Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12.02.2018
Ran by Benyto (administrator) on BENYTO-PC (15-02-2018 19:01:21)
Running from C:\Users\Benyto\Downloads
Loaded Profiles: Benyto (Available Profiles: Benyto)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\netis\USB Wireless LAN Utility\RtlService.exe
() C:\Windows\runSW.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\netis\USB Wireless LAN Utility\RtWLan.exe
(Realtek) C:\Windows\SwUSB.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{7D9CF8AA-ED8B-4506-AB6C-1B273AD39B41}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{93BF9442-C2CB-475E-91FA-CB4133685B46}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{B297C1DB-985C-4409-ADE6-2639BE97B82C}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3066880665-722362445-698270547-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={0968C9C6-FE77-42AE-B0DA-5AA53F5F975D}&mid=081390139bcc47cca43ed154d4aff0db-a9d900fbfb3a49df4ad1bed27edd398324ee4a37&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0816tb&pr=fr&d=2016-06-09 12:54:17&v=4.3.8.510&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3066880665-722362445-698270547-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={0968C9C6-FE77-42AE-B0DA-5AA53F5F975D}&mid=081390139bcc47cca43ed154d4aff0db-a9d900fbfb3a49df4ad1bed27edd398324ee4a37&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0816tb&pr=fr&d=2016-06-09 12:54:17&v=4.3.8.510&pid=wtu&sg=&sap=dsp&q={searchTerms}
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://
www.seznam.cz/"
CHR Profile: C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default [2018-02-15]
CHR Extension: (Prezentace) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Dokumenty) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Disk Google) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-18]
CHR Extension: (YouTube) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-18]
CHR Extension: (Vyhledávání Google) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05]
CHR Extension: (Tabulky) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Dokumenty Google offline) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-18]
CHR Extension: (Chrome Media Router) - C:\Users\Benyto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-15]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-29] (Advanced Micro Devices, Inc.) [File not signed]
S3 AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [348160 2009-10-31] (AVerMedia) [File not signed]
S3 AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [397312 2009-12-07] () [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 RtlService; C:\Program Files (x86)\netis\USB Wireless LAN Utility\RtlService.exe [36864 2012-05-10] (Realtek Semiconductor Corp.) [File not signed]
R2 RunSwUSB; C:\Windows\runSW.exe [44104 2013-05-14] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Cam5603D; C:\Windows\System32\Drivers\BisonCam.sys [1013544 2008-08-15] (Bison Electronics. Inc. )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKsl8b1a890e; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5950B5EC-34CA-48FB-A925-4900E26DB0AB}\MpKsl8b1a890e.sys [58120 2018-02-15] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [2350152 2013-05-07] (Realtek Semiconductor Corporation )
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2018-02-14] ()
S3 USBAVCap; C:\Windows\System32\drivers\USBAVCap.sys [904192 2009-10-08] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
S3 pwdspio; \??\C:\Windows\system32\pwdspio.sys [X]
S3 SliceDisk5; \??\C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-15 13:01 - 2018-02-15 13:02 - 000020490 _____ C:\Users\Benyto\Downloads\Addition.txt
2018-02-15 12:59 - 2018-02-15 19:02 - 000009667 _____ C:\Users\Benyto\Downloads\FRST.txt
2018-02-15 12:59 - 2018-02-15 19:01 - 000000000 ____D C:\FRST
2018-02-15 12:59 - 2018-02-15 12:59 - 002405376 _____ (Farbar) C:\Users\Benyto\Downloads\FRST64.exe
2018-02-14 14:31 - 2018-02-14 14:34 - 067292528 _____ (Malwarebytes ) C:\Users\Benyto\Downloads\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3932.exe
2018-02-14 13:59 - 2018-02-14 14:01 - 017720322 _____ C:\Users\Benyto\Downloads\Nepotvrzeno 799421.crdownload
2018-02-10 16:10 - 2018-02-14 15:03 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-02-10 16:10 - 2018-02-10 16:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-02-10 16:09 - 2018-02-10 16:10 - 000000000 ____D C:\Program Files\RogueKiller
2018-02-10 16:09 - 2018-02-10 16:09 - 000000000 ____D C:\ProgramData\RogueKiller
2018-02-10 16:07 - 2018-02-10 16:08 - 031926992 _____ (Adlice Software ) C:\Users\Benyto\Downloads\setup.exe
2018-02-09 17:45 - 2018-02-15 14:05 - 000000000 ____D C:\AdwCleaner
2018-02-09 17:45 - 2018-02-09 17:46 - 008222496 _____ (Malwarebytes) C:\Users\Benyto\Downloads\adwcleaner_7.0.8.0.exe
2018-02-08 14:56 - 2018-02-08 14:56 - 000001630 _____ C:\Users\Benyto\Documents\startup.txt
2018-02-03 20:53 - 2018-01-23 19:58 - 000548000 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-02-03 20:39 - 2018-02-03 20:39 - 000001912 _____ C:\Windows\epplauncher.mif
2018-02-03 20:38 - 2018-02-03 20:38 - 000002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2018-02-03 20:38 - 2018-02-03 20:38 - 000000000 ____D C:\Program Files\Microsoft Security Client
2018-02-03 20:38 - 2018-02-03 20:38 - 000000000 ____D C:\Program Files (x86)\Microsoft Security Client
2018-02-03 20:36 - 2018-02-03 20:37 - 015085248 _____ (Microsoft Corporation) C:\Users\Benyto\Downloads\mseinstall.exe
2018-01-28 10:55 - 2018-01-28 10:55 - 000343599 _____ C:\Users\Benyto\Downloads\Přehled stavu pojistné smlouvy (1).pdf
2018-01-28 10:47 - 2018-01-28 10:47 - 000343599 _____ C:\Users\Benyto\Downloads\Přehled stavu pojistné smlouvy.pdf
2018-01-18 18:06 - 2018-01-18 18:06 - 000358228 _____ C:\Users\Benyto\Downloads\Export_20180118060627.zip
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-15 14:19 - 2009-07-14 05:45 - 000013952 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-02-15 14:19 - 2009-07-14 05:45 - 000013952 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-02-15 14:02 - 2016-01-20 19:46 - 000000290 _____ C:\Windows\Tasks\CheckDriveBackgroundGuard.job
2018-02-15 14:02 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-15 09:52 - 2016-04-20 09:34 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-15 09:51 - 2016-04-20 09:33 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-02-14 07:39 - 2009-07-14 06:08 - 000032580 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-02-13 14:18 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\NDF
2018-02-11 10:57 - 2017-12-31 12:25 - 000000000 ____D C:\Users\Benyto\Documents\NFS Carbon
2018-02-11 08:49 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-02-07 14:46 - 2016-01-21 18:18 - 000007610 _____ C:\Users\Benyto\AppData\Local\resmon.resmoncfg
2018-02-07 13:01 - 2015-12-18 19:41 - 000000000 ____D C:\Users\Benyto\AppData\Roaming\AVG
2018-02-07 13:01 - 2015-12-18 19:36 - 000000000 ____D C:\ProgramData\Avg
2018-02-07 13:01 - 2015-12-18 19:36 - 000000000 ____D C:\Program Files (x86)\AVG
2018-02-07 13:01 - 2015-12-18 19:33 - 000000000 ____D C:\Users\Benyto\AppData\Local\Avg
2018-02-03 20:41 - 2015-12-18 19:34 - 000000000 ____D C:\Users\Benyto\AppData\Local\AvgSetupLog
2018-02-03 20:38 - 2015-12-19 09:37 - 000000000 ____D C:\Windows\system32\MRT
2018-02-03 20:31 - 2017-10-11 19:37 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-03 20:30 - 2015-12-19 09:37 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-31 16:35 - 2009-07-14 16:18 - 000668724 _____ C:\Windows\system32\perfh005.dat
2018-01-31 16:35 - 2009-07-14 16:18 - 000141352 _____ C:\Windows\system32\perfc005.dat
2018-01-31 16:35 - 2009-07-14 06:13 - 001582942 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-28 19:05 - 2016-01-14 23:23 - 000000000 ____D C:\Filmy
2018-01-27 22:57 - 2017-07-15 16:19 - 000019120 _____ C:\Windows\KernelMessage
2018-01-21 09:51 - 2016-01-14 11:27 - 000000000 ____D C:\Disk
2018-01-21 09:38 - 2017-03-19 18:52 - 000004608 _____ C:\Users\Benyto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-01-17 20:27 - 2017-08-23 10:49 - 000016384 _____ C:\Users\Benyto\Documents\PŘEHLED K ÚVĚRU OD BUŘINKY.xls
==================== Files in the root of some directories =======
2017-03-19 18:52 - 2018-01-21 09:38 - 000004608 _____ () C:\Users\Benyto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-01-21 18:18 - 2018-02-07 14:46 - 000007610 _____ () C:\Users\Benyto\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
2018-02-10 16:10 - 2017-09-13 16:31 - 001732864 _____ (Microsoft Corporation) C:\Users\Benyto\AppData\Local\Temp\dllnt_dump.dll
2016-10-19 16:11 - 2016-10-19 16:11 - 002458672 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\Users\Benyto\AppData\Local\Temp\libeay32.dll
2016-10-19 16:11 - 2016-10-19 16:11 - 000970912 _____ (Microsoft Corporation) C:\Users\Benyto\AppData\Local\Temp\msvcr120.dll
2016-10-19 16:11 - 2016-10-19 16:11 - 000772672 _____ () C:\Users\Benyto\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-02-07 07:28
==================== End of FRST.txt ============================