Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-08-2017
Ran by Terouš123 (administrator) on TEROUS (17-08-2017 17:45:34)
Running from C:\Users\Terouš123\Desktop
Loaded Profiles: Terouš123 (Available Profiles: Terouš123)
Platform: Windows 8.1 Connected (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\SMService.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\StartMenu_Hook.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\InstallServices.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\Users\Terouš123\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(OpenOffice.org) C:\OpenOffice.org 3\program\soffice.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(OpenOffice.org) C:\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Users\Terouš123\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Terouš123\Desktop\FRST64(1).exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-11-04] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-11-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-11-04] (Lenovo(beijing) Limited)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-08-15] (AVAST Software)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (CANON INC.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Terouš123\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Terouš123\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\...\MountPoints2: {b5375676-c050-11e5-8275-d07e352270ad} - "E:\SETUP.EXE"
Startup: C:\Users\Terouš123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2015-12-30]
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicy: Restriction - Chrome <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.169.1.254
Tcpip\..\Interfaces\{850BF180-2DAF-4A02-9F3E-400A2921EAD9}: [DhcpNameServer] 192.169.1.254
Tcpip\..\Interfaces\{D21874A6-7CC9-4F73-95F2-D1CBF3B5346C}: [DhcpNameServer] 150.206.1.3
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3711724810-2781737708-1749865010-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3711724810-2781737708-1749865010-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3711724810-2781737708-1749865010-1001 -> {1A1EA4EB-46C6-4261-B471-C9C2E1FE7464} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=227087&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3711724810-2781737708-1749865010-1001 -> {A0C491AD-D9FB-42B2-A65D-A9E664E3BD09} URL =
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-08-15] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-08-15] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2015-12-30] (Sun Microsystems, Inc.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
FireFox:
========
FF ProfilePath: C:\Users\Terouš123\AppData\Roaming\Mozilla\Firefox\Profiles\v7rprzqo.default-1485073331522 [2017-08-17]
FF Homepage: Mozilla\Firefox\Profiles\v7rprzqo.default-1485073331522 -> hxxps://
www.seznam.cz/
FF Extension: (Avast SafePrice) - C:\Users\Terouš123\AppData\Roaming\Mozilla\Firefox\Profiles\v7rprzqo.default-1485073331522\Extensions\
sp@avast.com.xpi [2017-06-30]
FF Extension: (Avast Online Security) - C:\Users\Terouš123\AppData\Roaming\Mozilla\Firefox\Profiles\v7rprzqo.default-1485073331522\Extensions\
wrc@avast.com.xpi [2017-08-17]
FF Extension: (Seznam lištička) - C:\Users\Terouš123\AppData\Roaming\Mozilla\Firefox\Profiles\v7rprzqo.default-1485073331522\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-08-14]
FF HKLM-x32\...\Firefox\Extensions: [
deskCutv2@gmail.com] - C:\Users\Terouš123\AppData\Roaming\Mozilla\Firefox\Profiles\jnxk3zh6.default\extensions\
deskCutv2@gmail.com => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-15] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-15] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2015-12-30] (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-07] (Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.google.com
CHR Profile: C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default [2017-08-17]
CHR Extension: (Prezentace Google) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-04-11]
CHR Extension: (Dokumenty Google) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-11]
CHR Extension: (Disk Google) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-11]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2017-08-17]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2017-08-17]
CHR Extension: (YouTube) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-11]
CHR Extension: (Avast SafePrice) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-04-11]
CHR Extension: (Tabulky Google) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-14]
CHR Extension: (Avast Online Security) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-08-14]
CHR Extension: (Skype) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-08-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-11]
CHR Extension: (Gmail) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-11]
CHR Extension: (Chrome Media Router) - C:\Users\Terouš123\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-17]
CHR HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [blmojkbhnkkphngknkmgccmlenfaelkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3711724810-2781737708-1749865010-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olfeabkoenfaoljndfecamgilllcpiak] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-08-15] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-08-15] (AVAST Software)
R2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [130008 2014-01-22] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-02] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-02] (Intel(R) Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-11-04] (Lenovo(beijing) Limited)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-18] ()
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-11-04] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [305136 2014-11-04] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S2 SkypeUpdate; C:\Program Files (x86)\Skype\Updater\Updater.exe [317400 2017-02-27] () [File not signed]
R2 SMService; C:\program files (x86)\iobit\Classic Start\SMService.exe [1077536 2017-01-16] (IObit)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-11-04] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-18] (Intel® Corporation)
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [320008 2017-08-15] (AVAST Software s.r.o.)
R0 aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [198976 2017-08-15] (AVAST Software s.r.o.)
R0 aswblog; C:\windows\system32\drivers\aswbloga.sys [343288 2017-08-15] (AVAST Software s.r.o.)
R0 aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [57728 2017-08-15] (AVAST Software s.r.o.)
S3 aswHwid; C:\windows\system32\drivers\aswHwid.sys [46984 2017-08-15] (AVAST Software)
R1 aswKbd; C:\windows\system32\drivers\aswKbd.sys [41800 2017-08-15] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [146704 2017-08-15] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [110352 2017-08-15] (AVAST Software)
R0 aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [84392 2017-08-15] (AVAST Software)
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1015880 2017-08-15] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [585608 2017-08-15] (AVAST Software)
R2 aswStm; C:\windows\system32\drivers\aswStm.sys [198768 2017-08-15] (AVAST Software)
R0 aswVmm; C:\windows\system32\drivers\aswVmm.sys [361336 2017-08-15] (AVAST Software)
R3 btmaux; C:\windows\system32\DRIVERS\btmaux.sys [140600 2013-11-07] (Motorola Solutions, Inc.)
R3 btmhsf; C:\windows\system32\DRIVERS\btmhsf.sys [1411384 2013-11-07] (Motorola Solutions, Inc.)
S3 dg_ssudbus; C:\windows\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
R3 ibtusb; C:\windows\system32\DRIVERS\ibtusb.sys [149448 2014-01-22] (Intel Corporation)
R0 MBI; C:\windows\System32\drivers\MBI.sys [29464 2013-10-10] (Intel Corporation)
R3 NETwNb64; C:\windows\system32\DRIVERS\Netwbw02.sys [3443680 2014-06-01] (Intel Corporation)
S3 NETwNe64; C:\windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 SmbDrvI; C:\windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-24] (Synaptics Incorporated)
R3 SNP2UVC; C:\windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-24] (Sonix Co. Ltd.)
S3 ssudmdm; C:\windows\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
R3 TXEIx64; C:\windows\System32\drivers\TXEIx64.sys [88592 2014-01-16] (Intel Corporation)
S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 wsvd; C:\windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-17 17:42 - 2017-08-17 17:42 - 002395648 _____ (Farbar) C:\Users\Terouš123\Desktop\FRST64(1).exe
2017-08-17 16:09 - 2017-08-17 16:09 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-08-16 18:50 - 2017-08-16 18:57 - 000000000 ____D C:\AdwCleaner
2017-08-16 18:50 - 2017-08-16 18:50 - 008185288 _____ (Malwarebytes) C:\Users\Terouš123\Desktop\adwcleaner_7.0.1.0.exe
2017-08-16 17:26 - 2017-07-29 02:03 - 000835576 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-08-16 17:26 - 2017-07-29 02:03 - 000177648 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-08-16 16:43 - 2017-04-21 23:50 - 000030912 _____ (Microsoft Corporation) C:\windows\system32\aspnet_counters.dll
2017-08-16 16:42 - 2017-04-21 23:53 - 000029376 _____ (Microsoft Corporation) C:\windows\SysWOW64\aspnet_counters.dll
2017-08-16 16:42 - 2017-04-21 23:53 - 000018600 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100_clr0400.dll
2017-08-16 16:42 - 2017-04-21 23:50 - 000018592 _____ (Microsoft Corporation) C:\windows\system32\msvcr100_clr0400.dll
2017-08-16 16:42 - 2017-04-11 20:27 - 000987840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120_clr0400.dll
2017-08-16 16:42 - 2017-04-11 20:27 - 000485576 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp120_clr0400.dll
2017-08-16 16:42 - 2017-03-15 20:15 - 000993632 _____ (Microsoft Corporation) C:\windows\system32\msvcr120_clr0400.dll
2017-08-16 16:42 - 2017-03-15 20:15 - 000690008 _____ (Microsoft Corporation) C:\windows\system32\msvcp120_clr0400.dll
2017-08-16 16:23 - 2017-05-04 01:11 - 000103600 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2017-08-16 16:23 - 2017-05-03 15:43 - 001555968 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 001206272 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 000620544 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 000535552 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 000325632 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 000311296 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 000217088 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2017-08-16 16:23 - 2017-05-03 15:43 - 000127488 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2017-08-16 16:06 - 2017-08-16 16:16 - 000036772 _____ C:\Users\Terouš123\Desktop\Addition.txt
2017-08-16 16:05 - 2017-07-21 15:40 - 000518144 _____ C:\windows\SysWOW64\msjetoledb40.dll
2017-08-16 16:05 - 2017-07-21 15:40 - 000290816 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjtes40.dll
2017-08-16 16:05 - 2017-07-14 08:49 - 025733632 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2017-08-16 16:05 - 2017-07-14 08:44 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2017-08-16 16:05 - 2017-07-14 08:19 - 000817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2017-08-16 16:05 - 2017-07-14 07:35 - 005981184 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2017-08-16 16:05 - 2017-07-14 07:26 - 001033216 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2017-08-16 16:05 - 2017-07-14 07:10 - 000806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2017-08-16 16:05 - 2017-07-14 06:40 - 015254016 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2017-08-16 16:05 - 2017-07-14 06:23 - 003240960 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2017-08-16 16:05 - 2017-07-14 06:07 - 001545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2017-08-16 16:05 - 2017-07-14 05:58 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2017-08-16 16:05 - 2017-07-14 04:54 - 020270080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2017-08-16 16:05 - 2017-07-14 04:48 - 000499200 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2017-08-16 16:05 - 2017-07-14 04:38 - 000663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2017-08-16 16:05 - 2017-07-14 04:17 - 004546048 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2017-08-16 16:05 - 2017-07-14 04:17 - 000880640 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2017-08-16 16:05 - 2017-07-14 04:12 - 000693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2017-08-16 16:05 - 2017-07-14 04:09 - 013663744 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2017-08-16 16:05 - 2017-07-14 03:53 - 002767872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2017-08-16 16:05 - 2017-07-14 03:50 - 001314816 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2017-08-16 16:05 - 2017-07-14 03:48 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2017-08-16 16:05 - 2017-07-08 22:14 - 000376672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\clfs.sys
2017-08-16 16:05 - 2017-07-08 21:12 - 004169728 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2017-08-16 16:05 - 2017-07-08 19:45 - 007078912 _____ (Microsoft Corporation) C:\windows\system32\glcndFilter.dll
2017-08-16 16:05 - 2017-07-08 19:05 - 003631616 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2017-08-16 16:05 - 2017-07-08 18:39 - 005274624 _____ (Microsoft Corporation) C:\windows\SysWOW64\glcndFilter.dll
2017-08-16 16:05 - 2017-07-08 18:37 - 007797248 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2017-08-16 16:05 - 2017-07-08 18:23 - 002749952 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2017-08-16 16:05 - 2017-07-08 17:59 - 005270016 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2017-08-16 16:05 - 2017-07-08 05:16 - 007440728 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2017-08-16 16:05 - 2017-07-08 05:16 - 001674520 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2017-08-16 16:05 - 2017-07-08 05:16 - 001534072 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2017-08-16 16:05 - 2017-07-08 05:16 - 001499920 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2017-08-16 16:05 - 2017-07-08 05:16 - 001370328 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2017-08-16 16:05 - 2017-07-08 05:16 - 000086360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pdc.sys
2017-08-16 16:05 - 2017-07-01 15:47 - 001311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjet40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000616448 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrepl40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000475648 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxbde40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000375808 _____ (Microsoft Corporation) C:\windows\SysWOW64\mspbde40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000343552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrd3x40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000339968 _____ (Microsoft Corporation) C:\windows\SysWOW64\msexcl40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000310272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrd2x40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000272896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstext40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000240640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msltus40.dll
2017-08-16 16:05 - 2017-07-01 15:47 - 000144896 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjint40.dll
2017-08-16 16:05 - 2017-06-24 18:46 - 000424448 _____ (Microsoft Corporation) C:\windows\system32\mprapi.dll
2017-08-16 16:05 - 2017-06-16 00:02 - 000990040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2017-08-16 16:05 - 2017-06-15 16:17 - 002551808 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2017-08-16 16:05 - 2017-06-15 16:16 - 001920000 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2017-08-16 16:05 - 2017-06-13 19:51 - 000324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-08-16 16:05 - 2017-06-13 19:23 - 000499200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll
2017-08-16 16:05 - 2017-06-13 16:17 - 000656384 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll
2017-08-16 16:05 - 2017-06-13 11:09 - 000445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-08-16 16:05 - 2017-06-13 10:22 - 001436160 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-08-16 16:05 - 2017-06-13 09:50 - 001547264 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
2017-08-16 16:05 - 2017-06-11 23:15 - 001436672 _____ (Microsoft Corporation) C:\windows\system32\wdc.dll
2017-08-16 16:05 - 2017-06-11 23:08 - 000358912 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll
2017-08-16 16:05 - 2017-06-11 23:00 - 000962560 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-08-16 16:05 - 2017-06-11 22:35 - 000325120 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll
2017-08-16 16:05 - 2017-06-11 22:31 - 000781312 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-08-16 16:05 - 2017-06-11 22:13 - 000301056 _____ (Microsoft Corporation) C:\windows\system32\umrdp.dll
2017-08-16 16:05 - 2017-06-11 22:11 - 000346112 _____ (Microsoft Corporation) C:\windows\system32\SessEnv.dll
2017-08-16 16:05 - 2017-06-11 22:02 - 002778112 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2017-08-16 16:05 - 2017-06-11 21:52 - 002463744 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2017-08-16 16:05 - 2017-06-11 17:15 - 002013528 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2017-08-16 16:05 - 2017-06-09 15:47 - 000448629 _____ C:\windows\system32\ApnDatabase.xml
2017-08-16 16:05 - 2017-06-08 19:01 - 001737600 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2017-08-16 16:05 - 2017-06-08 19:01 - 001502000 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2017-08-16 16:05 - 2017-06-08 03:48 - 002457936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2017-08-16 16:05 - 2017-06-06 22:52 - 003120640 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2017-08-16 16:05 - 2017-06-06 22:42 - 000925696 _____ (Microsoft Corporation) C:\windows\system32\autoconv.exe
2017-08-16 16:05 - 2017-06-06 22:35 - 000517120 _____ (Microsoft Corporation) C:\windows\system32\uReFS.dll
2017-08-16 16:05 - 2017-06-06 21:11 - 000557568 _____ (Microsoft Corporation) C:\windows\system32\untfs.dll
2017-08-16 16:05 - 2017-06-06 21:08 - 002712576 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2017-08-16 16:05 - 2017-06-06 21:03 - 000837632 _____ (Microsoft Corporation) C:\windows\SysWOW64\autoconv.exe
2017-08-16 16:05 - 2017-06-06 20:56 - 000375296 _____ (Microsoft Corporation) C:\windows\SysWOW64\uReFS.dll
2017-08-16 16:05 - 2017-06-06 20:02 - 000513536 _____ (Microsoft Corporation) C:\windows\SysWOW64\untfs.dll
2017-08-16 16:05 - 2017-06-03 18:27 - 002346496 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2017-08-16 16:05 - 2017-06-03 18:03 - 001549312 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2017-08-16 16:05 - 2017-06-02 14:15 - 000337408 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2017-08-16 16:05 - 2017-06-02 14:12 - 000468992 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2017-08-16 16:05 - 2017-06-02 14:12 - 000248832 _____ (Microsoft Corporation) C:\windows\system32\mssphtb.dll
2017-08-16 16:05 - 2017-06-02 14:01 - 000774144 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2017-08-16 16:05 - 2017-06-02 13:03 - 000903168 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2017-08-16 16:05 - 2017-06-02 12:25 - 000272896 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2017-08-16 16:05 - 2017-06-02 12:24 - 000391680 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2017-08-16 16:05 - 2017-06-02 12:17 - 000699392 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2017-08-16 16:05 - 2017-06-02 11:43 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2017-08-16 16:05 - 2017-05-27 18:42 - 001115136 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2017-08-16 16:05 - 2017-05-27 18:38 - 000056832 _____ (Microsoft Corporation) C:\windows\system32\rdsdwmdr.dll
2017-08-16 16:05 - 2017-05-14 22:19 - 001364040 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2017-08-16 16:05 - 2017-05-12 18:16 - 001084928 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2017-08-16 16:05 - 2017-05-12 18:13 - 001559552 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2017-08-16 16:05 - 2017-05-12 04:58 - 001985536 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2017-08-16 16:05 - 2017-05-12 04:48 - 001377792 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2017-08-16 16:05 - 2017-05-12 04:18 - 003714560 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-08-16 16:05 - 2017-05-12 01:36 - 022361848 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2017-08-16 16:05 - 2017-05-12 01:32 - 019788672 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2017-08-16 16:05 - 2017-05-09 16:35 - 000555520 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSDApi.dll
2017-08-16 16:05 - 2017-05-06 18:05 - 001094656 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2017-08-16 16:05 - 2017-04-28 03:13 - 001292288 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2017-08-16 16:05 - 2017-04-28 03:11 - 001060352 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe
2017-08-16 16:05 - 2017-04-06 18:46 - 000434688 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-08-16 16:05 - 2017-04-06 18:35 - 001362432 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll
2017-08-16 16:05 - 2017-04-06 18:15 - 000358912 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-08-16 16:04 - 2017-08-02 05:17 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2017-08-16 16:04 - 2017-07-15 12:10 - 000536688 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2017-08-16 16:04 - 2017-07-15 12:10 - 000140016 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
2017-08-16 16:04 - 2017-07-15 12:06 - 000449840 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2017-08-16 16:04 - 2017-07-15 12:06 - 000136832 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
2017-08-16 16:04 - 2017-07-14 22:08 - 000037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2017-08-16 16:04 - 2017-07-14 20:44 - 000033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\werdiagcontroller.dll
2017-08-16 16:04 - 2017-07-08 05:46 - 000377688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\volmgrx.sys
2017-08-16 16:04 - 2017-07-06 10:52 - 000119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthpan.sys
2017-08-16 16:04 - 2017-07-01 15:47 - 000866816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswdat10.dll
2017-08-16 16:04 - 2017-07-01 15:47 - 000641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswstr10.dll
2017-08-16 16:04 - 2017-07-01 15:47 - 000083968 _____ (Microsoft Corporation) C:\windows\SysWOW64\msjter40.dll
2017-08-16 16:04 - 2017-06-24 18:16 - 000352768 _____ (Microsoft Corporation) C:\windows\SysWOW64\mprapi.dll
2017-08-16 16:04 - 2017-06-13 19:19 - 000383488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlansec.dll
2017-08-16 16:04 - 2017-06-13 19:16 - 000024064 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfdprov.dll
2017-08-16 16:04 - 2017-06-13 19:11 - 000238080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanapi.dll
2017-08-16 16:04 - 2017-06-13 19:07 - 000304128 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanmsm.dll
2017-08-16 16:04 - 2017-06-13 16:16 - 000252416 _____ (Microsoft Corporation) C:\windows\system32\dnsrslvr.dll
2017-08-16 16:04 - 2017-06-13 11:47 - 000445440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nwifi.sys
2017-08-16 16:04 - 2017-06-13 10:16 - 000445952 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll
2017-08-16 16:04 - 2017-06-13 10:10 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\wfdprov.dll
2017-08-16 16:04 - 2017-06-13 10:07 - 000301568 _____ (Microsoft Corporation) C:\windows\system32\ProximityService.dll
2017-08-16 16:04 - 2017-06-13 10:03 - 000302080 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll
2017-08-16 16:04 - 2017-06-13 09:54 - 000374272 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll
2017-08-16 16:04 - 2017-06-12 02:14 - 000276320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2017-08-16 16:04 - 2017-06-12 00:21 - 000590848 _____ (Microsoft Corporation) C:\windows\system32\wvc.dll
2017-08-16 16:04 - 2017-06-11 23:43 - 000371200 _____ (Microsoft Corporation) C:\windows\system32\msinfo32.exe
2017-08-16 16:04 - 2017-06-11 23:25 - 000478720 _____ (Microsoft Corporation) C:\windows\SysWOW64\wvc.dll
2017-08-16 16:04 - 2017-06-11 23:07 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\sysmon.ocx
2017-08-16 16:04 - 2017-06-11 22:58 - 000334336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msinfo32.exe
2017-08-16 16:04 - 2017-06-11 22:40 - 001323008 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdc.dll
2017-08-16 16:04 - 2017-06-11 22:02 - 000299520 _____ (Microsoft Corporation) C:\windows\SysWOW64\SessEnv.dll
2017-08-16 16:04 - 2017-06-07 06:25 - 000428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2017-08-16 16:04 - 2017-06-06 22:38 - 000039424 _____ (Microsoft Corporation) C:\windows\system32\cnvfat.dll
2017-08-16 16:04 - 2017-06-06 22:36 - 000168448 _____ (Microsoft Corporation) C:\windows\system32\uudf.dll
2017-08-16 16:04 - 2017-06-06 22:36 - 000020992 _____ (Microsoft Corporation) C:\windows\system32\convert.exe
2017-08-16 16:04 - 2017-06-06 21:13 - 000177664 _____ (Microsoft Corporation) C:\windows\system32\ulib.dll
2017-08-16 16:04 - 2017-06-06 21:11 - 000220672 _____ (Microsoft Corporation) C:\windows\system32\ifsutil.dll
2017-08-16 16:04 - 2017-06-06 21:11 - 000131072 _____ (Microsoft Corporation) C:\windows\system32\ufat.dll
2017-08-16 16:04 - 2017-06-06 21:11 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\uexfat.dll
2017-08-16 16:04 - 2017-06-06 20:59 - 000034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\cnvfat.dll
2017-08-16 16:04 - 2017-06-06 20:57 - 000141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\uudf.dll
2017-08-16 16:04 - 2017-06-06 20:38 - 000607232 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2017-08-16 16:04 - 2017-06-06 20:03 - 000143360 _____ (Microsoft Corporation) C:\windows\SysWOW64\ulib.dll
2017-08-16 16:04 - 2017-06-06 20:02 - 000197120 _____ (Microsoft Corporation) C:\windows\SysWOW64\ifsutil.dll
2017-08-16 16:04 - 2017-06-06 20:02 - 000106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\ufat.dll
2017-08-16 16:04 - 2017-06-06 20:02 - 000074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\uexfat.dll
2017-08-16 16:04 - 2017-06-06 19:44 - 000530432 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2017-08-16 16:04 - 2017-06-02 14:06 - 001001984 _____ (Microsoft Corporation) C:\windows\HelpPane.exe
2017-08-16 16:04 - 2017-05-31 23:20 - 000470360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2017-08-16 16:04 - 2017-05-16 00:09 - 000057688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\stornvme.sys
2017-08-16 16:04 - 2017-05-15 22:03 - 000379744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2017-08-16 16:04 - 2017-05-15 21:58 - 000121184 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tm.sys
2017-08-16 16:04 - 2017-05-14 21:04 - 000315224 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2017-08-16 16:04 - 2017-05-14 21:03 - 000373080 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2017-08-16 16:04 - 2017-05-14 20:13 - 000136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-08-16 16:04 - 2017-05-12 19:05 - 000035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2017-08-16 16:04 - 2017-05-12 17:51 - 000029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2017-08-16 16:04 - 2017-05-12 17:50 - 000124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2017-08-16 16:04 - 2017-05-12 17:48 - 000081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2017-08-16 16:04 - 2017-05-12 17:47 - 000726528 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2017-08-16 16:04 - 2017-05-12 06:10 - 000044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2017-08-16 16:04 - 2017-05-12 04:11 - 000035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-08-16 16:04 - 2017-05-12 04:10 - 000140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-08-16 16:04 - 2017-05-12 04:07 - 000409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2017-08-16 16:04 - 2017-05-12 04:06 - 000095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-08-16 16:04 - 2017-05-12 04:04 - 000897024 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-08-16 16:04 - 2017-05-12 04:00 - 002240512 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-08-16 16:04 - 2017-05-10 20:19 - 000101720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2017-08-16 16:04 - 2017-05-09 16:37 - 000658432 _____ (Microsoft Corporation) C:\windows\system32\WSDApi.dll
2017-08-16 16:04 - 2017-05-09 16:29 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsdchngr.dll
2017-08-16 16:04 - 2017-05-09 16:29 - 000014848 _____ (Microsoft Corporation) C:\windows\system32\snmptrap.exe
2017-08-16 16:04 - 2017-05-09 16:28 - 000193024 _____ (Microsoft Corporation) C:\windows\system32\DAFWSD.dll
2017-08-16 16:04 - 2017-05-09 16:28 - 000030208 _____ (Microsoft Corporation) C:\windows\system32\wsdchngr.dll
2017-08-16 16:04 - 2017-05-06 18:04 - 000865792 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2017-08-16 16:04 - 2017-05-02 22:09 - 000686592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2017-08-16 16:04 - 2017-05-02 22:08 - 000415744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2017-08-16 16:04 - 2017-05-02 22:08 - 000243200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2017-08-16 16:04 - 2017-05-02 20:41 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\sscore.dll
2017-08-16 16:04 - 2017-05-02 20:31 - 000329216 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll
2017-08-16 16:04 - 2017-05-02 20:31 - 000207360 _____ (Microsoft Corporation) C:\windows\system32\smbwmiv2.dll
2017-08-16 16:04 - 2017-05-02 19:35 - 000031744 _____ (Microsoft Corporation) C:\windows\SysWOW64\sscore.dll
2017-08-16 16:04 - 2017-04-30 18:48 - 000080078 _____ C:\windows\system32\normidna.nls
2017-08-16 16:04 - 2017-04-06 19:16 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\wpd_ci.dll
2017-08-16 16:04 - 2017-04-06 17:44 - 000087040 _____ (Microsoft Corporation) C:\windows\system32\wpdbusenum.dll
2017-08-16 16:04 - 2017-04-02 16:49 - 000186880 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll
2017-08-16 16:01 - 2017-08-17 17:46 - 000021904 _____ C:\Users\Terouš123\Desktop\FRST.txt
2017-08-16 16:00 - 2017-08-17 17:45 - 000000000 ____D C:\FRST
2017-08-16 15:58 - 2017-08-16 15:59 - 002395648 _____ (Farbar) C:\Users\Terouš123\Desktop\FRST64.exe
2017-08-15 19:43 - 2017-08-15 19:43 - 000400464 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2017-08-15 19:36 - 2017-08-15 19:36 - 021540440 _____ (Malwarebytes Corporation ) C:\Users\Terouš123\Downloads\mbam-setup-2.1.4.1018.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-17 17:02 - 2016-11-19 21:54 - 000000000 ____D C:\Users\Terouš123\AppData\LocalLow\Mozilla
2017-08-17 16:32 - 2015-12-25 16:05 - 000003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3711724810-2781737708-1749865010-1001
2017-08-17 16:17 - 2015-12-25 16:06 - 000003978 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{DBBDB273-5971-4326-B3B7-80ACE8186A1C}
2017-08-17 16:14 - 2017-01-22 10:40 - 000000000 ____D C:\Users\Terouš123\AppData\Roaming\Seznam.cz
2017-08-17 16:14 - 2015-12-26 13:48 - 000000000 ____D C:\ProgramData\CanonIJPLM
2017-08-17 16:07 - 2013-08-22 16:45 - 000000006 ____H C:\windows\Tasks\SA.DAT
2017-08-16 19:51 - 2014-11-04 08:23 - 000004608 _____ C:\windows\system32\VfService.trf
2017-08-16 19:50 - 2017-06-30 14:23 - 000000248 _____ C:\windows\Tasks\StartMenu8_Start.job
2017-08-16 19:44 - 2017-04-19 23:46 - 000000000 ____D C:\Users\Terouš123\AppData\Local\ElevatedDiagnostics
2017-08-16 19:12 - 2014-11-04 07:43 - 000000000 ____D C:\Program Files (x86)\Lenovo
2017-08-16 19:11 - 2015-12-25 16:07 - 000001283 _____ C:\Users\Terouš123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2017-08-16 19:06 - 2014-11-04 08:07 - 000740822 _____ C:\windows\system32\perfh005.dat
2017-08-16 19:06 - 2014-11-04 08:07 - 000151948 _____ C:\windows\system32\perfc005.dat
2017-08-16 19:06 - 2014-03-18 11:53 - 001748728 _____ C:\windows\system32\PerfStringBackup.INI
2017-08-16 19:06 - 2013-08-22 15:36 - 000000000 ____D C:\windows\Inf
2017-08-16 18:57 - 2015-12-25 15:40 - 000000000 ____D C:\ProgramData\IObit
2017-08-16 18:55 - 2015-12-25 15:40 - 000000000 ____D C:\Users\Terouš123\AppData\Roaming\IObit
2017-08-16 17:43 - 2017-03-27 11:30 - 000001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-08-16 17:43 - 2016-10-07 18:32 - 000003888 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1475857930
2017-08-16 17:25 - 2013-08-22 16:44 - 000494464 _____ C:\windows\system32\FNTCACHE.DAT
2017-08-16 17:20 - 2016-01-31 23:11 - 000000000 ____D C:\windows\system32\appraiser
2017-08-16 17:20 - 2013-08-22 17:36 - 000000000 ___RD C:\windows\ToastData
2017-08-16 17:12 - 2015-12-25 15:58 - 000000000 ____D C:\Users\Terouš123\AppData\Local\Packages
2017-08-16 17:12 - 2013-08-22 17:36 - 000000000 ___HD C:\Program Files\WindowsApps
2017-08-16 17:12 - 2013-08-22 17:36 - 000000000 ____D C:\windows\AppReadiness
2017-08-16 17:08 - 2013-08-22 15:25 - 000000167 _____ C:\windows\win.ini
2017-08-16 17:06 - 2013-08-22 17:20 - 000000000 ____D C:\windows\CbsTemp
2017-08-16 16:58 - 2015-12-27 15:45 - 000000000 ____D C:\windows\system32\MRT
2017-08-16 16:52 - 2015-12-27 15:45 - 140394280 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-08-16 16:18 - 2017-04-11 19:35 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-16 16:18 - 2017-04-11 19:35 - 000002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-15 19:46 - 2013-08-22 15:25 - 000262144 ___SH C:\windows\system32\config\BBI
2017-08-15 19:44 - 2017-02-11 12:06 - 000003914 _____ C:\windows\System32\Tasks\Avast Emergency Update
2017-08-15 19:44 - 2015-12-25 16:22 - 001015880 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2017-08-15 19:44 - 2015-12-25 16:22 - 000146704 _____ (AVAST Software) C:\windows\system32\Drivers\aswmonflt.sys
2017-08-15 19:44 - 2015-12-25 16:22 - 000146696 _____ (AVAST Software) C:\windows\system32\Drivers\aswmonflt.sys.150281906668707
2017-08-15 19:43 - 2015-12-25 16:22 - 000585608 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2017-08-15 19:43 - 2015-12-25 16:22 - 000361336 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2017-08-15 19:43 - 2015-12-25 16:22 - 000198768 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2017-08-15 19:43 - 2015-12-25 16:22 - 000146664 _____ (AVAST Software) C:\windows\system32\Drivers\aswmonflt.sys.150281906106203
2017-08-15 19:43 - 2015-12-25 16:22 - 000110352 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2017-08-15 19:43 - 2015-12-25 16:22 - 000084392 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2017-08-15 19:43 - 2015-12-25 16:22 - 000046984 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2017-08-15 19:43 - 2015-12-25 16:20 - 000000000 ____D C:\ProgramData\AVAST Software
2017-08-15 19:42 - 2017-02-11 12:06 - 000343288 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbloga.sys
2017-08-15 19:42 - 2017-02-11 12:06 - 000320008 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsdrivera.sys
2017-08-15 19:42 - 2017-02-11 12:06 - 000198976 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsha.sys
2017-08-15 19:42 - 2017-02-11 12:06 - 000057728 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbuniva.sys
2017-08-15 19:42 - 2016-10-02 12:50 - 000041800 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2017-08-15 19:42 - 2015-12-25 23:15 - 000004372 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-08-15 19:42 - 2015-12-25 16:22 - 001015848 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys.150281906668707
2017-08-15 19:42 - 2013-08-22 17:36 - 000000000 ____D C:\windows\SysWOW64\Macromed
2017-08-15 19:42 - 2013-08-22 17:36 - 000000000 ____D C:\windows\system32\Macromed
2017-08-15 19:37 - 2015-12-25 15:39 - 000000000 ____D C:\ProgramData\ProductData
2017-08-15 19:30 - 2017-01-22 10:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-08-15 19:21 - 2017-01-22 10:32 - 000000000 ____D C:\Program Files\Mozilla Firefox
==================== Files in the root of some directories =======
2014-11-04 07:35 - 2014-11-04 07:35 - 000000000 ____H () C:\ProgramData\DP45977C.lfl
2017-08-16 19:12 - 2017-08-16 19:12 - 000000086 _____ () C:\ProgramData\log_for_LU.txt
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-08-16 16:40
==================== End of FRST.txt ============================