Kontrola logu- zpomalený PC
Napsal: 08 lis 2020 16:49
Dobrý den, prosím o kontrolu logu. Poslední dobou trvá strašně dlouho než je možno po startu počítač ovládat.Vkládám log rsit i FRST. Předem děkuji.
Logfile of random's system information tool 1.10 (written by random/random)
Run by ASRock at 2020-11-08 16:20:48
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 169 GB (55%) free of 305 GB
Total RAM: 3327 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:20:54, on 8.11.2020
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19597)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe
C:\Program Files\DriverToolkit\DriverToolkit.exe
C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\McAfee\WebAdvisor\UIHost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\cmd.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Program Files\McAfee\WebAdvisor\browserhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\ASRock\Downloads\RSIT.exe
C:\Program Files\trend micro\ASRock.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkI ... id=UE12DHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll
O2 - BHO: McAfee WebAdvisor - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\GENIAT~1\TOTALT~1\THCDES~1.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [MTPW] "C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe"
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [Remote Control Editor] "C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O9 - Extra 'Tools' menuitem: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
O23 - Service: Služba CCleaner Browser Update (ccleaner) (ccleaner) - Piriform Software - C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe
O23 - Service: CCleaner Browser Elevation Service (CCleanerBrowserElevationService) - Piriform Software - C:\Program Files\CCleaner Browser\Application\86.1.6738.114\elevation_service.exe
O23 - Service: Služba CCleaner Browser Update (ccleanerm) (ccleanerm) - Piriform Software - C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe
O23 - Service: EyeTV Netstream - Elgato Systems GmbH - C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Foxit Reader Update Service (FoxitReaderUpdateService) - Foxit Software Inc. - C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files\Google\Chrome\Application\86.0.4240.183\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WebAdvisor - McAfee, LLC - C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MTAgentService - Unknown owner - C:\Program Files\MiniTool ShadowMaker\AgentService.exe
O23 - Service: MTSchedulerService - Unknown owner - C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) - Reimage® - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: O&O Syspectr (SyspectrAgent) - O&O Software GmbH - C:\Program Files\OO Software\Syspectr\OOSysAgent.exe
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - VIA Technologies, Inc. - C:\Windows\system32\viakaraokesrv.exe
O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
O23 - Service: WDFMEService - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
O23 - Service: WDRulesService - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
--
End of file - 10437 bytes
======Scheduled tasks folder======
C:\Windows\tasks\DriverToolkit Autorun.job - C:\Program Files\DriverToolkit\DriverToolkit.exe --autorun
C:\Windows\tasks\Google Software Updater.job - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe scheduled_start
=========Mozilla firefox=========
ProfilePath - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.251.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.251.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_251\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=14]
"Description"=Google Updater
"Path"=C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@update.ccleanerbrowser.com/CCleaner Browser;version=3]
"Description"=CCleaner Browser
"Path"=C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@update.ccleanerbrowser.com/CCleaner Browser;version=9]
"Description"=CCleaner Browser
"Path"=C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.7.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=
C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\searchplugins\
seznam-avast.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll [2020-05-16 480424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-10-30 1099008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll [2020-05-16 194728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]
{AD6E6555-FB2C-47D4-8339-3E2965509877} - TerraTec Home Cinema - C:\PROGRA~1\GENIAT~1\TOTALT~1\THCDES~1.DLL [2017-06-19 526336]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2020-10-18 98408]
"MTPW"=C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [2020-02-19 175584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner.exe [2020-10-23 26069176]
"Remote Control Editor"=C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe [2017-06-19 1836544]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2020-09-06 1341008]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud]
C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13 472984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2015-10-13 60688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AshSnap]
C:\Program Files\Ashampoo\Ashampoo Snap 4\ashsnap.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-07-26 2569616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-09-04 767312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\ASRock\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\ASRock\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
C:\Program Files\DAEMON Tools Pro\DTAgent.exe [2012-04-26 3111744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe /autorun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\ASRock\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-21 107912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google+ Auto Backup]
C:\Users\ASRock\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [2014-08-12 3746120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Opera Browser Assistant]
C:\Program Files\Opera\assistant\browser_assistant.exe [2020-07-15 3105304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe /Background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2020-03-12 646776]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TuneupUI.exe]
C:\Program Files\Avast Software\Cleanup\TuneupUI.exe /nogui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2016-10-08 2137744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Avast Cleanup Premium.lnk]
C:\Program Files\AVAST Software\Avast Cleanup\TuneupUI.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AVer HID Receiver.lnk]
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERHI~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AVerQuick.lnk]
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERQU~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ASRock^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.lnk]
C:\Program Files\OpenOffice.org 3\program\quickstart.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ASRock^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sound Control.lnk]
C:\PROGRA~1\SOUNDC~1\SC.EXE [2002-04-13 695808]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\epmntdrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EuGdiDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\epmntdrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EuGdiDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
"EnableLinkedConnections"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2020-10-27 22:55:36 ----A---- C:\Windows\ntbtlog.txt
2020-10-20 23:41:35 ----D---- C:\ProgramData\SystemAcCrux
2020-10-20 23:41:27 ----A---- C:\Windows\system32\drivers\EUDCPEPM.sys
2020-10-20 23:41:25 ----A---- C:\Windows\system32\drivers\EUEDKEPM.sys
2020-10-20 23:41:05 ----A---- C:\Windows\system32\setupepmdrv.ini
2020-10-20 23:41:05 ----A---- C:\Windows\system32\setupempdrv03.exe
2020-10-20 23:41:05 ----A---- C:\Windows\system32\EuGdiDrv.sys
2020-10-20 23:41:05 ----A---- C:\Windows\system32\EPMVolFl.sys
2020-10-20 23:41:05 ----A---- C:\Windows\system32\drivers\EPMVolFl.sys
2020-10-20 23:41:04 ----A---- C:\Windows\system32\EuEpmGdi.dll
2020-10-20 23:41:04 ----A---- C:\Windows\system32\epmntdrv.sys
2020-10-20 23:41:04 ----A---- C:\Windows\system32\BootMan.exe
2020-10-20 23:40:42 ----D---- C:\Program Files\EaseUS
2020-10-18 09:04:00 ----A---- C:\Windows\system32\aswBoot.exe
2020-10-18 09:03:55 ----A---- C:\Windows\system32\drivers\aswStm.sys
2020-10-18 09:03:54 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
======List of files/folders modified in the last 1 month======
2020-11-08 16:20:53 ----D---- C:\Windows\Prefetch
2020-11-08 16:20:52 ----D---- C:\Program Files\trend micro
2020-11-08 16:19:39 ----D---- C:\Windows\Temp
2020-11-08 16:11:07 ----D---- C:\FRST
2020-11-08 16:00:24 ----D---- C:\Windows
2020-11-08 15:23:14 ----SHD---- C:\Windows\Installer
2020-11-08 11:32:57 ----D---- C:\Windows\system32\config
2020-11-08 10:59:19 ----D---- C:\Users\ASRock\AppData\Roaming\QtProject
2020-11-08 10:48:09 ----D---- C:\ProgramData\AVAST Software
2020-11-08 02:02:54 ----D---- C:\Windows\tracing
2020-11-06 19:05:28 ----D---- C:\Config.Msi
2020-11-06 19:04:03 ----D---- C:\Windows\System32
2020-11-05 21:20:52 ----D---- C:\Program Files\CCleaner Browser
2020-11-05 21:20:50 ----D---- C:\Windows\system32\Tasks
2020-11-03 21:57:02 ----D---- C:\Program Files\Opera
2020-10-31 22:59:53 ----SHD---- C:\System Volume Information
2020-10-31 00:34:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2020-10-31 00:34:22 ----D---- C:\Windows\inf
2020-10-21 23:20:16 ----D---- C:\Program Files\USB Disk Storage Format Tool
2020-10-20 23:41:35 ----HD---- C:\ProgramData
2020-10-20 23:41:27 ----D---- C:\Windows\system32\drivers
2020-10-20 23:40:42 ----D---- C:\Program Files
2020-10-19 21:47:16 ----D---- C:\Users\ASRock\AppData\Roaming\Skype
2020-10-19 21:46:57 ----D---- C:\ProgramData\Foxit Software
2020-10-18 09:06:59 ----D---- C:\Windows\system32\Macromed
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
R0 aswArDisk;aswArDisk; C:\Windows\system32\drivers\aswArDisk.sys [2020-10-18 35040]
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsh.sys [2020-10-18 154696]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniv.sys [2020-10-18 55888]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2020-10-18 72840]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2020-10-18 277960]
R0 EPMVolFl;EPMVolFl; C:\Windows\System32\drivers\EPMVolFl.sys [2020-07-07 17672]
R0 EUDCPEPM;EUDCPEPM; C:\Windows\system32\drivers\EUDCPEPM.sys [2020-07-07 66184]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2019-11-08 17160]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 173288]
R1 aswArPot;aswArPot; C:\Windows\system32\drivers\aswArPot.sys [2020-10-18 175776]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriver.sys [2020-10-18 189520]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2020-10-18 40736]
R1 aswNetHub;aswNetHub; C:\Windows\system32\drivers\aswNetHub.sys [2020-10-18 375192]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2020-10-18 94192]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2020-10-18 691064]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2020-10-18 396616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-01-01 242240]
R1 EUEDKEPM;EUEDKEPM; \??\C:\Windows\system32\drivers\EUEDKEPM.sys [2020-07-07 21640]
R1 HWiNFO_150;HWiNFO Kernel Driver (v150); \??\C:\Windows\system32\drivers\HWiNFO32_150.SYS [2020-05-24 53152]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO32.SYS [2020-01-28 52376]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2020-10-18 147712]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2020-10-18 163312]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 290304]
R3 aswNetNd6;Avast Firewall NDIS6 Helper; C:\Windows\system32\DRIVERS\aswNetNd6.sys [2020-04-15 36104]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2016-07-24 78848]
R3 CYDTV_SRV;cydtv Driver; C:\Windows\system32\drivers\cydtv.sys [2017-06-28 1203200]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2020-09-15 73984]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2016-07-24 169472]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2010-03-22 18944]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32k.sys [2009-11-11 30576]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2014-11-24 116184]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2016-12-19 575696]
S1 HWiNFO;HWiNFO Kernel Driver; \??\C:\Users\ASRock\AppData\Local\Temp\HWiNFO32.SYS []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2019-04-19 52968]
S3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x86; C:\Windows\system32\DRIVERS\Apfiltr.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
S3 AVerA706;AVerMedia A706 BDA Service; C:\Windows\system32\DRIVERS\AVerA706.sys [2010-04-08 1223040]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2019-07-30 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2017-07-06 94208]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2019-07-30 396800]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2019-07-30 60416]
S3 epmntdrv;epmntdrv; C:\Windows\system32\epmntdrv.sys [2020-07-07 23688]
S3 EuGdiDrv;EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [2020-07-07 13832]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2011-03-19 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\k750mdfl.sys [2011-03-19 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\Windows\system32\DRIVERS\k750mdm.sys [2011-03-19 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\Windows\system32\DRIVERS\k750mgmt.sys [2011-03-19 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\Windows\system32\DRIVERS\k750obex.sys [2011-03-19 79488]
S3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2010-03-04 296936]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf_x86.sys [2013-12-06 16024]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2019-11-08 13064]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2016-09-09 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2019-04-19 51944]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2016-09-09 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2016-09-09 27136]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 VBoxUSB;VirtualBox USB; C:\Windows\System32\Drivers\VBoxUSB.sys [2013-07-04 84752]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2019-04-19 52968]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\drivers\viac7.sys [2020-01-03 53248]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2011-02-16 11520]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2020-09-06 169544]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-11-16 291840]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2020-10-18 332344]
R2 avast! Tools;Avast Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [2020-10-18 2511456]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 EyeTV Netstream;EyeTV Netstream; C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe [2013-04-15 400864]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2010-01-21 370792]
R2 FoxitReaderUpdateService;Foxit Reader Update Service; C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe [2020-07-08 1995184]
R2 McAfee WebAdvisor;McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [2020-10-30 729632]
R2 MTAgentService;MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [2020-08-30 676336]
R2 MTSchedulerService;MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [2020-08-30 204272]
R2 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2010-01-21 167528]
R2 RosettaStoneDaemon;RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2012-06-19 1646608]
R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [2013-12-06 1229528]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2016-07-22 754784]
R2 SyspectrAgent;O&O Syspectr; C:\Program Files\OO Software\Syspectr\OOSysAgent.exe [2020-09-18 310328]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2016-12-19 36496]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2020-10-18 7522208]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 ccleaner;Služba CCleaner Browser Update (ccleaner); C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [2020-09-03 200928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2019-03-28 132792]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-10-04 194104]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2019-03-28 47960]
S3 CCleanerBrowserElevationService;CCleaner Browser Elevation Service; C:\Program Files\CCleaner Browser\Application\86.1.6738.114\elevation_service.exe [2020-11-02 1136920]
S3 ccleanerm;Služba CCleaner Browser Update (ccleanerm); C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [2020-09-03 200928]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2019-09-26 1045256]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files\Google\Chrome\Application\86.0.4240.183\elevation_service.exe [2020-11-02 1123312]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2019-12-17 104960]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2020-07-09 222928]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]
S3 ReimageRealTimeProtector;Reimage Real Time Protector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2018-02-08 7027568]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2015-06-10 155520]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-20 1343400]
S3 WDDMService;WDDMService; C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [2011-08-01 263056]
S3 WDFMEService;WDFMEService; C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [2011-08-01 1592208]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 NetMsmqActivator;Adaptér naslouchání Net.Msmq; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
-----------------EOF-----------------
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-11-2017 (ATTENTION: ====> FRSTversion is 1082 days old and could be outdated)
Ran by ASRock (administrator) on ASROCK-PC (08-11-2020 16:09:44)
Running from C:\Users\ASRock\Desktop
Loaded Profiles: ASRock (Available Profiles: ASRock & DefaultAppPool)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Adobe Inc.) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Piriform Software) C:\Program Files\CCleaner Browser\Update\1.8.1067.0\CCleanerBrowserCrashHandler.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe
(GENIATECH INC.,LTD) C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe
(Megaify Software Co., Ltd.) C:\Program Files\DriverToolkit\DriverToolkit.exe
(Elgato Systems GmbH) C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe
(Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe
(McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
() C:\Program Files\MiniTool ShadowMaker\AgentService.exe
(Google LLC) C:\Program Files\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
() C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
(Rosetta Stone Ltd.) C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(O&O Software GmbH) C:\Program Files\OO Software\Syspectr\OOSysAgent.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [98408 2020-10-18] (AVAST Software)
HKLM\...\Run: [MTPW] => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [175584 2020-02-19] ()
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [26069176 2020-10-23] (Piriform Software Ltd)
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Run: [Remote Control Editor] => C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe [1836544 2017-06-19] (GENIATECH INC.,LTD)
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\MountPoints2: {b367d44f-541b-11e2-b3af-002522739666} - I:\wubi.exe --cdmenu
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2020-10-07]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll => No File
Winsock: Catalog9 01 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 02 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 03 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 04 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 05 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 06 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 18 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 19 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 46.16.122.2
Tcpip\..\Interfaces\{E33BE343-EF5F-45B5-8D94-A4D01331B8FF}: [DhcpNameServer] 46.16.122.2
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2661226761-2934294044-4021329715-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll [2020-05-16] (Oracle Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-10-30] (McAfee, LLC)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll [2020-05-16] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKLM - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files\Geniatech\TotalTV Player\THCDeskBand.dll [2017-06-19] (GENIATECH INC.,LTD)
Toolbar: HKU\S-1-5-21-2661226761-2934294044-4021329715-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKU\S-1-5-21-2661226761-2934294044-4021329715-1000 -> No Name - {124D001A-BDCB-472F-AA59-BBE7E4BC3204} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: j9cebcfi.default
FF ProfilePath: Profiles/j9cebcfi.default [not found] <==== ATTENTION
FF ProfilePath: C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default [2020-11-08]
FF user.js: detected! => C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\user.js [2016-07-24]
FF Homepage: Mozilla\Firefox\Profiles\j9cebcfi.default -> hxxps://www.seznam.cz/?clid=22668
FF Extension: (Dashlane) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\jetpack-extension@dashlane.com.xpi [2020-06-16]
FF Extension: (Avast Passwords) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi [2020-05-23]
FF Extension: (Emoji Cheatsheet for GitHub, Basecamp etc.) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\jid1-Xo5SuA6qc1DFpw@jetpack.xpi [2017-11-15]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\langpack-cs@firefox.mozilla.org.xpi [2020-06-16]
FF Extension: (Video DownloadHelper) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-05-23]
FF SearchPlugin: C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\searchplugins\seznam-avast.xml [2015-03-16]
FF Extension: (DoH Roll-Out) - C:\Program Files\Mozilla Firefox\browser\features\doh-rollout@mozilla.org.xpi [2020-07-09] [not signed]
FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2020-07-09] [not signed]
FF HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-03-27] (CANON INC.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-05-16] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-05-16] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-10-04] (Google)
FF Plugin: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll [2020-09-03] (Piriform Software)
FF Plugin: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll [2020-09-03] (Piriform Software)
FF Plugin: @videolan.org/vlc,version=1.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-10-22] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2661226761-2934294044-4021329715-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ASRock\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-20] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2661226761-2934294044-4021329715-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\ASRock\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-03-25] (Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-2661226761-2934294044-4021329715-1000: sony.com/MediaGoDetector -> C:\Program Files\Sony\Media Go\npMediaGoDetector.dll [2016-10-24] (Sony Network Entertainment International LLC)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\all-gemius.js [2016-07-16]
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.centrum.cz/
CHR StartupUrls: Default -> "hxxp://centrum.cz/","hxxps://www.duolingo.com/","hxxps://app.mondly. ... x.php/live"
CHR Profile: C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default [2020-11-08]
CHR Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2019-08-12]
CHR Extension: (Avast Passwords) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2020-02-10]
CHR Extension: (Avast SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-07-05]
CHR Extension: (Dashlane - Password Manager) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2020-11-07]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-10-31]
CHR Extension: (Duolingo Tweaks) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcankdajnfcbepbhjhfechmandhfplen [2015-12-06]
CHR Extension: (Duolingo Vocabulary Manager) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\mglmcjokbicehcaojghjmhfjnaooffcd [2015-12-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-10]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files\Sony\Media Go\MediaGoDetector.crx" <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-11-16] (Advanced Micro Devices, Inc.) [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [7522208 2020-10-18] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [332344 2020-10-18] (AVAST Software)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [2511456 2020-10-18] (AVAST Software)
S2 ccleaner; C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200928 2020-09-03] (Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files\CCleaner Browser\Application\86.1.6738.114\elevation_service.exe [1136920 2020-11-02] (Piriform Software)
S3 ccleanerm; C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200928 2020-09-03] (Piriform Software)
R2 EyeTV Netstream; C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe [400864 2013-04-15] (Elgato Systems GmbH)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [370792 2010-01-21] ()
R2 FoxitReaderUpdateService; C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe [1995184 2020-07-08] (Foxit Software Inc.)
S3 GoogleChromeElevationService; C:\Program Files\Google\Chrome\Application\86.0.4240.183\elevation_service.exe [1123312 2020-11-02] (Google LLC)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [729632 2020-10-30] (McAfee, LLC)
R2 MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [676336 2020-08-30] ()
R2 MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [204272 2020-08-30] ()
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [167528 2010-01-21] ()
S3 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7027568 2018-02-08] (Reimage®)
R2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646608 2012-06-19] (Rosetta Stone Ltd.)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software) [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R2 SyspectrAgent; C:\Program Files\OO Software\Syspectr\OOSysAgent.exe [310328 2020-09-18] (O&O Software GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36496 2016-12-19] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [35040 2020-10-18] (AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [175776 2020-10-18] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [189520 2020-10-18] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [154696 2020-10-18] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [55888 2020-10-18] (AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [40736 2020-10-18] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [147712 2020-10-18] (AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [375192 2020-10-18] (AVAST Software)
R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [36104 2020-04-15] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [94192 2020-10-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [72840 2020-10-18] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [691064 2020-10-18] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [396616 2020-10-18] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [163312 2020-10-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [277960 2020-10-18] (AVAST Software)
S3 AVerA706; C:\Windows\System32\DRIVERS\AVerA706.sys [1223040 2010-04-08] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R3 CYDTV_SRV; C:\Windows\System32\drivers\cydtv.sys [1203200 2017-06-28] ( )
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-01-01] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [23688 2020-07-07] ()
R0 EPMVolFl; C:\Windows\System32\drivers\EPMVolFl.sys [17672 2020-07-07] (Windows (R) Codename Longhorn DDK provider)
R0 EUDCPEPM; C:\Windows\System32\drivers\EUDCPEPM.sys [66184 2020-07-07] (CHENGDU YIWO Tech Development Co., Ltd)
R1 EUEDKEPM; C:\Windows\system32\drivers\EUEDKEPM.sys [21640 2020-07-07] (CHENGDU YIWO Tech Development Co., Ltd)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [13832 2020-07-07] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [52376 2020-01-28] (REALiX(tm))
R1 HWiNFO_150; C:\Windows\system32\drivers\HWiNFO32_150.SYS [53152 2020-05-24] (REALiX(tm))
S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2011-03-19] (MCCI)
S3 k750mdfl; C:\Windows\System32\DRIVERS\k750mdfl.sys [6576 2011-03-19] (MCCI)
S3 k750mdm; C:\Windows\System32\DRIVERS\k750mdm.sys [89872 2011-03-19] (MCCI)
S3 k750mgmt; C:\Windows\System32\DRIVERS\k750mgmt.sys [81728 2011-03-19] (MCCI)
S3 k750obex; C:\Windows\System32\DRIVERS\k750obex.sys [79488 2011-03-19] (MCCI)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [73984 2020-09-15] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [169472 2016-07-24] (Renesas Electronics Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [17160 2019-11-08] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13064 2019-11-08] ()
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [575696 2016-12-19] (VIA Technologies, Inc.)
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
U3 DfSdkS; no ImagePath
S1 HWiNFO; \??\C:\Users\ASRock\AppData\Local\Temp\HWiNFO32.SYS [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-08 16:07 - 2020-11-08 16:08 - 000060069 _____ C:\Users\ASRock\Desktop\Addition.txt
2020-11-08 16:01 - 2020-11-08 16:10 - 000027277 _____ C:\Users\ASRock\Desktop\FRST.txt
2020-11-07 22:33 - 2020-11-07 22:33 - 000711408 _____ C:\Users\ASRock\Downloads\cz_manual_evolveo_sigma_t2 (6).pdf
2020-11-07 22:33 - 2020-11-07 22:33 - 000711408 _____ C:\Users\ASRock\Downloads\cz_manual_evolveo_sigma_t2 (5).pdf
2020-11-07 22:13 - 2020-11-07 22:13 - 000000000 ____D C:\Users\ASRock\AppData\LocalLow\Foxit
2020-11-02 21:06 - 2020-11-02 21:06 - 000000000 ____D C:\Users\ASRock\Downloads\Simca
2020-11-02 20:56 - 2020-11-02 20:59 - 406931777 _____ C:\Users\ASRock\Downloads\Simca.zip
2020-10-27 22:55 - 2020-11-08 10:46 - 000223096 _____ C:\Windows\ntbtlog.txt
2020-10-26 20:33 - 2020-10-26 20:34 - 000007664 _____ C:\Users\ASRock\Documents\cc_20201026_203352.reg
2020-10-26 20:23 - 2020-10-26 20:24 - 029853224 _____ (Piriform Software Ltd) C:\Users\ASRock\Downloads\ccsetup573.exe
2020-10-21 23:09 - 2020-10-21 23:09 - 000570586 _____ (Authorsoft Corporation ) C:\Users\ASRock\Downloads\USBFormatToolSetup (1).exe
2020-10-20 23:41 - 2020-10-20 23:41 - 000001220 _____ C:\Users\Public\Desktop\EaseUS Partition Master 14.5.lnk
2020-10-20 23:41 - 2020-10-20 23:41 - 000000000 ____D C:\ProgramData\SystemAcCrux
2020-10-20 23:41 - 2020-10-20 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 14.5
2020-10-20 23:41 - 2020-07-07 14:14 - 000149128 _____ C:\Windows\system32\setupempdrv03.exe
2020-10-20 23:41 - 2020-07-07 14:14 - 000023688 _____ C:\Windows\system32\epmntdrv.sys
2020-10-20 23:41 - 2020-07-07 14:14 - 000017672 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\EPMVolFl.sys
2020-10-20 23:41 - 2020-07-07 14:14 - 000017672 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\EPMVolFl.sys
2020-10-20 23:41 - 2020-07-07 14:14 - 000013832 _____ C:\Windows\system32\EuGdiDrv.sys
2020-10-20 23:41 - 2020-07-07 14:12 - 003734664 _____ C:\Windows\system32\BootMan.exe
2020-10-20 23:41 - 2020-07-07 14:12 - 000024712 _____ C:\Windows\system32\EuEpmGdi.dll
2020-10-20 23:41 - 2020-07-07 14:11 - 000066184 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\EUDCPEPM.sys
2020-10-20 23:41 - 2020-07-07 14:11 - 000021640 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\EUEDKEPM.sys
2020-10-20 23:41 - 2020-02-23 13:49 - 000000057 _____ C:\Windows\system32\setupepmdrv.ini
2020-10-20 23:40 - 2020-10-20 23:40 - 047169616 _____ (EaseUS ) C:\Users\ASRock\Downloads\epm_free_easeus.exe
2020-10-20 23:40 - 2020-10-20 23:40 - 000000000 ____D C:\Program Files\EaseUS
2020-10-20 23:39 - 2020-10-20 23:39 - 001710608 _____ C:\Users\ASRock\Downloads\epm_free_installer.exe
2020-10-20 23:06 - 2020-10-20 23:06 - 000226437 _____ C:\Users\ASRock\Downloads\Stepankovi_2.pdf.zip
2020-10-20 00:30 - 2020-10-20 00:30 - 000080038 _____ C:\Users\ASRock\Downloads\kupon.pdf
2020-10-19 21:46 - 2020-10-19 21:46 - 000002060 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2020-10-19 21:46 - 2020-10-19 21:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2020-10-18 09:04 - 2020-10-18 09:03 - 000285280 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2020-10-18 09:03 - 2020-10-18 09:03 - 000163312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2020-10-18 09:03 - 2020-10-18 09:03 - 000147712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2020-10-17 22:19 - 2020-10-17 22:19 - 000000000 ____D C:\Users\ASRock\Downloads\Honza_Kozel.pdf
2020-10-17 22:16 - 2020-10-17 22:17 - 000206693 _____ C:\Users\ASRock\Downloads\Honza_Kozel.pdf.zip
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-08 16:09 - 2017-11-23 10:39 - 000000000 ____D C:\FRST
2020-11-08 15:59 - 2016-09-09 22:25 - 000000000 ____D C:\Users\ASRock\AppData\Local\AVAST Software
2020-11-08 12:19 - 2009-07-14 05:34 - 000026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-11-08 12:19 - 2009-07-14 05:34 - 000026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-11-08 12:13 - 2020-09-04 19:04 - 000000348 _____ C:\Windows\Tasks\DriverToolkit Autorun.job
2020-11-08 12:13 - 2015-05-16 22:51 - 000000924 _____ C:\Windows\Tasks\Google Software Updater.job
2020-11-08 10:59 - 2020-10-01 23:34 - 000000000 ____D C:\Users\ASRock\AppData\Roaming\QtProject
2020-11-08 10:48 - 2011-03-07 17:49 - 000000000 ____D C:\ProgramData\AVAST Software
2020-11-08 10:32 - 2016-05-31 15:13 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2020-11-08 10:32 - 2009-07-14 05:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-11-08 02:02 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\tracing
2020-11-06 19:04 - 2020-05-29 14:30 - 000001994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-11-05 21:20 - 2019-07-18 11:40 - 000002233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2020-11-05 21:20 - 2019-07-18 11:40 - 000002190 _____ C:\Users\Public\Desktop\CCleaner Browser.lnk
2020-11-05 21:20 - 2019-07-18 11:37 - 000000000 ____D C:\Program Files\CCleaner Browser
2020-11-04 23:42 - 2014-02-22 21:06 - 000002135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-04 23:42 - 2014-02-22 21:06 - 000002094 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-03 21:57 - 2017-06-05 17:06 - 000000000 ____D C:\Program Files\Opera
2020-11-03 00:09 - 2013-08-16 20:00 - 000000000 ____D C:\Users\ASRock\Desktop\Pro Honzíka
2020-10-31 00:34 - 2011-03-07 17:09 - 001704428 _____ C:\Windows\system32\PerfStringBackup.INI
2020-10-31 00:34 - 2009-07-14 09:44 - 000713412 _____ C:\Windows\system32\perfh005.dat
2020-10-31 00:34 - 2009-07-14 09:44 - 000158440 _____ C:\Windows\system32\perfc005.dat
2020-10-31 00:34 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\inf
2020-10-26 20:34 - 2014-10-19 21:29 - 000796160 ___SH C:\Users\ASRock\Desktop\Thumbs.db
2020-10-26 20:26 - 2011-03-21 00:23 - 000000934 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-10-21 23:20 - 2018-06-23 18:38 - 000001099 _____ C:\Users\ASRock\Desktop\USB Disk Storage Format Tool.lnk
2020-10-21 23:20 - 2018-06-23 18:38 - 000000063 _____ C:\Users\ASRock\Desktop\Create Bootable USB.url
2020-10-21 23:20 - 2018-06-23 18:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Disk Storage Format Tool 5.3
2020-10-21 23:20 - 2018-06-23 18:38 - 000000000 ____D C:\Program Files\USB Disk Storage Format Tool
2020-10-19 21:49 - 2013-08-04 13:27 - 000000993 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-10-19 21:47 - 2018-12-06 21:52 - 000001233 _____ C:\Users\Public\Desktop\Skype.lnk
2020-10-19 21:47 - 2018-12-06 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-10-19 21:47 - 2012-05-06 17:59 - 000000000 ____D C:\Users\ASRock\AppData\Roaming\Skype
2020-10-19 21:46 - 2016-08-25 21:41 - 000000000 ____D C:\ProgramData\Foxit Software
2020-10-19 21:44 - 2019-11-13 20:00 - 000000068 _____ C:\Users\Public\Documents\pre_fileassoc.tmp
2020-10-18 09:19 - 2020-04-15 18:34 - 000375192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetHub.sys
2020-10-18 09:06 - 2011-03-26 10:56 - 000000000 ____D C:\Windows\system32\Macromed
2020-10-18 09:03 - 2019-01-08 23:14 - 000154696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2020-10-18 09:03 - 2019-01-08 23:14 - 000055888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2020-10-18 09:03 - 2018-11-15 20:43 - 000040736 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2020-10-18 09:03 - 2013-03-18 13:32 - 000277960 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2020-10-18 09:03 - 2013-03-18 13:32 - 000072840 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2020-10-18 09:03 - 2012-03-14 14:35 - 000094192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2020-10-18 09:03 - 2011-03-07 17:50 - 000396616 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2020-10-18 09:02 - 2019-01-14 20:32 - 000189520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2020-10-18 09:02 - 2019-01-08 23:14 - 000035040 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2020-10-18 09:02 - 2018-01-10 20:27 - 000175776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2020-10-18 09:02 - 2011-03-07 17:50 - 000691064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2020-10-15 23:41 - 2014-05-29 10:05 - 000000000 ____D C:\Users\ASRock\Desktop\SonEric_28_5_2014
2020-10-14 22:38 - 2013-02-14 17:37 - 000000000 ____D C:\Users\ASRock\Desktop\RECEPTY
==================== Files in the root of some directories =======
2013-09-19 16:58 - 2013-09-19 16:58 - 000000000 _____ () C:\Users\ASRock\AppData\Roaming\pdfperformer
2015-01-05 14:23 - 2015-01-05 14:25 - 000011264 ___SH () C:\Users\ASRock\AppData\Roaming\Thumbs.db
2011-06-23 17:32 - 2016-06-06 22:30 - 000006144 _____ () C:\Users\ASRock\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-06-23 19:04 - 2018-06-23 19:04 - 000000001 _____ () C:\Users\ASRock\AppData\Local\llftool.4.40.agreement
2016-01-16 15:19 - 2016-01-16 15:19 - 000003977 _____ () C:\Users\ASRock\AppData\Local\recently-used.xbel
2011-09-05 13:04 - 2012-04-11 23:24 - 000007605 _____ () C:\Users\ASRock\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2020-11-05 21:39
==================== End of FRST.txt ============================
Logfile of random's system information tool 1.10 (written by random/random)
Run by ASRock at 2020-11-08 16:20:48
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 169 GB (55%) free of 305 GB
Total RAM: 3327 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:20:54, on 8.11.2020
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19597)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe
C:\Program Files\DriverToolkit\DriverToolkit.exe
C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\McAfee\WebAdvisor\UIHost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\cmd.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Program Files\McAfee\WebAdvisor\browserhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\ASRock\Downloads\RSIT.exe
C:\Program Files\trend micro\ASRock.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkI ... id=UE12DHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll
O2 - BHO: McAfee WebAdvisor - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\PROGRA~1\GENIAT~1\TOTALT~1\THCDES~1.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [MTPW] "C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe"
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [Remote Control Editor] "C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O9 - Extra 'Tools' menuitem: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
O23 - Service: Služba CCleaner Browser Update (ccleaner) (ccleaner) - Piriform Software - C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe
O23 - Service: CCleaner Browser Elevation Service (CCleanerBrowserElevationService) - Piriform Software - C:\Program Files\CCleaner Browser\Application\86.1.6738.114\elevation_service.exe
O23 - Service: Služba CCleaner Browser Update (ccleanerm) (ccleanerm) - Piriform Software - C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe
O23 - Service: EyeTV Netstream - Elgato Systems GmbH - C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Foxit Reader Update Service (FoxitReaderUpdateService) - Foxit Software Inc. - C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files\Google\Chrome\Application\86.0.4240.183\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WebAdvisor - McAfee, LLC - C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MTAgentService - Unknown owner - C:\Program Files\MiniTool ShadowMaker\AgentService.exe
O23 - Service: MTSchedulerService - Unknown owner - C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) - Reimage® - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
O23 - Service: RosettaStoneDaemon - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: O&O Syspectr (SyspectrAgent) - O&O Software GmbH - C:\Program Files\OO Software\Syspectr\OOSysAgent.exe
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - VIA Technologies, Inc. - C:\Windows\system32\viakaraokesrv.exe
O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
O23 - Service: WDFMEService - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
O23 - Service: WDRulesService - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
--
End of file - 10437 bytes
======Scheduled tasks folder======
C:\Windows\tasks\DriverToolkit Autorun.job - C:\Program Files\DriverToolkit\DriverToolkit.exe --autorun
C:\Windows\tasks\Google Software Updater.job - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe scheduled_start
=========Mozilla firefox=========
ProfilePath - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.251.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.251.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_251\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pack.google.com/Google Updater;version=14]
"Description"=Google Updater
"Path"=C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@update.ccleanerbrowser.com/CCleaner Browser;version=3]
"Description"=CCleaner Browser
"Path"=C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@update.ccleanerbrowser.com/CCleaner Browser;version=9]
"Description"=CCleaner Browser
"Path"=C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.7.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=3.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=
C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\searchplugins\
seznam-avast.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll [2020-05-16 480424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-10-30 1099008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll [2020-05-16 194728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]
{AD6E6555-FB2C-47D4-8339-3E2965509877} - TerraTec Home Cinema - C:\PROGRA~1\GENIAT~1\TOTALT~1\THCDES~1.DLL [2017-06-19 526336]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2020-10-18 98408]
"MTPW"=C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [2020-02-19 175584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner.exe [2020-10-23 26069176]
"Remote Control Editor"=C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe [2017-06-19 1836544]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2020-09-06 1341008]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud]
C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13 472984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2015-10-13 60688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AshSnap]
C:\Program Files\Ashampoo\Ashampoo Snap 4\ashsnap.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-07-26 2569616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-09-04 767312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\ASRock\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\ASRock\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
C:\Program Files\DAEMON Tools Pro\DTAgent.exe [2012-04-26 3111744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe /autorun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\ASRock\AppData\Local\Google\Update\GoogleUpdate.exe [2014-10-21 107912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google+ Auto Backup]
C:\Users\ASRock\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [2014-08-12 3746120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Opera Browser Assistant]
C:\Program Files\Opera\assistant\browser_assistant.exe [2020-07-15 3105304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe /Background []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2020-03-12 646776]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TuneupUI.exe]
C:\Program Files\Avast Software\Cleanup\TuneupUI.exe /nogui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2016-10-08 2137744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Avast Cleanup Premium.lnk]
C:\Program Files\AVAST Software\Avast Cleanup\TuneupUI.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AVer HID Receiver.lnk]
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERHI~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AVerQuick.lnk]
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERQU~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ASRock^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.lnk]
C:\Program Files\OpenOffice.org 3\program\quickstart.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ASRock^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sound Control.lnk]
C:\PROGRA~1\SOUNDC~1\SC.EXE [2002-04-13 695808]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\epmntdrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EuGdiDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\epmntdrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EuGdiDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
"EnableLinkedConnections"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSimpleNetIDList"=1
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2020-10-27 22:55:36 ----A---- C:\Windows\ntbtlog.txt
2020-10-20 23:41:35 ----D---- C:\ProgramData\SystemAcCrux
2020-10-20 23:41:27 ----A---- C:\Windows\system32\drivers\EUDCPEPM.sys
2020-10-20 23:41:25 ----A---- C:\Windows\system32\drivers\EUEDKEPM.sys
2020-10-20 23:41:05 ----A---- C:\Windows\system32\setupepmdrv.ini
2020-10-20 23:41:05 ----A---- C:\Windows\system32\setupempdrv03.exe
2020-10-20 23:41:05 ----A---- C:\Windows\system32\EuGdiDrv.sys
2020-10-20 23:41:05 ----A---- C:\Windows\system32\EPMVolFl.sys
2020-10-20 23:41:05 ----A---- C:\Windows\system32\drivers\EPMVolFl.sys
2020-10-20 23:41:04 ----A---- C:\Windows\system32\EuEpmGdi.dll
2020-10-20 23:41:04 ----A---- C:\Windows\system32\epmntdrv.sys
2020-10-20 23:41:04 ----A---- C:\Windows\system32\BootMan.exe
2020-10-20 23:40:42 ----D---- C:\Program Files\EaseUS
2020-10-18 09:04:00 ----A---- C:\Windows\system32\aswBoot.exe
2020-10-18 09:03:55 ----A---- C:\Windows\system32\drivers\aswStm.sys
2020-10-18 09:03:54 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
======List of files/folders modified in the last 1 month======
2020-11-08 16:20:53 ----D---- C:\Windows\Prefetch
2020-11-08 16:20:52 ----D---- C:\Program Files\trend micro
2020-11-08 16:19:39 ----D---- C:\Windows\Temp
2020-11-08 16:11:07 ----D---- C:\FRST
2020-11-08 16:00:24 ----D---- C:\Windows
2020-11-08 15:23:14 ----SHD---- C:\Windows\Installer
2020-11-08 11:32:57 ----D---- C:\Windows\system32\config
2020-11-08 10:59:19 ----D---- C:\Users\ASRock\AppData\Roaming\QtProject
2020-11-08 10:48:09 ----D---- C:\ProgramData\AVAST Software
2020-11-08 02:02:54 ----D---- C:\Windows\tracing
2020-11-06 19:05:28 ----D---- C:\Config.Msi
2020-11-06 19:04:03 ----D---- C:\Windows\System32
2020-11-05 21:20:52 ----D---- C:\Program Files\CCleaner Browser
2020-11-05 21:20:50 ----D---- C:\Windows\system32\Tasks
2020-11-03 21:57:02 ----D---- C:\Program Files\Opera
2020-10-31 22:59:53 ----SHD---- C:\System Volume Information
2020-10-31 00:34:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2020-10-31 00:34:22 ----D---- C:\Windows\inf
2020-10-21 23:20:16 ----D---- C:\Program Files\USB Disk Storage Format Tool
2020-10-20 23:41:35 ----HD---- C:\ProgramData
2020-10-20 23:41:27 ----D---- C:\Windows\system32\drivers
2020-10-20 23:40:42 ----D---- C:\Program Files
2020-10-19 21:47:16 ----D---- C:\Users\ASRock\AppData\Roaming\Skype
2020-10-19 21:46:57 ----D---- C:\ProgramData\Foxit Software
2020-10-18 09:06:59 ----D---- C:\Windows\system32\Macromed
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
R0 aswArDisk;aswArDisk; C:\Windows\system32\drivers\aswArDisk.sys [2020-10-18 35040]
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsh.sys [2020-10-18 154696]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniv.sys [2020-10-18 55888]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2020-10-18 72840]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2020-10-18 277960]
R0 EPMVolFl;EPMVolFl; C:\Windows\System32\drivers\EPMVolFl.sys [2020-07-07 17672]
R0 EUDCPEPM;EUDCPEPM; C:\Windows\system32\drivers\EUDCPEPM.sys [2020-07-07 66184]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 pwdrvio;pwdrvio; C:\Windows\system32\pwdrvio.sys [2019-11-08 17160]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 173288]
R1 aswArPot;aswArPot; C:\Windows\system32\drivers\aswArPot.sys [2020-10-18 175776]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriver.sys [2020-10-18 189520]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2020-10-18 40736]
R1 aswNetHub;aswNetHub; C:\Windows\system32\drivers\aswNetHub.sys [2020-10-18 375192]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2020-10-18 94192]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2020-10-18 691064]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2020-10-18 396616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-01-01 242240]
R1 EUEDKEPM;EUEDKEPM; \??\C:\Windows\system32\drivers\EUEDKEPM.sys [2020-07-07 21640]
R1 HWiNFO_150;HWiNFO Kernel Driver (v150); \??\C:\Windows\system32\drivers\HWiNFO32_150.SYS [2020-05-24 53152]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO32.SYS [2020-01-28 52376]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2020-10-18 147712]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2020-10-18 163312]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-11-16 290304]
R3 aswNetNd6;Avast Firewall NDIS6 Helper; C:\Windows\system32\DRIVERS\aswNetNd6.sys [2020-04-15 36104]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2016-07-24 78848]
R3 CYDTV_SRV;cydtv Driver; C:\Windows\system32\drivers\cydtv.sys [2017-06-28 1203200]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2020-09-15 73984]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2016-07-24 169472]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2010-03-22 18944]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32k.sys [2009-11-11 30576]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2014-11-24 116184]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2016-12-19 575696]
S1 HWiNFO;HWiNFO Kernel Driver; \??\C:\Users\ASRock\AppData\Local\Temp\HWiNFO32.SYS []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2019-04-19 52968]
S3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x86; C:\Windows\system32\DRIVERS\Apfiltr.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-11-16 10070016]
S3 AVerA706;AVerMedia A706 BDA Service; C:\Windows\system32\DRIVERS\AVerA706.sys [2010-04-08 1223040]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2019-07-30 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2017-07-06 94208]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2019-07-30 396800]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2019-07-30 60416]
S3 epmntdrv;epmntdrv; C:\Windows\system32\epmntdrv.sys [2020-07-07 23688]
S3 EuGdiDrv;EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [2020-07-07 13832]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2011-03-19 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\k750mdfl.sys [2011-03-19 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\Windows\system32\DRIVERS\k750mdm.sys [2011-03-19 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\Windows\system32\DRIVERS\k750mgmt.sys [2011-03-19 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\Windows\system32\DRIVERS\k750obex.sys [2011-03-19 79488]
S3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2010-03-04 296936]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf_x86.sys [2013-12-06 16024]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2019-11-08 13064]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2016-09-09 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2019-04-19 51944]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2016-09-09 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2016-09-09 27136]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 VBoxUSB;VirtualBox USB; C:\Windows\System32\Drivers\VBoxUSB.sys [2013-07-04 84752]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2019-04-19 52968]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\drivers\viac7.sys [2020-01-03 53248]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2011-02-16 11520]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2020-09-06 169544]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-11-16 291840]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2020-10-18 332344]
R2 avast! Tools;Avast Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [2020-10-18 2511456]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 EyeTV Netstream;EyeTV Netstream; C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe [2013-04-15 400864]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2010-01-21 370792]
R2 FoxitReaderUpdateService;Foxit Reader Update Service; C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe [2020-07-08 1995184]
R2 McAfee WebAdvisor;McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [2020-10-30 729632]
R2 MTAgentService;MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [2020-08-30 676336]
R2 MTSchedulerService;MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [2020-08-30 204272]
R2 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2010-01-21 167528]
R2 RosettaStoneDaemon;RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2012-06-19 1646608]
R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [2013-12-06 1229528]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2016-07-22 754784]
R2 SyspectrAgent;O&O Syspectr; C:\Program Files\OO Software\Syspectr\OOSysAgent.exe [2020-09-18 310328]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2016-12-19 36496]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2020-10-18 7522208]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 ccleaner;Služba CCleaner Browser Update (ccleaner); C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [2020-09-03 200928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2019-03-28 132792]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-10-04 194104]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2019-03-28 47960]
S3 CCleanerBrowserElevationService;CCleaner Browser Elevation Service; C:\Program Files\CCleaner Browser\Application\86.1.6738.114\elevation_service.exe [2020-11-02 1136920]
S3 ccleanerm;Služba CCleaner Browser Update (ccleanerm); C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [2020-09-03 200928]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2019-09-26 1045256]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files\Google\Chrome\Application\86.0.4240.183\elevation_service.exe [2020-11-02 1123312]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2019-12-17 104960]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2020-07-09 222928]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-08 271920]
S3 ReimageRealTimeProtector;Reimage Real Time Protector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2018-02-08 7027568]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2015-06-10 155520]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-20 1343400]
S3 WDDMService;WDDMService; C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [2011-08-01 263056]
S3 WDFMEService;WDFMEService; C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [2011-08-01 1592208]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 NetMsmqActivator;Adaptér naslouchání Net.Msmq; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
-----------------EOF-----------------
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-11-2017 (ATTENTION: ====> FRSTversion is 1082 days old and could be outdated)
Ran by ASRock (administrator) on ASROCK-PC (08-11-2020 16:09:44)
Running from C:\Users\ASRock\Desktop
Loaded Profiles: ASRock (Available Profiles: ASRock & DefaultAppPool)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Adobe Inc.) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Piriform Software) C:\Program Files\CCleaner Browser\Update\1.8.1067.0\CCleanerBrowserCrashHandler.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe
(GENIATECH INC.,LTD) C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe
(Megaify Software Co., Ltd.) C:\Program Files\DriverToolkit\DriverToolkit.exe
(Elgato Systems GmbH) C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe
(Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe
(McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
() C:\Program Files\MiniTool ShadowMaker\AgentService.exe
(Google LLC) C:\Program Files\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
() C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe
(Rosetta Stone Ltd.) C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(O&O Software GmbH) C:\Program Files\OO Software\Syspectr\OOSysAgent.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [98408 2020-10-18] (AVAST Software)
HKLM\...\Run: [MTPW] => C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe [175584 2020-02-19] ()
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [26069176 2020-10-23] (Piriform Software Ltd)
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Run: [Remote Control Editor] => C:\Program Files\Common Files\TotalTV Player\Remote\TTTvRc.exe [1836544 2017-06-19] (GENIATECH INC.,LTD)
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\MountPoints2: {b367d44f-541b-11e2-b3af-002522739666} - I:\wubi.exe --cdmenu
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2020-10-07]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll => No File
Winsock: Catalog9 01 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 02 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 03 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 04 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 05 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 06 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 18 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Winsock: Catalog9 19 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll [258664 2010-01-21] (NVIDIA)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 46.16.122.2
Tcpip\..\Interfaces\{E33BE343-EF5F-45B5-8D94-A4D01331B8FF}: [DhcpNameServer] 46.16.122.2
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2661226761-2934294044-4021329715-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_251\bin\ssv.dll [2020-05-16] (Oracle Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-10-30] (McAfee, LLC)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_251\bin\jp2ssv.dll [2020-05-16] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKLM - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files\Geniatech\TotalTV Player\THCDeskBand.dll [2017-06-19] (GENIATECH INC.,LTD)
Toolbar: HKU\S-1-5-21-2661226761-2934294044-4021329715-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKU\S-1-5-21-2661226761-2934294044-4021329715-1000 -> No Name - {124D001A-BDCB-472F-AA59-BBE7E4BC3204} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: j9cebcfi.default
FF ProfilePath: Profiles/j9cebcfi.default [not found] <==== ATTENTION
FF ProfilePath: C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default [2020-11-08]
FF user.js: detected! => C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\user.js [2016-07-24]
FF Homepage: Mozilla\Firefox\Profiles\j9cebcfi.default -> hxxps://www.seznam.cz/?clid=22668
FF Extension: (Dashlane) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\jetpack-extension@dashlane.com.xpi [2020-06-16]
FF Extension: (Avast Passwords) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi [2020-05-23]
FF Extension: (Emoji Cheatsheet for GitHub, Basecamp etc.) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\jid1-Xo5SuA6qc1DFpw@jetpack.xpi [2017-11-15]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\langpack-cs@firefox.mozilla.org.xpi [2020-06-16]
FF Extension: (Video DownloadHelper) - C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2020-05-23]
FF SearchPlugin: C:\Users\ASRock\AppData\Roaming\Mozilla\Firefox\Profiles\j9cebcfi.default\searchplugins\seznam-avast.xml [2015-03-16]
FF Extension: (DoH Roll-Out) - C:\Program Files\Mozilla Firefox\browser\features\doh-rollout@mozilla.org.xpi [2020-07-09] [not signed]
FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2020-07-09] [not signed]
FF HKU\S-1-5-21-2661226761-2934294044-4021329715-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-03-27] (CANON INC.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2020-07-08] (Foxit Corporation)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-05-16] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-05-16] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-10-04] (Google)
FF Plugin: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll [2020-09-03] (Piriform Software)
FF Plugin: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files\CCleaner Browser\Update\1.8.1067.0\npCCleanerBrowserUpdate3.dll [2020-09-03] (Piriform Software)
FF Plugin: @videolan.org/vlc,version=1.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-10-22] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2661226761-2934294044-4021329715-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ASRock\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-20] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2661226761-2934294044-4021329715-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\ASRock\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-03-25] (Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-2661226761-2934294044-4021329715-1000: sony.com/MediaGoDetector -> C:\Program Files\Sony\Media Go\npMediaGoDetector.dll [2016-10-24] (Sony Network Entertainment International LLC)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\all-gemius.js [2016-07-16]
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.centrum.cz/
CHR StartupUrls: Default -> "hxxp://centrum.cz/","hxxps://www.duolingo.com/","hxxps://app.mondly. ... x.php/live"
CHR Profile: C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default [2020-11-08]
CHR Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2019-08-12]
CHR Extension: (Avast Passwords) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2020-02-10]
CHR Extension: (Avast SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-07-05]
CHR Extension: (Dashlane - Password Manager) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2020-11-07]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-10-31]
CHR Extension: (Duolingo Tweaks) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcankdajnfcbepbhjhfechmandhfplen [2015-12-06]
CHR Extension: (Duolingo Vocabulary Manager) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\mglmcjokbicehcaojghjmhfjnaooffcd [2015-12-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\ASRock\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-10]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files\Sony\Media Go\MediaGoDetector.crx" <not found>
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-11-16] (Advanced Micro Devices, Inc.) [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [7522208 2020-10-18] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [332344 2020-10-18] (AVAST Software)
R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [2511456 2020-10-18] (AVAST Software)
S2 ccleaner; C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200928 2020-09-03] (Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files\CCleaner Browser\Application\86.1.6738.114\elevation_service.exe [1136920 2020-11-02] (Piriform Software)
S3 ccleanerm; C:\Program Files\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [200928 2020-09-03] (Piriform Software)
R2 EyeTV Netstream; C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe [400864 2013-04-15] (Elgato Systems GmbH)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [370792 2010-01-21] ()
R2 FoxitReaderUpdateService; C:\Program Files\Foxit Software\Foxit Reader\FoxitReaderUpdateService.exe [1995184 2020-07-08] (Foxit Software Inc.)
S3 GoogleChromeElevationService; C:\Program Files\Google\Chrome\Application\86.0.4240.183\elevation_service.exe [1123312 2020-11-02] (Google LLC)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [729632 2020-10-30] (McAfee, LLC)
R2 MTAgentService; C:\Program Files\MiniTool ShadowMaker\AgentService.exe [676336 2020-08-30] ()
R2 MTSchedulerService; C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe [204272 2020-08-30] ()
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [167528 2010-01-21] ()
S3 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7027568 2018-02-08] (Reimage®)
R2 RosettaStoneDaemon; C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [1646608 2012-06-19] (Rosetta Stone Ltd.)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software) [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R2 SyspectrAgent; C:\Program Files\OO Software\Syspectr\OOSysAgent.exe [310328 2020-09-18] (O&O Software GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36496 2016-12-19] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [35040 2020-10-18] (AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [175776 2020-10-18] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [189520 2020-10-18] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [154696 2020-10-18] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [55888 2020-10-18] (AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [40736 2020-10-18] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [147712 2020-10-18] (AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [375192 2020-10-18] (AVAST Software)
R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [36104 2020-04-15] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [94192 2020-10-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [72840 2020-10-18] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [691064 2020-10-18] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [396616 2020-10-18] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [163312 2020-10-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [277960 2020-10-18] (AVAST Software)
S3 AVerA706; C:\Windows\System32\DRIVERS\AVerA706.sys [1223040 2010-04-08] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R3 CYDTV_SRV; C:\Windows\System32\drivers\cydtv.sys [1203200 2017-06-28] ( )
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-01-01] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [23688 2020-07-07] ()
R0 EPMVolFl; C:\Windows\System32\drivers\EPMVolFl.sys [17672 2020-07-07] (Windows (R) Codename Longhorn DDK provider)
R0 EUDCPEPM; C:\Windows\System32\drivers\EUDCPEPM.sys [66184 2020-07-07] (CHENGDU YIWO Tech Development Co., Ltd)
R1 EUEDKEPM; C:\Windows\system32\drivers\EUEDKEPM.sys [21640 2020-07-07] (CHENGDU YIWO Tech Development Co., Ltd)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [13832 2020-07-07] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [52376 2020-01-28] (REALiX(tm))
R1 HWiNFO_150; C:\Windows\system32\drivers\HWiNFO32_150.SYS [53152 2020-05-24] (REALiX(tm))
S3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2011-03-19] (MCCI)
S3 k750mdfl; C:\Windows\System32\DRIVERS\k750mdfl.sys [6576 2011-03-19] (MCCI)
S3 k750mdm; C:\Windows\System32\DRIVERS\k750mdm.sys [89872 2011-03-19] (MCCI)
S3 k750mgmt; C:\Windows\System32\DRIVERS\k750mgmt.sys [81728 2011-03-19] (MCCI)
S3 k750obex; C:\Windows\System32\DRIVERS\k750obex.sys [79488 2011-03-19] (MCCI)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [73984 2020-09-15] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [169472 2016-07-24] (Renesas Electronics Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [17160 2019-11-08] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13064 2019-11-08] ()
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [575696 2016-12-19] (VIA Technologies, Inc.)
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
U3 DfSdkS; no ImagePath
S1 HWiNFO; \??\C:\Users\ASRock\AppData\Local\Temp\HWiNFO32.SYS [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-08 16:07 - 2020-11-08 16:08 - 000060069 _____ C:\Users\ASRock\Desktop\Addition.txt
2020-11-08 16:01 - 2020-11-08 16:10 - 000027277 _____ C:\Users\ASRock\Desktop\FRST.txt
2020-11-07 22:33 - 2020-11-07 22:33 - 000711408 _____ C:\Users\ASRock\Downloads\cz_manual_evolveo_sigma_t2 (6).pdf
2020-11-07 22:33 - 2020-11-07 22:33 - 000711408 _____ C:\Users\ASRock\Downloads\cz_manual_evolveo_sigma_t2 (5).pdf
2020-11-07 22:13 - 2020-11-07 22:13 - 000000000 ____D C:\Users\ASRock\AppData\LocalLow\Foxit
2020-11-02 21:06 - 2020-11-02 21:06 - 000000000 ____D C:\Users\ASRock\Downloads\Simca
2020-11-02 20:56 - 2020-11-02 20:59 - 406931777 _____ C:\Users\ASRock\Downloads\Simca.zip
2020-10-27 22:55 - 2020-11-08 10:46 - 000223096 _____ C:\Windows\ntbtlog.txt
2020-10-26 20:33 - 2020-10-26 20:34 - 000007664 _____ C:\Users\ASRock\Documents\cc_20201026_203352.reg
2020-10-26 20:23 - 2020-10-26 20:24 - 029853224 _____ (Piriform Software Ltd) C:\Users\ASRock\Downloads\ccsetup573.exe
2020-10-21 23:09 - 2020-10-21 23:09 - 000570586 _____ (Authorsoft Corporation ) C:\Users\ASRock\Downloads\USBFormatToolSetup (1).exe
2020-10-20 23:41 - 2020-10-20 23:41 - 000001220 _____ C:\Users\Public\Desktop\EaseUS Partition Master 14.5.lnk
2020-10-20 23:41 - 2020-10-20 23:41 - 000000000 ____D C:\ProgramData\SystemAcCrux
2020-10-20 23:41 - 2020-10-20 23:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 14.5
2020-10-20 23:41 - 2020-07-07 14:14 - 000149128 _____ C:\Windows\system32\setupempdrv03.exe
2020-10-20 23:41 - 2020-07-07 14:14 - 000023688 _____ C:\Windows\system32\epmntdrv.sys
2020-10-20 23:41 - 2020-07-07 14:14 - 000017672 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\EPMVolFl.sys
2020-10-20 23:41 - 2020-07-07 14:14 - 000017672 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\EPMVolFl.sys
2020-10-20 23:41 - 2020-07-07 14:14 - 000013832 _____ C:\Windows\system32\EuGdiDrv.sys
2020-10-20 23:41 - 2020-07-07 14:12 - 003734664 _____ C:\Windows\system32\BootMan.exe
2020-10-20 23:41 - 2020-07-07 14:12 - 000024712 _____ C:\Windows\system32\EuEpmGdi.dll
2020-10-20 23:41 - 2020-07-07 14:11 - 000066184 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\EUDCPEPM.sys
2020-10-20 23:41 - 2020-07-07 14:11 - 000021640 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\EUEDKEPM.sys
2020-10-20 23:41 - 2020-02-23 13:49 - 000000057 _____ C:\Windows\system32\setupepmdrv.ini
2020-10-20 23:40 - 2020-10-20 23:40 - 047169616 _____ (EaseUS ) C:\Users\ASRock\Downloads\epm_free_easeus.exe
2020-10-20 23:40 - 2020-10-20 23:40 - 000000000 ____D C:\Program Files\EaseUS
2020-10-20 23:39 - 2020-10-20 23:39 - 001710608 _____ C:\Users\ASRock\Downloads\epm_free_installer.exe
2020-10-20 23:06 - 2020-10-20 23:06 - 000226437 _____ C:\Users\ASRock\Downloads\Stepankovi_2.pdf.zip
2020-10-20 00:30 - 2020-10-20 00:30 - 000080038 _____ C:\Users\ASRock\Downloads\kupon.pdf
2020-10-19 21:46 - 2020-10-19 21:46 - 000002060 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2020-10-19 21:46 - 2020-10-19 21:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2020-10-18 09:04 - 2020-10-18 09:03 - 000285280 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2020-10-18 09:03 - 2020-10-18 09:03 - 000163312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2020-10-18 09:03 - 2020-10-18 09:03 - 000147712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2020-10-17 22:19 - 2020-10-17 22:19 - 000000000 ____D C:\Users\ASRock\Downloads\Honza_Kozel.pdf
2020-10-17 22:16 - 2020-10-17 22:17 - 000206693 _____ C:\Users\ASRock\Downloads\Honza_Kozel.pdf.zip
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-11-08 16:09 - 2017-11-23 10:39 - 000000000 ____D C:\FRST
2020-11-08 15:59 - 2016-09-09 22:25 - 000000000 ____D C:\Users\ASRock\AppData\Local\AVAST Software
2020-11-08 12:19 - 2009-07-14 05:34 - 000026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-11-08 12:19 - 2009-07-14 05:34 - 000026000 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-11-08 12:13 - 2020-09-04 19:04 - 000000348 _____ C:\Windows\Tasks\DriverToolkit Autorun.job
2020-11-08 12:13 - 2015-05-16 22:51 - 000000924 _____ C:\Windows\Tasks\Google Software Updater.job
2020-11-08 10:59 - 2020-10-01 23:34 - 000000000 ____D C:\Users\ASRock\AppData\Roaming\QtProject
2020-11-08 10:48 - 2011-03-07 17:49 - 000000000 ____D C:\ProgramData\AVAST Software
2020-11-08 10:32 - 2016-05-31 15:13 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2020-11-08 10:32 - 2009-07-14 05:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-11-08 02:02 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\tracing
2020-11-06 19:04 - 2020-05-29 14:30 - 000001994 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-11-05 21:20 - 2019-07-18 11:40 - 000002233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2020-11-05 21:20 - 2019-07-18 11:40 - 000002190 _____ C:\Users\Public\Desktop\CCleaner Browser.lnk
2020-11-05 21:20 - 2019-07-18 11:37 - 000000000 ____D C:\Program Files\CCleaner Browser
2020-11-04 23:42 - 2014-02-22 21:06 - 000002135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-04 23:42 - 2014-02-22 21:06 - 000002094 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-03 21:57 - 2017-06-05 17:06 - 000000000 ____D C:\Program Files\Opera
2020-11-03 00:09 - 2013-08-16 20:00 - 000000000 ____D C:\Users\ASRock\Desktop\Pro Honzíka
2020-10-31 00:34 - 2011-03-07 17:09 - 001704428 _____ C:\Windows\system32\PerfStringBackup.INI
2020-10-31 00:34 - 2009-07-14 09:44 - 000713412 _____ C:\Windows\system32\perfh005.dat
2020-10-31 00:34 - 2009-07-14 09:44 - 000158440 _____ C:\Windows\system32\perfc005.dat
2020-10-31 00:34 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\inf
2020-10-26 20:34 - 2014-10-19 21:29 - 000796160 ___SH C:\Users\ASRock\Desktop\Thumbs.db
2020-10-26 20:26 - 2011-03-21 00:23 - 000000934 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-10-21 23:20 - 2018-06-23 18:38 - 000001099 _____ C:\Users\ASRock\Desktop\USB Disk Storage Format Tool.lnk
2020-10-21 23:20 - 2018-06-23 18:38 - 000000063 _____ C:\Users\ASRock\Desktop\Create Bootable USB.url
2020-10-21 23:20 - 2018-06-23 18:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Disk Storage Format Tool 5.3
2020-10-21 23:20 - 2018-06-23 18:38 - 000000000 ____D C:\Program Files\USB Disk Storage Format Tool
2020-10-19 21:49 - 2013-08-04 13:27 - 000000993 _____ C:\Users\Public\Desktop\VLC media player.lnk
2020-10-19 21:47 - 2018-12-06 21:52 - 000001233 _____ C:\Users\Public\Desktop\Skype.lnk
2020-10-19 21:47 - 2018-12-06 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-10-19 21:47 - 2012-05-06 17:59 - 000000000 ____D C:\Users\ASRock\AppData\Roaming\Skype
2020-10-19 21:46 - 2016-08-25 21:41 - 000000000 ____D C:\ProgramData\Foxit Software
2020-10-19 21:44 - 2019-11-13 20:00 - 000000068 _____ C:\Users\Public\Documents\pre_fileassoc.tmp
2020-10-18 09:19 - 2020-04-15 18:34 - 000375192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetHub.sys
2020-10-18 09:06 - 2011-03-26 10:56 - 000000000 ____D C:\Windows\system32\Macromed
2020-10-18 09:03 - 2019-01-08 23:14 - 000154696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2020-10-18 09:03 - 2019-01-08 23:14 - 000055888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2020-10-18 09:03 - 2018-11-15 20:43 - 000040736 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2020-10-18 09:03 - 2013-03-18 13:32 - 000277960 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2020-10-18 09:03 - 2013-03-18 13:32 - 000072840 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2020-10-18 09:03 - 2012-03-14 14:35 - 000094192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2020-10-18 09:03 - 2011-03-07 17:50 - 000396616 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2020-10-18 09:02 - 2019-01-14 20:32 - 000189520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2020-10-18 09:02 - 2019-01-08 23:14 - 000035040 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2020-10-18 09:02 - 2018-01-10 20:27 - 000175776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2020-10-18 09:02 - 2011-03-07 17:50 - 000691064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2020-10-15 23:41 - 2014-05-29 10:05 - 000000000 ____D C:\Users\ASRock\Desktop\SonEric_28_5_2014
2020-10-14 22:38 - 2013-02-14 17:37 - 000000000 ____D C:\Users\ASRock\Desktop\RECEPTY
==================== Files in the root of some directories =======
2013-09-19 16:58 - 2013-09-19 16:58 - 000000000 _____ () C:\Users\ASRock\AppData\Roaming\pdfperformer
2015-01-05 14:23 - 2015-01-05 14:25 - 000011264 ___SH () C:\Users\ASRock\AppData\Roaming\Thumbs.db
2011-06-23 17:32 - 2016-06-06 22:30 - 000006144 _____ () C:\Users\ASRock\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-06-23 19:04 - 2018-06-23 19:04 - 000000001 _____ () C:\Users\ASRock\AppData\Local\llftool.4.40.agreement
2016-01-16 15:19 - 2016-01-16 15:19 - 000003977 _____ () C:\Users\ASRock\AppData\Local\recently-used.xbel
2011-09-05 13:04 - 2012-04-11 23:24 - 000007605 _____ () C:\Users\ASRock\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2020-11-05 21:39
==================== End of FRST.txt ============================