Prosím o kontrolu
Napsal: 12 lis 2017 04:20
Zdavím, poslední dobou je pomalejší PC. Hlavně prohlížeč, prosím o radu na zrychlení.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-11-2017
Ran by C_zek (administrator) on RADEK (12-11-2017 04:10:54)
Running from C:\Users\C_zek\Downloads
Loaded Profiles: C_zek (Available Profiles: C_zek)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\WINDOWS\System32\atiesrxx.exe
(AMD) C:\WINDOWS\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [323328 2017-11-11] (ESET)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1960248 2015-10-29] ()
HKU\S-1-5-21-2640610849-859800793-2110194236-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd)
HKU\S-1-5-21-2640610849-859800793-2110194236-1001\...\MountPoints2: {7d195d32-6c2b-11e4-8266-bc5ff4805ef3} - "F:\Autorun.exe"
HKU\S-1-5-21-2640610849-859800793-2110194236-1001\...\MountPoints2: {bce32d59-fea8-11e4-825a-bc5ff4805ef3} - "G:\startme.exe"
Startup: C:\Users\C_zek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2015-08-15]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{23243872-6C07-4495-A3A0-E43E47A99E8F}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2640610849-859800793-2110194236-1001 -> {BB2B34E3-F21D-47F5-A6F5-21038A3406FB} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2015-10-29] (Wondershare)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
Handler: WSISAllmytubechrome - No CLSID Value
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File
FireFox:
========
FF DefaultProfile: pfk9j87o.default
FF ProfilePath: C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default [2017-11-12]
FF Homepage: Mozilla\Firefox\Profiles\pfk9j87o.default -> hxxps://www.seznam.cz/
FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-11-08]
FF Extension: (uBlock Origin) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\uBlock0@raymondhill.net.xpi [2017-11-08]
FF Extension: (Adblock Plus) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-11-08]
FF Extension: (Seznam pro Firefox - Email) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}.xpi [2017-11-12]
FF Extension: (Fixing the geo timeline) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\features\{e1c3c710-51f9-40e4-9a10-841de946a1fd}\timecop@mozilla.com.xpi [2017-11-11]
FF HKLM-x32\...\Firefox\Extensions: [ISVCU@iSkysoft.com] - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com
FF Extension: (iSkysoft iMedia Converter Deluxe) - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com [2016-11-12] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-10-25] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-10-25] ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-10] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://seznam.cz/"
CHR Profile: C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default [2017-11-05]
CHR Extension: (Prezentace Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-01]
CHR Extension: (Dokumenty Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-01]
CHR Extension: (Disk Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tabulky Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-08-19]
CHR Extension: (Proxmate) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifalmiidchkjjmkkbkoaibpmoeichmki [2017-08-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-09]
CHR Extension: (Gmail) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR Extension: (Chrome Media Router) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-19]
CHR HKU\S-1-5-21-2640610849-859800793-2110194236-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [1932336 2017-11-11] (ESET)
S2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-03-27] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2016-10-25] (DT Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [133856 2017-11-05] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107336 2017-09-19] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15392 2017-11-05] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180088 2017-11-05] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50744 2017-09-19] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [81888 2017-09-19] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [106312 2017-09-19] (ESET)
S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2015-07-28] (Sony Mobile Communications)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-06-10] (Apple, Inc.) [File not signed]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [71680 2016-08-13] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 WsAudioDevice_383; C:\WINDOWS\system32\drivers\VirtualAudio.sys [31080 2016-02-29] (Wondershare)
S3 SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-12 04:10 - 2017-11-12 04:11 - 000012312 _____ C:\Users\C_zek\Downloads\FRST.txt
2017-11-12 04:10 - 2017-11-12 04:10 - 000000000 ____D C:\FRST
2017-11-12 04:09 - 2017-11-12 04:09 - 002392576 _____ (Farbar) C:\Users\C_zek\Downloads\FRST64.exe
2017-11-07 23:15 - 2017-11-07 23:16 - 000000000 ____D C:\Users\C_zek\Downloads\Bon.Cop.Bad.Cop.2.2017.720.WEBRip
2017-11-07 23:15 - 2017-11-07 23:15 - 000019681 _____ C:\Users\C_zek\Downloads\[CzT]Bon_Cop_Bad_Cop_2_2017_Webrip_720p_.torrent
2017-11-05 23:58 - 2017-11-05 23:59 - 000000000 ____D C:\Users\C_zek\Desktop\Čtení
2017-11-05 23:26 - 2017-11-07 00:11 - 000002351 _____ C:\Users\C_zek\Downloads\Bon.Cop.Bad.Cop.2.2017.720p.BluRay.H264.AAC-RARBG.mp4
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-12 04:10 - 2016-11-19 05:38 - 000000000 ____D C:\Users\C_zek\AppData\LocalLow\Mozilla
2017-11-11 22:39 - 2016-03-28 15:16 - 000281872 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2017-11-11 22:39 - 2015-09-27 11:41 - 000281872 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2017-11-11 17:11 - 2015-09-27 11:41 - 000281872 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2017-11-11 16:44 - 2015-04-01 19:16 - 001739092 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-11 16:44 - 2013-08-22 23:08 - 000733268 _____ C:\WINDOWS\system32\perfh005.dat
2017-11-11 16:44 - 2013-08-22 23:08 - 000148614 _____ C:\WINDOWS\system32\perfc005.dat
2017-11-11 16:44 - 2013-08-22 14:36 - 000000000 ____D C:\WINDOWS\Inf
2017-11-11 16:38 - 2013-08-22 15:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-11 14:50 - 2015-04-01 19:11 - 000000000 ____D C:\Users\C_zek
2017-11-11 04:13 - 2016-11-12 14:50 - 000000000 ____D C:\ProgramData\iSkysoft iMedia Converter Deluxe
2017-11-08 13:13 - 2015-04-02 19:08 - 000000000 ____D C:\Users\C_zek\AppData\Roaming\uTorrent
2017-11-05 22:20 - 2015-12-26 00:48 - 000000000 ____D C:\WINDOWS\Minidump
2017-11-05 20:40 - 2017-09-19 09:05 - 000180088 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2017-11-05 20:40 - 2017-07-25 14:43 - 000133856 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2017-11-05 20:40 - 2017-07-25 14:43 - 000015392 _____ (ESET) C:\WINDOWS\system32\Drivers\eelam.sys
2017-11-05 05:44 - 2015-04-01 19:23 - 000003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2640610849-859800793-2110194236-1001
2017-11-03 19:13 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-10-29 11:18 - 2015-05-01 11:42 - 000000000 ____D C:\KMPlayer
2017-10-29 11:13 - 2016-10-21 06:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-10-25 15:30 - 2016-08-29 03:03 - 000004372 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-10-25 15:30 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-25 15:30 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-18 01:30 - 2013-08-22 16:20 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-10-13 20:12 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\rescache
==================== Files in the root of some directories =======
2015-09-26 12:31 - 2015-09-26 12:31 - 000000026 _____ () C:\Users\C_zek\AppData\Local\isoworkshop.ini
2015-05-22 19:06 - 2015-05-22 19:07 - 028684424 _____ (Sony Mobile Communications ) C:\Users\C_zek\AppData\Local\pcc.exe
Files to move or delete:
====================
C:\Users\C_zek\license.dat
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-10-14 20:35
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-11-2017
Ran by C_zek (administrator) on RADEK (12-11-2017 04:10:54)
Running from C:\Users\C_zek\Downloads
Loaded Profiles: C_zek (Available Profiles: C_zek)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\WINDOWS\System32\atiesrxx.exe
(AMD) C:\WINDOWS\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [323328 2017-11-11] (ESET)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1960248 2015-10-29] ()
HKU\S-1-5-21-2640610849-859800793-2110194236-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd)
HKU\S-1-5-21-2640610849-859800793-2110194236-1001\...\MountPoints2: {7d195d32-6c2b-11e4-8266-bc5ff4805ef3} - "F:\Autorun.exe"
HKU\S-1-5-21-2640610849-859800793-2110194236-1001\...\MountPoints2: {bce32d59-fea8-11e4-825a-bc5ff4805ef3} - "G:\startme.exe"
Startup: C:\Users\C_zek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2015-08-15]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{23243872-6C07-4495-A3A0-E43E47A99E8F}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2640610849-859800793-2110194236-1001 -> {BB2B34E3-F21D-47F5-A6F5-21038A3406FB} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2015-10-29] (Wondershare)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
Handler: WSISAllmytubechrome - No CLSID Value
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File
FireFox:
========
FF DefaultProfile: pfk9j87o.default
FF ProfilePath: C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default [2017-11-12]
FF Homepage: Mozilla\Firefox\Profiles\pfk9j87o.default -> hxxps://www.seznam.cz/
FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-11-08]
FF Extension: (uBlock Origin) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\uBlock0@raymondhill.net.xpi [2017-11-08]
FF Extension: (Adblock Plus) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-11-08]
FF Extension: (Seznam pro Firefox - Email) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}.xpi [2017-11-12]
FF Extension: (Fixing the geo timeline) - C:\Users\C_zek\AppData\Roaming\Mozilla\Firefox\Profiles\pfk9j87o.default\features\{e1c3c710-51f9-40e4-9a10-841de946a1fd}\timecop@mozilla.com.xpi [2017-11-11]
FF HKLM-x32\...\Firefox\Extensions: [ISVCU@iSkysoft.com] - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com
FF Extension: (iSkysoft iMedia Converter Deluxe) - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com [2016-11-12] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-10-25] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-10-25] ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-10] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://seznam.cz/"
CHR Profile: C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default [2017-11-05]
CHR Extension: (Prezentace Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-01]
CHR Extension: (Dokumenty Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-01]
CHR Extension: (Disk Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tabulky Google) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-08-19]
CHR Extension: (Proxmate) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifalmiidchkjjmkkbkoaibpmoeichmki [2017-08-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-09]
CHR Extension: (Gmail) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR Extension: (Chrome Media Router) - C:\Users\C_zek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-19]
CHR HKU\S-1-5-21-2640610849-859800793-2110194236-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [1932336 2017-11-11] (ESET)
S2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-03-27] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2016-10-25] (DT Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [133856 2017-11-05] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107336 2017-09-19] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15392 2017-11-05] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180088 2017-11-05] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50744 2017-09-19] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [81888 2017-09-19] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [106312 2017-09-19] (ESET)
S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2015-07-28] (Sony Mobile Communications)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-06-10] (Apple, Inc.) [File not signed]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [71680 2016-08-13] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 WsAudioDevice_383; C:\WINDOWS\system32\drivers\VirtualAudio.sys [31080 2016-02-29] (Wondershare)
S3 SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-12 04:10 - 2017-11-12 04:11 - 000012312 _____ C:\Users\C_zek\Downloads\FRST.txt
2017-11-12 04:10 - 2017-11-12 04:10 - 000000000 ____D C:\FRST
2017-11-12 04:09 - 2017-11-12 04:09 - 002392576 _____ (Farbar) C:\Users\C_zek\Downloads\FRST64.exe
2017-11-07 23:15 - 2017-11-07 23:16 - 000000000 ____D C:\Users\C_zek\Downloads\Bon.Cop.Bad.Cop.2.2017.720.WEBRip
2017-11-07 23:15 - 2017-11-07 23:15 - 000019681 _____ C:\Users\C_zek\Downloads\[CzT]Bon_Cop_Bad_Cop_2_2017_Webrip_720p_.torrent
2017-11-05 23:58 - 2017-11-05 23:59 - 000000000 ____D C:\Users\C_zek\Desktop\Čtení
2017-11-05 23:26 - 2017-11-07 00:11 - 000002351 _____ C:\Users\C_zek\Downloads\Bon.Cop.Bad.Cop.2.2017.720p.BluRay.H264.AAC-RARBG.mp4
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-12 04:10 - 2016-11-19 05:38 - 000000000 ____D C:\Users\C_zek\AppData\LocalLow\Mozilla
2017-11-11 22:39 - 2016-03-28 15:16 - 000281872 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2017-11-11 22:39 - 2015-09-27 11:41 - 000281872 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2017-11-11 17:11 - 2015-09-27 11:41 - 000281872 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2017-11-11 16:44 - 2015-04-01 19:16 - 001739092 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-11 16:44 - 2013-08-22 23:08 - 000733268 _____ C:\WINDOWS\system32\perfh005.dat
2017-11-11 16:44 - 2013-08-22 23:08 - 000148614 _____ C:\WINDOWS\system32\perfc005.dat
2017-11-11 16:44 - 2013-08-22 14:36 - 000000000 ____D C:\WINDOWS\Inf
2017-11-11 16:38 - 2013-08-22 15:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-11 14:50 - 2015-04-01 19:11 - 000000000 ____D C:\Users\C_zek
2017-11-11 04:13 - 2016-11-12 14:50 - 000000000 ____D C:\ProgramData\iSkysoft iMedia Converter Deluxe
2017-11-08 13:13 - 2015-04-02 19:08 - 000000000 ____D C:\Users\C_zek\AppData\Roaming\uTorrent
2017-11-05 22:20 - 2015-12-26 00:48 - 000000000 ____D C:\WINDOWS\Minidump
2017-11-05 20:40 - 2017-09-19 09:05 - 000180088 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2017-11-05 20:40 - 2017-07-25 14:43 - 000133856 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2017-11-05 20:40 - 2017-07-25 14:43 - 000015392 _____ (ESET) C:\WINDOWS\system32\Drivers\eelam.sys
2017-11-05 05:44 - 2015-04-01 19:23 - 000003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2640610849-859800793-2110194236-1001
2017-11-03 19:13 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-10-29 11:18 - 2015-05-01 11:42 - 000000000 ____D C:\KMPlayer
2017-10-29 11:13 - 2016-10-21 06:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-10-25 15:30 - 2016-08-29 03:03 - 000004372 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-10-25 15:30 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-25 15:30 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-18 01:30 - 2013-08-22 16:20 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-10-13 20:12 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\rescache
==================== Files in the root of some directories =======
2015-09-26 12:31 - 2015-09-26 12:31 - 000000026 _____ () C:\Users\C_zek\AppData\Local\isoworkshop.ini
2015-05-22 19:06 - 2015-05-22 19:07 - 028684424 _____ (Sony Mobile Communications ) C:\Users\C_zek\AppData\Local\pcc.exe
Files to move or delete:
====================
C:\Users\C_zek\license.dat
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-10-14 20:35
==================== End of FRST.txt ============================