monika 1\AppData\LocalLow\Mozilla
2017-06-09 15:49 - 2014-12-09 19:09 - 00000000 ____D C:\Users\Monika 1\AppData\Local\CrashDumps
2017-06-09 13:45 - 2017-03-09 20:52 - 00004172 _____ C:\windows\System32\Tasks\Avast Emergency Update
2017-06-08 19:11 - 2009-07-14 06:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-08 19:11 - 2009-07-14 06:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-08 19:03 - 2009-07-14 05:20 - 00000000 ____D C:\windows\inf
2017-06-08 16:30 - 2014-10-18 11:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-08 16:29 - 2016-12-17 08:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-08 16:20 - 2013-04-06 08:29 - 00000000 ____D C:\Program Files (x86)\PC Tools Registry Mechanic
2017-06-08 16:20 - 2011-10-13 02:49 - 00000000 ____D C:\ProgramData\Temp
2017-06-08 16:18 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-05-31 16:22 - 2016-06-18 08:02 - 00003896 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1466229769
2017-05-16 15:10 - 2013-03-05 09:48 - 00002155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-16 15:10 - 2013-03-05 09:48 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-14 20:46 - 2013-01-25 18:46 - 00003384 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-14 20:46 - 2013-01-25 18:46 - 00003256 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-05-14 20:45 - 2011-12-30 05:34 - 00000000 ____D C:\ProgramData\Skype
2017-05-14 20:44 - 2016-06-18 07:57 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-05-14 20:38 - 2012-04-15 09:55 - 00803320 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-05-14 20:38 - 2012-04-15 09:55 - 00004396 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-05-14 20:38 - 2012-03-28 22:49 - 00000000 ____D C:\windows\system32\Macromed
2017-05-14 20:38 - 2011-12-31 19:53 - 00144888 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-14 20:38 - 2011-10-13 01:55 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-05-12 21:05 - 2017-03-19 13:24 - 00000000 ____D C:\windows\Minidump
2017-05-12 20:59 - 2014-01-06 16:18 - 00158880 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2017-05-12 20:58 - 2015-07-14 09:18 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-05-12 20:57 - 2014-05-01 16:54 - 00038296 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2017-05-12 20:57 - 2014-01-06 16:18 - 00158368 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys.149461555908402
2017-05-12 20:57 - 2013-03-05 09:27 - 00339696 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2017-05-12 20:57 - 2013-03-05 09:27 - 00075704 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2017-05-12 20:57 - 2012-05-04 16:14 - 00569192 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2017-05-12 20:57 - 2012-05-04 16:14 - 00128648 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2017-05-12 20:57 - 2012-05-04 16:14 - 00101152 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2017-05-12 20:54 - 2017-03-09 20:52 - 00334576 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbloga.sys
2017-05-12 20:54 - 2017-03-09 20:52 - 00311808 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsdrivera.sys
2017-05-12 20:54 - 2017-03-09 20:52 - 00190256 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsha.sys
2017-05-12 20:54 - 2017-03-09 20:52 - 00049016 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbuniva.sys
2017-05-12 20:54 - 2016-06-18 07:58 - 00032600 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2017-05-12 20:54 - 2012-05-04 16:14 - 01007160 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
==================== Files in the root of some directories =======
2017-05-12 20:39 - 2017-05-12 20:39 - 7649280 _____ () C:\Program Files (x86)\GUTF285.tmp
2014-07-02 14:00 - 2016-12-22 13:58 - 0005120 _____ () C:\Users\Monika 1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-13 02:58 - 2011-10-13 02:58 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2011-10-13 02:49 - 2011-10-13 02:51 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2011-10-13 02:55 - 2011-10-13 02:56 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2011-10-13 02:51 - 2011-10-13 02:55 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2011-10-13 02:56 - 2011-10-13 02:58 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-09 08:46
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:230 GB) (Free:24.38 GB) NTFS
Drive d: () (Fixed) (Total:343.51 GB) (Free:297.01 GB) NTFS
Available physical RAM: 2327.7 MB
Total physical RAM: 4009.55 MB
Percentage of memory in use: 41%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 596.2 GB) (Disk ID: AE14AA3C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=230 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=343.5 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=22.6 GB) - (Type=27)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 [106]
==================== Security Center ==================
AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Monika 1\Desktop" je 7733 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================