Preventivní kontrola
Napsal: 28 čer 2019 12:56
Nejsem připojen na Net...
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-06-2019
Ran by Kengura (administrator) on KENGURA-PC (24-06-2019 16:03:51)
Running from C:\Users\Kengura\Pictures
Loaded Profiles: Kengura (Available Profiles: Kengura)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrB.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) [File not signed]
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: E - E:\autorun.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: F - F:\setup.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: G - G:\setup.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: H - H:\m.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: I - I:\m.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [242688 2013-01-08] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2005-06-24] (EA.com/On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2005-06-24] (EA.com/On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP62] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2005-06-24] (EA.com/On2.com) [File not signed]
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {034133F4-20D6-4608-90CD-C90403E43787} - System32\Tasks\{7E6C0C3F-7AC7-47C5-9ECD-54395B2318CD} => C:\Windows\system32\pcalua.exe -a "D:\Half Life\vcredist_x64.exe" -d "D:\Half Life"
Task: {05A1F426-DE4F-451B-A43C-20F126D517F3} - System32\Tasks\{858E6A57-8E30-4C61-A552-31FFDAA25449} => C:\Windows\system32\pcalua.exe -a "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War\CoDWaW.exe" -d "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War"
Task: {0A25FC29-77CE-4CDC-B301-56F428189792} - System32\Tasks\{1E644B9F-37A8-4587-B94C-A444306E413E} => C:\Windows\system32\pcalua.exe -a E:\GDFTHR_inst.exe -d E:\
Task: {0A9495C7-F7D4-4CFC-B3F5-8ED54216FFF8} - System32\Tasks\{6810D009-5302-497C-AC3B-DC98F3EAA823} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War\CoDWaW.exe" -d "C:\Program Files (x86)\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War"
Task: {112DB0BC-A603-4702-99C8-1CE2E90A6FC9} - System32\Tasks\{50B18B69-DF98-47D0-A443-A98C5956B6EC} => C:\Windows\system32\pcalua.exe -a D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack\Vietcong_v130.exe -d D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack
Task: {129709D0-2FA9-4453-9A57-974841762215} - System32\Tasks\{782CD81C-0545-459D-955B-F7D303BA9DB7} => C:\Windows\system32\pcalua.exe -a G:\CRACK\Čeština\MaxPayne2CZ_komplet.exe -d G:\CRACK\Čeština
Task: {14978ECF-6898-4A88-904B-FF347079504C} - System32\Tasks\{FCA47BA9-75D6-4099-ADA2-B343C8905931} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Patch 1.01 + crack\far_cry_2_1.01.exe" -d "D:\Far Cry 2\Patch 1.01 + crack"
Task: {1B99B09F-7A5A-4818-B9C2-79019F844487} - System32\Tasks\{178D66A8-4A0B-4B2C-8DB0-67865DF065AA} => C:\Windows\system32\pcalua.exe -a D:\Manhunt\cz\cz.exe -d D:\Manhunt\cz
Task: {1FEFD606-98ED-4353-96EF-0024B028EC13} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks [Argument = /run /TN "\Microsoft\Windows\Setup\gwx\refreshgwxconfig"]
Task: {20C432A5-FC57-44A2-A5C5-62CC5FDC5DAD} - System32\Tasks\{403F7465-23B6-42F4-B0A4-74F8B133FEED} => C:\Windows\system32\pcalua.exe -a "C:\Nová složka\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Nová složka\Assassin's Creed CZ by Tw22ty"
Task: {264E95FD-A920-47EF-9170-0C1F50A9A846} - System32\Tasks\{72F78116-D245-4599-A955-CCDBF600F92F} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game\Odinstalovat.exe" -d "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game"
Task: {268B635D-61AF-41D5-A8AA-DC528FB5AE1A} - System32\Tasks\{89B29A7E-AC41-4F4B-8A6F-5D089CF89C09} => C:\Windows\system32\pcalua.exe -a "D:\Nová složka\CZ\cz\InstallOblivionCZ.exe" -d "D:\Nová složka\CZ\cz"
Task: {270E1E9D-E551-4B08-BCF8-E6953B1C8937} - System32\Tasks\{19144672-213B-4E0A-8C62-5B805948C173} => "C:\Program Files\Internet Explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/7.0.0.102/cs/abandoninstall?page=tsMain
Task: {2E5CC331-9577-4924-AA58-ADAA70129C9F} - System32\Tasks\{77959336-2A4E-443E-8EA2-9C6B7B09365E} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\Oblinion\cz_oblivion_standard_1.05\InstallOblivionCZ.exe -d D:\Češtiny\Oblinion\cz_oblivion_standard_1.05
Task: {2E8EE109-EA2C-4AF6-898F-4F9C8FCE828B} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Command(2): %windir%\system32\rundll32.exe -> aepdu.dll,AePduRunUpdate -nolegacy
Task: {2E8EE109-EA2C-4AF6-898F-4F9C8FCE828B} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Command(3): %windir%\system32\rundll32.exe -> appraiser.dll,DoScheduledTelemetryRun
Task: {2EF37033-CFC4-4B4A-8EF7-18B7649B8209} - System32\Tasks\{0FEEA325-EDA6-45FC-A2C6-2248D4A25066} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {3253721E-4FBD-4BAD-AAD9-F5F56AF39E9C} - System32\Tasks\{80702A4C-4AB2-4D95-BB14-67DA77B01443} => C:\Windows\system32\pcalua.exe -a E:\GDFTHR_uninst.exe -d E:\
Task: {36437A5C-E7F3-472E-9821-CD07E4F16A19} - System32\Tasks\{646A331F-45B2-45E0-8848-EC8A2238DDEC} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\mohpacificassault_cz.exe -d D:\Češtiny
Task: {36C977BE-4266-41E5-A1CF-97FEC618318B} - System32\Tasks\{5624CF3A-AA0B-4238-97C5-DA1EBC153E16} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kengura\Desktop\DVD1\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Users\Kengura\Desktop\DVD1\Assassin's Creed CZ by Tw22ty"
Task: {3C302C3F-D05B-49D2-88C4-F88ADB54C454} - System32\Tasks\{B120B17E-0A9F-4244-96A6-DAFCDDA963FA} => C:\Windows\system32\pcalua.exe -a F:\far_cry_v1.32.exe -d F:\
Task: {3C4C4868-0DFA-4068-8F9C-EFE0D8B9C7CC} - System32\Tasks\{1C094734-8764-414D-A046-94C65B799FBD} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {40A177AE-CD31-49FE-AC7E-73BBAD55B115} - System32\Tasks\{8BD692AD-85FC-432B-85A1-DC2168DEDFE6} => C:\GOG Games\The Witcher 2 Assassins of Kings\Launcher.exe
Task: {40A2787F-AC5D-4CE2-9495-12C6F47F5801} - System32\Tasks\{F3C5C2CE-B304-46F4-97F5-40292B4A680E} => C:\Windows\system32\pcalua.exe -a D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack\Vietcong_v141.exe -d D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack
Task: {45B2AC2E-7D94-4894-9399-897FAF6C1EA1} - System32\Tasks\{256334CB-D171-426E-B3F5-CDBF56249674} => C:\Windows\system32\pcalua.exe -a D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack\Vietcong-v160.exe -d D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack
Task: {4620D7B1-8400-4A87-81F1-7B4B39F2D721} - System32\Tasks\{6E904970-3CD1-4D6C-ACC6-454297A90B98} => C:\Windows\system32\pcalua.exe -a "D:\Half Life\HalfLife2_CZ.exe" -d "D:\Half Life"
Task: {4B59F7B8-7A48-4239-8E40-F7C59310483F} - System32\Tasks\{A6B5AD12-171A-4E8B-BA60-5B425D65126A} => C:\Windows\system32\pcalua.exe -a F:\setup.exe -d F:\
Task: {4C5D6D63-3650-4634-8841-CFC53D94FC5D} - System32\Tasks\{CEA487D2-DF66-414C-9DDE-75DD792E04A8} => C:\Windows\system32\pcalua.exe -a C:\Users\Kengura\Desktop\hl2_ep_cz.exe -d C:\Users\Kengura\Desktop
Task: {4FB274B8-2D94-46C4-A7DD-9E4A9AE6C70A} - System32\Tasks\{7388A0C8-FCBA-4C6C-900F-CFBD7CB101CC} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {56391FCD-AD2F-47A4-9295-B5BF018B3D94} - System32\Tasks\{39F63C95-859A-49DF-A046-F12E1ACBF3A2} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Patch 1.03 + crack\far_cry_2_1.03.exe" -d "D:\Far Cry 2\Patch 1.03 + crack"
Task: {57159F6D-91CC-4FA2-B8DB-45866B9CB193} - System32\Tasks\{BF0965C6-7032-407E-93BD-F589FABBA642} => C:\GOG Games\The Witcher 2 Assassins of Kings\Launcher.exe
Task: {58BEA721-38EA-46A7-916B-3EF4EE5039DF} - System32\Tasks\{BB098232-5762-4739-8E0B-A999188B8BAA} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\assassins_creed_1.02.exe -d D:\Češtiny
Task: {606AA06C-0A06-4136-A98E-D91FBCED90DE} - System32\Tasks\{22471DC0-8704-4B42-8DD5-919580EF3169} => C:\Windows\system32\pcalua.exe -a "F:\Potřebné programy\Ubisoft Game Launcher\UbisoftGameLauncherInstaller.exe" -d "F:\Potřebné programy\Ubisoft Game Launcher"
Task: {661926E9-5299-4BBD-8DD3-92CF169E6E51} - System32\Tasks\{600C9C37-2D55-43EA-A0E1-73326F7EF38D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\WinRAR\WinRAR.exe" -d C:\Users\Kengura\Desktop
Task: {66433877-4512-4F82-9E64-D043BB2C93B6} - System32\Tasks\{246639CD-5F59-434B-8F3B-4C567D76B2BF} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Activision\Call of Duty - Black Ops\Redist\vcredist_x86.exe" -d "C:\Program Files (x86)\Activision\Call of Duty - Black Ops\Redist"
Task: {669D4148-FA6A-43CB-8511-48A84AB52223} - System32\Tasks\Norton Security Scan for Kengura => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
Task: {70EBBB9A-3748-4213-A901-A676FC4899EA} - System32\Tasks\{C9785EA8-9991-48F6-A759-C2811ACEECAD} => C:\Windows\system32\pcalua.exe -a F:\AC2.part01.exe -d F:\
Task: {73CD4531-ED74-47E6-B405-55A1822A6D8B} - System32\Tasks\{3408B213-E2BD-41E7-9777-C2D723CD04B5} => C:\Windows\system32\pcalua.exe -a C:\Users\Kengura\Desktop\cz_moh_pacific_assault\mohpacificassault_cz.exe -d C:\Users\Kengura\Desktop\cz_moh_pacific_assault
Task: {74EFD15F-274A-4049-A731-B6DC9D4A9F24} - System32\Tasks\{471383DC-0CF7-4011-84EA-559169489C0C} => C:\Program Files (x86)\Cenega Czech\VIETCONG\vietcong.exe
Task: {77886FCE-2755-4F9A-94DA-D62FD9230BAA} - System32\Tasks\{C25F5777-F70F-4D99-AE0C-F288AD5E26B1} => C:\Windows\system32\pcalua.exe -a "D:\Assassins Creed\assassins_creed_1.02.exe" -d "D:\Assassins Creed"
Task: {7906EE58-EE3A-407C-BAB9-9891C7176912} - System32\Tasks\{CB7B2527-D182-4C5D-9087-54096CA3833B} => C:\Windows\system32\pcalua.exe -a D:\Oblivion.cz\cz_oblivion_standard_1.05\InstallOblivionCZ.exe -d D:\Oblivion.cz\cz_oblivion_standard_1.05
Task: {79C19AF2-C56E-45F7-8C01-C021B6F014B4} - System32\Tasks\{631D0B84-5148-4D81-BBC1-41ACBDE5481D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\Mafia\Setup.exe" -d "C:\Program Files\Mafia"
Task: {7A6235C4-DD46-4DF6-80F5-CA8F945FCF5A} - System32\Tasks\{0BFB0B7F-5F54-4D63-98F0-F56955FB3CF0} => C:\Windows\system32\pcalua.exe -a G:\GDFTHR_inst.exe -d G:\
Task: {7D758CDF-DDA4-40FB-907A-61813231DAAD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-02-07] (Google Inc -> Google Inc.)
Task: {7D7E4CCB-ABD5-44A0-B1A3-48B81754ECB1} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {7E558DAF-4005-493C-A162-C088DC6704B0} - System32\Tasks\{4BD9D941-FBBD-4CC6-B75E-90C2983F1151} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\cod_uo_cestina.exe -d D:\Češtiny
Task: {818FE93D-7352-4786-97EF-4F8B801D8BAB} - System32\Tasks\{81B3ED82-0F5A-4FDC-9F6E-41E6AFA5E86D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Translator_2016\TRNIKONY.EXE" -d "C:\Program Files (x86)\Translator_2016"
Task: {83F9AC61-40FE-4196-9476-59638A5EC030} - System32\Tasks\{C260F016-B648-4F0B-9894-A58B36D10A56} => C:\Windows\system32\pcalua.exe -a D:\Manhunt\Manhunt2CZE.exe -d D:\Manhunt
Task: {8B578532-D64E-4D7F-819C-6C7BDA0BE72E} - System32\Tasks\{218F1408-B4AA-469A-A8B4-0DF12E089EDE} => C:\Windows\system32\pcalua.exe -a D:\Gothi\Gothic_3_MDS_EU.exe -d D:\Gothi
Task: {8BBFFB8C-95E7-4EA0-A566-D5C76F4CDCC5} - System32\Tasks\{8512B359-7FB1-48FE-90BF-B3C3DB6CB5AF} => C:\Windows\system32\pcalua.exe -a D:\Instal\Translator_2016\TRNIKONY.EXE -d D:\Instal\Translator_2016
Task: {8BEEA774-9B54-47EE-836A-5B55663EBF25} - System32\Tasks\{5C66CBA1-6087-472F-ADDC-B3ACD5A4B065} => C:\Windows\system32\pcalua.exe -a E:\autorun.exe -d E:\
Task: {8C4A02E2-237C-40C3-9F95-9D754B90188D} - System32\Tasks\{CCA2EB60-19EB-4FF6-BA70-D3D0750E6F02} => C:\Windows\system32\pcalua.exe -a "D:\Half Life\hl2_ep_cz.exe" -d "D:\Half Life"
Task: {8D47791B-6463-4185-858E-2346F900F9F9} - System32\Tasks\{91EF7452-2219-4546-97C6-42B0A73A9781} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {947CC427-784E-40F4-8A62-D17E50646923} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-02-07] (Google Inc -> Google Inc.)
Task: {956543F2-F2B1-459D-B5E0-8E819796455C} - System32\Tasks\{8B72E981-D81B-47B8-ADBD-81C8438D8787} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kengura\Desktop\Nová složka\Setup.EXE" -d "C:\Users\Kengura\Desktop\Nová složka"
Task: {99AD046F-2027-4763-92FD-387A36D341C8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998088 2015-06-12] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {9AC3A4B1-357B-4386-A424-C0F47FE37443} - System32\Tasks\{F1069528-A8A5-43FD-A9E1-0FEE54E35E85} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kengura\Videos\max payne 2 čeština a patch\MaxPayne2cestina.exe" -d "C:\Users\Kengura\Videos\max payne 2 čeština a patch"
Task: {A62C8294-0F97-4442-B807-A9BFC5E151A3} - System32\Tasks\{6DE04359-2890-4F43-A39C-429C3A42208F} => C:\Windows\system32\pcalua.exe -a E:\AMD-64BIT_PATCH\SORM_32BIT-AMD64BIT.EXE -d E:\AMD-64BIT_PATCH
Task: {AD8D910F-A632-410A-AED5-C3D772E91391} - System32\Tasks\{525C8C3B-9F12-4673-A06A-69F744F208DC} => C:\Program Files (x86)\Cenega Czech\VIETCONG\vietcong.exe
Task: {B25F336E-8D53-44FD-B717-1ACC9BF1B6F9} - System32\Tasks\{0BDD501F-55CD-405D-A300-6011213A9E80} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {B735ABB3-5C54-4364-B346-944ED3500324} - System32\Tasks\{5805A922-B392-442C-B23F-6BEDA60E9396} => C:\Windows\system32\pcalua.exe -a C:\Users\Kengura\Desktop\cod_uo_cestina.exe -d C:\Users\Kengura\Desktop
Task: {B9BD6340-EE2C-4225-A4C1-E7E6E934555A} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Command(1): %windir%\system32\rundll32.exe -> aepdu.dll,AePduRunUpdate
Task: {B9BD6340-EE2C-4225-A4C1-E7E6E934555A} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Command(2): %windir%\system32\rundll32.exe -> invagent.dll,RunUpdate -noappraiser
Task: {BB5EDFB8-D6DF-441D-AECF-0050F276E5CF} - System32\Tasks\{86EEFF58-1822-4A89-A6BF-ADE5E0A3B8CB} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\OpenAL\oalinst.exe" -d "C:\Program Files (x86)\OpenAL"
Task: {BC2D01BF-0B6D-4130-915C-55D42C7138DB} - System32\Tasks\{C1927AA2-3A17-4076-8D97-94C87770164C} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Patch 1.02 + crack\far_cry_2_1.02.exe" -d "D:\Far Cry 2\Patch 1.02 + crack"
Task: {BC788224-2B9E-4968-A439-B7BCD5CA0573} - System32\Tasks\{466745EC-5C0B-48CF-802A-F8E675AD5EB9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Nová složka\DVD1\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Program Files (x86)\Nová složka\DVD1\Assassin's Creed CZ by Tw22ty"
Task: {C10964D6-1ABD-4CEA-9082-5BA8708B7436} - System32\Tasks\{7D7FE2CC-3A70-44C9-B18E-35665D7785D9} => C:\Windows\system32\pcalua.exe -a F:\setup.exe -d F:\
Task: {C14A5141-0498-4D72-8140-3DBD96F50A7E} - System32\Tasks\{881E1FB6-DF9F-4F85-9AC1-1C6E6D11141F} => C:\Windows\system32\pcalua.exe -a "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War\CoDWaW.exe" -d "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War"
Task: {CF14EAFC-78CB-48F3-9646-80C28904965A} - System32\Tasks\{50923AF9-D634-4E90-9215-B3D304D6C572} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Bonusy\Far Cry 2 - The Fortune's Pack\F2FP_setup.exe" -d "D:\Far Cry 2\Bonusy\Far Cry 2 - The Fortune's Pack"
Task: {DAA0E401-F7D9-476E-BD11-0AB9DDEF77F5} - System32\Tasks\{2E6DDF41-D032-4AEB-BBE9-59D6EADD4079} => C:\Windows\system32\pcalua.exe -a "D:\FAr Cry\farcry_amd64upgrade_us_uk.exe" -d "D:\FAr Cry"
Task: {DFFB58B8-4BAB-4CC2-A832-544DFC56482D} - System32\Tasks\{689AA895-69E0-487D-82B0-EED522E13945} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\Translator_2016\TRNIKONY.EXE" -d "C:\Program Files (x86)\Electronic Arts\Translator_2016"
Task: {EBAD9728-D2A1-4909-9248-F824BBE90AFE} - System32\Tasks\{713AC9CC-C970-4A23-905F-ECD2456E2EF1} => C:\GOG Games\The Witcher Enhanced Edition Director's Cut\launcher.exe
Task: {F0617499-8A8F-4806-B9FA-F7CBB7C7E552} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [272384 2017-11-02] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {F63F3EA8-C076-4137-A252-BD3337870F51} - System32\Tasks\{78DE7B11-5507-4BE7-8B4B-72326267C7A0} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game\GDFTHR_uninst.exe" -d "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game"
Task: {F7AEB2B7-05F9-4412-8420-9D9AA0E82A39} - System32\Tasks\{DE3310A4-F167-4C26-B584-1CB97D86DDF5} => C:\Windows\system32\pcalua.exe -a "C:\Nová složka\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Nová složka\Assassin's Creed CZ by Tw22ty"
Task: {FAFD5085-A263-443F-A5FB-E074270079C5} - System32\Tasks\{086F1C2C-E2F7-49B6-8CCC-2BC8C0EAF3E2} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\Ubisoft\Assassin's Creed II\UbisoftGameLauncherInstaller.exe" -d "C:\Program Files\Ubisoft\Assassin's Creed II"
Task: {FD8AF20B-27DE-4BAF-8749-8BDC75B9D4C9} - System32\Tasks\{2DE264B9-9F04-4B5C-928D-471D1B5DFB7D} => C:\GOG Games\The Witcher Enhanced Edition Director's Cut\launcher.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Norton Security Scan for Kengura.job => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{1FF80274-5A8A-4731-92C6-A2EA8D10DC61}: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{B8835B1F-9A53-4FF1-92A4-90FF0D73217C}: [DhcpNameServer] 192.168.11.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.centrum.cz/
BHO-x32: No Name -> {53707962-6F74-2D53-2644-206D7942484F} -> No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Kengura\AppData\Roaming\Mozilla\Firefox\Profiles\m2usc0l4.default [2019-06-23]
FF user.js: detected! => C:\Users\Kengura\AppData\Roaming\Mozilla\Firefox\Profiles\m2usc0l4.default\user.js [2014-09-04]
FF Homepage: Mozilla\Firefox\Profiles\m2usc0l4.default -> hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-02] (Adobe Systems Incorporated -> )
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-02] (Adobe Systems Incorporated -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-11-14] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-11-14] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-11-02] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-11-02] (Google Inc -> Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2263194865-3938205509-2482612845-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-06-13] (Ubisoft Entertainment Sweden AB -> )
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [203264 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2019-02-01] (Even Balance, Inc. -> )
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2019-02-01] (Even Balance, Inc. -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AmdTools64; C:\Windows\System32\DRIVERS\AmdTools64.sys [47616 2006-06-27] (Advanced Micro Devices, Inc. -> AMD, Inc.)
R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [82048 2011-12-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [42624 2011-12-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6037504 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.)
R0 AtiPcie; C:\Windows\System32\DRIVERS\AtiPcie.sys [16440 2009-05-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.)
S2 CLFCL5.18; C:\Windows\System32\DRIVERS\CLFCL5.18\000.fcl [46848 2018-11-12] (CyberLink Corp. -> CyberLink Corp.)
S3 nmwcd; C:\Windows\System32\drivers\ccdcmbx64.sys [19968 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbox64.sys [27136 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdnsux64; C:\Windows\System32\drivers\nmwcdnsux64.sys [171008 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Inc.)
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S2 tandpl; C:\Windows\SysWOW64\drivers\tandpl.sys [4736 2003-04-19] () [File not signed]
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [9216 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 DCamUSBSTK02N; system32\DRIVERS\STK02NW2.sys [X]
S0 pelhmrss; System32\drivers\ujenbxfs.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-06-24 16:03 - 2019-06-24 16:03 - 000000000 ____D C:\FRST
2019-06-20 12:56 - 2019-06-20 12:56 - 000000110 ____H C:\Users\Kengura\Desktop\Obraz0118.jpg.uid-zps
2019-06-07 11:55 - 2019-06-08 15:50 - 000000000 ____D C:\Program Files (x86)\Activision
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-06-24 16:01 - 2014-06-27 14:04 - 000000000 ____D C:\ProgramData\NVIDIA
2019-06-24 16:01 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-06-24 11:21 - 2018-02-05 17:33 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-06-24 11:20 - 2009-07-14 06:45 - 000014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-06-24 11:20 - 2009-07-14 06:45 - 000014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-06-24 11:18 - 2009-07-14 17:18 - 000671796 _____ C:\Windows\system32\perfh005.dat
2019-06-24 11:18 - 2009-07-14 17:18 - 000142392 _____ C:\Windows\system32\perfc005.dat
2019-06-24 11:18 - 2009-07-14 07:13 - 001591814 _____ C:\Windows\system32\PerfStringBackup.INI
2019-06-24 11:18 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2019-06-20 11:59 - 2019-04-24 14:54 - 000000000 ____D C:\Program Files (x86)\FormatFactory
2019-06-11 11:09 - 2015-05-01 14:41 - 000000456 ____H C:\Windows\Tasks\Norton Security Scan for Kengura.job
2019-05-30 12:39 - 2019-04-24 14:56 - 000000000 ____D C:\FFOutput
==================== Files in the root of some directories ================
2019-04-05 16:31 - 2015-11-17 16:01 - 000000422 _____ () C:\Program Files\update-ASCreedSyndicate.bat
2019-04-05 16:31 - 2013-10-12 20:47 - 000000732 _____ () C:\Program Files\visit-www.nosteam.ro.html
2014-10-29 15:18 - 2014-10-29 15:19 - 000002292 _____ () C:\Users\Kengura\AppData\Roaming\ASSDraw3.cfg
2014-06-28 23:09 - 2018-02-23 16:20 - 000099384 _____ () C:\Users\Kengura\AppData\Roaming\inst.exe
2002-08-29 19:33 - 2002-08-29 19:33 - 000319488 ____R () C:\Users\Kengura\AppData\Roaming\MafiaSetup.exe
2014-06-28 23:09 - 2018-02-23 16:20 - 000007859 _____ () C:\Users\Kengura\AppData\Roaming\pcouffin.cat
2014-06-28 23:09 - 2018-02-23 16:20 - 000001167 _____ () C:\Users\Kengura\AppData\Roaming\pcouffin.inf
2014-06-28 23:09 - 2018-02-23 16:20 - 000000055 _____ () C:\Users\Kengura\AppData\Roaming\pcouffin.log
2014-06-28 23:09 - 2018-02-23 16:20 - 000082816 _____ (VSO Software) C:\Users\Kengura\AppData\Roaming\pcouffin.sys
2016-02-22 17:56 - 2018-10-27 10:27 - 000047648 _____ () C:\Users\Kengura\AppData\Roaming\SLOVA.WAV
2016-02-22 17:56 - 2018-10-27 10:27 - 000047248 _____ () C:\Users\Kengura\AppData\Roaming\TMP.WAV
2014-06-28 23:09 - 2018-02-21 18:26 - 000001041 _____ () C:\Users\Kengura\AppData\Roaming\vso_ts_preview.xml
2017-12-11 16:57 - 2017-12-11 16:57 - 000003584 _____ () C:\Users\Kengura\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-28 19:39 - 2016-02-28 17:30 - 000007598 _____ () C:\Users\Kengura\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-06-12 12:42
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-06-2019
Ran by Kengura (administrator) on KENGURA-PC (24-06-2019 16:03:51)
Running from C:\Users\Kengura\Pictures
Loaded Profiles: Kengura (Available Profiles: Kengura)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrB.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) [File not signed]
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: E - E:\autorun.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: F - F:\setup.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: G - G:\setup.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: H - H:\m.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\...\MountPoints2: I - I:\m.exe
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [242688 2013-01-08] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2005-06-24] (EA.com/On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2005-06-24] (EA.com/On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP62] => C:\Windows\SysWOW64\vp6vfw.dll [438272 2005-06-24] (EA.com/On2.com) [File not signed]
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {034133F4-20D6-4608-90CD-C90403E43787} - System32\Tasks\{7E6C0C3F-7AC7-47C5-9ECD-54395B2318CD} => C:\Windows\system32\pcalua.exe -a "D:\Half Life\vcredist_x64.exe" -d "D:\Half Life"
Task: {05A1F426-DE4F-451B-A43C-20F126D517F3} - System32\Tasks\{858E6A57-8E30-4C61-A552-31FFDAA25449} => C:\Windows\system32\pcalua.exe -a "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War\CoDWaW.exe" -d "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War"
Task: {0A25FC29-77CE-4CDC-B301-56F428189792} - System32\Tasks\{1E644B9F-37A8-4587-B94C-A444306E413E} => C:\Windows\system32\pcalua.exe -a E:\GDFTHR_inst.exe -d E:\
Task: {0A9495C7-F7D4-4CFC-B3F5-8ED54216FFF8} - System32\Tasks\{6810D009-5302-497C-AC3B-DC98F3EAA823} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War\CoDWaW.exe" -d "C:\Program Files (x86)\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War"
Task: {112DB0BC-A603-4702-99C8-1CE2E90A6FC9} - System32\Tasks\{50B18B69-DF98-47D0-A443-A98C5956B6EC} => C:\Windows\system32\pcalua.exe -a D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack\Vietcong_v130.exe -d D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack
Task: {129709D0-2FA9-4453-9A57-974841762215} - System32\Tasks\{782CD81C-0545-459D-955B-F7D303BA9DB7} => C:\Windows\system32\pcalua.exe -a G:\CRACK\Čeština\MaxPayne2CZ_komplet.exe -d G:\CRACK\Čeština
Task: {14978ECF-6898-4A88-904B-FF347079504C} - System32\Tasks\{FCA47BA9-75D6-4099-ADA2-B343C8905931} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Patch 1.01 + crack\far_cry_2_1.01.exe" -d "D:\Far Cry 2\Patch 1.01 + crack"
Task: {1B99B09F-7A5A-4818-B9C2-79019F844487} - System32\Tasks\{178D66A8-4A0B-4B2C-8DB0-67865DF065AA} => C:\Windows\system32\pcalua.exe -a D:\Manhunt\cz\cz.exe -d D:\Manhunt\cz
Task: {1FEFD606-98ED-4353-96EF-0024B028EC13} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks [Argument = /run /TN "\Microsoft\Windows\Setup\gwx\refreshgwxconfig"]
Task: {20C432A5-FC57-44A2-A5C5-62CC5FDC5DAD} - System32\Tasks\{403F7465-23B6-42F4-B0A4-74F8B133FEED} => C:\Windows\system32\pcalua.exe -a "C:\Nová složka\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Nová složka\Assassin's Creed CZ by Tw22ty"
Task: {264E95FD-A920-47EF-9170-0C1F50A9A846} - System32\Tasks\{72F78116-D245-4599-A955-CCDBF600F92F} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game\Odinstalovat.exe" -d "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game"
Task: {268B635D-61AF-41D5-A8AA-DC528FB5AE1A} - System32\Tasks\{89B29A7E-AC41-4F4B-8A6F-5D089CF89C09} => C:\Windows\system32\pcalua.exe -a "D:\Nová složka\CZ\cz\InstallOblivionCZ.exe" -d "D:\Nová složka\CZ\cz"
Task: {270E1E9D-E551-4B08-BCF8-E6953B1C8937} - System32\Tasks\{19144672-213B-4E0A-8C62-5B805948C173} => "C:\Program Files\Internet Explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/7.0.0.102/cs/abandoninstall?page=tsMain
Task: {2E5CC331-9577-4924-AA58-ADAA70129C9F} - System32\Tasks\{77959336-2A4E-443E-8EA2-9C6B7B09365E} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\Oblinion\cz_oblivion_standard_1.05\InstallOblivionCZ.exe -d D:\Češtiny\Oblinion\cz_oblivion_standard_1.05
Task: {2E8EE109-EA2C-4AF6-898F-4F9C8FCE828B} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Command(2): %windir%\system32\rundll32.exe -> aepdu.dll,AePduRunUpdate -nolegacy
Task: {2E8EE109-EA2C-4AF6-898F-4F9C8FCE828B} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Command(3): %windir%\system32\rundll32.exe -> appraiser.dll,DoScheduledTelemetryRun
Task: {2EF37033-CFC4-4B4A-8EF7-18B7649B8209} - System32\Tasks\{0FEEA325-EDA6-45FC-A2C6-2248D4A25066} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {3253721E-4FBD-4BAD-AAD9-F5F56AF39E9C} - System32\Tasks\{80702A4C-4AB2-4D95-BB14-67DA77B01443} => C:\Windows\system32\pcalua.exe -a E:\GDFTHR_uninst.exe -d E:\
Task: {36437A5C-E7F3-472E-9821-CD07E4F16A19} - System32\Tasks\{646A331F-45B2-45E0-8848-EC8A2238DDEC} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\mohpacificassault_cz.exe -d D:\Češtiny
Task: {36C977BE-4266-41E5-A1CF-97FEC618318B} - System32\Tasks\{5624CF3A-AA0B-4238-97C5-DA1EBC153E16} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kengura\Desktop\DVD1\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Users\Kengura\Desktop\DVD1\Assassin's Creed CZ by Tw22ty"
Task: {3C302C3F-D05B-49D2-88C4-F88ADB54C454} - System32\Tasks\{B120B17E-0A9F-4244-96A6-DAFCDDA963FA} => C:\Windows\system32\pcalua.exe -a F:\far_cry_v1.32.exe -d F:\
Task: {3C4C4868-0DFA-4068-8F9C-EFE0D8B9C7CC} - System32\Tasks\{1C094734-8764-414D-A046-94C65B799FBD} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {40A177AE-CD31-49FE-AC7E-73BBAD55B115} - System32\Tasks\{8BD692AD-85FC-432B-85A1-DC2168DEDFE6} => C:\GOG Games\The Witcher 2 Assassins of Kings\Launcher.exe
Task: {40A2787F-AC5D-4CE2-9495-12C6F47F5801} - System32\Tasks\{F3C5C2CE-B304-46F4-97F5-40292B4A680E} => C:\Windows\system32\pcalua.exe -a D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack\Vietcong_v141.exe -d D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack
Task: {45B2AC2E-7D94-4894-9399-897FAF6C1EA1} - System32\Tasks\{256334CB-D171-426E-B3F5-CDBF56249674} => C:\Windows\system32\pcalua.exe -a D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack\Vietcong-v160.exe -d D:\vietcong.pterodon\vietcong.pterodon\vietcong.uncensored.iso\Patches+crack
Task: {4620D7B1-8400-4A87-81F1-7B4B39F2D721} - System32\Tasks\{6E904970-3CD1-4D6C-ACC6-454297A90B98} => C:\Windows\system32\pcalua.exe -a "D:\Half Life\HalfLife2_CZ.exe" -d "D:\Half Life"
Task: {4B59F7B8-7A48-4239-8E40-F7C59310483F} - System32\Tasks\{A6B5AD12-171A-4E8B-BA60-5B425D65126A} => C:\Windows\system32\pcalua.exe -a F:\setup.exe -d F:\
Task: {4C5D6D63-3650-4634-8841-CFC53D94FC5D} - System32\Tasks\{CEA487D2-DF66-414C-9DDE-75DD792E04A8} => C:\Windows\system32\pcalua.exe -a C:\Users\Kengura\Desktop\hl2_ep_cz.exe -d C:\Users\Kengura\Desktop
Task: {4FB274B8-2D94-46C4-A7DD-9E4A9AE6C70A} - System32\Tasks\{7388A0C8-FCBA-4C6C-900F-CFBD7CB101CC} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {56391FCD-AD2F-47A4-9295-B5BF018B3D94} - System32\Tasks\{39F63C95-859A-49DF-A046-F12E1ACBF3A2} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Patch 1.03 + crack\far_cry_2_1.03.exe" -d "D:\Far Cry 2\Patch 1.03 + crack"
Task: {57159F6D-91CC-4FA2-B8DB-45866B9CB193} - System32\Tasks\{BF0965C6-7032-407E-93BD-F589FABBA642} => C:\GOG Games\The Witcher 2 Assassins of Kings\Launcher.exe
Task: {58BEA721-38EA-46A7-916B-3EF4EE5039DF} - System32\Tasks\{BB098232-5762-4739-8E0B-A999188B8BAA} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\assassins_creed_1.02.exe -d D:\Češtiny
Task: {606AA06C-0A06-4136-A98E-D91FBCED90DE} - System32\Tasks\{22471DC0-8704-4B42-8DD5-919580EF3169} => C:\Windows\system32\pcalua.exe -a "F:\Potřebné programy\Ubisoft Game Launcher\UbisoftGameLauncherInstaller.exe" -d "F:\Potřebné programy\Ubisoft Game Launcher"
Task: {661926E9-5299-4BBD-8DD3-92CF169E6E51} - System32\Tasks\{600C9C37-2D55-43EA-A0E1-73326F7EF38D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\WinRAR\WinRAR.exe" -d C:\Users\Kengura\Desktop
Task: {66433877-4512-4F82-9E64-D043BB2C93B6} - System32\Tasks\{246639CD-5F59-434B-8F3B-4C567D76B2BF} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Activision\Call of Duty - Black Ops\Redist\vcredist_x86.exe" -d "C:\Program Files (x86)\Activision\Call of Duty - Black Ops\Redist"
Task: {669D4148-FA6A-43CB-8511-48A84AB52223} - System32\Tasks\Norton Security Scan for Kengura => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
Task: {70EBBB9A-3748-4213-A901-A676FC4899EA} - System32\Tasks\{C9785EA8-9991-48F6-A759-C2811ACEECAD} => C:\Windows\system32\pcalua.exe -a F:\AC2.part01.exe -d F:\
Task: {73CD4531-ED74-47E6-B405-55A1822A6D8B} - System32\Tasks\{3408B213-E2BD-41E7-9777-C2D723CD04B5} => C:\Windows\system32\pcalua.exe -a C:\Users\Kengura\Desktop\cz_moh_pacific_assault\mohpacificassault_cz.exe -d C:\Users\Kengura\Desktop\cz_moh_pacific_assault
Task: {74EFD15F-274A-4049-A731-B6DC9D4A9F24} - System32\Tasks\{471383DC-0CF7-4011-84EA-559169489C0C} => C:\Program Files (x86)\Cenega Czech\VIETCONG\vietcong.exe
Task: {77886FCE-2755-4F9A-94DA-D62FD9230BAA} - System32\Tasks\{C25F5777-F70F-4D99-AE0C-F288AD5E26B1} => C:\Windows\system32\pcalua.exe -a "D:\Assassins Creed\assassins_creed_1.02.exe" -d "D:\Assassins Creed"
Task: {7906EE58-EE3A-407C-BAB9-9891C7176912} - System32\Tasks\{CB7B2527-D182-4C5D-9087-54096CA3833B} => C:\Windows\system32\pcalua.exe -a D:\Oblivion.cz\cz_oblivion_standard_1.05\InstallOblivionCZ.exe -d D:\Oblivion.cz\cz_oblivion_standard_1.05
Task: {79C19AF2-C56E-45F7-8C01-C021B6F014B4} - System32\Tasks\{631D0B84-5148-4D81-BBC1-41ACBDE5481D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\Mafia\Setup.exe" -d "C:\Program Files\Mafia"
Task: {7A6235C4-DD46-4DF6-80F5-CA8F945FCF5A} - System32\Tasks\{0BFB0B7F-5F54-4D63-98F0-F56955FB3CF0} => C:\Windows\system32\pcalua.exe -a G:\GDFTHR_inst.exe -d G:\
Task: {7D758CDF-DDA4-40FB-907A-61813231DAAD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-02-07] (Google Inc -> Google Inc.)
Task: {7D7E4CCB-ABD5-44A0-B1A3-48B81754ECB1} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {7E558DAF-4005-493C-A162-C088DC6704B0} - System32\Tasks\{4BD9D941-FBBD-4CC6-B75E-90C2983F1151} => C:\Windows\system32\pcalua.exe -a D:\Češtiny\cod_uo_cestina.exe -d D:\Češtiny
Task: {818FE93D-7352-4786-97EF-4F8B801D8BAB} - System32\Tasks\{81B3ED82-0F5A-4FDC-9F6E-41E6AFA5E86D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Translator_2016\TRNIKONY.EXE" -d "C:\Program Files (x86)\Translator_2016"
Task: {83F9AC61-40FE-4196-9476-59638A5EC030} - System32\Tasks\{C260F016-B648-4F0B-9894-A58B36D10A56} => C:\Windows\system32\pcalua.exe -a D:\Manhunt\Manhunt2CZE.exe -d D:\Manhunt
Task: {8B578532-D64E-4D7F-819C-6C7BDA0BE72E} - System32\Tasks\{218F1408-B4AA-469A-A8B4-0DF12E089EDE} => C:\Windows\system32\pcalua.exe -a D:\Gothi\Gothic_3_MDS_EU.exe -d D:\Gothi
Task: {8BBFFB8C-95E7-4EA0-A566-D5C76F4CDCC5} - System32\Tasks\{8512B359-7FB1-48FE-90BF-B3C3DB6CB5AF} => C:\Windows\system32\pcalua.exe -a D:\Instal\Translator_2016\TRNIKONY.EXE -d D:\Instal\Translator_2016
Task: {8BEEA774-9B54-47EE-836A-5B55663EBF25} - System32\Tasks\{5C66CBA1-6087-472F-ADDC-B3ACD5A4B065} => C:\Windows\system32\pcalua.exe -a E:\autorun.exe -d E:\
Task: {8C4A02E2-237C-40C3-9F95-9D754B90188D} - System32\Tasks\{CCA2EB60-19EB-4FF6-BA70-D3D0750E6F02} => C:\Windows\system32\pcalua.exe -a "D:\Half Life\hl2_ep_cz.exe" -d "D:\Half Life"
Task: {8D47791B-6463-4185-858E-2346F900F9F9} - System32\Tasks\{91EF7452-2219-4546-97C6-42B0A73A9781} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {947CC427-784E-40F4-8A62-D17E50646923} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2015-02-07] (Google Inc -> Google Inc.)
Task: {956543F2-F2B1-459D-B5E0-8E819796455C} - System32\Tasks\{8B72E981-D81B-47B8-ADBD-81C8438D8787} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kengura\Desktop\Nová složka\Setup.EXE" -d "C:\Users\Kengura\Desktop\Nová složka"
Task: {99AD046F-2027-4763-92FD-387A36D341C8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998088 2015-06-12] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {9AC3A4B1-357B-4386-A424-C0F47FE37443} - System32\Tasks\{F1069528-A8A5-43FD-A9E1-0FEE54E35E85} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kengura\Videos\max payne 2 čeština a patch\MaxPayne2cestina.exe" -d "C:\Users\Kengura\Videos\max payne 2 čeština a patch"
Task: {A62C8294-0F97-4442-B807-A9BFC5E151A3} - System32\Tasks\{6DE04359-2890-4F43-A39C-429C3A42208F} => C:\Windows\system32\pcalua.exe -a E:\AMD-64BIT_PATCH\SORM_32BIT-AMD64BIT.EXE -d E:\AMD-64BIT_PATCH
Task: {AD8D910F-A632-410A-AED5-C3D772E91391} - System32\Tasks\{525C8C3B-9F12-4673-A06A-69F744F208DC} => C:\Program Files (x86)\Cenega Czech\VIETCONG\vietcong.exe
Task: {B25F336E-8D53-44FD-B717-1ACC9BF1B6F9} - System32\Tasks\{0BDD501F-55CD-405D-A300-6011213A9E80} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {B735ABB3-5C54-4364-B346-944ED3500324} - System32\Tasks\{5805A922-B392-442C-B23F-6BEDA60E9396} => C:\Windows\system32\pcalua.exe -a C:\Users\Kengura\Desktop\cod_uo_cestina.exe -d C:\Users\Kengura\Desktop
Task: {B9BD6340-EE2C-4225-A4C1-E7E6E934555A} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Command(1): %windir%\system32\rundll32.exe -> aepdu.dll,AePduRunUpdate
Task: {B9BD6340-EE2C-4225-A4C1-E7E6E934555A} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Command(2): %windir%\system32\rundll32.exe -> invagent.dll,RunUpdate -noappraiser
Task: {BB5EDFB8-D6DF-441D-AECF-0050F276E5CF} - System32\Tasks\{86EEFF58-1822-4A89-A6BF-ADE5E0A3B8CB} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\OpenAL\oalinst.exe" -d "C:\Program Files (x86)\OpenAL"
Task: {BC2D01BF-0B6D-4130-915C-55D42C7138DB} - System32\Tasks\{C1927AA2-3A17-4076-8D97-94C87770164C} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Patch 1.02 + crack\far_cry_2_1.02.exe" -d "D:\Far Cry 2\Patch 1.02 + crack"
Task: {BC788224-2B9E-4968-A439-B7BCD5CA0573} - System32\Tasks\{466745EC-5C0B-48CF-802A-F8E675AD5EB9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Nová složka\DVD1\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Program Files (x86)\Nová složka\DVD1\Assassin's Creed CZ by Tw22ty"
Task: {C10964D6-1ABD-4CEA-9082-5BA8708B7436} - System32\Tasks\{7D7FE2CC-3A70-44C9-B18E-35665D7785D9} => C:\Windows\system32\pcalua.exe -a F:\setup.exe -d F:\
Task: {C14A5141-0498-4D72-8140-3DBD96F50A7E} - System32\Tasks\{881E1FB6-DF9F-4F85-9AC1-1C6E6D11141F} => C:\Windows\system32\pcalua.exe -a "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War\CoDWaW.exe" -d "D:\Call of Duty 5 World at War v_1.7 full game -=AviaRa=-\Call of Duty - World at War"
Task: {CF14EAFC-78CB-48F3-9646-80C28904965A} - System32\Tasks\{50923AF9-D634-4E90-9215-B3D304D6C572} => C:\Windows\system32\pcalua.exe -a "D:\Far Cry 2\Bonusy\Far Cry 2 - The Fortune's Pack\F2FP_setup.exe" -d "D:\Far Cry 2\Bonusy\Far Cry 2 - The Fortune's Pack"
Task: {DAA0E401-F7D9-476E-BD11-0AB9DDEF77F5} - System32\Tasks\{2E6DDF41-D032-4AEB-BBE9-59D6EADD4079} => C:\Windows\system32\pcalua.exe -a "D:\FAr Cry\farcry_amd64upgrade_us_uk.exe" -d "D:\FAr Cry"
Task: {DFFB58B8-4BAB-4CC2-A832-544DFC56482D} - System32\Tasks\{689AA895-69E0-487D-82B0-EED522E13945} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\Translator_2016\TRNIKONY.EXE" -d "C:\Program Files (x86)\Electronic Arts\Translator_2016"
Task: {EBAD9728-D2A1-4909-9248-F824BBE90AFE} - System32\Tasks\{713AC9CC-C970-4A23-905F-ECD2456E2EF1} => C:\GOG Games\The Witcher Enhanced Edition Director's Cut\launcher.exe
Task: {F0617499-8A8F-4806-B9FA-F7CBB7C7E552} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [272384 2017-11-02] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {F63F3EA8-C076-4137-A252-BD3337870F51} - System32\Tasks\{78DE7B11-5507-4BE7-8B4B-72326267C7A0} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game\GDFTHR_uninst.exe" -d "C:\Program Files (x86)\Electronic Arts\The Godfather® The Game"
Task: {F7AEB2B7-05F9-4412-8420-9D9AA0E82A39} - System32\Tasks\{DE3310A4-F167-4C26-B584-1CB97D86DDF5} => C:\Windows\system32\pcalua.exe -a "C:\Nová složka\Assassin's Creed CZ by Tw22ty\assassins_creed_1.02.exe" -d "C:\Nová složka\Assassin's Creed CZ by Tw22ty"
Task: {FAFD5085-A263-443F-A5FB-E074270079C5} - System32\Tasks\{086F1C2C-E2F7-49B6-8CCC-2BC8C0EAF3E2} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\Ubisoft\Assassin's Creed II\UbisoftGameLauncherInstaller.exe" -d "C:\Program Files\Ubisoft\Assassin's Creed II"
Task: {FD8AF20B-27DE-4BAF-8749-8BDC75B9D4C9} - System32\Tasks\{2DE264B9-9F04-4B5C-928D-471D1B5DFB7D} => C:\GOG Games\The Witcher Enhanced Edition Director's Cut\launcher.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Norton Security Scan for Kengura.job => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{1FF80274-5A8A-4731-92C6-A2EA8D10DC61}: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{B8835B1F-9A53-4FF1-92A4-90FF0D73217C}: [DhcpNameServer] 192.168.11.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2263194865-3938205509-2482612845-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.centrum.cz/
BHO-x32: No Name -> {53707962-6F74-2D53-2644-206D7942484F} -> No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Kengura\AppData\Roaming\Mozilla\Firefox\Profiles\m2usc0l4.default [2019-06-23]
FF user.js: detected! => C:\Users\Kengura\AppData\Roaming\Mozilla\Firefox\Profiles\m2usc0l4.default\user.js [2014-09-04]
FF Homepage: Mozilla\Firefox\Profiles\m2usc0l4.default -> hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-02] (Adobe Systems Incorporated -> )
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-02] (Adobe Systems Incorporated -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-11-14] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-11-14] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-11-02] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-11-02] (Google Inc -> Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2263194865-3938205509-2482612845-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-06-13] (Ubisoft Entertainment Sweden AB -> )
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [203264 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2019-02-01] (Even Balance, Inc. -> )
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2019-02-01] (Even Balance, Inc. -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AmdTools64; C:\Windows\System32\DRIVERS\AmdTools64.sys [47616 2006-06-27] (Advanced Micro Devices, Inc. -> AMD, Inc.)
R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [82048 2011-12-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [42624 2011-12-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [6037504 2009-08-18] (Microsoft Windows Hardware Compatibility Publisher -> ATI Technologies Inc.)
R0 AtiPcie; C:\Windows\System32\DRIVERS\AtiPcie.sys [16440 2009-05-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.)
S2 CLFCL5.18; C:\Windows\System32\DRIVERS\CLFCL5.18\000.fcl [46848 2018-11-12] (CyberLink Corp. -> CyberLink Corp.)
S3 nmwcd; C:\Windows\System32\drivers\ccdcmbx64.sys [19968 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdc; C:\Windows\System32\drivers\ccdcmbox64.sys [27136 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 nmwcdnsux64; C:\Windows\System32\drivers\nmwcdnsux64.sys [171008 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-11-14] (NVIDIA Corporation -> NVIDIA Corporation)
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Inc.)
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S2 tandpl; C:\Windows\SysWOW64\drivers\tandpl.sys [4736 2003-04-19] () [File not signed]
S3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerfltx64.sys [9216 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltjx64.sys [9216 2011-08-17] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 DCamUSBSTK02N; system32\DRIVERS\STK02NW2.sys [X]
S0 pelhmrss; System32\drivers\ujenbxfs.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-06-24 16:03 - 2019-06-24 16:03 - 000000000 ____D C:\FRST
2019-06-20 12:56 - 2019-06-20 12:56 - 000000110 ____H C:\Users\Kengura\Desktop\Obraz0118.jpg.uid-zps
2019-06-07 11:55 - 2019-06-08 15:50 - 000000000 ____D C:\Program Files (x86)\Activision
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-06-24 16:01 - 2014-06-27 14:04 - 000000000 ____D C:\ProgramData\NVIDIA
2019-06-24 16:01 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-06-24 11:21 - 2018-02-05 17:33 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-06-24 11:20 - 2009-07-14 06:45 - 000014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-06-24 11:20 - 2009-07-14 06:45 - 000014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-06-24 11:18 - 2009-07-14 17:18 - 000671796 _____ C:\Windows\system32\perfh005.dat
2019-06-24 11:18 - 2009-07-14 17:18 - 000142392 _____ C:\Windows\system32\perfc005.dat
2019-06-24 11:18 - 2009-07-14 07:13 - 001591814 _____ C:\Windows\system32\PerfStringBackup.INI
2019-06-24 11:18 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2019-06-20 11:59 - 2019-04-24 14:54 - 000000000 ____D C:\Program Files (x86)\FormatFactory
2019-06-11 11:09 - 2015-05-01 14:41 - 000000456 ____H C:\Windows\Tasks\Norton Security Scan for Kengura.job
2019-05-30 12:39 - 2019-04-24 14:56 - 000000000 ____D C:\FFOutput
==================== Files in the root of some directories ================
2019-04-05 16:31 - 2015-11-17 16:01 - 000000422 _____ () C:\Program Files\update-ASCreedSyndicate.bat
2019-04-05 16:31 - 2013-10-12 20:47 - 000000732 _____ () C:\Program Files\visit-www.nosteam.ro.html
2014-10-29 15:18 - 2014-10-29 15:19 - 000002292 _____ () C:\Users\Kengura\AppData\Roaming\ASSDraw3.cfg
2014-06-28 23:09 - 2018-02-23 16:20 - 000099384 _____ () C:\Users\Kengura\AppData\Roaming\inst.exe
2002-08-29 19:33 - 2002-08-29 19:33 - 000319488 ____R () C:\Users\Kengura\AppData\Roaming\MafiaSetup.exe
2014-06-28 23:09 - 2018-02-23 16:20 - 000007859 _____ () C:\Users\Kengura\AppData\Roaming\pcouffin.cat
2014-06-28 23:09 - 2018-02-23 16:20 - 000001167 _____ () C:\Users\Kengura\AppData\Roaming\pcouffin.inf
2014-06-28 23:09 - 2018-02-23 16:20 - 000000055 _____ () C:\Users\Kengura\AppData\Roaming\pcouffin.log
2014-06-28 23:09 - 2018-02-23 16:20 - 000082816 _____ (VSO Software) C:\Users\Kengura\AppData\Roaming\pcouffin.sys
2016-02-22 17:56 - 2018-10-27 10:27 - 000047648 _____ () C:\Users\Kengura\AppData\Roaming\SLOVA.WAV
2016-02-22 17:56 - 2018-10-27 10:27 - 000047248 _____ () C:\Users\Kengura\AppData\Roaming\TMP.WAV
2014-06-28 23:09 - 2018-02-21 18:26 - 000001041 _____ () C:\Users\Kengura\AppData\Roaming\vso_ts_preview.xml
2017-12-11 16:57 - 2017-12-11 16:57 - 000003584 _____ () C:\Users\Kengura\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-28 19:39 - 2016-02-28 17:30 - 000007598 _____ () C:\Users\Kengura\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-06-12 12:42
==================== End of FRST.txt ============================