Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 15 úno 2017 22:01

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Stáhni si Security Check by screen317 z některého odkazu
http://www.bleepingcomputer.com/download/securitycheck/
http://screen317.spywareinfoforum.org/SecurityCheck.exe
http://screen317.changelog.fr/SecurityCheck.exe

ulož si ho na plochu, poklepej na něj a postupuj podle instrukcí v černém okně. Potom se automaticky otevře pozn. Blok, bude mít název checkup.txt. Jeho obsah sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 15 úno 2017 22:22

# DelFix v1.012 - Logfile created 15/02/2017 at 22:18:32
# Updated 04/03/2015 by Xplode
# Username : Chvála Pánu - DOMÁCÍ
# Operating System : Windows 10 Home (32 bits)

~ Removing disinfection tools ...

Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\Users\Chvála Pánu\Desktop\AdwCleaner.exe
Deleted : C:\Users\Chvála Pánu\Desktop\AdwCleaner[C0].txt
Deleted : C:\Users\Chvála Pánu\Desktop\AdwCleaner[S0].txt
Deleted : C:\Users\Chvála Pánu\Desktop\JRT.exe
Deleted : C:\Users\Chvála Pánu\Desktop\JRT.txt
Deleted : C:\Users\Chvála Pánu\Desktop\hijackthis 1.txt
Deleted : C:\Users\Chvála Pánu\Desktop\HijackThis.exe
Deleted : C:\Users\Chvála Pánu\Desktop\hijackthis.log
Deleted : C:\Users\Chvála Pánu\Desktop\RogueKiller.exe
Deleted : C:\Users\Chvála Pánu\Desktop\SecurityCheck.exe
Deleted : C:\Users\Chvála Pánu\Desktop\TFC.exe
Deleted : C:\Users\Chvála Pánu\Desktop\zoek-results.txt
Deleted : C:\Users\Chvála Pánu\Desktop\zoek.exe
Deleted : C:\Users\Chvála Pánu\Downloads\hijackthis.log
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #1 [zoek.exe restore point | 02/15/2017 15:51:47]

New restore point created !

########## - EOF - ##########

Results of screen317's Security Check version 1.014 --- 12/23/15
x86 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Windows Firewall Disabled!
Windows Defender
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Zemana AntiMalware
AVG PC TuneUp
Java 8 Update 121
Java version 32-bit out of Date!
Adobe Flash Player 24.0.0.221
Mozilla Firefox (51.0.1)
````````Process Check: objlist.exe by Laurent````````
Windows Defender MSMpEng.exe
Zemana AntiMalware ZAM.exe
Windows Defender MpCmdRun.exe
Windows Defender MSASCuiL.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 16 úno 2017 08:59

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 16 úno 2017 09:16

wMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software
Run date: 2017-02-16 09:10:24
-----------------------------
09:10:24.523 OS Version: Windows 6.2.9200
09:10:24.523 Number of processors: 4 586 0x1C0A
09:10:24.523 ComputerName: DOMÁCÍ UserName:
09:10:25.648 Initialize success
09:10:25.695 VM: initialized successfully
09:10:25.695 VM: Intel CPU virtualization not supported
09:10:36.585 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
09:10:36.601 Disk 0 Vendor: SAMSUNG_HD502HJ 1AJ10001 Size: 476940MB BusType: 3
09:10:36.726 Disk 0 MBR read successfully
09:10:36.726 Disk 0 MBR scan
09:10:36.741 Disk 0 Windows 7 default MBR code
09:10:36.757 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 101 MB offset 2048
09:10:36.773 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 168702 MB offset 208896
09:10:36.804 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 450 MB offset 345712640
09:10:36.804 Disk 0 Partition - 00 0F Extended LBA 307682 MB offset 346634505
09:10:36.851 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 307681 MB offset 346636288
09:10:36.866 Disk 0 scanning sectors +976768065
09:10:36.929 Disk 0 scanning C:\WINDOWS\system32\drivers
09:10:44.195 Service scanning
09:10:58.820 Modules scanning
09:10:58.835 Disk 0 trace - called modules:
09:10:58.866 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
09:10:58.882 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afda030]
09:10:58.898 3 CLASSPNP.SYS[82eb423a] -> nt!IofCallDriver -> [0x8ae08e10]
09:10:58.913 5 ACPI.sys[864c3c72] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x8ae2e878]
09:10:58.929 Disk 0 statistics 118604/0/0 @ 11,68 MB/s
09:10:58.960 Scan finished successfully
09:11:13.757 Disk 0 MBR has been saved successfully to "C:\Users\Chvála Pánu\Desktop\MBR.dat"
09:11:13.773 The log file has been saved successfully to "C:\Users\Chvála Pánu\Desktop\aswMBR.txt"
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 16 úno 2017 09:17

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-02-2017 02
Ran by Chvála Pánu (administrator) on DOMÁCÍ (16-02-2017 09:13:26)
Running from C:\Users\Chvála Pánu\Desktop
Loaded Profiles: Chvála Pánu (Available Profiles: Chvála Pánu)
Platform: Microsoft Windows 10 Home Version 1607 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Windows\System32\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Copyright 2017.) C:\Program Files\Zemana AntiMalware\ZAM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [483840 2016-07-16] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [7545088 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2016-01-29] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM\...\Run: [ZAM] => C:\Program Files\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Chvála Pánu\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll [2017-02-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Chvála Pánu\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll [2017-02-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Chvála Pánu\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll [2017-02-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 185.160.208.50 78.108.152.158
Tcpip\..\Interfaces\{199effd4-d8d1-4eb9-a28b-59f7162ffa83}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{22238426-badf-4f4a-a897-cdaf3c9f540d}: [DhcpNameServer] 185.160.208.50 78.108.152.158

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-13] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-13] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-01-24] (CANON INC.)
Toolbar: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-01-24] (CANON INC.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab

FireFox:
========
FF DefaultProfile: qf8v0k0o.default
FF ProfilePath: C:\Users\Chvála Pánu\AppData\Roaming\Mozilla\Firefox\Profiles\qf8v0k0o.default [2017-02-16]
FF NewTab: Mozilla\Firefox\Profiles\qf8v0k0o.default -> about:newtab
FF Homepage: Mozilla\Firefox\Profiles\qf8v0k0o.default -> about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] ()
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-13] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-13] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-11-14] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-11-14] (NVIDIA Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer -> p:\TVUPlayer\npTVUAx.dll [No File]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-01-18] (Adobe Systems Inc.)

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 Atheros Bt&Wlan Coex Agent; C:\Program Files\Atheros\Ath_CoexAgent.exe [151552 2010-04-29] (Atheros) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [915600 2016-01-29] (NVIDIA Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3303888 2017-01-20] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2016-01-29] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19775632 2016-01-29] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2015-07-28] ()
S4 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-29] (Ulead Systems, Inc.) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [271496 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [84928 2016-07-16] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 athr; C:\WINDOWS\System32\drivers\athwn.sys [3228672 2016-07-16] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_BUS; C:\WINDOWS\System32\drivers\btath_bus.sys [28200 2010-03-30] (Atheros)
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [509224 2015-03-09] (Qualcomm Atheros)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [243128 2014-11-15] (Disc Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [15968 2014-11-18] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10208 2014-11-18] ()
S3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [62976 2016-07-16] ()
R3 nuviocir; C:\WINDOWS\system32\DRIVERS\nuviocir_x86.sys [36360 2015-05-07] (Nuvoton Technology Corp.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2016-01-29] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad32v.sys [32912 2016-01-29] (NVIDIA Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
R3 rt640x86; C:\WINDOWS\System32\drivers\rt640x86.sys [494080 2016-07-16] (Realtek )
S3 StkCMini; C:\WINDOWS\System32\Drivers\StkCMini.sys [1521544 2010-04-16] (Syntek)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [37912 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [244576 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [100192 2016-07-16] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam32.sys [181496 2017-02-15] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard32.sys [181496 2017-02-15] (Zemana Ltd.)
U3 aswMBR; C:\Users\Chvála Pánu\AppData\Local\Temp\aswMBR.sys [56704 2017-02-16] () [File not signed] <==== ATTENTION
U3 aswVmm; C:\Users\Chvála Pánu\AppData\Local\Temp\aswVmm.sys [192224 2017-02-16] () <==== ATTENTION
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-16 09:13 - 2017-02-16 09:14 - 00012816 _____ C:\Users\Chvála Pánu\Desktop\FRST.txt
2017-02-16 09:13 - 2017-02-16 09:13 - 00000000 ____D C:\FRST
2017-02-16 09:12 - 2017-02-16 09:13 - 01764352 _____ (Farbar) C:\Users\Chvála Pánu\Desktop\FRST.exe
2017-02-16 09:11 - 2017-02-16 09:11 - 00002115 _____ C:\Users\Chvála Pánu\Desktop\aswMBR.txt
2017-02-16 09:11 - 2017-02-16 09:11 - 00000512 _____ C:\Users\Chvála Pánu\Desktop\MBR.dat
2017-02-16 09:08 - 2017-02-16 09:10 - 05200384 _____ (AVAST Software) C:\Users\Chvála Pánu\Desktop\aswmbr.exe
2017-02-15 22:21 - 2017-02-15 22:21 - 00852798 _____ C:\Users\Chvála Pánu\Desktop\SecurityCheck.exe
2017-02-15 22:17 - 2017-02-15 22:18 - 08262488 _____ C:\Users\Chvála Pánu\Desktop\delfix_1.012.exe
2017-02-15 19:45 - 2017-02-15 19:45 - 01728451 _____ C:\Users\Chvála Pánu\Desktop\AvgInstallLog.cab
2017-02-15 19:38 - 2017-02-15 19:38 - 00000835 _____ C:\Users\Chvála Pánu\Desktop\zeman.txt
2017-02-15 19:24 - 2017-02-16 09:13 - 00060182 _____ C:\WINDOWS\ZAM.krnl.trace
2017-02-15 19:24 - 2017-02-16 09:13 - 00029381 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-02-15 19:24 - 2017-02-15 19:24 - 00181496 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard32.sys
2017-02-15 19:24 - 2017-02-15 19:24 - 00181496 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam32.sys
2017-02-15 19:24 - 2017-02-15 19:24 - 00001968 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2017-02-15 19:24 - 2017-02-15 19:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-02-15 19:23 - 2017-02-15 19:24 - 00000000 ____D C:\Program Files\Zemana AntiMalware
2017-02-15 19:23 - 2017-02-15 19:23 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Zemana
2017-02-15 19:21 - 2017-02-15 19:22 - 05677776 _____ (Zemana Ltd. ) C:\Users\Chvála Pánu\Desktop\Zemana.AntiMalware.Setup.exe
2017-02-15 19:19 - 2017-02-15 22:07 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\VirtualStore
2017-02-15 19:05 - 2017-02-15 18:25 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2017-02-15 18:50 - 2016-12-21 05:22 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-02-15 18:50 - 2016-12-14 06:04 - 00261984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2017-02-15 18:50 - 2016-12-14 05:46 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-02-15 18:50 - 2016-12-14 05:38 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-02-15 18:50 - 2016-12-09 11:10 - 00583136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-02-15 18:50 - 2016-12-09 10:57 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-02-15 18:50 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-02-15 18:50 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-02-15 18:50 - 2016-11-11 08:47 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-02-15 18:50 - 2016-11-11 08:46 - 00186720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-02-15 18:50 - 2016-11-11 08:45 - 00355680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-02-15 18:50 - 2016-11-11 08:42 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-02-15 18:50 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-02-15 18:50 - 2016-11-11 08:11 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-02-15 18:50 - 2016-11-11 08:07 - 01136128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-02-15 18:49 - 2016-12-21 06:03 - 00136544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqmigplugin.dll
2017-02-15 18:49 - 2016-12-21 06:02 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-02-15 18:49 - 2016-12-21 06:02 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-02-15 18:49 - 2016-12-21 06:02 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2017-02-15 18:49 - 2016-12-21 06:02 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-02-15 18:49 - 2016-12-21 06:02 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-02-15 18:49 - 2016-12-21 06:02 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-02-15 18:49 - 2016-12-21 06:00 - 01384704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-02-15 18:49 - 2016-12-21 05:47 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2017-02-15 18:49 - 2016-12-21 05:45 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2017-02-15 18:49 - 2016-12-21 05:44 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2017-02-15 18:49 - 2016-12-21 05:43 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-02-15 18:49 - 2016-12-21 05:42 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-02-15 18:49 - 2016-12-21 05:41 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-02-15 18:49 - 2016-12-21 05:41 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-02-15 18:49 - 2016-12-21 05:40 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-02-15 18:49 - 2016-12-21 05:40 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-02-15 18:49 - 2016-12-21 05:39 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-02-15 18:49 - 2016-12-21 05:35 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-02-15 18:49 - 2016-12-21 05:30 - 01406976 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2017-02-15 18:49 - 2016-12-21 05:25 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-02-15 18:49 - 2016-12-21 05:24 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-02-15 18:49 - 2016-12-14 06:01 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-02-15 18:49 - 2016-12-14 05:45 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2017-02-15 18:49 - 2016-12-14 05:42 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2017-02-15 18:49 - 2016-12-14 05:41 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2017-02-15 18:49 - 2016-12-14 05:40 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2017-02-15 18:49 - 2016-12-14 05:40 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-15 18:49 - 2016-12-14 05:38 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2017-02-15 18:49 - 2016-12-14 05:38 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-02-15 18:49 - 2016-12-14 05:37 - 00247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-02-15 18:49 - 2016-12-14 05:37 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-02-15 18:49 - 2016-12-14 05:36 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2017-02-15 18:49 - 2016-12-14 05:35 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-02-15 18:49 - 2016-12-14 05:23 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-02-15 18:49 - 2016-12-14 05:23 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-02-15 18:49 - 2016-12-14 05:22 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-02-15 18:49 - 2016-12-14 05:22 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-02-15 18:49 - 2016-12-14 05:22 - 01235456 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-02-15 18:49 - 2016-12-14 05:22 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-02-15 18:49 - 2016-12-09 11:16 - 00890984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-02-15 18:49 - 2016-12-09 11:16 - 00784064 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-02-15 18:49 - 2016-12-09 11:12 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-02-15 18:49 - 2016-12-09 11:11 - 02048496 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-02-15 18:49 - 2016-12-09 11:01 - 01897824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-02-15 18:49 - 2016-12-09 11:01 - 00551264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-02-15 18:49 - 2016-12-09 11:01 - 00342880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-02-15 18:49 - 2016-12-09 10:52 - 01413664 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-02-15 18:49 - 2016-12-09 10:52 - 01344992 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-02-15 18:49 - 2016-12-09 10:41 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2017-02-15 18:49 - 2016-12-09 10:37 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2017-02-15 18:49 - 2016-12-09 10:31 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2017-02-15 18:49 - 2016-12-09 10:31 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-02-15 18:49 - 2016-12-09 10:28 - 01284096 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-02-15 18:49 - 2016-12-09 10:23 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-02-15 18:49 - 2016-12-09 10:18 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-02-15 18:49 - 2016-12-09 10:18 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2017-02-15 18:49 - 2016-12-09 10:16 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2017-02-15 18:49 - 2016-12-09 10:15 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-02-15 18:49 - 2016-12-09 10:15 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2017-02-15 18:49 - 2016-12-09 10:15 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2017-02-15 18:49 - 2016-11-11 09:07 - 00081760 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
2017-02-15 18:49 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2017-02-15 18:49 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-02-15 18:49 - 2016-11-11 08:45 - 00175968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-02-15 18:49 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-02-15 18:49 - 2016-11-11 08:42 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-02-15 18:49 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-02-15 18:49 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
2017-02-15 18:49 - 2016-11-11 08:41 - 00802608 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2017-02-15 18:49 - 2016-11-11 08:41 - 00675568 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-02-15 18:49 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-02-15 18:49 - 2016-11-11 08:30 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-02-15 18:49 - 2016-11-11 08:29 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
2017-02-15 18:49 - 2016-11-11 08:27 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2017-02-15 18:49 - 2016-11-11 08:27 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
2017-02-15 18:49 - 2016-11-11 08:25 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-02-15 18:49 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2017-02-15 18:49 - 2016-11-11 08:25 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-02-15 18:49 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2017-02-15 18:49 - 2016-11-11 08:25 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
2017-02-15 18:49 - 2016-11-11 08:24 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2017-02-15 18:49 - 2016-11-11 08:24 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2017-02-15 18:49 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-02-15 18:49 - 2016-11-11 08:22 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-02-15 18:49 - 2016-11-11 08:22 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2017-02-15 18:49 - 2016-11-11 08:22 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
2017-02-15 18:49 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2017-02-15 18:49 - 2016-11-11 08:21 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-02-15 18:49 - 2016-11-11 08:21 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2017-02-15 18:49 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-15 18:49 - 2016-11-11 08:20 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
2017-02-15 18:49 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-02-15 18:49 - 2016-11-11 08:19 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2017-02-15 18:49 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-02-15 18:49 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-02-15 18:49 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-02-15 18:49 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2017-02-15 18:49 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2017-02-15 18:49 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2017-02-15 18:49 - 2016-11-11 08:18 - 00725504 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-02-15 18:49 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-02-15 18:49 - 2016-11-11 08:18 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2017-02-15 18:49 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2017-02-15 18:49 - 2016-11-11 08:18 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2017-02-15 18:49 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2017-02-15 18:49 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-15 18:49 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2017-02-15 18:49 - 2016-11-11 08:15 - 00561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-02-15 18:49 - 2016-11-11 08:15 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-02-15 18:49 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2017-02-15 18:49 - 2016-11-11 08:15 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2017-02-15 18:49 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2017-02-15 18:49 - 2016-11-11 08:14 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2017-02-15 18:49 - 2016-11-11 08:13 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-02-15 18:49 - 2016-11-11 08:13 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2017-02-15 18:49 - 2016-11-11 08:12 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-02-15 18:49 - 2016-11-11 08:11 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-02-15 18:49 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-02-15 18:49 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
2017-02-15 18:49 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-02-15 18:49 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-02-15 18:49 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\xolehlp.dll
2017-02-15 18:49 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-02-15 18:49 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-02-15 18:49 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-02-15 18:49 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxclu.dll
2017-02-15 18:49 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2017-02-15 18:49 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-02-15 18:49 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-02-15 18:49 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-02-15 18:49 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2017-02-15 18:49 - 2016-11-11 08:04 - 00706048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-02-15 18:49 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-02-15 18:49 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2017-02-15 18:49 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2017-02-15 18:49 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2017-02-15 18:49 - 2016-11-11 08:02 - 00612352 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2017-02-15 18:48 - 2016-12-21 06:59 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2017-02-15 18:48 - 2016-12-21 06:59 - 00101728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-02-15 18:48 - 2016-12-21 06:20 - 06020448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-02-15 18:48 - 2016-12-21 06:09 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-02-15 18:48 - 2016-12-21 06:05 - 00523784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-02-15 18:48 - 2016-12-21 06:02 - 00080224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-02-15 18:48 - 2016-12-21 06:01 - 00198496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-02-15 18:48 - 2016-12-21 05:40 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-02-15 18:48 - 2016-12-21 05:40 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-02-15 18:48 - 2016-12-21 05:38 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-02-15 18:48 - 2016-12-21 05:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-02-15 18:48 - 2016-12-21 05:33 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-02-15 18:48 - 2016-12-21 05:32 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-02-15 18:48 - 2016-12-21 05:30 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2017-02-15 18:48 - 2016-12-21 05:30 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-02-15 18:48 - 2016-12-21 05:30 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-02-15 18:48 - 2016-12-21 05:27 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-02-15 18:48 - 2016-12-21 05:26 - 03776000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-02-15 18:48 - 2016-12-21 05:25 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-02-15 18:48 - 2016-12-21 05:24 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-02-15 18:48 - 2016-12-21 05:24 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-02-15 18:48 - 2016-12-21 05:23 - 01120256 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-02-15 18:48 - 2016-12-21 05:22 - 03596800 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-02-15 18:48 - 2016-12-14 06:58 - 01026912 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-02-15 18:48 - 2016-12-14 06:26 - 01127040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-02-15 18:48 - 2016-12-14 06:21 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2017-02-15 18:48 - 2016-12-14 06:08 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-02-15 18:48 - 2016-12-14 06:06 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 16 úno 2017 09:18

2017-02-15 18:48 - 2016-12-14 06:05 - 00544608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-02-15 18:48 - 2016-12-14 06:01 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2017-02-15 18:48 - 2016-12-14 06:01 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2017-02-15 18:48 - 2016-12-14 05:43 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-02-15 18:48 - 2016-12-14 05:40 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-02-15 18:48 - 2016-12-14 05:40 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-02-15 18:48 - 2016-12-14 05:37 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2017-02-15 18:48 - 2016-12-14 05:36 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-02-15 18:48 - 2016-12-14 05:36 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-02-15 18:48 - 2016-12-14 05:36 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-02-15 18:48 - 2016-12-14 05:35 - 01722368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2017-02-15 18:48 - 2016-12-14 05:35 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-02-15 18:48 - 2016-12-14 05:35 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-02-15 18:48 - 2016-12-14 05:35 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-02-15 18:48 - 2016-12-14 05:32 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2017-02-15 18:48 - 2016-12-14 05:32 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-02-15 18:48 - 2016-12-14 05:24 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-02-15 18:48 - 2016-12-14 05:22 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-02-15 18:48 - 2016-12-14 05:21 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-02-15 18:48 - 2016-12-09 11:54 - 01415520 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-02-15 18:48 - 2016-12-09 11:54 - 00115552 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-02-15 18:48 - 2016-12-09 11:09 - 00133296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-02-15 18:48 - 2016-12-09 11:01 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-02-15 18:48 - 2016-12-09 11:01 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-02-15 18:48 - 2016-12-09 11:00 - 00117720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-02-15 18:48 - 2016-12-09 10:35 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2017-02-15 18:48 - 2016-12-09 10:32 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2017-02-15 18:48 - 2016-12-09 10:20 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-02-15 18:48 - 2016-12-09 10:18 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-02-15 18:48 - 2016-12-09 10:17 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-02-15 18:48 - 2016-12-09 10:16 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-02-15 18:48 - 2016-11-11 09:07 - 00448864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-02-15 18:48 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2017-02-15 18:48 - 2016-11-11 09:00 - 01725136 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-02-15 18:48 - 2016-11-11 08:59 - 01586736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-02-15 18:48 - 2016-11-11 08:59 - 00292192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-02-15 18:48 - 2016-11-11 08:59 - 00106336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2017-02-15 18:48 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
2017-02-15 18:48 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-02-15 18:48 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2017-02-15 18:48 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2017-02-15 18:48 - 2016-11-11 08:45 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-02-15 18:48 - 2016-11-11 08:45 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-02-15 18:48 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
2017-02-15 18:48 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-02-15 18:48 - 2016-11-11 08:37 - 00381720 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2017-02-15 18:48 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2017-02-15 18:48 - 2016-11-11 08:27 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2017-02-15 18:48 - 2016-11-11 08:26 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-02-15 18:48 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
2017-02-15 18:48 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2017-02-15 18:48 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
2017-02-15 18:48 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-02-15 18:48 - 2016-11-11 08:24 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-02-15 18:48 - 2016-11-11 08:23 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2017-02-15 18:48 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2017-02-15 18:48 - 2016-11-11 08:23 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2017-02-15 18:48 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2017-02-15 18:48 - 2016-11-11 08:22 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-02-15 18:48 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2017-02-15 18:48 - 2016-11-11 08:22 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2017-02-15 18:48 - 2016-11-11 08:21 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-02-15 18:48 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-02-15 18:48 - 2016-11-11 08:20 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2017-02-15 18:48 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-02-15 18:48 - 2016-11-11 08:19 - 00384512 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-02-15 18:48 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-02-15 18:48 - 2016-11-11 08:18 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-02-15 18:48 - 2016-11-11 08:18 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-02-15 18:48 - 2016-11-11 08:18 - 00294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-02-15 18:48 - 2016-11-11 08:18 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2017-02-15 18:48 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-02-15 18:48 - 2016-11-11 08:17 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2017-02-15 18:48 - 2016-11-11 08:16 - 01377792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-02-15 18:48 - 2016-11-11 08:15 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-02-15 18:48 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-02-15 18:48 - 2016-11-11 08:14 - 00473600 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-02-15 18:48 - 2016-11-11 08:13 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-02-15 18:48 - 2016-11-11 08:12 - 00529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-02-15 18:48 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
2017-02-15 18:48 - 2016-11-11 08:12 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
2017-02-15 18:48 - 2016-11-11 08:10 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2017-02-15 18:48 - 2016-11-11 08:07 - 01948160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-02-15 18:48 - 2016-11-11 08:07 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2017-02-15 18:48 - 2016-11-11 08:06 - 01602048 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-02-15 18:48 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-02-15 18:48 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-02-15 18:48 - 2016-11-11 08:04 - 00818176 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-02-15 18:48 - 2016-11-11 08:04 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2017-02-15 18:48 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-02-15 18:48 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-02-15 18:41 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-02-15 16:48 - 2017-02-15 16:48 - 00004544 _____ C:\Users\Chvála Pánu\Desktop\rk_13C6.tmp 2.txt
2017-02-15 09:44 - 2016-11-14 10:45 - 00615992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvStreaming.exe
2017-02-15 09:42 - 2016-12-09 12:32 - 00076864 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2017-02-15 09:17 - 2017-02-15 09:17 - 00000020 ___SH C:\Users\Chvála Pánu\ntuser.ini
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Šablony
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Poslední
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Okolní síť
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Dokumenty
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\Data aplikací
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-02-15 09:16 - 2017-02-15 09:16 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2017-02-15 09:15 - 2017-02-15 09:15 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2017-02-15 09:15 - 2017-02-15 09:15 - 00007623 _____ C:\WINDOWS\diagerr.xml
2017-02-15 08:57 - 2017-02-15 08:57 - 00001487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default\AppData\Local\AVG
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2017-02-15 08:57 - 2017-02-15 08:57 - 00000000 ____D C:\Users\Default User\AppData\Local\AVG
2017-02-15 08:48 - 2017-02-15 08:48 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2017-02-15 08:46 - 2017-02-15 08:59 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-02-15 08:44 - 2017-02-16 07:01 - 00000000 ____D C:\Users\Chvála Pánu
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Šablony
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Soubory cookie
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Poslední
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Okolní tiskárny
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Okolní síť
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Nabídka Start
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Dokumenty
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Documents\Obrázky
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Documents\Hudba
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Documents\Filmy
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\Data aplikací
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-02-15 08:44 - 2017-02-15 08:44 - 00000000 _SHDL C:\Users\Chvála Pánu\AppData\Local\Data aplikací
2017-02-15 08:42 - 2017-02-16 07:07 - 01645254 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-15 08:38 - 2017-02-16 07:00 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-15 08:38 - 2017-02-15 08:38 - 00000000 ____D C:\Program Files\Common Files\Atheros
2017-02-15 08:38 - 2016-11-14 12:00 - 04395456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-02-15 08:38 - 2016-11-14 12:00 - 03069496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc.dll
2017-02-15 08:38 - 2016-11-14 12:00 - 02563128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-02-15 08:38 - 2016-11-14 12:00 - 00677312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2017-02-15 08:38 - 2016-11-14 12:00 - 00381888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-02-15 08:38 - 2016-11-14 12:00 - 00070200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-02-15 08:38 - 2016-11-11 20:51 - 07513855 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-02-15 08:37 - 2017-02-15 09:39 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-15 08:37 - 2017-02-15 08:48 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-02-15 08:37 - 2017-02-15 08:48 - 00000000 ____D C:\Program Files\Realtek
2017-02-15 08:37 - 2017-02-15 08:37 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_nuviocir_x86_01009.Wdf
2017-02-15 08:37 - 2017-02-15 08:37 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-02-15 08:37 - 2017-02-15 08:37 - 00000000 ____D C:\WINDOWS\system32\RTCOM
2017-02-15 08:37 - 2017-02-15 08:37 - 00000000 ____D C:\WINDOWS\system32\DAX2
2017-02-15 08:34 - 2017-02-15 09:16 - 00000000 ___DC C:\WINDOWS\Panther
2017-02-15 08:26 - 2017-02-15 08:27 - 00000000 ____D C:\Windows.old
2017-02-15 08:22 - 2017-02-15 08:22 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-02-15 08:16 - 2017-02-15 08:16 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2017-02-15 08:16 - 2017-02-15 08:16 - 00000000 ____D C:\WINDOWS\system32\msmq
2017-02-15 08:16 - 2017-02-15 08:16 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2017-02-15 08:16 - 2017-02-15 08:16 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-02-15 08:16 - 2017-02-15 08:16 - 00000000 ____D C:\Program Files\MSBuild
2017-02-15 08:16 - 2017-02-15 08:16 - 00000000 ____D C:\inetpub
2017-02-15 08:15 - 2016-05-25 11:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-02-15 08:15 - 2016-05-25 11:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-02-15 08:15 - 2016-05-25 11:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-02-14 23:40 - 2017-02-14 23:40 - 00004382 _____ C:\Users\Chvála Pánu\Desktop\rk_2A13.tmp.txt
2017-02-14 19:41 - 2017-02-15 08:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-02-14 19:41 - 2017-02-14 19:41 - 00002763 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2017-02-14 19:41 - 2017-02-14 19:41 - 00000000 ____D C:\ProgramData\Sophos
2017-02-14 19:41 - 2017-02-14 19:41 - 00000000 ____D C:\Program Files\Sophos
2017-02-14 19:40 - 2017-02-14 19:40 - 00001844 _____ C:\Users\Chvála Pánu\Desktop\mb3 b.txt
2017-02-14 19:08 - 2017-02-14 19:40 - 161455800 _____ (Sophos Limited) C:\Users\Chvála Pánu\Desktop\Sophos Virus Removal Tool.exe
2017-02-14 10:42 - 2017-02-14 11:09 - 00001883 _____ C:\Users\Chvála Pánu\Desktop\mb3.txt
2017-02-14 10:37 - 2017-02-14 10:37 - 00152512 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-02-14 10:36 - 2017-02-16 07:01 - 00219584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-14 10:36 - 2017-02-15 08:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-02-14 10:36 - 2017-02-14 10:38 - 00073672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-02-14 10:36 - 2017-02-14 10:36 - 00094656 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-02-14 10:36 - 2017-02-14 10:36 - 00039360 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-02-14 10:36 - 2017-02-14 10:36 - 00002104 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-02-14 10:35 - 2017-02-14 10:35 - 00000000 ____D C:\Program Files\Malwarebytes
2017-02-14 10:35 - 2017-01-20 07:47 - 00059976 _____ C:\WINDOWS\system32\Drivers\mbae.sys
2017-02-14 10:10 - 2017-02-14 10:10 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Macromedia
2017-02-13 19:39 - 2017-02-13 19:39 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\CEF
2017-02-13 19:35 - 2017-02-15 19:48 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\AvgSetupLog
2017-02-13 19:31 - 2017-02-13 19:35 - 03449312 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Chvála Pánu\Desktop\Antivirus_Free_1894.exe
2017-02-13 19:26 - 2017-02-14 10:34 - 55566792 _____ (Malwarebytes ) C:\Users\Chvála Pánu\Desktop\mb3-setup-consumer-3.0.6.1469.exe
2017-02-13 19:20 - 2017-02-14 10:12 - 00050688 _____ (Atribune.org) C:\Users\Chvála Pánu\Desktop\ATF-Cleaner.exe
2017-02-13 19:10 - 2017-02-16 09:14 - 00000000 ____D C:\Users\Chvála Pánu\AppData\LocalLow\Mozilla
2017-02-13 19:10 - 2017-02-13 19:16 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Mozilla
2017-02-13 19:10 - 2017-02-13 19:10 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Roaming\Mozilla
2017-02-13 19:09 - 2017-02-13 19:09 - 00001197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-13 19:09 - 2017-02-13 19:09 - 00001185 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-13 19:08 - 2017-02-13 19:08 - 00245544 _____ C:\Users\Chvála Pánu\Downloads\Firefox Setup Stub 51.0.1.exe
2017-02-13 18:28 - 2017-02-13 18:28 - 08813488 _____ (Piriform Ltd) C:\Users\Chvála Pánu\Desktop\ccsetup526.exe
2017-02-13 18:20 - 2017-02-13 18:20 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Roaming\Macromedia
2017-02-13 18:17 - 2017-02-13 18:17 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\MicrosoftEdge
2017-02-13 18:15 - 2017-02-13 18:15 - 00000000 ____D C:\Users\Chvála Pánu\AppData\LocalLow\Canon Easy-WebPrint EX2
2017-02-13 18:15 - 2017-02-13 18:15 - 00000000 ____D C:\Users\Chvála Pánu\AppData\LocalLow\Canon Easy-WebPrint EX
2017-02-13 18:12 - 2017-02-13 18:12 - 00000518 _____ C:\Users\Chvála Pánu\Desktop\Interní I.lnk
2017-02-13 18:12 - 2017-02-13 18:12 - 00000436 _____ C:\Users\Chvála Pánu\Desktop\Tento počítač.lnk
2017-02-13 17:38 - 2017-02-13 17:38 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Comms
2017-02-13 17:21 - 2017-02-13 17:21 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Roaming\Skype
2017-02-13 17:20 - 2017-02-15 09:26 - 00002453 _____ C:\Users\Chvála Pánu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-13 17:20 - 2017-02-15 09:26 - 00000000 ___RD C:\Users\Chvála Pánu\OneDrive
2017-02-13 17:19 - 2017-02-13 17:19 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Publishers
2017-02-13 17:18 - 2017-02-13 17:21 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\NVIDIA Corporation
2017-02-13 17:16 - 2017-02-15 09:38 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Packages
2017-02-13 17:16 - 2017-02-13 17:22 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\NVIDIA
2017-02-13 17:16 - 2017-02-13 17:16 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Roaming\Adobe
2017-02-13 17:16 - 2017-02-13 17:16 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\TileDataLayer
2017-02-13 17:16 - 2017-02-13 12:52 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\AVG
2017-02-13 17:16 - 2016-05-05 10:22 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Roaming\TuneUp Software
2017-02-13 17:16 - 2016-05-05 10:22 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Roaming\Media Center Programs
2017-02-13 17:16 - 2016-05-05 10:22 - 00000000 ____D C:\Users\Chvála Pánu\AppData\Local\Microsoft Help
2017-02-13 17:16 - 2014-06-30 09:44 - 00002093 _____ C:\Users\Chvála Pánu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-16 09:07 - 2016-11-20 05:29 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-16 07:07 - 2016-11-20 14:08 - 00510766 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-16 07:07 - 2016-11-20 14:08 - 00112982 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-16 07:05 - 2016-07-16 09:29 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-16 07:05 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-16 07:04 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\appcompat
2017-02-16 07:00 - 2016-11-20 14:29 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-15 23:02 - 2016-07-16 03:22 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-02-15 22:19 - 2015-05-23 07:27 - 00001338 _____ C:\DelFix.txt
2017-02-15 19:19 - 2016-11-20 14:37 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-15 19:17 - 2016-07-16 09:28 - 00000000 ____D C:\WINDOWS\INF
2017-02-15 19:16 - 2016-11-20 05:28 - 00389248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-15 19:15 - 2016-07-16 09:29 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-02-15 19:15 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-02-15 19:15 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-02-15 19:15 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-02-15 19:15 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\Provisioning
2017-02-15 19:15 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-02-15 19:15 - 2016-07-16 03:22 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-02-15 19:15 - 2016-07-16 03:22 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-02-15 19:15 - 2016-07-16 03:22 - 00000000 ____D C:\WINDOWS\servicing
2017-02-15 18:56 - 2016-07-16 09:19 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-15 17:24 - 2009-07-14 03:37 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-02-15 09:42 - 2015-05-20 20:10 - 00024688 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-02-15 09:31 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\Registration
2017-02-15 09:21 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\rescache
2017-02-15 09:16 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Windows NT
2017-02-15 09:14 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-02-15 09:14 - 2015-10-30 06:48 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-02-15 09:05 - 2015-08-07 20:27 - 00021592 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-02-15 09:04 - 2016-07-16 09:29 - 00000000 __RHD C:\Users\Public\Libraries
2017-02-15 09:04 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\Media
2017-02-15 08:59 - 2016-07-16 03:22 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-15 08:59 - 2016-03-17 08:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-02-15 08:59 - 2015-09-12 12:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2017-02-15 08:59 - 2015-04-22 12:55 - 00000000 ____D C:\WINDOWS\system32\vbox
2017-02-15 08:59 - 2014-07-26 10:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2017-02-15 08:59 - 2014-06-30 09:51 - 00000000 ____D C:\WINDOWS\cs
2017-02-15 08:59 - 2014-03-14 12:39 - 00000000 ____D C:\WINDOWS\system32\STRING
2017-02-15 08:59 - 2013-10-14 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-02-15 08:59 - 2011-06-14 07:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2017-02-15 08:59 - 2011-06-04 14:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-02-15 08:59 - 2010-11-16 08:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Suite
2017-02-15 08:59 - 2009-07-14 05:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-02-15 08:57 - 2016-07-16 09:29 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-02-15 08:57 - 2015-10-30 06:13 - 00000000 ____D C:\Users\Default.migrated
2017-02-15 08:50 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-15 08:50 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-15 08:50 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\IME
2017-02-15 08:50 - 2013-07-24 12:02 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-15 08:50 - 2011-09-02 09:52 - 00000000 ____D C:\WINDOWS\system32\SPReview
2017-02-15 08:50 - 2011-09-02 09:51 - 00000000 ____D C:\WINDOWS\system32\EventProviders
2017-02-15 08:49 - 2016-11-20 14:12 - 00000000 ____D C:\WINDOWS\OCR
2017-02-15 08:49 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\schemas
2017-02-15 08:49 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\Resources
2017-02-15 08:49 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-02-15 08:49 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-15 08:49 - 2014-03-14 12:40 - 00000000 ___HD C:\WINDOWS\system32\CanonIJ Uninstaller Information
2017-02-15 08:48 - 2016-07-16 09:29 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-02-15 08:48 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-15 08:48 - 2011-07-07 13:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hasbro Interactive
2017-02-15 08:48 - 2010-11-16 08:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NEC Electronics
2017-02-15 08:48 - 2009-07-14 10:19 - 00000000 ___RD C:\Users\Public\Recorded TV
2017-02-15 08:48 - 2009-07-14 05:52 - 00000000 ____D C:\Program Files\Microsoft Games
2017-02-15 08:38 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\Help
2017-02-15 08:34 - 2016-07-16 09:30 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-02-15 08:16 - 2016-11-20 14:11 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2017-02-15 08:16 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-02-15 08:16 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-02-15 08:16 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\System
2017-02-15 08:16 - 2016-07-16 09:26 - 01003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00256192 _____ (Microsoft Corporation) C:\WINDOWS\winhelp.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00221600 _____ (Microsoft Corporation) C:\WINDOWS\system32\lanman.drv
2017-02-15 08:16 - 2016-07-16 09:26 - 00177856 _____ (Microsoft Corporation) C:\WINDOWS\system32\typelib.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00169520 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole2disp.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00153008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole2nls.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2017-02-15 08:16 - 2016-07-16 09:26 - 00127213 _____ C:\WINDOWS\system32\ega.cpi
2017-02-15 08:16 - 2016-07-16 09:26 - 00108464 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2017-02-15 08:16 - 2016-07-16 09:26 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2017-02-15 08:16 - 2016-07-16 09:26 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system\olecli.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00069886 _____ C:\WINDOWS\system32\edit.com
2017-02-15 08:16 - 2016-07-16 09:26 - 00068992 _____ (Microsoft Corporation) C:\WINDOWS\system\MMSYSTEM.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\graftabl.com
2017-02-15 08:16 - 2016-07-16 09:26 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2017-02-15 08:16 - 2016-07-16 09:26 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00050648 _____ C:\WINDOWS\system32\COMMAND.COM
2017-02-15 08:16 - 2016-07-16 09:26 - 00047840 _____ (Microsoft Corporation) C:\WINDOWS\system32\USER.EXE
2017-02-15 08:16 - 2016-07-16 09:26 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\pmspl.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00042809 _____ C:\WINDOWS\system32\KEY01.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00042592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole2.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00042537 _____ C:\WINDOWS\system32\KEYBOARD.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDEML.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00039274 _____ C:\WINDOWS\system32\mem.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2017-02-15 08:16 - 2016-07-16 09:26 - 00035776 _____ C:\WINDOWS\system32\NTIO411.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00035552 _____ C:\WINDOWS\system32\NTIO412.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00034688 _____ C:\WINDOWS\system32\NTIO804.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00034688 _____ C:\WINDOWS\system32\NTIO404.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00033968 _____ C:\WINDOWS\system32\NTIO.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00032816 _____ (Microsoft Corporation) C:\WINDOWS\system32\COMMDLG.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00032816 _____ (Microsoft Corporation) C:\WINDOWS\system\COMMDLG.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00028112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DRWATSON.EXE
2017-02-15 08:16 - 2016-07-16 09:26 - 00027866 _____ C:\WINDOWS\system32\NTDOS.SYS
2017-02-15 08:16 - 2016-07-16 09:26 - 00027792 _____ (Microsoft Corporation) C:\WINDOWS\system32\compobj.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00027200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ctl3dv2.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\GDI.EXE
2017-02-15 08:16 - 2016-07-16 09:26 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\OLESVR.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system\OLESVR.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdmredir.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00021232 _____ C:\WINDOWS\system32\graphics.pro
2017-02-15 08:16 - 2016-07-16 09:26 - 00020634 _____ C:\WINDOWS\system32\debug.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00019694 _____ C:\WINDOWS\system32\GRAPHICS.COM
2017-02-15 08:16 - 2016-07-16 09:26 - 00018896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysedit.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00018832 _____ C:\WINDOWS\system32\v7vga.rom
2017-02-15 08:16 - 2016-07-16 09:26 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdmd.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00014710 _____ C:\WINDOWS\system32\KB16.COM
2017-02-15 08:16 - 2016-07-16 09:26 - 00013888 _____ (Microsoft Corporation) C:\WINDOWS\system32\TOOLHELP.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00012704 _____ (Microsoft Corporation) C:\WINDOWS\system\WFWNET.DRV
2017-02-15 08:16 - 2016-07-16 09:26 - 00011753 _____ C:\WINDOWS\system32\setver.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00010790 _____ C:\WINDOWS\system32\EDIT.HLP
2017-02-15 08:16 - 2016-07-16 09:26 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00009936 _____ (Microsoft Corporation) C:\WINDOWS\system32\lzexpand.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00009936 _____ (Microsoft Corporation) C:\WINDOWS\system\lzexpand.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WIFEMAN.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2017-02-15 08:16 - 2016-07-16 09:26 - 00009008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ver.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00009008 _____ (Microsoft Corporation) C:\WINDOWS\system\ver.dll
2017-02-15 08:16 - 2016-07-16 09:26 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\win.com
2017-02-15 08:16 - 2016-07-16 09:26 - 00007052 _____ C:\WINDOWS\system32\nlsfunc.exe
2017-02-15 08:16 - 2016-07-16 09:26 - 00005532 _____ (Microsoft Corporation) C:\WINDOWS\system\stdole.tlb
2017-02-15 08:16 - 2016-07-16 09:26 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WINNLS.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHELL.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system\SHELL.DLL
2017-02-15 08:16 - 2016-07-16 09:26 - 00004208 _____ (Microsoft Corporation) C:\WINDOWS\system32\storage.dll
2017-02-15 08:15 - 2016-07-16 09:26 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2017-02-15 08:15 - 2016-07-16 09:26 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2017-02-15 08:15 - 2016-07-16 09:26 - 00092320 _____ (Microsoft Corporation) C:\WINDOWS\system32\krnl386.exe
2017-02-15 08:15 - 2016-07-16 09:26 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\olecli.dll
2017-02-15 08:15 - 2016-07-16 09:26 - 00068992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMSYSTEM.DLL
2017-02-15 08:15 - 2016-07-16 09:26 - 00053600 _____ C:\WINDOWS\system32\dosx.exe
2017-02-15 08:15 - 2016-07-16 09:26 - 00029370 _____ C:\WINDOWS\system32\NTDOS411.SYS
2017-02-15 08:15 - 2016-07-16 09:26 - 00029274 _____ C:\WINDOWS\system32\NTDOS412.SYS
2017-02-15 08:15 - 2016-07-16 09:26 - 00029146 _____ C:\WINDOWS\system32\NTDOS804.SYS
2017-02-15 08:15 - 2016-07-16 09:26 - 00029146 _____ C:\WINDOWS\system32\NTDOS404.SYS
2017-02-15 08:15 - 2016-07-16 09:26 - 00028420 _____ C:\WINDOWS\system32\bios1.rom
2017-02-15 08:15 - 2016-07-16 09:26 - 00027097 _____ C:\WINDOWS\system32\country.sys
2017-02-15 08:15 - 2016-07-16 09:26 - 00013312 _____ C:\WINDOWS\system32\win87em.dll
2017-02-15 08:15 - 2016-07-16 09:26 - 00012704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFWNET.DRV
2017-02-15 08:15 - 2016-07-16 09:26 - 00012642 _____ C:\WINDOWS\system32\edlin.exe
2017-02-15 08:15 - 2016-07-16 09:26 - 00012498 _____ C:\WINDOWS\system32\append.exe
2017-02-15 08:15 - 2016-07-16 09:26 - 00010544 _____ (Microsoft Corporation) C:\WINDOWS\system32\COMM.drv
2017-02-15 08:15 - 2016-07-16 09:26 - 00009029 _____ C:\WINDOWS\system32\ANSI.SYS
2017-02-15 08:15 - 2016-07-16 09:26 - 00008424 _____ C:\WINDOWS\system32\exe2bin.exe
2017-02-15 08:15 - 2016-07-16 09:26 - 00008191 _____ C:\WINDOWS\system32\bios4.rom
2017-02-15 08:15 - 2016-07-16 09:26 - 00004768 _____ C:\WINDOWS\system32\HIMEM.SYS
2017-02-15 08:07 - 2016-05-05 10:16 - 00000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2017-02-14 23:58 - 2012-04-01 16:55 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-14 23:52 - 2016-12-02 23:13 - 00000000 ___HD C:\$WINDOWS.~BT
2017-02-14 18:58 - 2010-11-16 08:46 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-02-14 13:47 - 2011-06-07 14:04 - 133456224 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-14 10:35 - 2015-05-20 17:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-14 07:33 - 2012-05-10 07:41 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-02-13 19:09 - 2012-08-03 10:25 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-02-13 16:15 - 2015-05-23 08:10 - 00000877 ____H C:\WINDOWS\EPMBatch.ept
2017-02-13 16:06 - 2015-05-19 18:10 - 00000000 ____D C:\ProgramData\MFAData
2017-02-13 15:58 - 2010-11-16 08:41 - 00000000 ____D C:\Program Files\Microsoft Office
2017-02-13 14:54 - 2011-06-15 17:18 - 00000000 ____D C:\Program Files\Java
2017-02-13 14:51 - 2015-05-23 00:04 - 00095808 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2017-02-13 14:48 - 2015-05-21 07:01 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-13 12:31 - 2014-03-14 12:34 - 00000000 ____D C:\Program Files\Canon
2017-02-13 12:28 - 2014-03-19 12:25 - 00000000 ___HD C:\ProgramData\CanonIJScan
2017-02-13 12:11 - 2016-07-31 18:58 - 00000000 ____D C:\Program Files\Steam

==================== Files in the root of some directories =======

2012-12-11 16:51 - 2012-12-11 16:53 - 0000085 ___SH () C:\ProgramData\.zreglib
2017-02-15 08:37 - 2017-02-15 08:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2011-07-24 10:53 - 2011-07-24 10:53 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2012-05-21 11:04 - 2012-05-21 11:04 - 0000094 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-02-15 08:35

==================== End of FRST.txt ============================
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 16 úno 2017 09:18

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-02-2017 02
Ran by Chvála Pánu (16-02-2017 09:15:14)
Running from C:\Users\Chvála Pánu\Desktop
Microsoft Windows 10 Home Version 1607 (X86) (2017-02-15 08:17:00)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3838077319-2819224973-1163748220-500 - Administrator - Disabled)
Chvála Pánu (S-1-5-21-3838077319-2819224973-1163748220-1697 - Administrator - Enabled) => C:\Users\Chvála Pánu
DefaultAccount (S-1-5-21-3838077319-2819224973-1163748220-503 - Limited - Disabled)
Guest (S-1-5-21-3838077319-2819224973-1163748220-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Aktualizace NVIDIA 17.12.8 (Version: 17.12.8 - NVIDIA Corporation) Hidden
AVG PC TuneUp (Version: 16.72.3 - AVG Technologies) Hidden
AVG Zen (Version: 1.113.1 - AVG Technologies) Hidden
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Java 8 Update 121 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
K-Lite Codec Pack 11.4.3 Full (HKLM\...\KLiteCodecPack_is1) (Version: 11.4.3 - )
Malwarebytes verze 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3838077319-2819224973-1163748220-1697\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 CSY (HKLM\...\{E8BEDB28-151D-465C-9BE0-F6EB930A629C}) (Version: 4.0.8482.1 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 51.0.1 (x86 cs) (HKLM\...\Mozilla Firefox 51.0.1 (x86 cs)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 51.0.1 - Mozilla)
NVIDIA GeForce Experience 2.2.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 342.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 342.01 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 342.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 342.01 - NVIDIA Corporation)
Ovládací panel NVIDIA 342.01 (Version: 342.01 - NVIDIA Corporation) Hidden
PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.17.304.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
Sophos Virus Removal Tool (HKLM\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM\...\{068B46A0-8858-4CEB-80BC-A4AE787A05FC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Zemana AntiMalware (HKLM\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.101 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01781431-650D-4DBE-873C-EBCA49288CBF} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe
Task: {01EF3D11-EAC5-43DB-AECB-9B8D39F8E8EC} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {0CAB5C7A-7866-4A21-BB17-11549759FA8B} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-12-12] (Oracle Corporation)
Task: {15BF56F8-9848-4AEE-8EB6-0146B174DEC8} - System32\Tasks\{B1FDE1FB-93A4-4B2F-A03B-CA3E8EBA00F2} => pcalua.exe -a C:\Users\Tomik\AppData\Local\Temp\Temp1_VirtualDub-1.10.4.zip\auxsetup.exe <==== ATTENTION
Task: {1B999E3F-3ECB-408F-946B-53F6D5B8EE7A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2B5C289C-918C-4CAE-AAD3-EBC5596F9D09} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe
Task: {2BF50089-FFFB-468B-895B-A2B6B8F25854} - System32\Tasks\{B87A1CDF-EFE9-419E-9B48-7D92101BA160} => pcalua.exe -a C:\Users\Tomik\Desktop\SindicateFULL109.exe -d C:\Users\Tomik\Desktop
Task: {33EB26F7-0C13-4D03-B714-79289C0575F0} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe
Task: {39195C4B-D9F8-4ABD-A686-8D2DF6BD6777} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe
Task: {3E5CE880-8BD3-443C-B2F8-0F34ED94EB54} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {40D1E1A0-28B5-4C4E-B57E-897F4DF39AED} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {460186DC-1CFE-4846-A3F2-89CB13B37629} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe
Task: {52A6A446-72D1-4A93-98CD-DCEF4CAD18DB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-14] (Adobe Systems Incorporated)
Task: {53469E19-9446-467E-9B84-48C550880495} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe
Task: {6113673B-EDD2-44A1-BBEA-F9B6573F73D3} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe
Task: {632EA38F-FA4C-4AAB-8406-7780B235E895} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {64084C01-7B33-4C6E-97C2-9BA2DDF195E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {66F19EBC-BFB6-4488-8309-A99C79292AD3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe
Task: {689A207C-EFDF-4562-BB89-B717615A85C3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6B530CA4-BEB6-4A8B-B073-8B96B86B75FE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe
Task: {73676AB8-E517-4120-B870-2C15D592FC03} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {7904B625-C9AA-4069-86E5-4FBEE592FF22} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {79F0B499-2935-43BE-93E4-F951589F68AA} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {820B555D-399F-48D8-A155-FFE878FFDF16} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => P:\AVG\AVG PC TuneUp\tuscanx.exe
Task: {82B7CFB7-AC90-40A1-9BFE-E8F795D9E724} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {8A7F0E4F-EAA7-4C14-BB9D-68D82E4BF6E8} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {8BAEF54E-3B9A-4492-B900-ED204476F430} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe
Task: {8BCF9965-0B1A-4453-A95E-043C918502CC} - System32\Tasks\{4F7DCE87-8229-4FB5-B1F9-2AD9F3034726} => pcalua.exe -a D:\Autorun\HAutoRun.exe -d D:\Autorun
Task: {8E034094-4614-4E93-BA1F-0DDD23F5E4D9} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe
Task: {90E5143C-445E-4984-BDCD-4BF9FD4FB4CA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe
Task: {9A130DEF-C370-49C2-AE8E-BCF0653A5A9A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {A0826DD5-E312-43EF-A1D9-568596A03FAC} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {A1139BED-C955-4DF2-9F8B-7540A04DC53B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A2E13DEC-9981-428F-B70A-B6EE9B926253} - System32\Tasks\{666CD5F8-F210-40A2-9F81-E6FF75ADC606} => pcalua.exe -a "C:\Users\Tomik\Desktop\Downloads\c\Users\Tomik\Desktop\Downloads\Age of Empires 2\age2upa.exe" -d "C:\Users\Tomik\Desktop\Downloads\c\Users\Tomik\Desktop\Downloads\Age of Empires 2"
Task: {A5E87B6E-9F42-4F66-84A4-8953FA763F24} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {B4FEE306-2481-4093-9DB6-9CBE351ED4C1} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe
Task: {B6D1241E-5F7F-4A23-B256-3A813DB4FEE5} - System32\Tasks\{290367C5-C01D-421F-B895-DB8DECEA4516} => pcalua.exe -a "C:\Users\Tomik\Downloads\EVEREST Home Edition\everest.exe" -d "C:\Users\Tomik\Downloads\EVEREST Home Edition"
Task: {BBA54EC9-44FE-4CAD-9AE7-C445440D25DA} - System32\Tasks\{6FFE22F2-4C31-4323-8B23-B981BEF46D46} => pcalua.exe -a C:\Users\Tomik\Desktop\ytd-1.37.exe -d C:\Users\Tomik\Desktop
Task: {BC4BAF69-1277-40DC-84E6-BE9DA584C843} - System32\Tasks\{F7B5B9FF-E66B-48DC-B90E-78430C08594E} => pcalua.exe -a "T:\Prográmky\EVEREST Home Edition\everest.exe" -d "T:\Prográmky\EVEREST Home Edition"
Task: {BDF185D0-CCA2-4167-B8BC-71E632A0AC0C} - System32\Tasks\{0D937996-70A1-4B36-A288-00AABEAC4156} => pcalua.exe -a "P:\EVEREST Home Edition\everest.exe" -d C:\Users\Tomik\Desktop
Task: {BF24F331-2923-4F62-8FD9-6B175C3805D0} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe
Task: {C4E8D4B0-AE4B-4A2F-83B3-3D1EFB1F13FA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {C83B6322-C2F3-4887-BE4D-E3ACDCB344C7} - System32\Tasks\{E8A00FDD-03CB-4974-AEE7-B28A855B7358} => pcalua.exe -a P:\FreeRapid\FreeRapid-0.85u1-build566\frd.exe -d P:\FreeRapid\FreeRapid-0.85u1-build566
Task: {C9364727-081F-485E-A734-A880BCE99FC7} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {C9B5C952-D12F-41B9-850B-D5BF1A7711CC} - System32\Tasks\{AF11359B-82C7-4EBA-9C59-5F2911F8F80B} => pcalua.exe -a C:\Users\Tomik\Desktop\frd.exe -d C:\Users\Tomik\Desktop
Task: {C9DF9660-2157-4AAD-92EF-A1B8CBF3B530} - System32\Tasks\{270845DA-A1DA-41CC-95EC-A8B66C756A90} => p:\Skype\Phone\Skype.exe
Task: {D468D93C-F364-4252-AD90-337923EF02B4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {D72BEC5C-E6B2-4F20-BD25-8521541D6A55} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe
Task: {DB530E4A-4403-48E1-8798-1D5DA1850F3E} - System32\Tasks\{62E92679-FDE0-4673-BEC4-4CF296AB7901} => pcalua.exe -a C:\Users\Tomik\Desktop\mp3gain-win-1_2_5.exe -d "p:\Mozilla Firefox"
Task: {E08C3482-A048-4839-8843-0A6650051316} - System32\Tasks\{377BD869-0773-4BB7-B609-AC2CE1A13647} => pcalua.exe -a "C:\Users\Tomik\Desktop\Nová složka\crack-internet-download-manager\SETUP FULL.exe" -d "C:\Users\Tomik\Desktop\Nová složka\crack-internet-download-manager"
Task: {E247D758-79EA-4368-A5BF-62824F73765C} - System32\Tasks\Adobe online aktualizační program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {E2A1863E-1A06-48D0-9C40-687614D1EA65} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe
Task: {E36CCC6E-F43A-4BA1-99E4-8BF051F4AD40} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {EED64996-E090-4D09-8C1D-2C5D3BA13BE1} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec.exe
Task: {F2329497-D718-470A-A280-757EFB71A935} - System32\Tasks\{58A3C637-E062-4809-B08D-21A333A68FEF} => pcalua.exe -a "P:\Total Uninstall\Tun.exe" -d C:\Users\Tomik\Desktop
Task: {F5BD0655-86FA-4B11-95F6-BD33B75CA456} - System32\Tasks\{C0FB86BC-8C39-4608-A7CC-718B8AEA8BC1} => pcalua.exe -a "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" -d "P:\TuneUp Utilities 2012" -c /uninstall SINGLEIMAGE /dll OSETUP.DLL
Task: {F7CD3EDD-1D93-4122-8191-52D902A082A0} - System32\Tasks\HP online update program => P:\HP\HP Software Update\HPWuSchd2.exe
Task: {F85C1CDB-04F7-47DC-A08B-30B1E48A091B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate.exe
Task: {FFFDCD9E-FADB-4422-A60D-440DAFDED1A6} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2016-07-16 09:25 - 2016-07-16 09:25 - 00190976 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-02-15 18:49 - 2016-12-09 11:11 - 02048496 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-02-15 08:38 - 2016-11-14 12:00 - 00123448 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-07-28 08:41 - 2015-07-28 08:41 - 00075136 _____ () C:\Windows\system32\PnkBstrA.exe
2017-02-15 18:49 - 2016-12-09 11:11 - 02048496 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-07-16 09:25 - 2016-07-16 09:25 - 00108032 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-02-15 18:48 - 2016-12-21 05:42 - 00321536 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-02-15 18:49 - 2016-12-21 05:25 - 06726656 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-02-15 18:49 - 2016-12-21 05:21 - 01150464 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-20 14:11 - 2016-11-20 14:11 - 00526848 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-02-15 18:49 - 2016-12-21 05:22 - 01724928 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-02-15 18:49 - 2016-12-21 05:24 - 03158016 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118]
AlternateDataStreams: C:\ProgramData\TEMP:A4510F75 [114]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2017-02-15 18:28 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3838077319-2819224973-1163748220-1697\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 185.160.208.50 - 78.108.152.158
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run: => "ProductUpdater"
HKLM\...\StartupApproved\Run: => "IJNetworkScannerSelectorEX"
HKLM\...\StartupApproved\Run: => "NvBackend"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "SunJavaUpdateSched"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) LPort=808
FirewallRules: [{29DB4542-C9E2-4D18-809D-E786E85787F0}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{32848D07-8D31-4D46-A3E5-9AAB79DEC444}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{F091758B-FA85-40BD-85AA-43D03AFEC982}] => (Allow) P:\AVG\Av\avgmfapx.exe
FirewallRules: [{AA0E6C28-EBDE-40DB-B2D4-B6B9F92A5CBF}] => (Allow) P:\AVG\Av\avgmfapx.exe
FirewallRules: [{1753691D-1E68-4AFC-980F-E47EB17FFE0C}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{2D3319B1-40CE-457D-A5ED-4647582E9853}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{C5A8BCC5-17C7-4430-93DA-EBE3A8F0E8A8}] => (Allow) C:\Windows\System32\PnkBstrA.exe
FirewallRules: [{0004C743-6E61-417C-A178-CDFEF1CD71B7}] => (Allow) C:\Windows\System32\PnkBstrA.exe
FirewallRules: [{5F406705-83B4-4D68-B317-FE71BBDCF0C4}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{3429B3B2-AE23-489E-B2F7-8FD3C5232586}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A02B107C-F86A-4734-B5FD-706936066617}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{8175B86D-47A4-4F6A-BA05-7C1389370321}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{0DC65C1D-5837-4291-9771-0D9CDF1C5861}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9D77CEF9-F864-4DDC-AA8D-EF43C893BC12}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/16/2017 07:07:55 AM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dll se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dll na řádku 2.
Neplatná syntaxe XML.

Error: (02/16/2017 07:07:11 AM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dll se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dll na řádku 2.
Neplatná syntaxe XML.

Error: (02/15/2017 10:19:27 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
Spouštění asynchronní operace

Kontext:
Aktuální stav: DoSnapshotSet

Error: (02/15/2017 10:18:44 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (02/15/2017 10:18:36 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {e25f1deb-3268-4799-9b6c-42bbac232f4e}

Error: (02/15/2017 04:51:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (02/15/2017 04:33:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: wmiprvse.exe, verze: 10.0.14393.0, časové razítko: 0x57898ff5
Název chybujícího modulu: ntdll.dll, verze: 10.0.14393.447, časové razítko: 0x5819be97
Kód výjimky: 0xc0000374
Posun chyby: 0x000ed9ac
ID chybujícího procesu: 0x26fc
Čas spuštění chybující aplikace: 0x01d287a0986f7aa0
Cesta k chybující aplikaci: C:\WINDOWS\system32\wbem\wmiprvse.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: 69f94d9d-588f-450f-9928-24d6db4cf8bf
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (02/15/2017 09:31:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: firefox.exe, verze: 51.0.1.6234, časové razítko: 0x5888f28c
Název chybujícího modulu: mozglue.dll, verze: 51.0.1.6234, časové razítko: 0x5888f27e
Kód výjimky: 0x80000003
Posun chyby: 0x0000ec83
ID chybujícího procesu: 0x1aa8
Čas spuštění chybující aplikace: 0x01d287648768e5ea
Cesta k chybující aplikaci: C:\Program Files\Mozilla Firefox\firefox.exe
Cesta k chybujícímu modulu: C:\Program Files\Mozilla Firefox\mozglue.dll
ID zprávy: b8e7d70f-8ddb-4fcc-9834-27684abaec22
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (02/15/2017 09:05:52 AM) (Source: MSDTC Client 2) (EventID: 4104) (User: )
Description: Pokus získat stav uzlu clusteru se nezdařil. Vrácený kód chyby: 0x8007085A

Error: (02/15/2017 09:05:43 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Zprostředkovatel událostí wsp_sr se pokusil zaregistrovat dotaz select * from WSP_ReplicationGroupModificationEvent, jehož cílová třída WSP_ReplicationGroupModificationEvent v oboru názvů //./ROOT/Microsoft/Windows/Storage/Providers_v2 neexistuje. Dotaz bude ignorován.


System errors:
=============
Error: (02/16/2017 07:01:24 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba CDPUserSvc_3bef8 byla ukončena s následující chybou:
Nespecifikovaná chyba

Error: (02/16/2017 07:01:20 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/16/2017 07:01:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/16/2017 07:01:10 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a69\??\C:\Users\Chvála Pánu\AppData\Local\Microsoft\Windows\UsrClass.dat

Error: (02/16/2017 07:00:59 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetTcpActivator závisí na službě NetTcpPortSharing, která neuspěla při spuštění v důsledku následující chyby:
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.

Error: (02/15/2017 08:29:40 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače LENOVO-PC,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{22238426-BADF-4F4A-A897-CDAF3C9F.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (02/15/2017 07:19:09 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/15/2017 07:19:09 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/15/2017 07:19:09 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba CDPUserSvc_1aedfd byla ukončena s následující chybou:
Nespecifikovaná chyba

Error: (02/15/2017 07:17:07 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetTcpActivator závisí na službě NetTcpPortSharing, která neuspěla při spuštění v důsledku následující chyby:
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.


CodeIntegrity:
===================================
Date: 2017-02-15 16:25:30.667
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 16:25:30.662
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 16:25:30.604
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 10:58:14.615
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 10:58:14.610
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 10:58:14.585
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 09:31:38.532
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 09:31:38.525
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 09:31:38.479
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Atom(TM) CPU D525 @ 1.80GHz
Percentage of memory in use: 37%
Total physical RAM: 3071.18 MB
Available physical RAM: 1904.94 MB
Total Virtual: 4351.18 MB
Available Virtual: 3011.1 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:164.75 GB) (Free:128.14 GB) NTFS
Drive i: (Interní) (Fixed) (Total:300.47 GB) (Free:300.34 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5054D2BA)
Partition 1: (Active) - (Size=101 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=164.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=300.5 GB) - (Type=OF Extended)

==================== End of Addition.txt ============================
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 16 úno 2017 19:00

Odinstaluj:
AVG PC TuneUp
TuneUp Utilities 2012



Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
SearchScopes: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
FF Plugin: @pages.tvunetworks.com/WebPlayer -> p:\TVUPlayer\npTVUAx.dll [No File]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
U3 aswMBR; C:\Users\Chvála Pánu\AppData\Local\Temp\aswMBR.sys [56704 2017-02-16] () [File not signed] <==== ATTENTION
U3 aswVmm; C:\Users\Chvála Pánu\AppData\Local\Temp\aswVmm.sys [192224 2017-02-16] () <==== ATTENTION
U3 idsvc; no ImagePath
C:\Users\Chvála Pánu\Desktop\AvgInstallLog.cab
C:\Users\Default\AppData\Local\AVG
C:\Users\Default User\AppData\Roaming\TuneUp Software
C:\Users\Default User\AppData\Local\AVG
C:\ProgramData\DP45977C.lfl
C:\Users\Chvála Pánu\AppData\Local\AvgSetupLog
C:\Users\Chvála Pánu\AppData\Local\AVG
C:\Users\Chvála Pánu\AppData\Roaming\TuneUp Software
C:\ProgramData\ezsidmv.dat
C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
Task: {15BF56F8-9848-4AEE-8EB6-0146B174DEC8} - System32\Tasks\{B1FDE1FB-93A4-4B2F-A03B-CA3E8EBA00F2} => pcalua.exe -a C:\Users\Tomik\AppData\Local\Temp\Temp1_VirtualDub-1.10.4.zip\auxsetup.exe <==== ATTENTION
Task: {1B999E3F-3ECB-408F-946B-53F6D5B8EE7A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {40D1E1A0-28B5-4C4E-B57E-897F4DF39AED} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {632EA38F-FA4C-4AAB-8406-7780B235E895} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {64084C01-7B33-4C6E-97C2-9BA2DDF195E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {689A207C-EFDF-4562-BB89-B717615A85C3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {73676AB8-E517-4120-B870-2C15D592FC03} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {7904B625-C9AA-4069-86E5-4FBEE592FF22} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {820B555D-399F-48D8-A155-FFE878FFDF16} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => P:\AVG\AVG PC TuneUp\tuscanx.exe
Task: {8A7F0E4F-EAA7-4C14-BB9D-68D82E4BF6E8} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {8BCF9965-0B1A-4453-A95E-043C918502CC} - System32\Tasks\{4F7DCE87-8229-4FB5-B1F9-2AD9F3034726} => pcalua.exe -a D:\Autorun\HAutoRun.exe -d D:\Autorun
Task: {9A130DEF-C370-49C2-AE8E-BCF0653A5A9A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {A1139BED-C955-4DF2-9F8B-7540A04DC53B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A5E87B6E-9F42-4F66-84A4-8953FA763F24} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C4E8D4B0-AE4B-4A2F-83B3-3D1EFB1F13FA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {C9364727-081F-485E-A734-A880BCE99FC7} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {E08C3482-A048-4839-8843-0A6650051316} - System32\Tasks\{377BD869-0773-4BB7-B609-AC2CE1A13647} => pcalua.exe -a "C:\Users\Tomik\Desktop\Nová složka\crack-internet-download-manager\SETUP FULL.exe" -d "C:\Users\Tomik\Desktop\Nová složka\crack-internet-download-manager"
Task: {E36CCC6E-F43A-4BA1-99E4-8BF051F4AD40} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118]
AlternateDataStreams: C:\ProgramData\TEMP:A4510F75 [114]
FirewallRules: [{F091758B-FA85-40BD-85AA-43D03AFEC982}] => (Allow) P:\AVG\Av\avgmfapx.exe
FirewallRules: [{AA0E6C28-EBDE-40DB-B2D4-B6B9F92A5CBF}] => (Allow) P:\AVG\Av\avgmfapx.exe

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 16 úno 2017 19:16

AVG PC TuneUp
TuneUp Utilities 2012 v PC nemám a není ani "odinstalovat progamy."

ix result of Farbar Recovery Scan Tool (x86) Version: 15-02-2017 02
Ran by Chvála Pánu (16-02-2017 19:10:12) Run:1
Running from C:\Users\Chvála Pánu\Desktop
Loaded Profiles: Chvála Pánu (Available Profiles: Chvála Pánu)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
SearchScopes: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3838077319-2819224973-1163748220-1697 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
FF Plugin: @pages.tvunetworks.com/WebPlayer -> p:\TVUPlayer\npTVUAx.dll [No File]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
U3 aswMBR; C:\Users\Chvála Pánu\AppData\Local\Temp\aswMBR.sys [56704 2017-02-16] () [File not signed] <==== ATTENTION
U3 aswVmm; C:\Users\Chvála Pánu\AppData\Local\Temp\aswVmm.sys [192224 2017-02-16] () <==== ATTENTION
U3 idsvc; no ImagePath
C:\Users\Chvála Pánu\Desktop\AvgInstallLog.cab
C:\Users\Default\AppData\Local\AVG
C:\Users\Default User\AppData\Roaming\TuneUp Software
C:\Users\Default User\AppData\Local\AVG
C:\ProgramData\DP45977C.lfl
C:\Users\Chvála Pánu\AppData\Local\AvgSetupLog
C:\Users\Chvála Pánu\AppData\Local\AVG
C:\Users\Chvála Pánu\AppData\Roaming\TuneUp Software
C:\ProgramData\ezsidmv.dat
C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
Task: {15BF56F8-9848-4AEE-8EB6-0146B174DEC8} - System32\Tasks\{B1FDE1FB-93A4-4B2F-A03B-CA3E8EBA00F2} => pcalua.exe -a C:\Users\Tomik\AppData\Local\Temp\Temp1_VirtualDub-1.10.4.zip\auxsetup.exe <==== ATTENTION
Task: {1B999E3F-3ECB-408F-946B-53F6D5B8EE7A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {40D1E1A0-28B5-4C4E-B57E-897F4DF39AED} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {632EA38F-FA4C-4AAB-8406-7780B235E895} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {64084C01-7B33-4C6E-97C2-9BA2DDF195E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {689A207C-EFDF-4562-BB89-B717615A85C3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {73676AB8-E517-4120-B870-2C15D592FC03} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {7904B625-C9AA-4069-86E5-4FBEE592FF22} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {820B555D-399F-48D8-A155-FFE878FFDF16} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => P:\AVG\AVG PC TuneUp\tuscanx.exe
Task: {8A7F0E4F-EAA7-4C14-BB9D-68D82E4BF6E8} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {8BCF9965-0B1A-4453-A95E-043C918502CC} - System32\Tasks\{4F7DCE87-8229-4FB5-B1F9-2AD9F3034726} => pcalua.exe -a D:\Autorun\HAutoRun.exe -d D:\Autorun
Task: {9A130DEF-C370-49C2-AE8E-BCF0653A5A9A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {A1139BED-C955-4DF2-9F8B-7540A04DC53B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A5E87B6E-9F42-4F66-84A4-8953FA763F24} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C4E8D4B0-AE4B-4A2F-83B3-3D1EFB1F13FA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {C9364727-081F-485E-A734-A880BCE99FC7} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {E08C3482-A048-4839-8843-0A6650051316} - System32\Tasks\{377BD869-0773-4BB7-B609-AC2CE1A13647} => pcalua.exe -a "C:\Users\Tomik\Desktop\Nová složka\crack-internet-download-manager\SETUP FULL.exe" -d "C:\Users\Tomik\Desktop\Nová složka\crack-internet-download-manager"
Task: {E36CCC6E-F43A-4BA1-99E4-8BF051F4AD40} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118]
AlternateDataStreams: C:\ProgramData\TEMP:A4510F75 [114]
FirewallRules: [{F091758B-FA85-40BD-85AA-43D03AFEC982}] => (Allow) P:\AVG\Av\avgmfapx.exe
FirewallRules: [{AA0E6C28-EBDE-40DB-B2D4-B6B9F92A5CBF}] => (Allow) P:\AVG\Av\avgmfapx.exe

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKU\S-1-5-21-3838077319-2819224973-1163748220-1697\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-21-3838077319-2819224973-1163748220-1697\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => key removed successfully.
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93} => key removed successfully.
HKCR\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93} => key not found.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} => key removed successfully.
HKCR\CLSID\{CAFEEFAC-0018-0000-0045-ABCDEFFEDCBA} => key not found.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} => key removed successfully.
HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} => key not found.
HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer => key removed successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => key removed successfully.
aswMBR => service not found.
aswVmm => service not found.
HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully.
idsvc => service removed successfully.
C:\Users\Chvála Pánu\Desktop\AvgInstallLog.cab => moved successfully
C:\Users\Default\AppData\Local\AVG => moved successfully
C:\Users\Default User\AppData\Roaming\TuneUp Software => moved successfully
"C:\Users\Default User\AppData\Local\AVG" => not found.
C:\ProgramData\DP45977C.lfl => moved successfully
C:\Users\Chvála Pánu\AppData\Local\AvgSetupLog => moved successfully
C:\Users\Chvála Pánu\AppData\Local\AVG => moved successfully
C:\Users\Chvála Pánu\AppData\Roaming\TuneUp Software => moved successfully
C:\ProgramData\ezsidmv.dat => moved successfully
C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15BF56F8-9848-4AEE-8EB6-0146B174DEC8} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15BF56F8-9848-4AEE-8EB6-0146B174DEC8} => key removed successfully.
C:\Windows\System32\Tasks\{B1FDE1FB-93A4-4B2F-A03B-CA3E8EBA00F2} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B1FDE1FB-93A4-4B2F-A03B-CA3E8EBA00F2} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1B999E3F-3ECB-408F-946B-53F6D5B8EE7A} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B999E3F-3ECB-408F-946B-53F6D5B8EE7A} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40D1E1A0-28B5-4C4E-B57E-897F4DF39AED} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40D1E1A0-28B5-4C4E-B57E-897F4DF39AED} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{632EA38F-FA4C-4AAB-8406-7780B235E895} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{632EA38F-FA4C-4AAB-8406-7780B235E895} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{64084C01-7B33-4C6E-97C2-9BA2DDF195E2} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{64084C01-7B33-4C6E-97C2-9BA2DDF195E2} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{689A207C-EFDF-4562-BB89-B717615A85C3} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{689A207C-EFDF-4562-BB89-B717615A85C3} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{73676AB8-E517-4120-B870-2C15D592FC03} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73676AB8-E517-4120-B870-2C15D592FC03} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7904B625-C9AA-4069-86E5-4FBEE592FF22} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7904B625-C9AA-4069-86E5-4FBEE592FF22} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{820B555D-399F-48D8-A155-FFE878FFDF16} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{820B555D-399F-48D8-A155-FFE878FFDF16} => key removed successfully.
C:\Windows\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8A7F0E4F-EAA7-4C14-BB9D-68D82E4BF6E8} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A7F0E4F-EAA7-4C14-BB9D-68D82E4BF6E8} => key removed successfully.
C:\Windows\System32\Tasks\AVG EUpdate Task => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG EUpdate Task => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8BCF9965-0B1A-4453-A95E-043C918502CC} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BCF9965-0B1A-4453-A95E-043C918502CC} => key removed successfully.
C:\Windows\System32\Tasks\{4F7DCE87-8229-4FB5-B1F9-2AD9F3034726} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4F7DCE87-8229-4FB5-B1F9-2AD9F3034726} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A130DEF-C370-49C2-AE8E-BCF0653A5A9A} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A130DEF-C370-49C2-AE8E-BCF0653A5A9A} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1139BED-C955-4DF2-9F8B-7540A04DC53B} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1139BED-C955-4DF2-9F8B-7540A04DC53B} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A5E87B6E-9F42-4F66-84A4-8953FA763F24} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A5E87B6E-9F42-4F66-84A4-8953FA763F24} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4E8D4B0-AE4B-4A2F-83B3-3D1EFB1F13FA} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E8D4B0-AE4B-4A2F-83B3-3D1EFB1F13FA} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C9364727-081F-485E-A734-A880BCE99FC7} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9364727-081F-485E-A734-A880BCE99FC7} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E08C3482-A048-4839-8843-0A6650051316} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E08C3482-A048-4839-8843-0A6650051316} => key removed successfully.
C:\Windows\System32\Tasks\{377BD869-0773-4BB7-B609-AC2CE1A13647} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{377BD869-0773-4BB7-B609-AC2CE1A13647} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E36CCC6E-F43A-4BA1-99E4-8BF051F4AD40} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E36CCC6E-F43A-4BA1-99E4-8BF051F4AD40} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key removed successfully.
C:\ProgramData\TEMP => ":56E2E879" ADS removed successfully..
C:\ProgramData\TEMP => ":A4510F75" ADS removed successfully..
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F091758B-FA85-40BD-85AA-43D03AFEC982} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AA0E6C28-EBDE-40DB-B2D4-B6B9F92A5CBF} => value removed successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 6578220 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8449873 B
Java, Flash, Steam htmlcache => 492 B
Windows/system/drivers => 244138305 B
Edge => 14892655 B
Chrome => 0 B
Firefox => 89759690 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 12814 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
LocalService => 0 B
NetworkService => 5184 B
Chvála Pánu => 7713662 B

RecycleBin => 3437 B
EmptyTemp: => 354.3 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:10:52 ====
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 16 úno 2017 19:18

Zkus to avg nainstalovat.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 16 úno 2017 19:21

Stále to píše tu cestu P/ AVG Nejde to.

0xE001003E: Zadaná cesta nebyla nalezena.
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 16 úno 2017 21:04

Použij tohle:
http://download.avg.com/filedir/util/AVG_Remover.exe
We are sorry to know that you are unable to uninstall AVG, please do not worry, you can use this AVG remover tool to completely remove all the traces of AVG from your computer. Use this link to download and run the AVG Remover tool http://download.avg.com/filedir/util/AVG_Remover.exe
Note: Once the removal of AVG is complete, go to C Drive and delete the AVG
https://support.avg.com/answers?id=906b000000057ljAAA
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 6 hostů