Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by TomikCR (administrator) on NOTEBOOK-TOMÁŠ (11-09-2016 14:49:32)
Running from C:\Users\TomikCR\Desktop
Loaded Profiles: TomikCR (Available Profiles: TomikCR & Administrator)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7573208 2014-04-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [653576 2015-06-29] (Hewlett-Packard Development Company, L.P.)
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\Run: [Power2GoExpress8] => C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1720584 2015-02-09] (CyberLink Corp.)
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [488640 2015-04-06] (AppEx Networks Corporation)
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {02d5e45b-4852-11e6-82c3-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {1cc9439c-a9f3-11e4-828b-1008b1bf986e} - "F:\LG_PC_Programs.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b299db7-35a0-11e6-82be-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b299e3d-35a0-11e6-82be-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {3b3586ed-7537-11e6-82d9-8cdcd48d65de} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {95275f61-179b-11e6-82bc-1008b1bf986d} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\...\MountPoints2: {95276210-179b-11e6-82bc-1008b1bf986d} - "F:\Lenovo_Suite.exe"
HKU\S-1-5-18\...\Run: [Advanced SystemCare 8] => "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
Tcpip\..\Interfaces\{CA7B9554-2C11-424B-BDEE-2333473482ED}: [DhcpNameServer] 94.74.192.252 94.74.192.244
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
www.google.comHKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
www.google.comHKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.google.comHKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
www.google.comHKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page =
hxxp://www.bing.com?pc=HPDTDFJSHKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhomeSearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1268798374-1140181337-1142225549-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
BHO: No Name -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-04-04] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
BHO-x32: Ukazatel S-Rank -> {EA837F48-5AD1-443E-AE34-FFE03CBF3099} -> C:\Program Files (x86)\Seznam.cz\core.2.dll [2010-05-19] ()
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-06-19] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-06-19] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin HKU\S-1-5-21-1268798374-1140181337-1142225549-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-23] ()
FF Extension: (No Name) - C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default\extensions\anttoolbar@ant.com [not found]
FF Extension: (No Name) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [not found]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2016-01-05]
FF Extension: (Video DownloadHelper) - C:\Users\TomikCR\AppData\Roaming\Mozilla\Firefox\Profiles\d1xemxoz.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-12-21]
FF HKLM-x32\...\Firefox\Extensions: [firefox@bho.com] - C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt
FF Extension: (HP SimplePass) - C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt [2015-06-17] [not signed]
Chrome:
=======
CHR HomePage: Default ->
hxxps://www.seznam.cz/CHR Profile: C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-09]
CHR Extension: (Disk Google) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-09]
CHR Extension: (YouTube) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-09]
CHR Extension: (Tabulky Google) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-09]
CHR Extension: (SiteAdvisor) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2016-09-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-09]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-09-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-09]
CHR Extension: (Gmail) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-09]
CHR Extension: (Chrome Media Router) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-09]
CHR Profile: C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-05]
CHR Extension: (Google Docs) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-05]
CHR Extension: (Google Drive) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-05]
CHR Extension: (YouTube) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-05]
CHR Extension: (Google Search) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-05]
CHR Extension: (Google Sheets) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-05]
CHR Extension: (Google Docs Offline) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-05]
CHR Extension: (Gmail) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-05]
CHR Profile: C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google Slides) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-05]
CHR Extension: (Google Docs) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-05]
CHR Extension: (Google Drive) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-05]
CHR Extension: (YouTube) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-05]
CHR Extension: (Google Search) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-05]
CHR Extension: (Google Sheets) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-05]
CHR Extension: (Google Docs Offline) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-05]
CHR Extension: (Gmail) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-05]
CHR Profile: C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3
CHR Extension: (Google Slides) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-05]
CHR Extension: (Google Docs) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-05]
CHR Extension: (Google Drive) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-05]
CHR Extension: (YouTube) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-05]
CHR Extension: (Google Search) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-05]
CHR Extension: (Google Sheets) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-05]
CHR Extension: (Google Docs Offline) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-05]
CHR Extension: (Gmail) - C:\Users\TomikCR\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-05]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] -
hxxp://clients2.google.com/service/update2/crxCHR HKU\S-1-5-21-1268798374-1140181337-1142225549-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] -
hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] -
hxxp://clients2.google.com/service/update2/crx==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
S3 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [98816 2014-10-11] () [File not signed]
R3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [29728 2016-08-15] (HP Inc.)
S3 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [602888 2015-06-29] (Hewlett-Packard Development Company, L.P.)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
S3 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [103424 2015-01-30] (Softex Inc.) [File not signed]
S3 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-10-28] ()
S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
S3 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2015-01-13] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 McAfee SiteAdvisor Service; "C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe" [X]
S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.2.3.2\WsAppService.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-03-28] (Google Inc)
S3 AndnetBus; C:\Windows\System32\drivers\lgandnetbus.sys [20992 2016-07-12] (LG Electronics Inc.)
S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [29184 2014-03-28] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [36352 2014-03-28] (LG Electronics Inc.)
S3 androidusb; C:\Windows\System32\Drivers\wsadb.sys [40720 2016-06-20] (Google Inc)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [102912 2015-07-15] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 ElRawDisk; C:\Windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-13] (REALiX(tm))
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [580824 2014-09-10] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3593432 2014-12-15] (Realtek Semiconductor Corporation )
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21360 2016-03-22] (IObit)
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] ()
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-09-09] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 cpuz138; \??\C:\Users\TomikCR\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X]
S3 mfesapsn; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [X]
S3 SmbDrv; \SystemRoot\system32\DRIVERS\Smb_driver_AMDASF.sys [X]
S3 SmbDrvI; \SystemRoot\System32\drivers\Smb_driver_Intel.sys [X]
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-11 14:49 - 2016-09-11 14:49 - 00020326 _____ C:\Users\TomikCR\Desktop\FRST.txt
2016-09-11 14:49 - 2016-09-11 14:49 - 00000000 ____D C:\FRST
2016-09-11 14:48 - 2016-09-11 14:48 - 02397696 _____ (Farbar) C:\Users\TomikCR\Desktop\FRST64.exe
2016-09-11 14:46 - 2016-09-11 14:46 - 00000000 ____D C:\Users\TomikCR\Desktop\backups
2016-09-10 23:24 - 2016-09-10 23:25 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\vlc
2016-09-10 23:24 - 2016-09-10 23:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-09-10 23:23 - 2016-09-10 23:23 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2016-09-10 23:21 - 2016-09-10 23:21 - 30533688 _____ C:\Users\TomikCR\Downloads\vlc-media-player_2.2.4.exe
2016-09-10 09:41 - 2016-09-10 09:41 - 00003188 _____ C:\Windows\System32\Tasks\HPCeeScheduleForTomikCR
2016-09-10 09:41 - 2016-09-10 09:41 - 00000370 _____ C:\Windows\Tasks\HPCeeScheduleForTomikCR.job
2016-09-09 23:23 - 2016-09-09 23:23 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\ProductData
2016-09-09 23:23 - 2016-09-09 23:23 - 00000000 ____D C:\ProgramData\ProductData
2016-09-09 23:21 - 2016-09-09 23:21 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-09-09 23:20 - 2016-09-09 23:20 - 00000000 ____D C:\Users\TomikCR\Downloads\RozboŔovaŔ
2016-09-09 23:20 - 2016-09-09 23:00 - 00024064 _____ C:\Windows\zoek-delete.exe
2016-09-09 23:02 - 2016-09-09 23:56 - 00000000 ____D C:\Users\TomikCR\AppData\Local\CrashDumps
2016-09-09 22:56 - 2016-09-09 23:18 - 00000000 ____D C:\zoek_backup
2016-09-09 22:54 - 2016-09-09 22:54 - 01309184 _____ C:\Users\TomikCR\Desktop\zoek.exe
2016-09-09 22:32 - 2016-09-09 22:32 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-09-06 23:47 - 2016-09-06 23:46 - 00830824 _____ C:\Users\TomikCR\Downloads\PowerPoint Document
2016-09-06 23:47 - 2016-09-06 23:46 - 00058080 _____ C:\Users\TomikCR\Downloads\[5]SummaryInformation
2016-09-06 23:47 - 2016-09-06 23:46 - 00004096 _____ C:\Users\TomikCR\Downloads\Current User
2016-09-06 23:47 - 2016-09-06 23:46 - 00004096 _____ C:\Users\TomikCR\Downloads\[5]DocumentSummaryInformation
2016-09-06 23:46 - 2016-09-06 23:46 - 03378688 _____ C:\Users\TomikCR\Downloads\Foto_s.pps
2016-09-04 14:48 - 2016-09-04 14:48 - 00000000 ____D C:\ProgramData\RogueKiller
2016-09-04 14:43 - 2016-09-04 14:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
2016-09-04 14:41 - 2016-09-04 14:45 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\Andy
2016-09-04 14:41 - 2016-09-04 14:41 - 00000000 ____D C:\Users\TomikCR\Andy
2016-09-04 13:56 - 2016-09-04 13:56 - 25124424 _____ C:\Users\TomikCR\Desktop\RogueKillerX64.exe
2016-09-04 12:23 - 2016-09-04 12:23 - 00002735 _____ C:\Users\TomikCR\Desktop\JRT.txt
2016-09-04 12:17 - 2016-09-04 12:18 - 01610560 _____ (Malwarebytes) C:\Users\TomikCR\Downloads\JRT.exe
2016-09-03 22:38 - 2016-09-03 22:38 - 00497836 _____ C:\Users\TomikCR\Downloads\diary_conversations (1).html
2016-09-03 22:37 - 2016-09-03 22:37 - 00030346 _____ C:\Users\TomikCR\Downloads\diary_statistics.html
2016-09-03 22:37 - 2016-09-03 22:37 - 00022194 _____ C:\Users\TomikCR\Downloads\diary_conversations.html
2016-09-03 00:58 - 2016-09-03 00:59 - 00000000 ____D C:\Users\TomikCR\Downloads\SPU
2016-09-03 00:12 - 2016-09-03 00:12 - 02139840 _____ (BitTorrent Inc.) C:\Users\TomikCR\Downloads\uTorrent.exe
2016-09-02 20:07 - 2016-09-09 23:56 - 00000000 ____D C:\KMPlayer
2016-09-02 20:04 - 2016-09-02 20:04 - 37232728 _____ (PandoraTV) C:\Users\TomikCR\Downloads\KMPlayer_4.1.2.2.exe
2016-09-02 20:02 - 2016-09-02 18:33 - 207549925 ____N C:\Users\TomikCR\Desktop\VID_20160902_183326.mp4
2016-09-02 20:02 - 2016-09-02 18:31 - 122786297 ____N C:\Users\TomikCR\Desktop\VID_20160902_183148.mp4
2016-09-01 23:45 - 2016-09-01 23:45 - 01028807 _____ C:\Users\TomikCR\Documents\Kniha - Zuzana Látalová.odt
2016-08-31 22:08 - 2016-09-10 23:22 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-08-31 22:08 - 2016-08-31 22:08 - 00001141 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-31 22:08 - 2016-08-31 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-31 22:08 - 2016-08-31 22:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-08-31 22:08 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-08-31 22:08 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-08-31 22:08 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-08-31 22:07 - 2016-08-31 22:07 - 22851472 _____ (Malwarebytes ) C:\Users\TomikCR\Downloads\mbam-setup-2.2.1.1043.exe
2016-08-31 21:55 - 2016-09-07 22:21 - 00000000 ____D C:\AdwCleaner
2016-08-31 21:53 - 2016-08-31 21:53 - 03826240 _____ C:\Users\TomikCR\Desktop\adwcleaner_6.010.exe
2016-08-31 20:11 - 2016-08-31 20:11 - 00001197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk
2016-08-31 20:11 - 2016-08-31 20:11 - 00001182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk
2016-08-31 20:11 - 2016-08-31 20:11 - 00001170 _____ C:\Users\Public\Desktop\Security Task Manager.lnk
2016-08-31 20:11 - 2016-08-31 20:11 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2016-08-31 19:37 - 2016-08-31 19:37 - 00000000 ____D C:\Users\TomikCR\Downloads\backups
2016-08-31 19:32 - 2016-08-31 19:32 - 00388608 _____ (Trend Micro Inc.) C:\Users\TomikCR\Desktop\HijackThis.exe
2016-08-31 18:56 - 2016-08-31 18:56 - 00007604 _____ C:\Users\TomikCR\AppData\Local\Resmon.ResmonCfg
2016-08-30 21:49 - 2016-08-30 21:49 - 00003308 _____ C:\Windows\System32\Tasks\{9D8EF746-B721-44F5-A499-74337197D5DB}
2016-08-30 19:57 - 2016-08-30 19:57 - 00000000 _____ C:\ProgramData\LauncherAccess.dt
2016-08-30 19:55 - 2016-08-30 19:55 - 00000000 ____D C:\Windows\SysWOW64\Samsung_USB_Drivers
2016-08-30 19:54 - 2016-08-30 23:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung PC Studio 3
2016-08-30 19:54 - 2006-07-24 16:05 - 00005632 _____ C:\Windows\SysWOW64\Drivers\StarOpen.sys
2016-08-30 18:26 - 2016-08-30 18:26 - 00000000 ____D C:\Users\TomikCR\AppData\Local\ElevatedDiagnostics
2016-08-30 18:18 - 2016-08-30 18:18 - 07445856 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-08-30 18:18 - 2016-08-30 18:18 - 03547136 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 02897920 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 02539008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 01661064 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 01212248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 01080320 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2016-08-30 18:18 - 2016-08-30 18:18 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00675328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-08-30 18:18 - 2016-08-30 18:18 - 00657920 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-08-30 18:18 - 2016-08-30 18:18 - 00377344 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2016-08-30 18:18 - 2016-08-30 18:18 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00272896 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-08-30 18:18 - 2016-08-30 18:18 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00197352 _____ (Microsoft Corporation) C:\Windows\system32\dssenh.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasppp.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\rasman.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00157016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dssenh.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasman.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-08-30 18:18 - 2016-08-30 18:18 - 00101208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2016-08-30 18:18 - 2016-08-30 18:18 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys
2016-08-30 18:18 - 2016-08-30 18:18 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2016-08-30 18:00 - 2016-08-30 18:00 - 00003188 _____ C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze
2016-08-30 18:00 - 2016-08-30 18:00 - 00003034 _____ C:\Windows\System32\Tasks\SmartDefrag_Update
2016-08-30 18:00 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
2016-08-30 18:00 - 2016-03-22 11:02 - 00021360 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2016-08-30 00:59 - 2016-06-18 22:06 - 00590688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2016-08-30 00:59 - 2016-06-18 22:06 - 00072408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpfve.sys
2016-08-30 00:59 - 2016-06-11 21:52 - 00379232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2016-08-30 00:59 - 2016-06-11 21:52 - 00057184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2016-08-30 00:59 - 2016-06-11 20:05 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe
2016-08-30 00:59 - 2016-06-11 19:14 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpresult.exe
2016-08-30 00:59 - 2016-06-11 18:50 - 00987136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-30 00:59 - 2016-06-11 18:46 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\tpmvsc.dll
2016-08-30 00:59 - 2016-06-11 18:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2016-08-30 00:59 - 2016-06-11 18:37 - 00796672 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-08-30 00:59 - 2016-06-11 18:24 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-30 00:59 - 2016-06-11 18:20 - 00413184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2016-08-30 00:59 - 2016-06-11 18:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2016-08-30 00:59 - 2016-06-11 05:44 - 00107984 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2016-08-30 00:59 - 2016-06-11 05:44 - 00091416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2016-08-30 00:59 - 2016-06-10 22:07 - 03820544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2016-08-30 00:59 - 2016-06-10 22:03 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-08-30 00:59 - 2016-06-10 20:11 - 06521800 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2016-08-30 00:59 - 2016-06-10 20:11 - 01487992 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-08-30 00:59 - 2016-06-10 20:11 - 00261376 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-08-30 00:59 - 2016-06-10 20:11 - 00125024 _____ (Microsoft Corporation) C:\Windows\system32\cryptxml.dll
2016-08-30 00:59 - 2016-06-10 20:10 - 00099136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptxml.dll
2016-08-30 00:59 - 2016-06-10 20:07 - 03273728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2016-08-30 00:59 - 2016-06-10 20:04 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-08-30 00:59 - 2016-06-09 21:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2016-08-30 00:59 - 2016-06-09 20:18 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2016-08-30 00:59 - 2016-06-07 20:10 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2016-08-30 00:59 - 2016-06-07 19:13 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hbaapi.dll
2016-08-30 00:59 - 2016-06-04 02:38 - 01613528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2016-08-30 00:59 - 2016-06-04 02:37 - 01970968 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-08-30 00:58 - 2016-08-02 08:54 - 25808384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-30 00:58 - 2016-08-02 08:32 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-30 00:58 - 2016-08-02 08:31 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-08-30 00:58 - 2016-08-02 08:20 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-08-30 00:58 - 2016-08-02 08:18 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-30 00:58 - 2016-08-02 08:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-08-30 00:58 - 2016-08-02 07:55 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-08-30 00:58 - 2016-08-02 07:54 - 20343808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-30 00:58 - 2016-08-02 07:51 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-08-30 00:58 - 2016-08-02 07:47 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-30 00:58 - 2016-08-02 07:46 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-08-30 00:58 - 2016-08-02 07:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-08-30 00:58 - 2016-08-02 07:40 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-08-30 00:58 - 2016-08-02 07:39 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-30 00:58 - 2016-08-02 07:38 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-30 00:58 - 2016-08-02 07:38 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-30 00:58 - 2016-08-02 07:36 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-30 00:58 - 2016-08-02 07:28 - 15412224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-30 00:58 - 2016-08-02 07:23 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-30 00:58 - 2016-08-02 07:21 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-30 00:58 - 2016-08-02 07:20 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-08-30 00:58 - 2016-08-02 07:15 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-30 00:58 - 2016-08-02 07:15 - 00330752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-30 00:58 - 2016-08-02 07:14 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-30 00:58 - 2016-08-02 07:11 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-30 00:58 - 2016-08-02 07:10 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-30 00:58 - 2016-08-02 06:59 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-30 00:58 - 2016-08-02 06:56 - 02393088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-30 00:58 - 2016-08-02 06:53 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-30 00:58 - 2016-08-02 06:51 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-30 00:58 - 2016-07-08 16:18 - 04169216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-08-30 00:57 - 2016-07-12 16:08 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2016-08-30 00:57 - 2016-07-09 02:09 - 00442712 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-08-30 00:57 - 2016-07-09 02:08 - 00332632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-08-30 00:57 - 2016-07-08 16:32 - 01753600 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-08-30 00:57 - 2016-07-08 16:25 - 01491456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2016-08-30 00:57 - 2016-07-08 16:22 - 01445376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-30 00:57 - 2016-07-08 16:19 - 00840704 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2016-08-30 00:57 - 2016-07-08 16:17 - 00696832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2016-08-30 00:57 - 2016-07-08 00:33 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-08-30 00:57 - 2016-07-07 23:53 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-08-30 00:57 - 2016-07-07 22:06 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-08-30 00:57 - 2016-07-06 16:26 - 07793152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-30 00:57 - 2016-07-06 16:26 - 07075328 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2016-08-30 00:57 - 2016-07-06 16:23 - 05270016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2016-08-30 00:57 - 2016-07-06 16:21 - 05265920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2016-08-30 00:54 - 2016-08-30 00:54 - 00000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2016-08-29 23:04 - 2016-09-03 19:10 - 00000000 ____D C:\Users\TomikCR\Desktop\složky plocha
2016-08-29 22:24 - 2016-08-30 00:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-08-29 21:05 - 2016-08-29 21:05 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\Apowersoft
2016-08-29 14:27 - 2016-08-29 14:27 - 00006769 _____ C:\Users\TomikCR\settings.dat
2016-08-29 14:27 - 2016-08-29 14:27 - 00004040 _____ C:\Users\TomikCR\dht.dat
2016-08-29 14:27 - 2016-08-29 14:27 - 00001020 _____ C:\Users\TomikCR\resume.dat
2016-08-29 14:27 - 2016-08-29 14:27 - 00000099 _____ C:\Users\TomikCR\rss.dat
2016-08-29 01:23 - 2016-08-29 01:23 - 00000000 ____D C:\Users\TomikCR\dlimagecache
2016-08-29 01:17 - 2016-08-29 01:17 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\.Torrent Swapper
2016-08-29 00:59 - 2016-08-29 22:09 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\DAEMON Tools Lite
2016-08-29 00:59 - 2016-08-29 00:59 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2016-08-29 00:57 - 2016-08-29 00:57 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-08-29 00:46 - 2015-04-25 20:30 - 00189387 _____ C:\Users\TomikCR\utorrent-221-25534.chm
2016-08-29 00:46 - 2015-04-25 20:30 - 00184512 _____ C:\Users\TomikCR\webui.zip
2016-08-29 00:46 - 2015-04-25 20:30 - 00039237 _____ C:\Users\TomikCR\utorrent.lng
2016-08-29 00:46 - 2015-04-25 20:30 - 00027702 _____ C:\Users\TomikCR\toolbar.bmp
2016-08-29 00:46 - 2015-04-25 20:30 - 00006026 _____ C:\Users\TomikCR\current.btskin
2016-08-29 00:46 - 2015-04-25 20:30 - 00000049 _____ C:\Users\TomikCR\utorrent.url
2016-08-29 00:35 - 2016-08-30 00:29 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\uTorrent
2016-08-29 00:35 - 2016-08-29 22:07 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\uTorrent
2016-08-29 00:15 - 2016-08-29 22:16 - 00000000 ____D C:\Users\TomikCR\Downloads\smetí
2016-08-29 00:01 - 2016-08-29 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Swapper
2016-08-29 00:01 - 2016-08-29 00:01 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\.Torrent Swapper
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-11 14:07 - 2016-07-29 19:02 - 00000990 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-11 11:44 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2016-09-11 11:18 - 2014-10-27 18:12 - 00004002 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{901E4CFD-6533-4966-B96F-CB91F4CEC206}
2016-09-10 11:18 - 2014-10-27 15:46 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1268798374-1140181337-1142225549-1002
2016-09-10 11:01 - 2014-10-27 21:05 - 00000000 ____D C:\Program Files (x86)\IObit
2016-09-09 23:25 - 2014-07-15 03:25 - 00768392 _____ C:\Windows\system32\perfh005.dat
2016-09-09 23:25 - 2014-07-15 03:25 - 00166490 _____ C:\Windows\system32\perfc005.dat
2016-09-09 23:25 - 2014-03-18 11:53 - 01883040 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-09 23:25 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf
2016-09-09 23:23 - 2014-10-27 15:42 - 00000000 ____D C:\Users\TomikCR\Documents\Youcam
2016-09-09 23:22 - 2016-07-29 19:02 - 00000986 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-09 23:21 - 2014-10-07 07:08 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2016-09-09 23:21 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-09 23:21 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-09-09 23:16 - 2016-02-18 08:29 - 00000000 ____D C:\Users\Administrator
2016-09-09 23:16 - 2014-10-27 15:40 - 00000000 ____D C:\Users\TomikCR
2016-09-09 23:16 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\GroupPolicy
2016-09-09 23:02 - 2014-11-20 20:57 - 06270464 ___SH C:\Users\TomikCR\Desktop\Thumbs.db
2016-09-08 22:50 - 2015-01-19 22:38 - 00002244 ____H C:\Users\TomikCR\Documents\Default.rdp
2016-09-08 22:49 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\FxsTmp
2016-09-04 14:43 - 2014-04-03 01:13 - 01910006 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-09-04 12:21 - 2014-10-27 21:06 - 00000000 ____D C:\ProgramData\IObit
2016-09-04 12:21 - 2014-10-27 21:04 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\IObit
2016-09-02 20:07 - 2014-10-31 22:06 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2016-09-01 23:45 - 2015-01-17 00:34 - 00103424 ___SH C:\Users\TomikCR\Documents\Thumbs.db
2016-08-31 21:25 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2016-08-31 20:59 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2016-08-31 19:30 - 2015-01-17 17:58 - 00000000 ____D C:\Users\TomikCR\Documents\Záloha CCleaner
2016-08-31 19:06 - 2014-10-27 15:40 - 00000000 ____D C:\Users\TomikCR\AppData\Local\Packages
2016-08-30 23:13 - 2014-07-14 18:53 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-08-30 22:10 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-30 21:57 - 2013-08-22 16:44 - 00382424 _____ C:\Windows\system32\FNTCACHE.DAT
2016-08-30 21:56 - 2016-06-26 15:36 - 68968448 _____ C:\Windows\system32\config\components.iodefrag.bak
2016-08-30 21:56 - 2015-01-14 20:27 - 86257664 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak
2016-08-30 21:56 - 2015-01-14 20:27 - 00327680 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak
2016-08-30 21:56 - 2015-01-14 20:27 - 00069632 _____ C:\Windows\system32\config\SAM.iodefrag.bak
2016-08-30 21:56 - 2015-01-14 20:27 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak
2016-08-30 21:54 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\setup
2016-08-30 21:54 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\setup
2016-08-30 21:39 - 2015-09-15 23:12 - 00000000 ____D C:\Users\TomikCR\Downloads\Rozbočovač
2016-08-30 19:59 - 2014-10-27 15:40 - 00000000 ____D C:\Users\TomikCR\AppData\Local\VirtualStore
2016-08-30 18:00 - 2016-05-06 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2016-08-30 17:59 - 2014-10-07 07:19 - 00000000 ____D C:\ProgramData\McAfee
2016-08-30 01:13 - 2014-10-28 18:34 - 00000000 ____D C:\Windows\system32\MRT
2016-08-30 01:13 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2016-08-30 01:07 - 2014-10-28 18:34 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-30 01:04 - 2016-06-25 21:02 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2016-08-30 01:04 - 2015-10-29 21:12 - 00000000 ____D C:\Program Files (x86)\GameforgeLive
2016-08-30 01:00 - 2016-02-18 08:35 - 00000000 ____D C:\Users\Administrator\Documents\Youcam
2016-08-30 00:30 - 2016-07-18 21:16 - 00000000 ____D C:\Users\TomikCR\Downloads\roztřídit balast
2016-08-30 00:30 - 2016-06-20 22:11 - 00000000 ____D C:\Users\TomikCR\Downloads\obnovovače
2016-08-30 00:30 - 2016-02-10 00:33 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2016-08-30 00:30 - 2016-01-30 19:54 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-30 00:30 - 2015-11-30 00:24 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicosmosTools
2016-08-30 00:30 - 2015-04-04 21:00 - 00000000 ___SD C:\Windows\system32\GWX
2016-08-30 00:30 - 2015-03-07 00:29 - 00000000 ____D C:\Program Files (x86)\Steam
2016-08-30 00:30 - 2015-01-17 17:56 - 00000000 ____D C:\Program Files\CCleaner
2016-08-30 00:30 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\WinMetadata
2016-08-30 00:29 - 2016-02-18 13:05 - 00000000 ____D C:\Users\Administrator\AppData\LocalLow\IObit
2016-08-30 00:29 - 2014-11-16 21:38 - 00000000 ____D C:\Users\TomikCR\AppData\Roaming\AIMP3
2016-08-30 00:29 - 2014-10-27 21:06 - 00000000 ____D C:\Users\TomikCR\AppData\LocalLow\IObit
2016-08-30 00:29 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\ADFS
2016-08-30 00:29 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Windows Defender
2016-08-30 00:29 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\system32\Sysprep
2016-08-30 00:19 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\registration
2016-08-30 00:16 - 2016-02-18 08:29 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\IObit
2016-08-30 00:16 - 2014-10-27 21:27 - 00000000 ____D C:\Users\TomikCR\AppData\Local\Google
==================== Files in the root of some directories =======
2015-12-12 21:41 - 2016-05-07 15:57 - 0003584 _____ () C:\Users\TomikCR\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-08-31 18:56 - 2016-08-31 18:56 - 0007604 _____ () C:\Users\TomikCR\AppData\Local\Resmon.ResmonCfg
2016-07-13 19:40 - 2016-07-13 19:40 - 0000173 _____ () C:\Users\TomikCR\AppData\Local\uts.ini
2016-08-30 19:57 - 2016-08-30 19:57 - 0000000 _____ () C:\ProgramData\LauncherAccess.dt
Files to move or delete:
====================
C:\Users\TomikCR\dht.dat
C:\Users\TomikCR\resume.dat
C:\Users\TomikCR\rss.dat
C:\Users\TomikCR\settings.dat
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-09-09 19:47
==================== End of FRST.txt ============================