Kontrola počítače [Zpomalený chod systému] - 31.01.2018 Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 14:13

Sophos nic nenašel, jdu na Zemana.

Reklama
Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 14:25

Zemana AntiMalware 2.74.2.150 (instalační verze)

-------------------------------------------------------
Scan Result : Dokončeno
Scan Date : 2018.2.2
Operating System : Windows 10 64-bit
Processor : 4X Intel(R) Core(TM) i3-6100U CPU @ 2.30GHz
BIOS Mode : UEFI
CUID : 12C4AD77F1F895A3D58274
Scan Type : Skenování systému
Duration : 8m 37s
Scanned Objects : 63307
Detected Objects : 0
Excluded Objects : 0
Read Level : SCSI
Auto Upload : Zapnuto
Detect All Extensions : Vypnuto
Scan Documents : Vypnuto
Domain Info : WORKGROUP,0,2

Detected Objects
-------------------------------------------------------

Nebyly zjištěny žádné hrozby

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 14:27

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:26:36, on 02.02.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.16299.0015)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\Conexant\SAII\SmartAudio.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avpui.exe
C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
C:\Users\derka\OneDrive\Plocha\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Windscribe] "C:\Program Files (x86)\Windscribe\Windscribe.exe" -os_restart
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Spotify Web Helper] C:\Users\derka\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\Windows\system32\AdminService.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 18.0.0 (AVP18.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\IntelCpHDCPSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: CxUtilSvc - Conexant Systems, Inc. - C:\Program Files\Conexant\SAII\CxUtilSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\igfxCUIService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: klvssbridge64_18.0.0 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\vssbridge64.exe
O23 - Service: Služba Kaspersky Secure Connection 2.0.0 (KSDE2.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Unknown owner - C:\Windows\system32\SAsrv.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)
O23 - Service: ZAM Controller Service (ZAMSvc) - Copyright 2017. - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe

--
End of file - 9338 bytes

Minimální změna jde vidět.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod jaro3 » 02 úno 2018 18:39

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=



Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.

Stáhni si Memtest:

Políčko , ve kterém je napsáno:
All unused RAM , změň na 2048.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".

Ještě zkontrolovat HDD na chyby ,popř. zkusit jeho defragmentaci ..

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 19:26

Při ASWMBR dostanu BSOD. (vyzkoušeno 5x)

----------------------------------------------------------------------------
CrystalDiskInfo 7.5.1 (C) 2008-2018 hiyohiyo
Crystal Dew World : https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 16299] (x64)
Date : 2018/02/02 19:25:17

-- Controller Map ----------------------------------------------------------
+ Standardní řadič SATA AHCI [ATA]
- WDC WD10JPCX-24UE4T0
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) WDC WD10JPCX-24UE4T0 : 1000,2 GB [0/0/0, pd1] - wd

----------------------------------------------------------------------------
(1) WDC WD10JPCX-24UE4T0
----------------------------------------------------------------------------
Model : WDC WD10JPCX-24UE4T0
Firmware : 01.01A01
Serial Number : WD-WXV1E265XTVA
Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2)
Buffer Size : 16384 KB
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ACS-2
Minor Version : ----
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 1781 hod.
Power On Count : 436 krát
Temperature : 35 C (95 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0060h [ON]
AAM Level : ----
Drive Letter : C:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 182 178 _21 00000000075B Čas na roztočení ploten
04 _95 _95 __0 000000001679 Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 _51 000000000000 Počet chybných hledání
09 _98 _98 __0 0000000006F5 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C 100 100 __0 0000000001B4 Počet cyklů zapnutí zařízení
C0 200 200 __0 000000000013 Počet vypnutí disku
C1 193 193 __0 000000005B77 Počet cyklů načítání/vymazání
C2 112 105 __0 000000000023 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů
F0 _98 _98 __0 0000000006B4 Čas nastavování hlaviček - v hodinách

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 5631 4532 3635 5854 5641
020: 0000 8000 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3130 4A50 4358 2D32 3455 4534 5430 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F FF0E 0006 004C 0040
080: 03FE 0000 346B 7D29 6123 3469 BC09 6123 407F 005D
090: 005D 0060 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5001 4EE6
110: B199 75CC 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0400
130: 0001 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 C6A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 B6 B2 5B 07 00 00 00 00 00 04 32 00 5F 5F 79
020: 16 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2F 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 62 62 F5 06 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 64 64 B4 01 00 00 00 00 00 C0 32
070: 00 C8 C8 13 00 00 00 00 00 00 C1 32 00 C1 C1 77
080: 5B 00 00 00 00 00 C2 22 00 70 69 23 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 64 FD 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 64 FD 00 00 00 00 00 00 00 F0 32
0D0: 00 62 62 B4 06 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 34 44 01 7B
170: 03 00 01 00 02 C3 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2C

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 33 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 00 00 00 00 00 00 00 00 00 00 F0 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5A

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod jaro3 » 02 úno 2018 21:33

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 22:34

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by derka (administrator) on DESKTOP-6B9SVO9 (02-02-2018 22:30:44)
Running from C:\Users\derka\OneDrive\Plocha
Loaded Profiles: derka (Available Profiles: derka)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\igfxCUIService.exe
(Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SAII\CxUtilSvc.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\IntelCpHDCPSvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\IntelCpHeciSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\igfxEM.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avpui.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [602968 2015-12-07] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [849920 2017-03-07] (Dolby Laboratories, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1831768 2016-08-29] (Conexant Systems, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-26] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems, Incorporated)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3111712 2017-12-15] (Valve Corporation)
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\Run: [Windscribe] => "C:\Program Files (x86)\Windscribe\Windscribe.exe" -os_restart
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10257872 2018-01-09] (Piriform Ltd)
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\Run: [Spotify Web Helper] => C:\Users\derka\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-01-31] (Spotify Ltd)
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\MountPoints2: {6fc3533c-f242-11e7-904b-ccb0daa7f7de} - "D:\Lenovo_Suite.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5498f1ea-e01e-4c65-9d20-ccfe510227a1}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================

FireFox:
========
FF DefaultProfile: y03ytv3f.default-1515609822354
FF ProfilePath: C:\Users\derka\AppData\Roaming\Mozilla\Firefox\Profiles\y03ytv3f.default-1515609822354 [2018-02-02]
FF Homepage: Mozilla\Firefox\Profiles\y03ytv3f.default-1515609822354 -> about:home
FF NewTab: Mozilla\Firefox\Profiles\y03ytv3f.default-1515609822354 -> about:newtab
FF Extension: (Hoxx VPN Proxy) - C:\Users\derka\AppData\Roaming\Mozilla\Firefox\Profiles\y03ytv3f.default-1515609822354\Extensions\@hoxx-vpn.xpi [2018-01-12]
FF Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\derka\AppData\Roaming\Mozilla\Firefox\Profiles\y03ytv3f.default-1515609822354\Extensions\@setupvpncom.xpi [2018-01-18]
FF Extension: (uBlock Origin) - C:\Users\derka\AppData\Roaming\Mozilla\Firefox\Profiles\y03ytv3f.default-1515609822354\Extensions\uBlock0@raymondhill.net.xpi [2018-01-13]
FF HKLM\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Ochrana Kaspersky) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\FFExt\light_plugin_firefox\addon.xpi [2018-01-31]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-20] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)

Chrome:
=======
CHR Profile: C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default [2018-02-02]
CHR Extension: (Prezentace) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-02]
CHR Extension: (Dokumenty) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-02]
CHR Extension: (Disk Google) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-02]
CHR Extension: (YouTube) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-02]
CHR Extension: (Tabulky) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-02]
CHR Extension: (Dokumenty Google offline) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-02]
CHR Extension: (Ochrana Kaspersky) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchjnmdbdlkdbfliogedbnpnanfjnolk [2018-02-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-02]
CHR Extension: (Gmail) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-02]
CHR Extension: (Chrome Media Router) - C:\Users\derka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-02]
CHR HKLM\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/deta ... pnanfjnolk
CHR HKLM-x32\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/deta ... pnanfjnolk

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
R2 AVP18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe [354672 2017-01-24] (AO Kaspersky Lab)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-11-26] ()
R2 CxUtilSvc; C:\Program Files\Conexant\SAII\CxUtilSvc.exe [132096 2016-05-12] (Conexant Systems, Inc.) [File not signed]
R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [194048 2017-03-07] (Dolby Laboratories, Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [134872 2017-04-12] (ELAN Microelectronics Corp.)
S3 klvssbridge64_18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\vssbridge64.exe [426416 2018-01-31] (AO Kaspersky Lab)
S3 KSDE2.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe [354672 2017-01-24] (AO Kaspersky Lab)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519992 2018-01-10] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519992 2018-01-10] (NVIDIA Corporation)
R2 SAService; C:\Windows\system32\SAsrv.exe [431960 2015-09-15] (Conexant Systems, Inc.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-20] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-20] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 22:35

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [605608 2017-01-18] (Qualcomm)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [247008 2016-12-26] (AO Kaspersky Lab)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [32328 2017-04-12] (ELAN Microelectronic Corp.)
R0 FACEIT; C:\Windows\System32\Drivers\FACEIT.sys [9143248 2018-01-21] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554408 2016-10-01] (AO Kaspersky Lab)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [70880 2017-12-25] (AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [117984 2017-12-25] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29816 2016-10-14] (AO Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [207576 2018-01-31] (AO Kaspersky Lab)
R1 KLHK; C:\Windows\System32\drivers\klhk.sys [594144 2018-01-31] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1055424 2018-01-31] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [57424 2016-10-12] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [57056 2016-12-23] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [58592 2016-12-07] (AO Kaspersky Lab)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [50672 2017-12-25] (AO Kaspersky Lab)
R3 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [44768 2017-01-20] (AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [230280 2018-02-01] (AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [87584 2018-01-31] (AO Kaspersky Lab)
R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [253192 2018-01-31] (AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [107680 2018-01-31] (AO Kaspersky Lab)
R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [173664 2018-01-31] (AO Kaspersky Lab)
S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [93920 2016-12-20] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [135904 2017-12-25] (AO Kaspersky Lab)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [199392 2017-12-25] (AO Kaspersky Lab)
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_706cb08068861f25\nvlddmkm.sys [17493824 2018-01-24] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31024 2018-01-10] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [59240 2017-12-15] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57928 2018-01-24] (NVIDIA Corporation)
S3 qcusbnet; C:\Windows\System32\drivers\qcusbnet.sys [428600 2017-03-15] (QUALCOMM Incorporated)
S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMM Incorporated)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [427520 2016-11-16] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3150336 2017-01-19] (Realtek Semiconductor Corp.)
S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [41512 2018-01-11] ()
S3 tapwindscribe0901; C:\Windows\System32\drivers\tapwindscribe0901.sys [54896 2017-09-13] (The OpenVPN Project)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46072 2018-01-20] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [288848 2018-01-20] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-20] (Microsoft Corporation)
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2018-02-02] (Zemana Ltd.)
R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2018-02-02] (Zemana Ltd.)
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-02-02 22:30 - 2018-02-02 22:30 - 002393088 _____ (Farbar) C:\Users\derka\Downloads\FRST64.exe
2018-02-02 22:30 - 2018-02-02 22:30 - 000000000 ____D C:\FRST
2018-02-02 22:03 - 2018-02-02 22:03 - 001117041 _____ C:\Users\derka\Downloads\Helvetica-Font.zip
2018-02-02 22:02 - 2018-02-02 22:02 - 000057405 _____ C:\Users\derka\Downloads\helvetica-neue.ttf.zip
2018-02-02 19:28 - 2018-02-02 19:28 - 000016850 _____ C:\Users\derka\Downloads\MemTest.zip
2018-02-02 19:25 - 2018-02-02 19:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2018-02-02 19:25 - 2018-02-02 19:25 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2018-02-02 19:21 - 2018-02-02 19:21 - 003947992 _____ (Crystal Dew World ) C:\Users\derka\Downloads\CrystalDiskInfo7_5_1.exe
2018-02-02 19:10 - 2018-02-02 19:10 - 005200384 _____ (AVAST Software) C:\Users\derka\Downloads\aswmbr.exe
2018-02-02 14:45 - 2018-02-02 14:46 - 000000000 ____D C:\Windows\LastGood
2018-02-02 14:42 - 2018-01-24 01:23 - 040269808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 035180016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 019796336 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 016449872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 013444552 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 012843496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 011026080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 010900248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 004308976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 003894304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 003709424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001976120 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6439077.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001673616 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6439077.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001325384 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001134768 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001126888 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001054704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 001043128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000988464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000939832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000885680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000795928 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000635248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000616240 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2018-02-02 14:42 - 2018-01-24 01:23 - 000506864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2018-02-02 14:30 - 2018-02-02 14:30 - 000000000 ____D C:\Windows\system32\Drivers\wd
2018-02-02 14:15 - 2018-02-02 22:31 - 000124405 _____ C:\Windows\ZAM.krnl.trace
2018-02-02 14:15 - 2018-02-02 22:31 - 000085094 _____ C:\Windows\ZAM_Guard.krnl.trace
2018-02-02 14:15 - 2018-02-02 14:15 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
2018-02-02 14:15 - 2018-02-02 14:15 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys
2018-02-02 14:15 - 2018-02-02 14:15 - 000000000 ____D C:\Users\derka\AppData\Local\Zemana
2018-02-02 14:15 - 2018-02-02 14:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2018-02-02 14:15 - 2018-02-02 14:15 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-02-02 14:14 - 2018-02-02 14:14 - 006625600 _____ (Zemana Ltd. ) C:\Users\derka\Downloads\Zemana.AntiMalware.Setup.exe
2018-02-02 13:41 - 2018-02-02 13:53 - 981798144 _____ C:\Users\derka\Downloads\Rychly Prachy - Daisy Lee.mp4
2018-02-02 11:32 - 2018-02-02 11:32 - 000000000 ____D C:\ProgramData\Sophos
2018-02-02 11:32 - 2018-02-02 11:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-02-02 11:31 - 2018-02-02 11:31 - 000000000 ____D C:\Program Files (x86)\Sophos
2018-02-02 11:26 - 2018-02-02 11:29 - 190199576 _____ (Sophos Limited) C:\Users\derka\Downloads\Sophos Virus Removal Tool.exe
2018-02-02 11:22 - 2018-02-02 11:17 - 000024064 _____ C:\Windows\zoek-delete.exe
2018-02-02 11:17 - 2018-02-02 11:17 - 000000000 ____D C:\zoek_backup
2018-02-02 11:14 - 2018-02-02 11:14 - 001313792 _____ C:\Users\derka\Downloads\zoek.exe
2018-02-01 21:22 - 2018-02-01 21:52 - 2913793343 _____ C:\Users\derka\Downloads\Fakju-pane-uciteli-2-2015-720p.BDRip.x264.CZ.dab.mkv
2018-02-01 20:39 - 2018-02-01 20:39 - 000132580 _____ C:\Users\derka\Downloads\nvidiaProfileInspector.zip
2018-02-01 19:58 - 2018-02-01 22:59 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-02-01 19:58 - 2018-02-01 20:38 - 000000000 ____D C:\ProgramData\RogueKiller
2018-02-01 19:57 - 2018-02-01 19:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-02-01 19:57 - 2018-02-01 19:57 - 000000000 ____D C:\Program Files\RogueKiller
2018-02-01 19:55 - 2018-02-01 19:55 - 036430896 _____ (Adlice Software ) C:\Users\derka\Downloads\RogueKiller_setup_ref3.exe
2018-02-01 19:46 - 2018-02-01 19:46 - 001790024 _____ (Malwarebytes) C:\Users\derka\Downloads\JRT.exe
2018-02-01 19:28 - 2018-02-01 19:28 - 000230280 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys
2018-02-01 17:41 - 2018-02-01 17:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-02-01 17:41 - 2018-02-01 17:41 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-02-01 17:41 - 2018-02-01 17:41 - 000000000 ____D C:\Program Files\Malwarebytes
2018-02-01 17:41 - 2017-11-29 09:11 - 000077432 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-02-01 17:39 - 2018-02-01 17:40 - 082095216 _____ (Malwarebytes ) C:\Users\derka\Downloads\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3830.exe
2018-02-01 17:37 - 2018-02-01 17:37 - 000003620 _____ C:\Windows\System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-derkapatrik@email.cz
2018-02-01 17:36 - 2018-02-01 17:37 - 000000000 ____D C:\AdwCleaner
2018-02-01 17:35 - 2018-02-01 17:36 - 008206624 _____ (Malwarebytes) C:\Users\derka\Downloads\AdwCleaner.exe
2018-02-01 17:33 - 2018-02-01 17:33 - 000050688 _____ (Atribune.org) C:\Users\derka\Downloads\ATF-Cleaner.exe
2018-02-01 17:29 - 2018-02-01 17:29 - 000448512 _____ (OldTimer Tools) C:\Users\derka\Downloads\TFC.exe
2018-01-31 22:42 - 2018-01-31 22:42 - 000000927 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublime Text 3.lnk
2018-01-31 22:42 - 2018-01-31 22:42 - 000000000 ____D C:\Users\derka\AppData\Roaming\Sublime Text 3
2018-01-31 22:42 - 2018-01-31 22:42 - 000000000 ____D C:\Users\derka\AppData\Local\Sublime Text 3
2018-01-31 22:42 - 2018-01-31 22:42 - 000000000 ____D C:\Program Files\Sublime Text 3
2018-01-31 22:41 - 2018-01-31 22:41 - 008952928 _____ (Sublime HQ Pty Ltd ) C:\Users\derka\Downloads\Sublime Text Build 3143 x64 Setup.exe
2018-01-31 14:31 - 2018-01-31 14:31 - 000253192 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys
2018-01-31 14:30 - 2018-01-31 20:02 - 000173664 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_mark.sys
2018-01-31 14:30 - 2018-01-31 20:02 - 000087584 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_kimul.sys
2018-01-31 14:30 - 2018-01-31 14:30 - 000107680 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klbg.sys
2018-01-31 14:26 - 2018-01-31 14:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2018-01-31 14:25 - 2018-01-31 14:26 - 000003392 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2018-01-31 14:25 - 2018-01-31 14:26 - 000000000 ____D C:\Program Files\Common Files\AV
2018-01-31 14:25 - 2018-01-31 14:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Free
2018-01-31 14:25 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2018-01-31 14:24 - 2018-02-02 21:01 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2018-01-31 14:24 - 2018-01-31 14:25 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2018-01-31 14:24 - 2018-01-31 14:24 - 001055424 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys
2018-01-31 14:24 - 2018-01-31 14:24 - 000594144 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys
2018-01-31 14:24 - 2018-01-31 14:24 - 000207576 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys
2018-01-31 14:24 - 2018-01-31 14:24 - 000149304 _____ (AO Kaspersky Lab) C:\Windows\system32\klhkum.dll
2018-01-31 14:23 - 2018-01-31 14:23 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2018-01-31 14:22 - 2018-01-31 14:22 - 002381360 _____ (Kaspersky Lab) C:\Users\derka\Downloads\kfa18.0.0.405abcs_13252.exe
2018-01-31 13:38 - 2018-01-31 13:39 - 000388608 _____ (Trend Micro Inc.) C:\Users\derka\Downloads\HijackThis.exe
2018-01-29 22:07 - 2018-01-29 22:25 - 000000000 ____D C:\Users\derka\AppData\Roaming\audacity
2018-01-29 22:07 - 2018-01-29 22:07 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2018-01-29 22:07 - 2018-01-29 22:07 - 000000000 ____D C:\Users\derka\AppData\Local\Audacity
2018-01-29 22:07 - 2018-01-29 22:07 - 000000000 ____D C:\Program Files (x86)\Audacity
2018-01-29 22:06 - 2018-01-29 22:06 - 024383624 _____ (Audacity Team ) C:\Users\derka\Downloads\audacity-win-2.2.1.exe
2018-01-28 19:15 - 2018-01-28 19:16 - 000000000 ____D C:\Program Files\CCleaner
2018-01-28 19:15 - 2018-01-28 19:15 - 000003938 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-01-28 19:15 - 2018-01-28 19:15 - 000002870 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-01-28 19:15 - 2018-01-28 19:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-01-28 19:14 - 2018-01-28 19:14 - 011205832 _____ (Piriform Ltd) C:\Users\derka\Downloads\ccsetup539.exe
2018-01-28 13:09 - 2018-01-28 13:09 - 000000000 ____D C:\ProgramData\Twitch
2018-01-28 00:10 - 2018-01-28 00:10 - 000000000 ____D C:\Users\derka\Documents\Zvukové záznamy
2018-01-25 18:52 - 2018-01-25 18:52 - 000003834 _____ C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2018-01-25 18:40 - 2018-01-25 18:40 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2018-01-25 18:39 - 2018-01-25 18:40 - 000000000 ____D C:\Windows\LastGood.Tmp
2018-01-24 14:52 - 2018-01-24 15:29 - 000003077 _____ C:\Users\derka\Documents\zav-report-denis.cech.html
2018-01-24 14:50 - 2018-01-24 15:29 - 000014774 _____ C:\Users\derka\Documents\zav-log[derka@DESKTOP-6B9SVO9].txt
2018-01-21 20:45 - 2018-01-21 20:45 - 009143248 _____ C:\Windows\system32\Drivers\FACEIT.sys
2018-01-21 14:15 - 2018-01-25 18:52 - 000000000 ____D C:\ProgramData\Intel
2018-01-21 14:15 - 2018-01-11 01:25 - 000041512 _____ C:\Windows\system32\Drivers\semav6msr64.sys
2018-01-21 14:11 - 2018-01-21 14:11 - 000000000 ____D C:\Users\derka\ansel
2018-01-20 21:16 - 2018-01-20 21:16 - 000003470 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-01-20 21:16 - 2018-01-20 21:16 - 000003346 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-01-20 21:16 - 2018-01-20 21:16 - 000002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-19 17:34 - 2018-01-19 17:48 - 1069742080 _____ C:\Users\derka\Downloads\Vybíjená =2004-B.Stiller-DVD-CZ.avi
2018-01-16 21:08 - 2018-01-16 02:06 - 000000234 ___SH C:\Users\Public\Libraries.ini
2018-01-14 21:47 - 2018-02-02 19:04 - 000000000 ____D C:\stream_highlights
2018-01-12 21:10 - 2018-01-12 21:10 - 000000000 ____D C:\Users\derka\AppData\Local\Daniele_S
2018-01-11 16:43 - 2018-02-02 20:42 - 000000000 ____D C:\Users\derka\AppData\Roaming\obs-studio
2018-01-11 16:42 - 2018-01-11 16:42 - 000000000 ____D C:\Program Files (x86)\obs-studio
2018-01-09 18:35 - 2018-01-09 18:43 - 000000000 ____D C:\Users\derka\AppData\Roaming\streamlabels
2018-01-09 18:35 - 2018-01-09 18:35 - 000000000 ____D C:\streamlabels
2018-01-09 18:34 - 2018-01-09 18:35 - 000002395 _____ C:\Users\derka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StreamLabels.lnk
2018-01-09 16:03 - 2018-01-09 16:03 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2018-01-09 15:59 - 2018-01-24 01:23 - 000048407 _____ C:\Windows\system32\nvinfo.pb
2018-01-09 15:59 - 2018-01-04 02:44 - 001975184 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6439065.dll
2018-01-09 15:59 - 2018-01-04 02:44 - 001674544 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6439065.dll
2018-01-09 15:43 - 2018-02-02 19:18 - 000000000 ____D C:\Windows\Minidump
2018-01-08 15:52 - 2018-01-08 15:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2018-01-06 22:41 - 2018-02-02 20:13 - 000004208 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3DBD8203-6571-43E2-BBF6-CA1713FB611C}
2018-01-06 22:19 - 2018-01-24 15:44 - 000000000 ____D C:\Users\derka\AppData\LocalLow\Mozilla
2018-01-06 22:19 - 2018-01-06 22:24 - 000000000 ____D C:\Users\derka\AppData\Local\Mozilla
2018-01-06 22:19 - 2018-01-06 22:19 - 000000000 ____D C:\Users\derka\AppData\Roaming\Mozilla
2018-01-06 17:32 - 2018-01-06 17:32 - 000000000 ____D C:\Users\derka\AppData\Local\4kdownload.com
2018-01-04 17:37 - 2018-01-01 18:15 - 000956416 _____ (Microsoft Corporation) C:\Windows\system32\Spectrum.exe
2018-01-04 17:37 - 2018-01-01 13:51 - 001055128 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2018-01-04 17:37 - 2018-01-01 13:51 - 000059800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bam.sys
2018-01-04 17:37 - 2018-01-01 13:50 - 005905752 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2018-01-04 17:37 - 2018-01-01 13:49 - 008605080 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-01-04 17:37 - 2018-01-01 13:49 - 000319352 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-01-04 17:37 - 2018-01-01 13:48 - 007831760 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2018-01-04 17:37 - 2018-01-01 13:48 - 001954048 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-01-04 17:37 - 2018-01-01 13:47 - 000082840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-01-04 17:37 - 2018-01-01 13:46 - 002709704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-01-04 17:37 - 2018-01-01 13:46 - 000471960 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-01-04 17:37 - 2018-01-01 13:45 - 002395032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-01-04 17:37 - 2018-01-01 13:45 - 001277848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-01-04 17:37 - 2018-01-01 13:45 - 000398744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-01-04 17:37 - 2018-01-01 13:42 - 000571288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2018-01-04 17:37 - 2018-01-01 13:42 - 000184984 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-01-04 17:37 - 2018-01-01 13:41 - 007676296 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2018-01-04 17:37 - 2018-01-01 13:40 - 001206680 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2018-01-04 17:37 - 2018-01-01 13:39 - 000902416 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-01-04 17:37 - 2018-01-01 13:39 - 000362904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-01-04 17:37 - 2018-01-01 13:39 - 000129432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvsocket.sys
2018-01-04 17:37 - 2018-01-01 13:38 - 003904808 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2018-01-04 17:37 - 2018-01-01 13:37 - 001426664 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2018-01-04 17:37 - 2018-01-01 13:36 - 000166296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2018-01-04 17:37 - 2018-01-01 13:35 - 001170008 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2018-01-04 17:37 - 2018-01-01 13:34 - 007385088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2018-01-04 17:37 - 2018-01-01 13:33 - 000603920 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2018-01-04 17:37 - 2018-01-01 13:32 - 004481240 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2018-01-04 17:37 - 2018-01-01 13:27 - 000713624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2018-01-04 17:37 - 2018-01-01 13:26 - 000428952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2018-01-04 17:37 - 2018-01-01 13:25 - 000615768 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2018-01-04 17:37 - 2018-01-01 13:25 - 000147864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcifs.sys
2018-01-04 17:37 - 2018-01-01 13:23 - 021352144 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-01-04 17:37 - 2018-01-01 13:03 - 000123512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-01-04 17:37 - 2018-01-01 12:53 - 001615712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-01-04 17:37 - 2018-01-01 12:46 - 003485392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2018-01-04 17:37 - 2018-01-01 12:45 - 006092152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2018-01-04 17:37 - 2018-01-01 12:45 - 005615968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2018-01-04 17:37 - 2018-01-01 12:45 - 002192624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-01-04 17:37 - 2018-01-01 12:43 - 020286120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-01-04 17:37 - 2018-01-01 12:42 - 006479552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-04 17:37 - 2018-01-01 12:42 - 004644912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2018-01-04 17:37 - 2018-01-01 12:42 - 001246432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2018-01-04 17:37 - 2018-01-01 12:42 - 000982528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2018-01-04 17:37 - 2018-01-01 12:37 - 025247232 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2018-01-04 17:37 - 2018-01-01 12:34 - 000703568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-01-04 17:37 - 2018-01-01 12:25 - 002905600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2018-01-04 17:37 - 2018-01-01 12:25 - 000344576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2018-01-04 17:37 - 2018-01-01 12:24 - 003668480 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2018-01-04 17:37 - 2018-01-01 12:24 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2018-01-04 17:37 - 2018-01-01 12:23 - 000536576 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2018-01-04 17:37 - 2018-01-01 12:23 - 000250368 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2018-01-04 17:37 - 2018-01-01 12:21 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netvsc.sys
2018-01-04 17:37 - 2018-01-01 12:20 - 019337216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-01-04 17:37 - 2018-01-01 12:20 - 018917888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2018-01-04 17:37 - 2018-01-01 12:19 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2018-01-04 17:37 - 2018-01-01 12:19 - 000369152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2018-01-04 17:37 - 2018-01-01 12:19 - 000365568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2018-01-04 17:37 - 2018-01-01 12:19 - 000334848 _____ (Microsoft Corporation) C:\Windows\system32\dusmsvc.dll
2018-01-04 17:37 - 2018-01-01 12:18 - 000431616 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
2018-01-04 17:37 - 2018-01-01 12:18 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-01-04 17:37 - 2018-01-01 12:18 - 000261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-01-04 17:37 - 2018-01-01 12:17 - 011923968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-01-04 17:37 - 2018-01-01 12:17 - 000708096 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-01-04 17:37 - 2018-01-01 12:17 - 000559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-01-04 17:37 - 2018-01-01 12:17 - 000542208 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 003676672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 000815616 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 000812544 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 000720896 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 000664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 000594944 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-01-04 17:37 - 2018-01-01 12:16 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-01-04 17:37 - 2018-01-01 12:15 - 012687872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2018-01-04 17:37 - 2018-01-01 12:15 - 006029312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2018-01-04 17:37 - 2018-01-01 12:15 - 000588800 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-01-04 17:37 - 2018-01-01 12:14 - 023655936 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-01-04 17:37 - 2018-01-01 12:14 - 002465280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2018-01-04 17:37 - 2018-01-01 12:13 - 013657600 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-01-04 17:37 - 2018-01-01 12:13 - 012830208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-01-04 17:37 - 2018-01-01 12:13 - 002869760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-01-04 17:37 - 2018-01-01 12:12 - 002633216 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2018-01-04 17:37 - 2018-01-01 12:12 - 001547776 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-01-04 17:37 - 2018-01-01 12:12 - 001424896 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2018-01-04 17:37 - 2018-01-01 12:11 - 008108544 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2018-01-04 17:37 - 2018-01-01 12:11 - 004748288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-01-04 17:37 - 2018-01-01 12:11 - 003334144 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-01-04 17:37 - 2018-01-01 12:11 - 002859520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2018-01-04 17:37 - 2018-01-01 12:11 - 000812032 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-01-04 17:37 - 2018-01-01 12:09 - 001487872 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2018-01-04 17:37 - 2018-01-01 12:09 - 000925184 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-01-04 17:37 - 2018-01-01 12:08 - 000685056 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2018-01-04 17:36 - 2018-01-01 13:54 - 000924648 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2018-01-04 17:36 - 2018-01-01 13:53 - 001090984 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-01-04 17:36 - 2018-01-01 13:52 - 000066712 _____ (Microsoft Corporation) C:\Windows\system32\iumcrypt.dll
2018-01-04 17:36 - 2018-01-01 13:51 - 001414784 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-01-04 17:36 - 2018-01-01 13:51 - 001209240 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-01-04 17:36 - 2018-01-01 13:51 - 000191816 _____ (Microsoft Corporation) C:\Windows\system32\skci.dll
2018-01-04 17:36 - 2018-01-01 13:50 - 000780464 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2018-01-04 17:36 - 2018-01-01 13:50 - 000479912 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase_enclave.dll
2018-01-04 17:36 - 2018-01-01 13:50 - 000077208 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2018-01-04 17:36 - 2018-01-01 13:49 - 000599448 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2018-01-04 17:36 - 2018-01-01 13:49 - 000292376 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2018-01-04 17:36 - 2018-01-01 13:48 - 000382360 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-01-04 17:36 - 2018-01-01 13:47 - 000649304 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-01-04 17:36 - 2018-01-01 13:46 - 000898216 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2018-01-04 17:36 - 2018-01-01 13:46 - 000733592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-01-04 17:36 - 2018-01-01 13:43 - 001173576 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-01-04 17:36 - 2018-01-01 13:43 - 000367336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2018-01-04 17:36 - 2018-01-01 13:43 - 000062872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fsdepends.sys
2018-01-04 17:36 - 2018-01-01 13:42 - 001029016 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2018-01-04 17:36 - 2018-01-01 13:42 - 000494488 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2018-01-04 17:36 - 2018-01-01 13:42 - 000109976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbus.sys
2018-01-04 17:36 - 2018-01-01 13:41 - 000559512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2018-01-04 17:36 - 2018-01-01 13:41 - 000549552 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
2018-01-04 17:36 - 2018-01-01 13:39 - 000677784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-01-04 17:36 - 2018-01-01 13:39 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2018-01-04 17:36 - 2018-01-01 13:38 - 000727448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2018-01-04 17:36 - 2018-01-01 13:38 - 000519152 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2018-01-04 17:36 - 2018-01-01 13:38 - 000103320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2018-01-04 17:36 - 2018-01-01 13:38 - 000038808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2018-01-04 17:36 - 2018-01-01 13:37 - 000461720 _____ (Microsoft Corporation) C:\Windows\system32\wifitask.exe
2018-01-04 17:36 - 2018-01-01 13:36 - 000413888 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2018-01-04 17:36 - 2018-01-01 13:36 - 000374032 _____ (Microsoft Corporation) C:\Windows\system32\vac.exe
2018-01-04 17:36 - 2018-01-01 13:36 - 000113560 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-01-04 17:36 - 2018-01-01 13:36 - 000057752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-01-04 17:36 - 2018-01-01 13:35 - 000075160 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthProxyStub.dll
2018-01-04 17:36 - 2018-01-01 13:34 - 001336344 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-01-04 17:36 - 2018-01-01 13:34 - 000260896 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-01-04 17:36 - 2018-01-01 13:34 - 000087384 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2018-01-04 17:36 - 2018-01-01 13:33 - 002773400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-01-04 17:36 - 2018-01-01 13:32 - 000617304 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
2018-01-04 17:36 - 2018-01-01 13:27 - 000163736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2018-01-04 17:36 - 2018-01-01 13:26 - 000081304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmcl.sys
2018-01-04 17:36 - 2018-01-01 13:21 - 001103768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-01-04 17:36 - 2018-01-01 13:21 - 000614296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2018-01-04 17:36 - 2018-01-01 13:06 - 000311192 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-01-04 17:36 - 2018-01-01 13:03 - 000777904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-01-04 17:36 - 2018-01-01 13:03 - 000650328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2018-01-04 17:36 - 2018-01-01 13:03 - 000566664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2018-01-04 17:36 - 2018-01-01 12:49 - 000481464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-01-04 17:36 - 2018-01-01 12:49 - 000258808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2018-01-04 17:36 - 2018-01-01 12:46 - 000289816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-04 17:36 - 2018-01-01 12:45 - 000450928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll
2018-01-04 17:36 - 2018-01-01 12:42 - 001003152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-01-04 17:36 - 2018-01-01 12:42 - 000386424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2018-01-04 17:36 - 2018-01-01 12:42 - 000129184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-01-04 17:36 - 2018-01-01 12:42 - 000074992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2018-01-04 17:36 - 2018-01-01 12:25 - 001008640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2018-01-04 17:36 - 2018-01-01 12:25 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-01-04 17:36 - 2018-01-01 12:25 - 000097792 _____ C:\Windows\system32\runexehelper.exe
2018-01-04 17:36 - 2018-01-01 12:24 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\AboutSettingsHandlers.dll
2018-01-04 17:36 - 2018-01-01 12:24 - 000096256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-01-04 17:36 - 2018-01-01 12:24 - 000038912 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-01-04 17:36 - 2018-01-01 12:23 - 001313792 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2018-01-04 17:36 - 2018-01-01 12:23 - 000561152 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-01-04 17:36 - 2018-01-01 12:23 - 000385024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cldflt.sys
2018-01-04 17:36 - 2018-01-01 12:23 - 000232960 _____ (Microsoft Corporation) C:\Windows\system32\convertvhd.exe
2018-01-04 17:36 - 2018-01-01 12:23 - 000121344 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-01-04 17:36 - 2018-01-01 12:23 - 000080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmclr.sys
2018-01-04 17:36 - 2018-01-01 12:23 - 000047104 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-01-04 17:36 - 2018-01-01 12:22 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-04 17:36 - 2018-01-01 12:22 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Dumpstorport.sys
2018-01-04 17:36 - 2018-01-01 12:22 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\VmApplicationHealthMonitorProxy.dll
2018-01-04 17:36 - 2018-01-01 12:21 - 000268288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-01-04 17:36 - 2018-01-01 12:21 - 000233984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppLockerCSP.dll
2018-01-04 17:36 - 2018-01-01 12:21 - 000133632 _____ (Microsoft Corporation) C:\Windows\system32\wificonnapi.dll
2018-01-04 17:36 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-01-04 17:36 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspptp.sys
2018-01-04 17:36 - 2018-01-01 12:21 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-01-04 17:36 - 2018-01-01 12:21 - 000062976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-01-04 17:36 - 2018-01-01 12:20 - 000524288 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000459776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000397824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys
2018-01-04 17:36 - 2018-01-01 12:20 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000212992 _____ (Microsoft Corporation) C:\Windows\system32\container.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000204288 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000186368 _____ (Microsoft Corporation) C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000134656 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000133632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\rasauto.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\SCardDlg.dll
2018-01-04 17:36 - 2018-01-01 12:20 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RfxVmt.sys
2018-01-04 17:36 - 2018-01-01 12:20 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshhttp.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 008014848 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000795136 _____ (Microsoft Corporation) C:\Windows\system32\NaturalAuth.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000675328 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000450048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TileDataRepository.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000416768 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-01-04 17:36 - 2018-01-01 12:19 - 000366080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-01-04 17:36 - 2018-01-01 12:19 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2018-01-04 17:36 - 2018-01-01 12:19 - 000188416 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenance.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000149504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\container.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msoert2.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000079872 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe
2018-01-04 17:36 - 2018-01-01 12:19 - 000063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-01-04 17:36 - 2018-01-01 12:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000748032 _____ (Microsoft Corporation) C:\Windows\system32\PhoneProviders.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000699904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000588800 _____ (Microsoft Corporation) C:\Windows\system32\SmsRouterSvc.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000465920 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000436224 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000432640 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000427008 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000425984 _____ (Microsoft Corporation) C:\Windows\system32\vmrdvcore.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000391168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000380928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\APHostService.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000336896 _____ (Microsoft Corporation) C:\Windows\system32\AppLockerCSP.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000276480 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000210944 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000144896 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-01-04 17:36 - 2018-01-01 12:18 - 000082944 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 006564864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 001485312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpserverbase.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000791552 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000616960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000594432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000568832 _____ (Microsoft Corporation) C:\Windows\system32\TileDataRepository.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000555520 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000456704 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000423936 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-01-04 17:36 - 2018-01-01 12:17 - 000228352 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-01-04 17:36 - 2018-01-01 12:17 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\msoert2.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 005833216 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 004839424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000966656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000956928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpbase.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000831488 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000624128 _____ (Microsoft Corporation) C:\Windows\system32\SyncController.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000401920 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\cldapi.dll
2018-01-04 17:36 - 2018-01-01 12:16 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cldapi.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 002349568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 001657856 _____ (Microsoft Corporation) C:\Windows\system32\rdpserverbase.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 001245184 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 000970240 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 000951808 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 000756736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 000434176 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 000366080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-01-04 17:36 - 2018-01-01 12:15 - 000258560 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-01-04 17:36 - 2018-01-01 12:14 - 001495040 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2018-01-04 17:36 - 2018-01-01 12:14 - 001097728 _____ (Microsoft Corporation) C:\Windows\system32\rdpbase.dll
2018-01-04 17:36 - 2018-01-01 12:14 - 001003008 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2018-01-04 17:36 - 2018-01-01 12:14 - 000985600 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-01-04 17:36 - 2018-01-01 12:14 - 000917504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2018-01-04 17:36 - 2018-01-01 12:14 - 000870912 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2018-01-04 17:36 - 2018-01-01 12:13 - 003121664 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-04 17:36 - 2018-01-01 12:13 - 002013184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-01-04 17:36 - 2018-01-01 12:13 - 001559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-01-04 17:36 - 2018-01-01 12:13 - 001474560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-01-04 17:36 - 2018-01-01 12:13 - 000897024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-01-04 17:36 - 2018-01-01 12:12 - 002208768 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2018-01-04 17:36 - 2018-01-01 12:12 - 001573376 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2018-01-04 17:36 - 2018-01-01 12:12 - 000760320 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-01-04 17:36 - 2018-01-01 12:12 - 000464384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 003165696 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 002082304 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-01-04 17:36 - 2018-01-01 12:11 - 001822208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 001816576 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 001597952 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 001343488 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 001231872 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-01-04 17:36 - 2018-01-01 12:11 - 000715776 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-01-04 17:36 - 2018-01-01 12:10 - 003126272 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2018-01-04 17:36 - 2018-01-01 12:10 - 002528256 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-01-04 17:36 - 2018-01-01 12:10 - 000012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscproxystub.dll
2018-01-04 17:36 - 2018-01-01 12:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\DbgModel.dll
2018-01-04 17:36 - 2018-01-01 12:09 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll
2018-01-04 17:36 - 2018-01-01 12:08 - 000963072 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2018-01-04 17:36 - 2018-01-01 12:08 - 000726016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-01-04 17:36 - 2018-01-01 12:08 - 000505344 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-01-04 17:36 - 2018-01-01 12:06 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wscproxystub.dll
2018-01-04 17:36 - 2018-01-01 12:05 - 002510848 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
2018-01-04 17:36 - 2018-01-01 12:05 - 001160704 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 22:36

2018-01-04 17:36 - 2018-01-01 12:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-02-02 22:27 - 2017-11-26 14:02 - 000000000 ____D C:\Program Files (x86)\Steam
2018-02-02 20:30 - 2017-12-21 15:46 - 000000000 ____D C:\Grafika
2018-02-02 20:30 - 2017-11-26 13:58 - 000000000 ____D C:\Users\derka\AppData\Local\NVIDIA
2018-02-02 20:29 - 2017-12-02 22:23 - 000000000 ____D C:\Users\derka\AppData\Local\CrashDumps
2018-02-02 20:02 - 2017-11-26 12:59 - 000000000 ____D C:\Windows\system32\SleepStudy
2018-02-02 19:22 - 2017-11-26 13:42 - 000000000 ____D C:\ProgramData\NVIDIA
2018-02-02 19:19 - 2017-11-26 13:23 - 000000000 __SHD C:\Users\derka\IntelGraphicsProfiles
2018-02-02 19:18 - 2017-11-26 13:00 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-02 19:18 - 2017-11-26 12:59 - 001638799 ____N C:\Windows\Minidump\020218-40421-01.dmp
2018-02-02 19:14 - 2017-11-26 13:10 - 000000000 ____D C:\Users\derka
2018-02-02 19:13 - 2017-11-26 12:59 - 002005679 ____N C:\Windows\Minidump\020218-32765-01.dmp
2018-02-02 19:09 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\system32\NDF
2018-02-02 17:34 - 2017-09-29 09:45 - 000524288 _____ C:\Windows\system32\config\BBI
2018-02-02 14:57 - 2017-11-26 13:12 - 002982462 _____ C:\Windows\system32\PerfStringBackup.INI
2018-02-02 14:57 - 2017-09-30 15:31 - 001376370 _____ C:\Windows\system32\perfh005.dat
2018-02-02 14:57 - 2017-09-30 15:31 - 000335894 _____ C:\Windows\system32\perfc005.dat
2018-02-02 14:47 - 2017-11-26 13:23 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-02-02 14:47 - 2017-09-29 14:44 - 000000000 ____D C:\Windows\INF
2018-02-02 14:32 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\DeliveryOptimization
2018-02-02 13:56 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-02 13:56 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\AppReadiness
2018-02-02 11:15 - 2017-12-21 16:01 - 000000000 ____D C:\Users\derka\AppData\Local\Adobe
2018-02-01 21:17 - 2017-11-26 15:21 - 000000000 ____D C:\Users\derka\AppData\Roaming\TS3Client
2018-02-01 20:35 - 2017-09-29 14:46 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-01-31 16:05 - 2017-12-05 15:55 - 000000000 ____D C:\Users\derka\AppData\Local\Spotify
2018-01-31 15:06 - 2017-12-05 15:54 - 000000000 ____D C:\Users\derka\AppData\Roaming\Spotify
2018-01-31 14:24 - 2017-09-29 14:46 - 000000000 ___HD C:\Windows\ELAMBKUP
2018-01-28 19:18 - 2017-11-26 12:59 - 000000000 ____D C:\Windows\Panther
2018-01-28 13:56 - 2017-11-26 13:39 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-24 18:24 - 2017-11-27 15:01 - 000548000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-01-24 14:50 - 2017-11-26 13:12 - 000000000 ____D C:\Users\derka\AppData\Local\VirtualStore
2018-01-24 01:23 - 2017-11-26 13:38 - 004580832 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2018-01-24 01:23 - 2017-11-26 13:38 - 000057928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2018-01-24 00:11 - 2017-11-26 13:42 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2018-01-23 23:57 - 2017-11-26 13:42 - 005950024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 002589168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 001766288 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 000633328 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 000450352 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 000147768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\oemdspif.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 000122768 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2018-01-23 23:57 - 2017-11-26 13:42 - 000082744 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-01-22 06:46 - 2017-11-26 13:42 - 007947791 _____ C:\Windows\system32\nvcoproc.bin
2018-01-21 20:46 - 2017-12-17 19:29 - 000000000 ____D C:\Program Files\FACEIT AC
2018-01-21 14:22 - 2017-11-26 19:30 - 000000000 ____D C:\Program Files\Epic Games
2018-01-21 14:15 - 2017-11-26 13:22 - 000000000 ____D C:\Program Files\Intel
2018-01-21 14:11 - 2017-11-26 13:43 - 000004000 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:11 - 2017-11-26 13:43 - 000003940 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:11 - 2017-11-26 13:41 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-01-21 14:11 - 2017-11-26 13:33 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-01-21 14:10 - 2017-11-26 13:43 - 000004308 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:10 - 2017-11-26 13:43 - 000003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:10 - 2017-11-26 13:43 - 000003866 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:10 - 2017-11-26 13:43 - 000003858 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:10 - 2017-11-26 13:43 - 000003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:10 - 2017-11-26 13:43 - 000003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-01-21 14:10 - 2017-11-26 13:33 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-01-20 21:16 - 2017-11-26 13:53 - 000000000 ____D C:\Users\derka\AppData\Local\Google
2018-01-20 21:16 - 2017-11-26 13:53 - 000000000 ____D C:\Program Files (x86)\Google
2018-01-16 21:04 - 2017-11-26 13:47 - 000000000 ____D C:\Users\derka\AppData\Local\NVIDIA Corporation
2018-01-10 18:15 - 2017-11-30 16:31 - 000000000 ____D C:\Windows\system32\MRT
2018-01-10 18:13 - 2017-11-30 16:31 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-01-10 18:13 - 2017-11-30 16:31 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-10 18:13 - 2017-09-29 14:37 - 000000000 ____D C:\Windows\CbsTemp
2018-01-10 16:44 - 2017-11-29 16:03 - 000000000 ____D C:\Users\derka\AppData\Roaming\Opera Software
2018-01-10 16:44 - 2017-11-29 16:03 - 000000000 ____D C:\Users\derka\AppData\Local\Opera Software
2018-01-10 16:44 - 2017-11-29 16:03 - 000000000 ____D C:\Program Files\Opera
2018-01-10 15:33 - 2017-11-26 13:43 - 002425656 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2018-01-10 15:33 - 2017-11-26 13:43 - 002090800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2018-01-10 15:33 - 2017-11-26 13:43 - 001310008 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2018-01-10 10:41 - 2017-11-26 13:42 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-01-09 15:20 - 2017-11-26 13:15 - 000000000 ___RD C:\Users\derka\OneDrive
2018-01-09 14:50 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\rescache
2018-01-08 15:38 - 2017-12-25 23:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VALOFEEU
2018-01-08 15:38 - 2017-12-17 22:52 - 000000000 ____D C:\Program Files (x86)\Windscribe
2018-01-05 19:04 - 2017-11-26 13:12 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-05 19:04 - 2017-11-26 13:12 - 000000000 ___RD C:\Users\derka\3D Objects
2018-01-05 19:02 - 2017-11-26 12:59 - 000248776 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ___SD C:\Windows\SysWOW64\F12
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ___SD C:\Windows\system32\F12
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\TextInput
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\SysWOW64\Dism
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\system32\oobe
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\system32\migwiz
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\system32\appraiser
2018-01-05 18:58 - 2017-09-29 14:46 - 000000000 ____D C:\Windows\Provisioning
2018-01-05 18:58 - 2017-09-29 09:45 - 000000000 ____D C:\Windows\system32\Dism
2018-01-04 17:42 - 2017-09-29 14:41 - 000403968 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
2018-01-04 17:41 - 2017-09-29 14:41 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2018-01-04 17:41 - 2017-09-29 14:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll

Some files in TEMP:
====================
2018-02-02 14:49 - 2018-02-02 14:49 - 005022256 _____ () C:\Users\derka\AppData\Local\Temp\NVI2_29.DLL

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-01-27 19:59

==================== End of FRST.txt ============================

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 02 úno 2018 22:36

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by derka (02-02-2018 22:32:42)
Running from C:\Users\derka\OneDrive\Plocha
Windows 10 Home Version 1709 16299.192 (X64) (2017-11-26 12:06:22)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2561146316-167023531-786741288-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2561146316-167023531-786741288-503 - Limited - Disabled)
derka (S-1-5-21-2561146316-167023531-786741288-1001 - Administrator - Enabled) => C:\Users\derka
Guest (S-1-5-21-2561146316-167023531-786741288-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2561146316-167023531-786741288-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Free (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Kaspersky Free (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Aktualizace NVIDIA 31.0.11.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.0.11.0 - NVIDIA Corporation) Hidden
Audacity 2.2.1 (HKLM-x32\...\Audacity_is1) (Version: 2.2.1 - Audacity Team)
CCleaner (HKLM\...\CCleaner) (Version: 5.39 - Piriform)
CrystalDiskInfo 7.5.1 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.5.1 - Crystal Dew World)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 390.77 - NVIDIA Corporation) Hidden
Dolby Audio X2 Windows API SDK (HKLM\...\{82C288CC-A96D-43E3-9119-944DABF5DD61}) (Version: 0.8.0.74 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows APP (HKLM\...\{9207D68E-666A-49C7-A900-9F5B2FF289E4}) (Version: 0.8.0.71 - Dolby Laboratories, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FACEIT 0.13.0 (HKLM\...\1b460c18-2611-5297-a1a8-4f35160a268c) (Version: 0.13.0 - FACEIT Ltd.)
FACEIT AC version 1.0 (HKLM\...\{1419E44C-0EF4-4822-9194-9F1A4D43973D}_is1) (Version: 1.0 - FACEIT LTD)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Kaspersky Free (HKLM-x32\...\{5AAE61FF-858E-453E-B8F3-944618149975}) (Version: 18.0.0.405 - Kaspersky Lab) Hidden
Kaspersky Free (HKLM-x32\...\InstallWIX_{5AAE61FF-858E-453E-B8F3-944618149975}) (Version: 18.0.0.405 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{F33C0717-8E04-4EB5-90C8-47221287DB4F}) (Version: 18.0.0.405 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F33C0717-8E04-4EB5-90C8-47221287DB4F}) (Version: 18.0.0.405 - Kaspersky Lab)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Malwarebytes verze 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
NVIDIA GeForce Experience 3.12.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.12.0.84 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 390.77 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 20.1.3 - OBS Project)
Ovládací panel NVIDIA 390.77 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 390.77 - NVIDIA Corporation) Hidden
RogueKiller version 12.12.2.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.2.0 - Adlice Software)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.6.1 - Sophos Limited)
Spotify (HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\Spotify) (Version: 1.0.73.345.g6c9971ef - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
StreamLabels 0.2.8 (only current user) (HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\8000d50a-fcb7-5b38-8a3b-a02a0ec79daa) (Version: 0.2.8 - Streamlabs)
Sublime Text Build 3143 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.6 - TeamSpeak Systems GmbH)
VEGAS Pro 14.0 (64-bit) (HKLM\...\{4C79D80F-79F9-11E6-8402-BB95F5A309BD}) (Version: 14.0.161 - VEGAS)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.)
Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2561146316-167023531-786741288-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\derka\AppData\Local\Microsoft\OneDrive\17.3.7076.1026_1\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2561146316-167023531-786741288-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\derka\AppData\Local\Microsoft\OneDrive\17.3.7076.1026_1\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2561146316-167023531-786741288-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\derka\AppData\Local\Microsoft\OneDrive\17.3.7076.1026_1\amd64\FileSyncShell64.dll => No File
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-02-02] ()
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\ShellEx.dll [2018-01-31] (AO Kaspersky Lab)
ContextMenuHandlers2: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\ShellEx.dll [2018-01-31] (AO Kaspersky Lab)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\ShellEx.dll [2018-01-31] (AO Kaspersky Lab)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_9dc776be3e13ad6d\igfxDTCM.dll [2017-11-21] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2018-01-23] (NVIDIA Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-02-02] ()
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\ShellEx.dll [2018-01-31] (AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1050DE16-82B0-4ED1-B274-07D1902CE0D3} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-derkapatrik@email.cz => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-05-26] (Adobe Systems Incorporated)
Task: {1A775D77-910E-47D1-8331-AABB27AD86B1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-20] (Google Inc.)
Task: {462D38F3-8A5F-4A50-B21D-63254220231A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {619FC30D-612A-4D87-A442-CB0E1617F4ED} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation)
Task: {6A5DC1EC-EE8F-47C6-85C6-6F407FBE478A} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-01-10] (NVIDIA Corporation)
Task: {8000D604-6E6F-43B9-B0E5-E6D2ECC88566} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation)
Task: {8DABCD3F-7BBA-4382-B2BD-7505C2E8A7B8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-01-09] (Piriform Ltd)
Task: {8E162218-F5F1-4029-8BBC-165D31C06D2D} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2018-01-31] (AO Kaspersky Lab)
Task: {997F34E9-1EEA-4422-BDBD-6B429ACDDB0B} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-01-10] (NVIDIA Corporation)
Task: {9B40BDFD-95C4-4597-B172-D015BAA390D8} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-01-10] (NVIDIA Corporation)
Task: {AEF4A9E2-3757-4B27-B2F0-CCCC0343AB23} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation)
Task: {CA8E157B-7A4A-410B-AF2E-82684E36E12B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-01-09] (Piriform Ltd)
Task: {D473777C-D5B4-428E-868A-5AE08F0B331E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-20] (Google Inc.)
Task: {DF99CD60-99B6-4E66-83BA-CE3756386E14} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-01-10] (NVIDIA Corporation)
Task: {FF2142D7-1810-4472-9A3D-52813154B4FC} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation)
Task: {FF6C7BD5-773E-4015-8A6F-B2021CC119CD} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-derkapatrik@email.cz => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\Windows\SYSTEM32\inputhost.dll
2018-01-09 16:06 - 2018-01-24 01:23 - 000544240 _____ () C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\DisplayDriverAnalyzer\_DisplayDriverCrashAnalyzer64.dll
2017-11-26 13:43 - 2018-01-10 15:33 - 001268024 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-12-13 18:42 - 2017-11-26 13:23 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-13 18:42 - 2017-11-26 13:01 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-11-26 13:27 - 2010-10-26 12:40 - 000049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2018-01-31 14:24 - 2018-01-31 14:24 - 000836968 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\kpcengine.2.3.dll
2017-11-26 13:43 - 2018-01-10 15:33 - 001041208 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-11-26 14:04 - 2016-09-01 02:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2017-11-26 14:05 - 2017-11-29 06:09 - 000781088 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2017-11-26 14:04 - 2016-09-01 02:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2017-11-26 14:04 - 2016-09-01 02:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2017-11-26 14:05 - 2017-12-15 20:59 - 002558752 _____ () C:\Program Files (x86)\Steam\video.dll
2017-12-15 14:55 - 2017-11-04 02:54 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll
2017-12-15 14:55 - 2017-11-04 02:54 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll
2017-12-15 14:55 - 2017-11-04 02:54 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll
2017-12-15 14:55 - 2017-11-04 02:54 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll
2017-12-15 14:55 - 2017-11-04 02:54 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll
2017-11-26 14:05 - 2017-12-15 20:59 - 000904992 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-11-26 14:04 - 2016-07-04 23:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-11-26 14:06 - 2017-09-07 03:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2017-11-26 14:06 - 2017-10-31 05:44 - 071471904 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-11-26 14:04 - 2015-09-25 00:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 14:46 - 2018-02-02 11:20 - 000000753 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2561146316-167023531-786741288-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\derka\OneDrive\Plocha\threeteamsnews.png
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "DAX2_APP"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "ZAM"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\StartupApproved\Run: => "Bloody2"
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\StartupApproved\Run: => "Windscribe"
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\StartupApproved\Run: => "CCleaner Monitoring"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D124E93C-03C8-4E90-8B75-3BF42026F824}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{47741963-0E3C-4D2F-81D9-1ADC34BE1920}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{805985FE-898A-4933-BB0B-AEA8EA566E8B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{05FF641C-F83D-4113-8602-3BE2C7444F8E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{8A2AB7D4-AB64-451D-A553-5591C7628687}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{335339C4-03B7-4C92-9C99-DDF970DF99A7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [TCP Query User{1ADA87EC-8723-43C9-A2EB-DCEC46E99C4C}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{98A91A11-88B6-428C-9ABE-0D7C76724D97}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{17EADFF8-2A64-4560-90C5-38EBC8651C1A}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{DDF8B094-F862-47D9-BFDF-AFDAFE0F89A6}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{19D1C877-8C3F-4532-9BFB-BDE64FFC3EE6}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [UDP Query User{F377E8EE-1568-4827-AA50-384892B73DCB}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [TCP Query User{CC657D4E-357C-4364-9B6E-DB709BBD95E5}C:\users\derka\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\derka\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E6791264-7F73-485E-81B7-EF7DD7CAED8E}C:\users\derka\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\derka\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{03736B5C-6660-480E-94B9-7BC6D834E926}C:\program files\faceit\faceit.exe] => (Allow) C:\program files\faceit\faceit.exe
FirewallRules: [UDP Query User{10350D2D-68C8-4231-A8D2-D68F9D4D5DB5}C:\program files\faceit\faceit.exe] => (Allow) C:\program files\faceit\faceit.exe
FirewallRules: [TCP Query User{F5CD89C0-078D-4195-8E2C-8554AE3E1078}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe
FirewallRules: [UDP Query User{51D1C036-6161-425D-B3AB-7AE1E4B86BDC}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe
FirewallRules: [TCP Query User{2042677E-7F56-4D8B-A732-B03CD3AEE83D}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [UDP Query User{E0A232C2-92A6-45A5-B34B-35B1110B3189}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [{3F31298C-A4D6-4189-A5BC-FAA501650514}] => (Allow) C:\VALOFEEU\CombatArms\NMService.exe
FirewallRules: [{0C24A17A-050F-4152-B5FC-650BE62668E4}] => (Allow) C:\VALOFEEU\CombatArms\NMService.exe
FirewallRules: [TCP Query User{6E91C0A9-5CC8-41CD-B58C-6C38B73DC18C}C:\valofeeu\combatarms\engine.exe] => (Allow) C:\valofeeu\combatarms\engine.exe
FirewallRules: [UDP Query User{E4CB4110-7D8D-4B72-B572-063502EF8681}C:\valofeeu\combatarms\engine.exe] => (Allow) C:\valofeeu\combatarms\engine.exe
FirewallRules: [TCP Query User{B315D46F-FB87-4737-A78B-F652BF11B0B9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{695AFC2F-A1AD-4DD4-9F4A-0D8AB6A9B9E8}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{AF6D0EE7-3DD6-47AF-9E47-BB704B8CDCEB}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [UDP Query User{E675C69C-80CB-40CD-9D1B-5F21DF856714}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [{8B42914C-8B3B-4E60-B6DC-6B75CC62986B}] => (Allow) C:\VALOFEEU\CombatArms\NMService.exe
FirewallRules: [{A5B21B77-C0CE-42D3-B8E6-03D0316C535C}] => (Allow) C:\VALOFEEU\CombatArms\NMService.exe
FirewallRules: [TCP Query User{073DEEBD-E3E5-4A5F-B0B7-0C44A6ED8BB1}C:\valofeeu\combatarms\engine.exe] => (Allow) C:\valofeeu\combatarms\engine.exe
FirewallRules: [UDP Query User{988D20E6-367E-4F9B-AF3B-0423EB6D2B2F}C:\valofeeu\combatarms\engine.exe] => (Allow) C:\valofeeu\combatarms\engine.exe
FirewallRules: [{205FBA49-C320-44F0-A421-B05CE0E2FACD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E81F1625-87E4-4685-ABB6-7DFD157AAD80}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{8D86CED6-78A7-440B-8391-191FA338DBEF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{F51373E6-8D11-4D6A-BF0D-B83C505E62DA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{D10FF3A4-71BD-43D0-B562-ACF13B483166}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{A1D6A294-AEF0-46E5-B3FB-38C438CB3001}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{74C1EC43-24EA-4733-AC85-5AD6E5D25A1F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe

==================== Restore Points =========================

21-01-2018 14:19:49 Removed Intel(R) Computing Improvement Program
28-01-2018 13:54:23 Removed Intel(R) Computing Improvement Program
01-02-2018 19:47:42 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/02/2018 08:29:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: obs64.exe, verze: 0.0.0.0, časové razítko: 0x5a668941
Název chybujícího modulu: libcef.dll, verze: 3.2987.1581.0, časové razítko: 0x58b1e66e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000001c56caa
ID chybujícího procesu: 0x1c34
Čas spuštění chybující aplikace: 0x01d39c5ba2c706b2
Cesta k chybující aplikaci: C:\Program Files (x86)\obs-studio\bin\64bit\obs64.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\obs-studio\obs-plugins\64bit\libcef.dll
ID zprávy: 4ed38a4f-df5e-4764-94de-7293c0356d80
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (02/02/2018 07:51:00 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (02/02/2018 07:51:00 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (02/02/2018 07:50:51 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (02/02/2018 07:50:51 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (02/02/2018 07:45:07 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {95CABCC9-BC57-4C12-B8DF-BA193232AA01} byla odmítnuta.

Error: (02/02/2018 07:44:54 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {95CABCC9-BC57-4C12-B8DF-BA193232AA01} byla odmítnuta.

Error: (02/02/2018 07:43:49 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {95CABCC9-BC57-4C12-B8DF-BA193232AA01} byla odmítnuta.

Error: (02/02/2018 07:34:45 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (02/02/2018 07:34:45 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {95CABCC9-BC57-4C12-B8DF-BA193232AA01} byla odmítnuta.


System errors:
=============
Error: (02/02/2018 09:25:20 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 09:21:02 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 09:18:39 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 09:14:57 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 09:09:45 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-6B9SVO9)
Description: Server {C41B1461-3F8C-4666-B512-6DF24DE566D1} se v daném časovém limitu neregistroval u služby DCOM.

Error: (02/02/2018 08:31:31 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 08:14:14 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 08:13:12 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-6B9SVO9)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DESKTOP-6B9SVO9\derka (SID: S-1-5-21-2561146316-167023531-786741288-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/02/2018 08:01:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Pomocník pro přihlášení pomocí účtu Microsoft neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (02/02/2018 08:01:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba AppX Deployment Service (AppXSVC) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.


CodeIntegrity:
===================================
Date: 2018-02-02 19:20:25.193
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-01 17:41:53.467
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 16:05:14.361
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 16:03:50.076
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 16:02:47.614
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 16:02:37.796
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 16:01:32.321
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 16:00:00.548
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 15:55:51.117
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-01-24 15:52:21.237
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-6100U CPU @ 2.30GHz
Percentage of memory in use: 49%
Total physical RAM: 4001.91 MB
Available physical RAM: 2020.66 MB
Total Virtual: 7225.3 MB
Available Virtual: 4626.59 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:886.2 GB) (Free:796.45 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: DE3B44E7)

Partition: GPT.

==================== End of Addition.txt ============================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod jaro3 » 02 úno 2018 23:04

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\MountPoints2: {6fc3533c-f242-11e7-904b-ccb0daa7f7de} - "D:\Lenovo_Suite.exe"
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
Task: {1A775D77-910E-47D1-8331-AABB27AD86B1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-20] (Google Inc.)
Task: {D473777C-D5B4-428E-868A-5AE08F0B331E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-20] (Google Inc.)

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
HelFix
Level 4.5
Level 4.5
Příspěvky: 1735
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola počítače [Zpomalený chod systému] - 31.01.2018

Příspěvekod HelFix » 03 úno 2018 00:50

Fix result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by derka (03-02-2018 00:45:05) Run:1
Running from C:\Users\derka\OneDrive\Plocha
Loaded Profiles: derka (Available Profiles: derka)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-2561146316-167023531-786741288-1001\...\MountPoints2: {6fc3533c-f242-11e7-904b-ccb0daa7f7de} - "D:\Lenovo_Suite.exe"
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
Task: {1A775D77-910E-47D1-8331-AABB27AD86B1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-20] (Google Inc.)
Task: {D473777C-D5B4-428E-868A-5AE08F0B331E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-20] (Google Inc.)

EmptyTemp:
End
*****************

Processes closed successfully.
"HKU\S-1-5-21-2561146316-167023531-786741288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6fc3533c-f242-11e7-904b-ccb0daa7f7de}" => removed successfully
HKLM\Software\Classes\CLSID\{6fc3533c-f242-11e7-904b-ccb0daa7f7de} => key not found
"HKLM\System\CurrentControlSet\Services\xhunter1" => removed successfully
xhunter1 => service removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1A775D77-910E-47D1-8331-AABB27AD86B1} => could not remove key. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A775D77-910E-47D1-8331-AABB27AD86B1}" => removed successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D473777C-D5B4-428E-868A-5AE08F0B331E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D473777C-D5B4-428E-868A-5AE08F0B331E}" => removed successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 26389446 B
Java, Flash, Steam htmlcache => 21770711 B
Windows/system/drivers => 159509 B
Edge => 517205 B
Chrome => 759170146 B
Firefox => 458752 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 29478 B
NetworkService => 10718 B
derka => 1193512926 B

RecycleBin => 0 B
EmptyTemp: => 1.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 00:46:19 ====


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 8 hostů