Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 3-07-2019
Ran by acer (administrator) on ACER-NTB (Acer Aspire E5-572G) (09-07-2019 10:43:26)
Running from C:\Users\acer\Desktop
Loaded Profiles: acer (Available Profiles: acer)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Default browser: Opera
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Fortemedia Inc -> ) C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Fortemedia Inc -> ) C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Gaijin Network LTD -> Gaijin Entertainment) C:\Users\acer\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel(R) Corporation) [File not signed] C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Mail.Ru, LLC -> ) C:\Users\acer\AppData\Local\GameCenter\GameCenter.exe
(Mail.Ru, LLC -> ) C:\Users\acer\AppData\Local\GameCenter\GameCenter.exe
(Mail.Ru, LLC -> ) C:\Users\acer\AppData\Local\GameCenter\GameCenter.exe
(Mail.Ru, LLC -> ) C:\Users\acer\AppData\Local\GameCenter\GameCenter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\62.0.3331.43\opera_crashreporter.exe
(Qualcomm Atheros -> ) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Qualcomm Atheros -> Qualcomm®Atheros®) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [File not signed] C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1923008 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671640 2014-04-10] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [262024 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [5580608 2019-06-24] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1069296 2018-03-27] (Seznam.cz, a.s. -> )
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Qualcomm Atheros -> Qualcomm®Atheros®) [File not signed]
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4701888 2017-02-07] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\acer\AppData\Roaming\Seznam.cz\szninstall.exe [1069296 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\acer\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [109808 2018-03-27] (Seznam.cz, a.s. -> )
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [AvastBrowserAutoLaunch_DDCF4F8EFD9886AA021E5A45064136EC] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1815792 2019-06-12] (AVAST Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\Run: [Gaijin.Net Updater] => C:\Users\acer\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2105416 2019-04-19] (Gaijin Network LTD -> Gaijin Entertainment)
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\...\MountPoints2: {010a4381-27b1-11e8-82e8-f8a963e3c09d} - "E:\Startme.exe"
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [71680 2013-02-26] (Beepa P/L) [File not signed]
HKLM\...\Drivers32-x32: [vidc.XVID] => xvidvfw.dll
HKLM\...\Drivers32-x32: [VIDC.VP80] => vp8vfw.dll
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [65536 2013-02-26] (Beepa P/L) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-24] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}] ->
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] -> C:\Windows\SysWOW64\advpack.dll [2014-11-21] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\75.0.1447.80\Installer\chrmstp.exe [2019-06-28] (AVAST Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2014-02-25] (Qualcomm Atheros -> Qualcomm®Atheros®) [File not signed]
HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2014-02-25] (Qualcomm Atheros -> Qualcomm®Atheros®) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-07-17] () [File not signed]
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {03FA82B1-B314-417A-8D16-93027263B20B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {0632E821-2F6B-484E-9DC1-C79C5A360EEC} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2281944 2019-06-04] (AVAST Software s.r.o. -> AVAST Software)
Task: {071189A0-163A-41BF-AED6-55C6BB0EB060} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [947136 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1262F7F3-8AC0-4CAC-82F3-8B14D3D7EC82} - System32\Tasks\{C28ADA92-6260-442F-A140-E81F92719D7B} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Cenega Czech\Mafia\Game.exe" -d "C:\Program Files (x86)\Cenega Czech\Mafia"
Task: {175E0419-7096-4FDD-BC0E-508F80107441} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-06] (Dropbox, Inc -> Dropbox, Inc.)
Task: {1ABDE700-2400-4089-A89F-4FFB3D9C8887} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-05-09] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {1DD87C4B-2A90-495D-B4DC-76AEB444E487} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_207_pepper.exe [1452600 2019-06-12] (Adobe Inc. -> Adobe)
Task: {1E93BCE7-BD2A-4019-9A4B-ADB75993B921} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16571320 2019-05-09] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {243CCD86-4262-4134-B232-BE2AEEB96BF3} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2436936 2019-02-25] (Overwolf Ltd -> Overwolf LTD)
Task: {31F3689F-1A4F-4AFC-BAE3-99C86CBC057B} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
Task: {5D5EDA04-E0FB-4642-AE04-EA8CCD593393} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436160 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {825B6D18-ECD0-4AD1-846E-11A8F36CA566} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2934152 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
Task: {8EA5463D-2C87-4374-A0F6-42F9B04159C9} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1815792 2019-06-12] (AVAST Software s.r.o. -> AVAST Software)
Task: {9218510F-4FDD-4BCB-B865-A103938988BF} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [722880 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {96802597-A604-4EE3-81C4-184E03EC45F0} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1815792 2019-06-12] (AVAST Software s.r.o. -> AVAST Software)
Task: {96FE842B-D48F-42DE-82D7-DC36D97CAF54} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-06] (Dropbox, Inc -> Dropbox, Inc.)
Task: {977FCA72-427B-4804-9333-D1A5E9048750} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {A9860504-4D5B-4AB5-9BFF-6153C2B0A553} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-05] (Google Inc -> Google Inc.)
Task: {AE7BC221-405B-4A19-AC69-4815687F5909} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [722880 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B6A988BF-1534-4466-A8C1-8F5A2EDDC0AD} - System32\Tasks\{9DC78F9B-20D1-4516-91C3-51B055297F0A} => C:\Windows\system32\pcalua.exe -a C:\Users\acer\Downloads\half-life2_cestina101.exe -d C:\Users\acer\Downloads
Task: {BCE8E201-2DBA-4F18-AE34-8CA926B3CAE9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2017-04-05] (Google Inc -> Google Inc.)
Task: {DAC02F93-A57D-4A4E-81E8-246F492F73E6} - System32\Tasks\{26832B36-9323-4DD7-8A43-6993DBAEE770} => C:\Windows\system32\pcalua.exe -a E:\panel.exe -d E:\
Task: {E51ED642-6BE5-4165-AC18-6536972F7237} - System32\Tasks\Opera scheduled Autoupdate 1491467924 => C:\Program Files\Opera\launcher.exe [1519640 2019-07-03] (Opera Software AS -> Opera Software)
Task: {E8E2DEEB-D251-4F85-9CAD-C0BBE8357957} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [651200 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {ED8E65F2-0A47-4C2D-B7DC-D509AEF2097A} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [512960 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F018BCBE-A3D7-4D51-B7D3-6AED706DD647} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
Task: {F2D829DB-901D-4079-A7FD-3AE2D52B2942} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1540544 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FD21F86C-4A73-473C-B67A-D58683DA250A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [651200 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{69D3633B-A6DF-453D-80A4-0B37BE5F59D2}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{B1B36B7F-210F-4AB0-B17A-D858CE9FBFBA}: [DhcpNameServer] 192.168.2.1 10.100.0.100 10.10.10.10
Internet Explorer:
==================
HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.seznam.cz/SearchScopes: HKU\S-1-5-21-2847046601-3309215626-2780992325-1001 -> {82D3FCE6-8CBE-4E3E-8EB3-D7DC0F409534} URL =
hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 5ofe4kzi.default
FF ProfilePath: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\5ofe4kzi.default [2019-07-04]
FF Extension: (Seznam doplněk - Esko) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\5ofe4kzi.default\Extensions\sko-extension@firma.seznam.cz [2018-08-17]
FF Extension: (Avast SafePrice | Srovnání, výhodné nabídky, kupóny) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\5ofe4kzi.default\Extensions\sp@avast.com.xpi [2019-07-04]
FF Extension: (Avast Online Security) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\5ofe4kzi.default\Extensions\wrc@avast.com.xpi [2018-07-17]
FF Extension: (Seznam doplněk - Email) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\5ofe4kzi.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2018-08-17]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-03] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR StartupUrls: Default -> "hxxps://worldoftanks.eu/","hxxp://forum.worldoftanks.eu/index.php?/forum/455-forum/","hxxp://www.modxvm.com/en/"
CHR NewTab: Default -> Active:"chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/speeddial/newTab.html"
CHR Profile: C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default [2019-07-09]
CHR Extension: (Prezentace) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Dokumenty) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Disk Google) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-05]
CHR Extension: (Seznam doplněk - Email) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2019-02-16]
CHR Extension: (YouTube) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-05]
CHR Extension: (Tabulky) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Dokumenty Google offline) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Seznam doplněk - Esko) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2019-02-16]
CHR Extension: (Gmail) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-30]
CHR Extension: (Chrome Media Router) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-26]
CHR HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig] -
hxxps://clients2.google.com/service/update2/crxCHR HKU\S-1-5-21-2847046601-3309215626-2780992325-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olfeabkoenfaoljndfecamgilllcpiak] -
hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] -
hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] -
hxxps://clients2.google.com/service/update2/crxOpera:
=======
OPR Session Restore: -> is enabled.
OPR Extension: (BetterTTV) - C:\Users\acer\AppData\Roaming\Opera Software\Opera Stable\Extensions\deofbbdfofnmppcjbhjibgodpcdchjii [2017-10-23]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6844776 2019-05-28] (AVAST Software s.r.o. -> AVAST Software)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [File not signed]
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [409224 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-05] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\75.0.1447.80\elevation_service.exe [978720 2019-06-12] (AVAST Software s.r.o. -> AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-06] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-04-06] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51024 2019-06-24] (Dropbox, Inc -> Dropbox, Inc.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-02-07] (Disc Soft Ltd -> Disc Soft Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [791112 2019-05-30] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7172680 2019-03-20] (GOG Sp. z o.o. -> GOG.com)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-21] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2436936 2019-02-25] (Overwolf Ltd -> Overwolf LTD)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2018-01-24] (Even Balance, Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [37104 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [207448 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [262496 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [205848 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [61472 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [279120 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42288 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [168104 2019-06-24] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [112312 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [87944 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1030784 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [477584 2019-05-27] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [225600 2019-06-17] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [385880 2019-05-30] (AVAST Software s.r.o. -> AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros Communications, Inc.)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Broadcom Corporation -> Windows (R) Win 7 DDK provider)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Hewlett-Packard Company -> Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Hewlett-Packard Company -> Windows (R) Win 7 DDK provider)
S3 dot4usb; C:\Windows\system32\DRIVERS\dot4usb.sys [49056 2012-10-19] (Hewlett-Packard Company -> Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2017-04-07] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2017-04-07] (Disc Soft Ltd -> Disc Soft Ltd)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-07-08] (Malwarebytes Corporation -> Malwarebytes)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48064 2017-09-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [59448 2017-03-17] (NVIDIA Corporation -> NVIDIA Corporation)
S4 RAMDiskVE; C:\Windows\System32\Drivers\RAMDiskVE.sys [86680 2018-03-28] (Dataram Corporation -> Dataram, Inc.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [476888 2014-04-02] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42736 2014-07-10] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (NGO -> MBB)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 cpuz139; \??\C:\Users\acer\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [X] <==== ATTENTION
S3 dbx; system32\DRIVERS\dbx.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-07-09 10:43 - 2019-07-09 10:44 - 000032725 _____ C:\Users\acer\Desktop\FRST.txt
2019-07-09 10:42 - 2019-07-09 10:43 - 000000000 ____D C:\FRST
2019-07-09 10:42 - 2019-07-09 10:42 - 002420224 _____ (Farbar) C:\Users\acer\Downloads\FRST64.exe
2019-07-09 10:42 - 2019-07-09 10:42 - 002420224 _____ (Farbar) C:\Users\acer\Desktop\FRST64.exe
2019-07-08 18:11 - 2019-07-08 19:14 - 697506615 _____ C:\Users\acer\Downloads\Stranger Things S03E07 The Bite,720p, CZ titulky.mkv
2019-07-08 14:04 - 2019-07-08 14:04 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-07-06 11:25 - 2019-07-06 11:25 - 001859837 _____ C:\Users\acer\Downloads\15623525676974_france_F113_Bretagne_Panther_campania_big.wotreplay
2019-07-06 11:25 - 2019-07-06 11:25 - 001292008 _____ C:\Users\acer\Downloads\15621456216025_usa_A123_T78_redshire.wotreplay
2019-07-06 11:24 - 2019-07-06 11:24 - 001489278 _____ C:\Users\acer\Downloads\15622250236036_uk_GB11_Caernarvon_minsk.wotreplay
2019-07-03 18:24 - 2019-07-03 21:24 - 1580439741 _____ C:\Users\acer\Downloads\Pulp Fiction - Historky z podsvětí [CZ EN 1080p].mkv
2019-07-03 14:17 - 2019-07-03 14:17 - 000000000 ____D C:\Users\acer\AppData\Local\mbam
2019-07-03 14:16 - 2019-07-03 14:16 - 000001883 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-07-03 14:16 - 2019-07-03 14:16 - 000000000 ____D C:\Users\acer\AppData\Local\mbamtray
2019-07-03 14:16 - 2019-07-03 14:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-07-03 14:16 - 2019-07-03 14:16 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-03 14:16 - 2019-07-03 14:16 - 000000000 ____D C:\Program Files\Malwarebytes
2019-07-03 14:16 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-07-03 10:20 - 2019-07-03 12:02 - 1402898832 _____ C:\Users\acer\Downloads\Top.Gear.S27E03.720p.HDTV.x264-MTB.mkv
2019-07-02 15:30 - 2019-07-08 23:41 - 000000000 ____D C:\Users\Public\Documents\GTA Vice City User Files
2019-07-02 15:04 - 2019-07-02 15:28 - 000000000 ____D C:\Users\acer\Documents\GTA Vice City User Files
2019-07-02 15:03 - 2019-07-02 15:03 - 000001314 _____ C:\Users\acer\Desktop\GTA Vice City.lnk
2019-07-02 14:59 - 2019-07-02 14:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2019-07-02 14:58 - 2019-07-02 14:58 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2019-07-01 21:50 - 2019-07-01 21:50 - 000000000 ____D C:\ProgramData\Caphyon
2019-07-01 21:47 - 2019-07-01 21:47 - 000000000 ____D C:\Users\acer\AppData\Roaming\Rockstar Games
2019-06-28 09:52 - 2019-06-28 10:06 - 261089292 _____ C:\Users\acer\Downloads\iZombie.S05E09.HDTV.x264-SVA[ettv].mkv
2019-06-26 10:44 - 2019-06-26 10:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2019-06-24 18:39 - 2019-06-24 19:54 - 1278102926 _____ C:\Users\acer\Downloads\Top Gear s27e02.mkv
2019-06-24 14:12 - 2019-06-24 14:12 - 000051024 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2019-06-24 14:12 - 2019-06-24 14:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2019-06-24 14:12 - 2019-06-24 14:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2019-06-24 14:12 - 2019-06-24 14:12 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2019-06-22 11:43 - 2019-06-22 12:00 - 190962830 _____ C:\Users\acer\Downloads\iZombie.S05E08.720p.WEB.x265-MiNX.mkv
2019-06-21 10:46 - 2019-06-21 10:46 - 000000000 _____ C:\Users\acer\AppData\Local\{BC26B681-C5EF-45F0-AB6C-8B77C621F924}
2019-06-21 10:46 - 2019-06-21 10:46 - 000000000 _____ C:\Users\acer\AppData\Local\{B2396E2A-5BB0-4E68-B2F7-1EC1643F34C9}
2019-06-20 14:56 - 2019-06-20 14:56 - 000000000 ____D C:\Users\acer\Documents\Hitman Blood Money
2019-06-20 11:06 - 2019-06-20 11:06 - 000000220 _____ C:\Users\acer\Desktop\Hitman Blood Money.url
2019-06-18 09:22 - 2019-06-18 11:51 - 1770310715 _____ C:\Users\acer\Downloads\Top Gear s27e01.1080p.hdtv.h264-mtb.mp4
2019-06-17 10:59 - 2019-06-16 19:33 - 226633545 _____ C:\Users\acer\Downloads\iZombie.S05E06.iNTERNAL.720p.WEB-DL.x265-HETeam.mkv
2019-06-14 17:53 - 2019-06-14 18:07 - 252730495 _____ C:\Users\acer\Downloads\iZombie.S05E07.HDTV.x264-SVA[ettv].mkv
2019-06-12 12:36 - 2019-05-22 19:50 - 000098320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2019-06-12 12:36 - 2019-05-21 02:45 - 001494016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2019-06-12 12:36 - 2019-04-12 15:20 - 000914584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2019-06-12 12:35 - 2019-05-31 18:53 - 000394240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2019-06-12 12:35 - 2019-05-25 02:42 - 002297344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-06-12 12:35 - 2019-05-25 02:20 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2019-06-12 12:35 - 2019-05-25 02:16 - 000333312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-06-12 12:35 - 2019-05-25 02:15 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-06-12 12:35 - 2019-05-25 02:02 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-06-12 12:35 - 2019-05-25 01:59 - 001323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-06-12 12:35 - 2019-05-25 01:56 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-06-12 12:35 - 2019-05-21 02:47 - 001560064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2019-06-12 12:35 - 2019-05-17 06:07 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2019-06-12 12:35 - 2019-05-11 18:00 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-06-12 12:35 - 2019-05-10 15:20 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-06-12 12:35 - 2019-05-10 15:20 - 000353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-06-12 12:35 - 2019-05-10 15:20 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2019-06-12 12:35 - 2019-05-10 15:20 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2019-06-12 12:35 - 2019-05-09 07:47 - 002464256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2019-06-12 12:34 - 2019-05-25 03:59 - 019790160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2019-06-12 12:34 - 2019-05-25 03:56 - 000370872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2019-06-12 12:34 - 2019-05-25 03:56 - 000344984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2019-06-12 12:34 - 2019-05-25 03:07 - 020275712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-06-12 12:34 - 2019-05-25 02:45 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-06-12 12:34 - 2019-05-25 02:37 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-06-12 12:34 - 2019-05-25 02:23 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-06-12 12:34 - 2019-05-25 02:23 - 000128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2019-06-12 12:34 - 2019-05-25 02:23 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-06-12 12:34 - 2019-05-25 02:22 - 004492800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-06-12 12:34 - 2019-05-25 02:17 - 013706240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-06-12 12:34 - 2019-05-25 02:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-06-12 12:34 - 2019-05-25 02:15 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-06-12 12:34 - 2019-05-21 02:46 - 001085952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2019-06-12 12:34 - 2019-05-16 20:22 - 000334280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-06-12 12:34 - 2019-05-11 17:34 - 000697344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2019-06-12 12:34 - 2019-05-09 08:30 - 003619328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2019-06-12 12:28 - 2019-05-31 18:55 - 001265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2019-06-12 12:28 - 2019-05-31 18:54 - 000504832 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2019-06-12 12:28 - 2019-05-25 04:36 - 022373096 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2019-06-12 12:28 - 2019-05-25 03:20 - 000579584 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-06-12 12:28 - 2019-05-25 03:10 - 000790528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-06-12 12:28 - 2019-05-25 03:09 - 005776384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-06-12 12:28 - 2019-05-25 02:31 - 000963072 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-06-12 12:28 - 2019-05-25 02:19 - 000551152 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2019-06-12 12:28 - 2019-05-22 20:20 - 000120312 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2019-06-12 12:28 - 2019-05-21 02:49 - 001756160 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2019-06-12 12:28 - 2019-05-16 20:23 - 000444144 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-06-12 12:28 - 2019-05-14 16:01 - 004168704 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-06-12 12:28 - 2019-05-11 17:46 - 000840704 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2019-06-12 12:28 - 2019-04-25 00:38 - 002452208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-06-12 12:28 - 2019-04-12 15:20 - 000994384 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2019-06-12 12:28 - 2019-04-12 15:20 - 000064248 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2019-06-12 12:27 - 2019-05-25 03:42 - 025733632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-06-12 12:27 - 2019-05-25 03:22 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-06-12 12:27 - 2019-05-25 02:52 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-06-12 12:27 - 2019-05-25 02:50 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-06-12 12:27 - 2019-05-25 02:50 - 000145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2019-06-12 12:27 - 2019-05-25 02:45 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2019-06-12 12:27 - 2019-05-25 02:40 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-06-12 12:27 - 2019-05-25 02:38 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-06-12 12:27 - 2019-05-25 02:38 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-06-12 12:27 - 2019-05-25 02:38 - 000381440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-06-12 12:27 - 2019-05-25 02:34 - 015311872 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-06-12 12:27 - 2019-05-25 02:30 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-06-12 12:27 - 2019-05-25 02:05 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-06-12 12:27 - 2019-05-21 03:34 - 007362808 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-06-12 12:27 - 2019-05-11 17:50 - 001441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-06-12 12:27 - 2019-05-09 09:41 - 003325440 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-06-12 12:26 - 2019-05-25 04:30 - 000500464 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-06-12 12:26 - 2019-05-25 04:30 - 000394568 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-06-12 12:26 - 2019-05-25 04:30 - 000272184 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-06-12 12:26 - 2019-05-25 02:36 - 002136064 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-06-12 12:26 - 2019-05-25 02:17 - 001557504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-06-12 12:26 - 2019-05-25 02:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2019-06-12 12:26 - 2019-05-25 02:16 - 000911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-06-12 12:26 - 2019-05-21 03:42 - 001368592 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2019-06-12 12:26 - 2019-05-21 02:57 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-06-12 12:26 - 2019-05-21 02:50 - 001383424 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2019-06-12 12:26 - 2019-05-17 06:47 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-06-12 12:26 - 2019-05-14 22:23 - 000377800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2019-06-12 12:26 - 2019-05-11 18:21 - 000445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-06-12 12:26 - 2019-05-09 08:40 - 002779648 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2019-06-12 12:25 - 2019-05-03 15:51 - 000081920 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2019-06-12 12:25 - 2019-05-03 15:34 - 001202176 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-07-09 10:37 - 2018-04-28 19:14 - 000000000 ____D C:\Users\acer\AppData\Local\GameCenter
2019-07-09 10:35 - 2017-04-03 16:56 - 000003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2847046601-3309215626-2780992325-1001
2019-07-09 10:31 - 2017-04-06 12:41 - 000000000 ____D C:\Users\acer\AppData\Roaming\discord
2019-07-09 10:05 - 2017-04-05 08:40 - 000000000 ____D C:\ProgramData\NVIDIA
2019-07-08 23:42 - 2017-04-06 12:48 - 000000000 ____D C:\Program Files (x86)\Steam
2019-07-08 23:41 - 2017-11-17 16:44 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-07-08 23:41 - 2017-04-06 12:24 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2019-07-08 23:41 - 2017-04-06 12:12 - 000002788 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2019-07-08 23:41 - 2017-04-06 10:38 - 000003834 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1491467924
2019-07-08 23:41 - 2017-04-05 09:20 - 000003386 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-07-08 23:41 - 2017-04-05 09:20 - 000003258 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-08 23:41 - 2017-04-05 09:18 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-07-08 23:08 - 2017-04-06 12:24 - 000004168 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2019-07-08 21:58 - 2017-04-05 09:25 - 000000000 ____D C:\Users\acer\AppData\Local\ClassicShell
2019-07-08 21:04 - 2017-04-06 14:04 - 000000000 ____D C:\Users\acer\AppData\Roaming\TS3Client
2019-07-08 14:04 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-07-08 14:01 - 2017-04-06 12:00 - 000000000 ____D C:\Users\acer\AppData\Local\Battle.net
2019-07-08 13:05 - 2017-04-06 12:09 - 000000000 ____D C:\Users\acer\AppData\Local\Overwolf
2019-07-08 11:12 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\LiveKernelReports
2019-07-08 11:10 - 2019-01-28 12:40 - 000000000 _____ C:\Windows\system32\last.dump
2019-07-07 18:08 - 2014-11-21 06:53 - 001739092 _____ C:\Windows\system32\PerfStringBackup.INI
2019-07-07 18:08 - 2014-11-21 06:10 - 000734510 _____ C:\Windows\system32\perfh005.dat
2019-07-07 18:08 - 2014-11-21 06:10 - 000148820 _____ C:\Windows\system32\perfc005.dat
2019-07-07 18:08 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf
2019-07-07 11:31 - 2017-04-06 10:40 - 000000000 ____D C:\Users\acer\AppData\Local\CrashDumps
2019-07-05 14:59 - 2017-06-29 16:45 - 000001050 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2019-07-05 14:59 - 2017-04-06 10:38 - 000001050 _____ C:\Users\Public\Desktop\Prohlížeč Opera.lnk
2019-07-05 14:59 - 2017-04-06 10:37 - 000000000 ____D C:\Program Files\Opera
2019-07-04 19:19 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\AppReadiness
2019-07-04 16:29 - 2017-04-03 16:51 - 000000000 ____D C:\Users\acer
2019-07-04 16:06 - 2019-03-19 11:38 - 000000000 ____D C:\FFOutput
2019-07-04 15:57 - 2017-04-05 09:22 - 000000000 ____D C:\Users\acer\AppData\Roaming\vlc
2019-07-04 10:54 - 2017-04-06 10:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-07-04 10:43 - 2017-04-06 10:55 - 000000000 ____D C:\Users\acer\AppData\LocalLow\Mozilla
2019-07-04 10:42 - 2017-04-06 10:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-07-03 18:11 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI
2019-07-03 12:49 - 2017-04-06 12:04 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2019-07-03 10:51 - 2017-04-06 12:47 - 000000000 ____D C:\Users\acer\AppData\Roaming\DAEMON Tools Lite
2019-07-02 14:59 - 2017-04-05 08:45 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2019-07-02 12:00 - 2017-04-05 13:47 - 000000000 ____D C:\Games
2019-06-30 19:02 - 2017-04-06 11:57 - 000000000 ____D C:\Program Files (x86)\Blizzard App
2019-06-28 16:01 - 2019-04-17 18:41 - 000003732 _____ C:\Windows\System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2019-06-28 16:01 - 2019-04-17 18:41 - 000003150 _____ C:\Windows\System32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2019-06-28 16:01 - 2018-04-05 09:35 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2019-06-26 10:44 - 2017-04-06 12:34 - 000000000 ____D C:\Program Files (x86)\Dropbox
2019-06-24 14:41 - 2017-04-05 09:21 - 000002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-06-24 14:41 - 2017-04-05 09:21 - 000002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-06-24 14:26 - 2017-04-06 12:24 - 000168104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2019-06-20 11:06 - 2017-06-21 07:45 - 000000000 ____D C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2019-06-19 23:07 - 2017-04-07 07:50 - 000000000 ____D C:\Users\acer\Documents\My Games
2019-06-19 23:07 - 2017-04-06 12:57 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2019-06-19 23:06 - 2019-02-02 15:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2019-06-19 18:33 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\rescache
2019-06-19 12:14 - 2017-04-06 12:10 - 000000000 ____D C:\Program Files\TeamSpeak 3 Client
2019-06-19 12:09 - 2017-04-06 12:57 - 000000000 ____D C:\Users\acer\AppData\Local\Ubisoft Game Launcher
2019-06-17 15:07 - 2017-04-06 12:24 - 000225600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2019-06-17 12:12 - 2017-12-07 21:37 - 000000000 ____D C:\Users\acer\AppData\Roaming\Bioshock2Steam
2019-06-17 11:16 - 2017-04-06 10:35 - 000000000 ____D C:\Users\acer\Documents\VOŠ
2019-06-14 20:03 - 2013-08-22 16:44 - 000616120 _____ C:\Windows\system32\FNTCACHE.DAT
2019-06-14 19:58 - 2013-08-22 17:36 - 000000000 ___RD C:\Windows\ToastData
2019-06-14 19:57 - 2013-08-22 17:20 - 000000000 ____D C:\Windows\CbsTemp
2019-06-13 19:16 - 2017-04-05 09:18 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-06-13 06:41 - 2017-04-06 11:53 - 135349160 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-06-13 06:41 - 2017-04-06 11:53 - 000000000 ____D C:\Windows\system32\MRT
2019-06-12 10:08 - 2017-04-05 09:25 - 000000000 ____D C:\Users\acer\AppData\Local\Adobe
2019-06-12 10:06 - 2017-04-07 11:33 - 000004540 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-06-12 10:06 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2019-06-12 10:06 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\Macromed
2019-06-10 18:39 - 2017-04-11 19:22 - 000000000 ____D C:\Users\acer\AppData\Roaming\MusicBee
2019-06-09 22:34 - 2017-04-07 10:43 - 000000000 ____D C:\KMPlayer
==================== Files in the root of some directories ================
2019-06-21 10:46 - 2019-06-21 10:46 - 000000000 _____ () C:\Users\acer\AppData\Local\{B2396E2A-5BB0-4E68-B2F7-1EC1643F34C9}
2019-06-21 10:46 - 2019-06-21 10:46 - 000000000 _____ () C:\Users\acer\AppData\Local\{BC26B681-C5EF-45F0-AB6C-8B77C621F924}
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-07-02 16:19
==================== End of FRST.txt ============================