Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 05 bře 2017 19:08

Nic nepomohlo. je to stejný
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 bře 2017 19:13

A co si dělal? Bod obnovy nejde? V nouz. režimu?

Udělej znovu CDI.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 05 bře 2017 21:19

jerabina píše:Zkus deaktivovat všechny bezpečnostní prvky tj. antivir, firewall atd.
Poté zkus obnovit systém.

Pokud problémy přetrvávají, proveď následující a zkus obnovit systém:
Ověříme integritu a úplnost všech systémových souborů:
- Zmáčkni Win + R najednou
- vepiš do spuštění "cmd" bez úvozovek. a stiskni Enter.
- do příkazového řádku vepiš "sfc /scannow" bez úvozovek a stiskni Enter.
- Po dokončení skenu restartuje počítač.

Pokud problémy přetrvávají, proveď následující a zkus obnovit systém:
Ověříme integritu a úplnost všech systémových souborů:
- Zmáčkni Win + R najednou
- vepiš do spuštění "cmd" bez úvozovek. a stiskni Enter.
- do příkazového řádku vepiš "chkdsk /f /r" bez úvozovek a stiskni Enter.
- Po dokončení skenu restartuje počítač.


deaktivoval jsem antivir i firewal a obnovoval systém. jak normálně tak v nouzovém režimu. Hláška byla stejná.
Potom jsem dělal bod 2 napsalo to, že se něco vyčistilo a provedl restart, tak jak při prvním, stejná hláška.
Bod3: chtělo to restart a pracovalo to v restartu. Taky se nic nezměnilo.
Kolečko jsem udělal znovu a potom už to psalo, že je vše v pořádku. Zkoušel jsem bod obnovy normálně i v nouzovém režimu. Obnovu jsem zkoušel ze 2.3., 3.3. A nakonec až z 28.2. Nic. Stále stejná hláška.


----------------------------------------------------------------------------
CrystalDiskInfo 7.0.5 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 14393] (x64)
Date : 2017/03/05 21:20:56

-- Controller Map ----------------------------------------------------------
+ Intel(R) 100 Series/C230 Chipset Family SATA AHCI Controller [ATA]
- ST1000DM003-1SB10C
- HL-DT-ST DVDRAM GH24NSD1
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) ST1000DM003-1SB10C : 1000,2 GB [0/0/0, pd1] - st

----------------------------------------------------------------------------
(1) ST1000DM003-1SB10C
----------------------------------------------------------------------------
Model : ST1000DM003-1SB10C
Firmware : CC43
Serial Number : Z9A1YF25
Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 7200 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 4
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 2133 hod.
Power On Count : 308 krát
Temperature : 34 C (93 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 8080h [ON]
AAM Level : ----
Drive Letter : B: C: F: G: P: T:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 _82 _63 __6 00000A0B5B14 Počet chyb čtení
03 _97 _97 __0 000000000000 Čas na roztočení ploten
04 100 100 _20 000000000134 Počet spuštění/zastavení
05 100 100 _10 000000000000 Počet přemapovaných sektorů
07 _79 _60 _45 000005615B1F Počet chybných hledání
09 _98 _98 __0 000000000855 Hodin v činnosti
0A 100 100 _97 000000000000 Počet opakovaných pokusů o roztočení ploten
0C 100 100 _20 000000000134 Počet cyklů zapnutí zařízení
B7 100 100 __0 000000000000 Specifický pro výrobce
B8 100 100 _99 000000000000 Ukončovacích chyb
BB 100 100 __0 000000000000 Ohlášeno neopravitelných chyb
BC 100 100 __0 000000000000 Časový limit příkazu
BD 100 100 __0 000000000000 Vysoká rychlost zápisu
BE _66 _53 _40 000024120022 Teplota toku vzduchu
C1 100 100 __0 000000000137 Počet cyklů načítání/vymazání
C2 _34 _15 __0 000F00000022 Teplota
C3 __1 __1 __0 00000A0B5B14 Počet oprav chybného čtení
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
F0 100 253 __0 D77500000853 Čas nastavování hlaviček - v hodinách
F1 100 253 __0 000251D97D08 Total Host Writes
F2 100 253 __0 0004AA72F408 Total Host Reads

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0C5A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2020 2020 2020 2020 5A39 4131 5946 3235
020: 0000 0000 0000 4343 3433 2020 2020 5354 3130 3030
030: 444D 3030 332D 3153 4231 3043 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 850E 0006 00CC 004C
080: 01F0 0029 346B 7D69 4163 3469 BC49 4163 407F 0035
090: 0035 8080 FFFE 0000 D0D0 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5000 C500
110: 90F1 791B 0000 0000 0000 0000 0000 0000 0000 401E
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 6DB0
130: 7470 6DB0 7470 2020 0002 0140 0100 5000 3C06 3C0A
140: 0000 003C 0000 0008 0000 0000 FDFF 0280 0000 0000
150: 0008 0000 0000 0000 0000 8000 0000 0184 9400 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0002 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 1085 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000
220: 0000 0000 1020 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 95A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 0A 00 01 0F 00 52 3F 14 5B 0B 0A 00 00 00 03 03
010: 00 61 61 00 00 00 00 00 00 00 04 32 00 64 64 34
020: 01 00 00 00 00 00 05 33 00 64 64 00 00 00 00 00
030: 00 00 07 0F 00 4F 3C 1F 5B 61 05 00 00 00 09 32
040: 00 62 62 55 08 00 00 00 00 00 0A 13 00 64 64 00
050: 00 00 00 00 00 00 0C 32 00 64 64 34 01 00 00 00
060: 00 00 B7 32 00 64 64 00 00 00 00 00 00 00 B8 32
070: 00 64 64 00 00 00 00 00 00 00 BB 32 00 64 64 00
080: 00 00 00 00 00 00 BC 32 00 64 64 00 00 00 00 00
090: 00 00 BD 3A 00 64 64 00 00 00 00 00 00 00 BE 22
0A0: 00 42 35 22 00 12 24 00 00 00 C1 32 00 64 64 37
0B0: 01 00 00 00 00 00 C2 22 00 22 0F 22 00 00 00 0F
0C0: 00 00 C3 1A 00 01 01 14 5B 0B 0A 00 00 00 C5 12
0D0: 00 64 64 00 00 00 00 00 00 00 C6 10 00 64 64 00
0E0: 00 00 00 00 00 00 C7 3E 00 C8 C8 00 00 00 00 00
0F0: 00 00 F0 00 00 64 FD 53 08 00 00 75 D7 2B F1 00
100: 00 64 FD 08 7D D9 51 02 00 00 F2 00 00 64 FD 08
110: F4 72 AA 04 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73
170: 03 00 01 00 01 69 02 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 0A 05 00 00 04 03 03 03 03 03 03 03
190: 03 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 62 A2 86 0D FC 06 00 00
1B0: 00 00 00 00 01 00 25 00 08 7D D9 51 02 00 00 00
1C0: 08 F4 72 AA 04 00 00 00 00 00 00 00 A9 F7 9F 0C
1D0: 00 00 00 00 00 00 00 00 E2 12 00 00 06 00 00 00
1E0: 00 00 00 00 84 02 00 00 00 00 00 00 00 00 00 06
1F0: 00 00 00 00 00 00 00 00 00 00 14 17 00 00 00 03

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 01 06 00 00 00 00 00 00 00 00 00 00 03 00
010: 00 00 00 00 00 00 00 00 00 00 04 14 00 00 00 00
020: 00 00 00 00 00 00 05 0A 00 00 00 00 00 00 00 00
030: 00 00 07 2D 00 00 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 61 00 00 00 00
050: 00 00 00 00 00 00 0C 14 00 00 00 00 00 00 00 00
060: 00 00 B7 00 00 00 00 00 00 00 00 00 00 00 B8 63
070: 00 00 00 00 00 00 00 00 00 00 BB 00 00 00 00 00
080: 00 00 00 00 00 00 BC 00 00 00 00 00 00 00 00 00
090: 00 00 BD 00 00 00 00 00 00 00 00 00 00 00 BE 28
0A0: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
0B0: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
0C0: 00 00 C3 00 00 00 00 00 00 00 00 00 00 00 C5 00
0D0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0E0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0F0: 00 00 F0 00 00 00 00 00 00 00 00 00 00 00 F1 00
100: 00 00 00 00 00 00 00 00 00 00 F2 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 AF
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 bře 2017 22:43

Disk OK.

Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt

Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 05 bře 2017 22:59

OTL logfile created on: 05.03.2017 22:49:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\FanEts\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.14393.0)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: dd.MM.yyyy

7,96 Gb Total Physical Memory | 5,62 Gb Available Physical Memory | 70,57% Memory free
16,96 Gb Paging File | 14,55 Gb Available in Paging File | 85,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 261,93 Gb Total Space | 206,33 Gb Free Space | 78,77% Space Free | Partition Type: NTFS
Drive F: | 46,46 Gb Total Space | 46,35 Gb Free Space | 99,77% Space Free | Partition Type: NTFS
Drive G: | 151,43 Gb Total Space | 151,31 Gb Free Space | 99,92% Space Free | Partition Type: NTFS
Drive P: | 10,25 Gb Total Space | 9,06 Gb Free Space | 88,43% Space Free | Partition Type: NTFS
Drive T: | 400,39 Gb Total Space | 333,98 Gb Free Space | 83,41% Space Free | Partition Type: NTFS

Computer Name: TOMÁŠ | User Name: FanEts | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found
PRC - C:\Users\FanEts\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Node.js)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
PRC - C:\Program Files (x86)\AVG\Av\avgfwsa.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit)
PRC - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (Micro-Star INT'L CO., LTD.)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Intel Corporation)
PRC - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\NVIDIA Corporation\NvContainer\poco.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvUtil.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvBackendAPINode.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameStreamAPINode.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node ()
MOD - \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node ()
MOD - C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll ()
MOD - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe ()
MOD - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\libcurl.dll ()
MOD - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\uexper.dll ()
MOD - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\traynet.dll ()
MOD - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\zlib1.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NvContainerNetworkService) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
SRV:64bit: - (NvContainerLocalSystem) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
SRV:64bit: - (NVDisplay.ContainerLocalSystem) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation)
SRV:64bit: - (MBAMService) -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes)
SRV:64bit: - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:64bit: - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:64bit: - (UsoSvc) -- C:\Windows\SysNative\usocore.dll (Microsoft Corporation)
SRV:64bit: - (DoSvc) -- C:\Windows\SysNative\dosvc.dll (Microsoft Corporation)
SRV:64bit: - (CoreMessagingRegistrar) -- C:\Windows\SysNative\CoreMessaging.dll (Microsoft Corporation)
SRV:64bit: - (MapsBroker) -- C:\Windows\SysNative\moshost.dll (Microsoft Corporation)
SRV:64bit: - (CDPUserSvc) -- C:\Windows\SysNative\cdpusersvc.dll (Microsoft Corporation)
SRV:64bit: - (DmEnrollmentSvc) -- C:\Windows\SysNative\Windows.Internal.Management.dll (Microsoft Corporation)
SRV:64bit: - (CDPSvc) -- C:\Windows\SysNative\cdpsvc.dll (Microsoft Corporation)
SRV:64bit: - (EntAppSvc) -- C:\Windows\SysNative\EnterpriseAppMgmtSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (RetailDemo) -- C:\Windows\SysNative\RDXService.dll (Microsoft Corporation)
SRV:64bit: - (StateRepository) -- C:\Windows\SysNative\Windows.StateRepository.dll (Microsoft Corporation)
SRV:64bit: - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (wisvc) -- C:\Windows\SysNative\FlightSettings.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (FrameServer) -- C:\Windows\SysNative\FrameServer.dll (Microsoft Corporation)
SRV:64bit: - (NetSetupSvc) -- C:\Windows\SysNative\NetSetupSvc.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
SRV:64bit: - (NgcSvc) -- C:\Windows\SysNative\ngcsvc.dll (Microsoft Corporation)
SRV:64bit: - (RmSvc) -- C:\Windows\SysNative\RMapi.dll (Microsoft Corporation)
SRV:64bit: - (PimIndexMaintenanceSvc) -- C:\Windows\SysNative\PimIndexMaintenance.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) -- C:\Windows\SysNative\icsvcext.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) -- C:\Windows\SysNative\icsvcext.dll (Microsoft Corporation)
SRV:64bit: - (SensorService) -- C:\Windows\SysNative\SensorService.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicvmsession) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (XblAuthManager) -- C:\Windows\SysNative\XblAuthManager.dll (Microsoft Corporation)
SRV:64bit: - (UserManager) -- C:\Windows\SysNative\usermgr.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (LicenseManager) -- C:\Windows\SysNative\LicenseManagerSvc.dll (Microsoft Corporation)
SRV:64bit: - (tzautoupdate) -- C:\Windows\SysNative\tzautoupdate.dll (Microsoft Corporation)
SRV:64bit: - (PhoneSvc) -- C:\Windows\SysNative\PhoneService.dll (Microsoft Corporation)
SRV:64bit: - (SensorDataService) -- C:\Windows\SysNative\SensorDataService.exe (Microsoft Corporation)
SRV:64bit: - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (WalletService) -- C:\Windows\SysNative\WalletService.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:64bit: - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (shpamsvc) -- C:\Windows\SysNative\Windows.SharedPC.AccountManager.dll (Microsoft Corporation)
SRV:64bit: - (XboxNetApiSvc) -- C:\Windows\SysNative\XboxNetApiSvc.dll (Microsoft Corporation)
SRV:64bit: - (dmwappushservice) -- C:\Windows\SysNative\dmwappushsvc.dll (Microsoft Corporation)
SRV:64bit: - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (DcpSvc) -- C:\Windows\SysNative\dcpsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (diagnosticshub.standardcollector.service) -- C:\Windows\SysNative\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (Microsoft Corporation)
SRV:64bit: - (WpnUserService_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (UserDataSvc_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (UnistoreSvc_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (PimIndexMaintenanceSvc_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (OneSyncSvc_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (MessagingService_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (CDPUserSvc_1b3942) -- C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:64bit: - (OneSyncSvc) -- C:\Windows\SysNative\APHostService.dll (Microsoft Corporation)
SRV:64bit: - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:64bit: - (TieringEngineService) -- C:\Windows\SysNative\TieringEngineService.exe (Microsoft Corporation)
SRV:64bit: - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (SmsRouter) -- C:\Windows\SysNative\SmsRouterSvc.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (MessagingService) -- C:\Windows\SysNative\MessagingService.dll (Microsoft Corporation)
SRV:64bit: - (UserDataSvc) -- C:\Windows\SysNative\UserDataService.dll (Microsoft Corporation)
SRV:64bit: - (UnistoreSvc) -- C:\Windows\SysNative\Unistore.dll (Microsoft Corporation)
SRV:64bit: - (tiledatamodelsvc) -- C:\Windows\SysNative\tileobjserver.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:64bit: - (NgcCtnrSvc) -- C:\Windows\SysNative\NgcCtnrSvc.dll (Microsoft Corporation)
SRV:64bit: - (WpnService) -- C:\Windows\SysNative\wpnservice.dll (Microsoft Corporation)
SRV:64bit: - (icssvc) -- C:\Windows\SysNative\tetheringservice.dll (Microsoft Corporation)
SRV:64bit: - (TimeBrokerSvc) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (WpnUserService) -- C:\Windows\SysNative\WpnUserService.dll (Microsoft Corporation)
SRV:64bit: - (lfsvc) -- C:\Windows\SysNative\lfsvc.dll (Microsoft Corporation)
SRV:64bit: - (DevQueryBroker) -- C:\Windows\SysNative\DevQueryBroker.dll (Microsoft Corporation)
SRV:64bit: - (XblGameSave) -- C:\Windows\SysNative\XblGameSave.dll (Microsoft Corporation)
SRV:64bit: - (ClipSVC) -- C:\Windows\SysNative\ClipSVC.dll (Microsoft Corporation)
SRV:64bit: - (AJRouter) -- C:\Windows\SysNative\AJRouter.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (DsSvc) -- C:\Windows\SysNative\dssvc.dll (Microsoft Corporation)
SRV:64bit: - (embeddedmode) -- C:\Windows\SysNative\embeddedmodesvc.dll (Microsoft Corporation)
SRV:64bit: - (HvHost) -- C:\Windows\SysNative\hvhostsvc.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (BthHFSrv) -- C:\Windows\SysNative\BthHFSrv.dll (Microsoft Corporation)
SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel(R) Corporation)
SRV - (NvTelemetryContainer) -- C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (ZAMSvc) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
SRV - (BEService) -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ()
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AVGIDSAgent) -- C:\Program Files (x86)\AVG\Av\avgidsagenta.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws) -- C:\Program Files (x86)\AVG\Av\avgfwsa.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (AVG Technologies CZ, s.r.o.)
SRV - (AvgAMPS) -- C:\Program Files (x86)\AVG\Av\avgamps.exe (AVG Technologies CZ, s.r.o.)
SRV - (LiveUpdateSvc) -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (IObit)
SRV - (CoreMessagingRegistrar) -- C:\Windows\SysWOW64\CoreMessaging.dll (Microsoft Corporation)
SRV - (avgsvc) -- C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (AVG Technologies CZ, s.r.o.)
SRV - (Freemake Improver) -- C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Freemake)
SRV - (DmEnrollmentSvc) -- C:\Windows\SysWOW64\Windows.Internal.Management.dll (Microsoft Corporation)
SRV - (StateRepository) -- C:\Windows\SysWOW64\Windows.StateRepository.dll (Microsoft Corporation)
SRV - (iumsvc) -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe (Intel Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (MSI_LiveUpdate_Service) -- C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (Micro-Star INT'L CO., LTD.)
SRV - (UnistoreSvc) -- C:\Windows\SysWOW64\Unistore.dll (Microsoft Corporation)
SRV - (PrintNotify) -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (SbaService) -- C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage Next\SbaService.exe (Intel Corporation)
SRV - (isaHelperSvc) -- C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe ()
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ZAM_Guard) -- C:\Windows\SysNative\drivers\zamguard64.sys (Zemana Ltd.)
DRV:64bit: - (ZAM) -- C:\Windows\SysNative\drivers\zam64.sys (Zemana Ltd.)
DRV:64bit: - (nvvhci) -- C:\Windows\SysNative\drivers\nvvhci.sys (NVIDIA Corporation)
DRV:64bit: - (NvStreamKms) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys (NVIDIA Corporation)
DRV:64bit: - (rt640x64) -- C:\Windows\SysNative\drivers\rt640x64.sys (Realtek )
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\TeeDriverW8x64.sys (Intel Corporation)
DRV:64bit: - (iaLPSS2_UART2) -- C:\Windows\SysNative\drivers\iaLPSS2_UART2.sys (Intel Corporation)
DRV:64bit: - (iaLPSS2_I2C) -- C:\Windows\SysNative\drivers\iaLPSS2_I2C.sys (Intel Corporation)
DRV:64bit: - (iaLPSS2_GPIO2) -- C:\Windows\SysNative\drivers\iaLPSS2_GPIO2.sys (Intel Corporation)
DRV:64bit: - (nvlddmkm) -- C:\Windows\SysNative\DriverStore\FileRepository\nv_dispi.inf_amd64_0cc477a6fec64d8c\nvlddmkm.sys (NVIDIA Corporation)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (nvvad_WaveExtensible) -- C:\Windows\SysNative\drivers\nvvad64v.sys (NVIDIA Corporation)
DRV:64bit: - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (xboxgip) -- C:\Windows\SysNative\drivers\xboxgip.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSDriver) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (iorate) -- C:\Windows\SysNative\drivers\iorate.sys (Microsoft Corporation)
DRV:64bit: - (Avgfwfd) -- C:\Windows\SysNative\drivers\avgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:64bit: - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) -- C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (megasas2i) -- C:\Windows\SysNative\drivers\MegaSas2i.sys (Avago Technologies)
DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:64bit: - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (wcifs) -- C:\Windows\SysNative\drivers\wcifs.sys (Microsoft Corporation)
DRV:64bit: - (wdiwifi) -- C:\Windows\SysNative\drivers\WdiWiFi.sys (Microsoft Corporation)
DRV:64bit: - (CapImg) -- C:\Windows\SysNative\drivers\capimg.sys (Microsoft Corporation)
DRV:64bit: - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (xinputhid) -- C:\Windows\SysNative\drivers\xinputhid.sys (Microsoft Corporation)
DRV:64bit: - (Wof) -- C:\WINDOWS\SysNative\drivers\wof.sys (Microsoft Corporation)
DRV:64bit: - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (wdm_usb) -- C:\Windows\SysNative\drivers\usb2ser.sys (MBB)
DRV:64bit: - (hvservice) -- C:\Windows\SysNative\drivers\hvservice.sys (Microsoft Corporation)
DRV:64bit: - (Avgwfpa) -- C:\Windows\SysNative\drivers\avgwfpa.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (applockerfltr) -- C:\Windows\SysNative\drivers\applockerfltr.sys (Microsoft Corporation)
DRV:64bit: - (ReFSv1) -- C:\WINDOWS\SysNative\drivers\refsv1.sys (Microsoft Corporation)
DRV:64bit: - (WindowsTrustedRT) -- C:\Windows\SysNative\drivers\WindowsTrustedRT.sys (Microsoft Corporation)
DRV:64bit: - (GpuEnergyDrv) -- C:\Windows\SysNative\drivers\gpuenergydrv.sys (Microsoft Corporation)
DRV:64bit: - (Ufx01000) -- C:\Windows\SysNative\drivers\ufx01000.sys (Microsoft Corporation)
DRV:64bit: - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:64bit: - (UcmTcpciCx0101) -- C:\Windows\SysNative\drivers\UcmTcpciCx.sys (Microsoft Corporation)
DRV:64bit: - (UcmCx0101) -- C:\Windows\SysNative\drivers\UcmCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (storqosflt) -- C:\Windows\SysNative\drivers\storqosflt.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (UrsCx01000) -- C:\Windows\SysNative\drivers\urscx01000.sys (Microsoft Corporation)
DRV:64bit: - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (IndirectKmd) -- C:\Windows\SysNative\drivers\IndirectKmd.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (cnghwassist) -- C:\Windows\SysNative\drivers\cnghwassist.sys (Microsoft Corporation)
DRV:64bit: - (MMCSS) -- C:\Windows\SysNative\drivers\mmcss.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (irda) -- C:\Windows\SysNative\drivers\irda.sys (Microsoft Corporation)
DRV:64bit: - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (clreg) -- C:\Windows\SysNative\drivers\registry.sys (Microsoft Corporation)
DRV:64bit: - (wcnfs) -- C:\Windows\SysNative\drivers\wcnfs.sys (Microsoft Corporation)
DRV:64bit: - (Ucx01000) -- C:\Windows\SysNative\drivers\Ucx01000.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (NetAdapterCx) -- C:\Windows\SysNative\drivers\NetAdapterCx.sys ()
DRV:64bit: - (FileCrypt) -- C:\Windows\SysNative\drivers\filecrypt.sys (Microsoft Corporation)
DRV:64bit: - (tsusbflt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (UdeCx) -- C:\Windows\SysNative\drivers\Udecx.sys (Microsoft Corporation)
DRV:64bit: - (vhf) -- C:\Windows\SysNative\drivers\vhf.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (ufxsynopsys) -- C:\Windows\SysNative\drivers\ufxsynopsys.sys (Microsoft Corporation)
DRV:64bit: - (UfxChipidea) -- C:\Windows\SysNative\drivers\UfxChipidea.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (UcmUcsi) -- C:\Windows\SysNative\drivers\UcmUcsi.sys (Microsoft Corporation)
DRV:64bit: - (UrsChipidea) -- C:\Windows\SysNative\drivers\urschipidea.sys (Microsoft Corporation)
DRV:64bit: - (UrsSynopsys) -- C:\Windows\SysNative\drivers\urssynopsys.sys (Microsoft Corporation)
DRV:64bit: - (genericusbfn) -- C:\Windows\SysNative\drivers\genericusbfn.sys (Microsoft Corporation)
DRV:64bit: - (WindowsTrustedRTProxy) -- C:\Windows\SysNative\drivers\WindowsTrustedRTProxy.sys (Microsoft Corporation)
DRV:64bit: - (iaLPSS2i_I2C) -- C:\Windows\SysNative\drivers\iaLPSS2i_I2C.sys (Intel Corporation)
DRV:64bit: - (iai2c) -- C:\Windows\SysNative\drivers\iai2c.sys (Intel(R) Corporation)
DRV:64bit: - (iaLPSS2i_GPIO2) -- C:\Windows\SysNative\drivers\iaLPSS2i_GPIO2.sys (Intel Corporation)
DRV:64bit: - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (hidinterrupt) -- C:\Windows\SysNative\drivers\hidinterrupt.sys (Microsoft Corporation)
DRV:64bit: - (buttonconverter) -- C:\Windows\SysNative\drivers\buttonconverter.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (iagpio) -- C:\Windows\SysNative\drivers\iagpio.sys (Intel(R) Corporation)
DRV:64bit: - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (cht4vbd) -- C:\Windows\SysNative\drivers\cht4vx64.sys (Chelsio Communications)
DRV:64bit: - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:64bit: - (mlx4_bus) -- C:\Windows\SysNative\drivers\mlx4_bus.sys (Mellanox)
DRV:64bit: - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:64bit: - (ibbus) -- C:\Windows\SysNative\drivers\ibbus.sys (Mellanox)
DRV:64bit: - (cht4iscsi) -- C:\Windows\SysNative\drivers\cht4sx64.sys (Chelsio Communications)
DRV:64bit: - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (scmdisk0101) -- C:\Windows\SysNative\drivers\scmdisk0101.sys (Microsoft Corporation)
DRV:64bit: - (ndfltr) -- C:\Windows\SysNative\drivers\ndfltr.sys (Mellanox)
DRV:64bit: - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:64bit: - (LSI_SAS2i) -- C:\Windows\SysNative\drivers\lsi_sas2i.sys (LSI Corporation)
DRV:64bit: - (LSI_SAS3i) -- C:\Windows\SysNative\drivers\lsi_sas3i.sys (Avago Technologies)
DRV:64bit: - (scmbus) -- C:\Windows\SysNative\drivers\scmbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (WinVerbs) -- C:\Windows\SysNative\drivers\winverbs.sys (Mellanox)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (percsas3i) -- C:\Windows\SysNative\drivers\percsas3i.sys (Avago Technologies)
DRV:64bit: - (percsas2i) -- C:\Windows\SysNative\drivers\percsas2i.sys (Avago Technologies)
DRV:64bit: - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (storufs) -- C:\Windows\SysNative\drivers\storufs.sys (Microsoft Corporation)
DRV:64bit: - (WinMad) -- C:\Windows\SysNative\drivers\winmad.sys (Mellanox)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AcpiDev) -- C:\Windows\SysNative\drivers\AcpiDev.sys (Microsoft Corporation)
DRV:64bit: - (volume) -- C:\Windows\SysNative\drivers\volume.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (bcmfn) -- C:\Windows\SysNative\drivers\bcmfn.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (QLogic Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (QLogic Corporation)
DRV:64bit: - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:64bit: - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:64bit: - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) -- C:\Windows\SysNative\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (vmgid) -- C:\Windows\SysNative\drivers\vmgid.sys (Microsoft Corporation)
DRV:64bit: - (avguniva) -- C:\Windows\SysNative\drivers\avguniva.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) -- C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgdiska) -- C:\Windows\SysNative\drivers\avgdiska.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (NvStUSB) -- C:\Windows\SysNative\drivers\nvstusb.sys (NVIDIA Corporation)
DRV:64bit: - (Avgloga) -- C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgboota) -- C:\Windows\SysNative\drivers\avgboota.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (epmntdrv) -- C:\Windows\SysNative\epmntdrv.sys ()
DRV:64bit: - (EuGdiDrv) -- C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:64bit: - (MBI) -- C:\Windows\SysNative\drivers\MBI.sys (Intel Corporation)
DRV:64bit: - (ISCT) -- C:\Windows\SysNative\drivers\ISCTD64.sys ()
DRV - (HWiNFO32) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS (REALiX(tm))
DRV - (nvlddmkm) -- C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_0cc477a6fec64d8c\nvlddmkm.sys (NVIDIA Corporation)
DRV - (CompositeBus) -- C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys (Microsoft Corporation)
DRV - (epmntdrv) -- C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\Windows\SysWOW64\EuGdiDrv.sys ()


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {012E1000-F331-11DB-8314-0800200C9A66}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.countryCode: "CZ"
FF - prefs.js..browser.search.region: "CZ"
FF - prefs.js..browser.startup.homepage: "about:superstart"
FF - prefs.js..extensions.enabledAddons: %7Ba0faa0a4-f1a7-4098-9a74-21efc3a92372%7D:45.0.0
FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.6.3.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7B6e84150a-d526-41f1-a480-a67d3fed910d%7D:1.5.6.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: extended.copy.menu%40fix.version:1.6.1c.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7BA4732521-77D9-447E-A557-B279AC923F06%7D:0.6.18
FF - prefs.js..extensions.enabledAddons: s3google%40translator:5.26
FF - prefs.js..extensions.enabledAddons: superstart%40enjoyfreeware.org:7.4.0.1-signed
FF - prefs.js..extensions.enabledAddons: mozilla_cc2%40internetdownloadmanager.com:6.27.3
FF - prefs.js..extensions.enabledAddons: check4change-owner%40mozdev.org:1.9.8.3
FF - prefs.js..extensions.enabledAddons: screenshotlink%40screenshotlink.ru:2.2.1.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:51.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc2@internetdownloadmanager.com: C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017.01.26 11:35:54 | 000,030,383 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\FanEts\AppData\Roaming\IDM\idmmzcc5 [2017.03.05 22:44:24 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc2@internetdownloadmanager.com: C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017.01.26 11:35:54 | 000,030,383 | ---- | M] ()

[2016.08.12 20:33:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Extensions
[2017.03.04 00:19:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (Unread Tabs) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{f57f9be0-5281-11d9-9669-0800200c9a664}
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\blockfall
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (ÄŚeskĂ˝ slovnĂ­k pro kontrolu pravopisu) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\cs@dictionaries.addons.mozilla.org
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (Super Start) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\tabbin
[2017.03.04 00:00:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\temp
[2015.04.13 09:45:26 | 002,813,104 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\bearbluebaby@loic.com.xpi
[2017.02.01 22:26:01 | 000,626,157 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\check4change-owner@mozdev.org.xpi
[2015.04.13 09:45:26 | 002,430,017 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\ecolo@loic.com.xpi
[2016.04.28 14:43:04 | 000,025,898 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\extended.copy.menu@fix.version.xpi
[2015.04.13 09:45:28 | 003,443,846 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\penguin@loic.com.xpi
[2016.10.19 14:36:08 | 000,379,658 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\s3google@translator.xpi
[2017.03.03 17:48:15 | 000,030,288 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\screenshotlink@screenshotlink.ru.xpi
[2017.02.20 13:04:52 | 000,595,958 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
[2016.04.28 14:43:04 | 000,103,645 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi
[2016.04.28 14:43:04 | 000,124,838 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}.xpi
[2015.08.22 06:24:28 | 004,110,416 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi
[2016.03.14 07:21:38 | 000,117,253 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}.xpi
[2016.05.10 08:45:40 | 000,109,711 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{A4732521-77D9-447E-A557-B279AC923F06}.xpi
[2017.03.03 17:24:38 | 000,088,616 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi
[2016.11.24 20:37:04 | 001,055,311 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.05.24 08:11:20 | 001,493,384 | R--- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi
[2017.03.04 00:19:26 | 000,007,704 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\aushelper@mozilla.org.xpi
[2017.03.04 00:19:26 | 000,005,527 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\diagnostics@mozilla.org.xpi
[2017.03.04 00:19:26 | 000,008,857 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\disableSHA1rollout@mozilla.org.xpi
[2017.03.04 00:19:26 | 000,005,336 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\hsts-priming@mozilla.org.xpi
[2011.07.24 09:29:52 | 000,001,459 | ---- | M] () -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\searchplugins\slovnk-encz.xml
[2017.01.27 21:09:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2017.01.26 11:35:54 | 000,030,383 | ---- | M] () (No name found) -- C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMMZCC2.XPI

O1 HOSTS File: ([2017.03.03 23:53:54 | 000,000,753 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Microsoft OneDrive for Business Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL (Microsoft Corporation)
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 05 bře 2017 23:00

O4:64bit: - HKLM..\Run: [Malwarebytes TrayApp] C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Malwarebytes)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\WINDOWS\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ZAM] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AvgUi] C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EaseUS EPM tray] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\EpmNews.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EaseUS EPM Tray Agent] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe ()
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKCU..\Run: [OneDrive] C:\Users\FanEts\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll (Microsoft Corporation)
O8:64bit: - Extra context menu item: Stáhnout s IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Stáhnout s IDM všechny odkazy - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Stáhnout s IDM všechny odkazy - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog_Before_Reset\Catalog_Entries64\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog_Before_Reset\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 185.160.208.50 78.108.152.158
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{d750fe37-8660-4591-9a5d-1c01525e302f}: DhcpNameServer = 185.160.208.50 78.108.152.158
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysNative\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\windows.tbauth {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\WINDOWS\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\WINDOWS\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\WINDOWS\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\SysWow64\msv1_0.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2017.03.05 22:44:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\FanEts\Desktop\OTL.exe
[2017.03.05 20:29:58 | 000,000,000 | R--D | C] -- C:\Users\FanEts\Desktop\Nová složka (2)
[2017.03.05 14:05:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2017.03.05 14:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2017.03.04 15:24:34 | 000,000,000 | ---D | C] -- C:\FRST
[2017.03.04 15:21:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2017.03.04 15:21:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CrystalDiskInfo
[2017.03.04 09:45:45 | 000,000,000 | ---D | C] -- C:\Users\FanEts\Desktop\Nová složka
[2017.03.04 09:32:25 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Local\CrashDumps
[2017.03.04 09:28:16 | 000,000,000 | ---D | C] -- C:\Users\FanEts\Desktop\backups
[2017.03.04 09:15:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2017.03.04 09:15:37 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2017.03.04 00:05:40 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\WINDOWS\SysNative\drivers\zamguard64.sys
[2017.03.04 00:05:40 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\WINDOWS\SysNative\drivers\zam64.sys
[2017.03.04 00:05:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
[2017.03.04 00:05:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zemana AntiMalware
[2017.03.04 00:05:15 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Local\Zemana
[2017.03.04 00:05:13 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Local\VirtualStore
[2017.03.04 00:04:26 | 000,000,000 | ---D | C] -- C:\ProgramData\IDM
[2017.03.04 00:03:26 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2017.03.04 00:02:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2017.03.04 00:02:11 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Local\Temp
[2017.03.03 22:13:35 | 000,000,000 | ---D | C] -- C:\zoek_backup
[2017.03.03 22:06:08 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Roaming\ProductData
[2017.03.03 20:13:34 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2017.03.03 19:01:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2017.03.03 19:01:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
[2017.03.03 12:19:55 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Local\Adobe
[2017.03.03 09:51:10 | 000,186,304 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMChameleon.sys
[2017.03.03 09:51:01 | 000,111,544 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2017.03.03 09:51:01 | 000,092,088 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2017.03.03 09:50:58 | 000,043,968 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2017.03.03 09:50:53 | 000,251,840 | ---- | C] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2017.03.03 09:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2017.03.03 09:50:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2017.03.03 09:50:46 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2017.03.03 09:47:50 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2017.03.03 09:42:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2017.03.03 03:44:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2017.02.18 18:13:04 | 000,000,000 | ---D | C] -- C:\Users\FanEts\ansel
[2017.02.18 16:48:37 | 000,134,592 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2017.02.18 16:48:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2017.02.18 16:45:03 | 019,007,016 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2017.02.18 16:45:03 | 011,019,704 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvptxJitCompiler.dll
[2017.02.18 16:45:03 | 008,990,072 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvptxJitCompiler.dll
[2017.02.18 16:45:02 | 034,979,384 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2017.02.18 16:45:02 | 028,242,488 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglv32.dll
[2017.02.18 16:45:02 | 014,674,896 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2017.02.18 16:45:02 | 001,983,424 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6437866.dll
[2017.02.18 16:45:02 | 001,589,696 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6437866.dll
[2017.02.18 16:45:02 | 001,052,096 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2017.02.18 16:45:02 | 000,991,288 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2017.02.18 16:45:02 | 000,959,424 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2017.02.18 16:45:02 | 000,946,456 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncMFTH264.dll
[2017.02.18 16:45:02 | 000,910,784 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2017.02.18 16:45:02 | 000,721,952 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncMFTH264.dll
[2017.02.18 16:45:02 | 000,687,224 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvfatbinaryLoader.dll
[2017.02.18 16:45:02 | 000,618,416 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmcumd.dll
[2017.02.18 16:45:02 | 000,609,728 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2017.02.18 16:45:02 | 000,605,120 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvDecMFTMjpeg.dll
[2017.02.18 16:45:02 | 000,576,192 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvfatbinaryLoader.dll
[2017.02.18 16:45:02 | 000,573,448 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2017.02.18 16:45:02 | 000,499,136 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2017.02.18 16:45:02 | 000,447,984 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2017.02.18 16:45:01 | 011,122,728 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2017.02.18 16:45:01 | 009,305,984 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2017.02.18 16:45:01 | 003,168,192 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2017.02.18 16:45:01 | 002,717,752 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2017.02.18 16:45:01 | 000,483,384 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvDecMFTMjpeg.dll
[2017.02.15 08:53:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2017.02.13 18:14:08 | 000,223,464 | ---- | C] (Tonec Inc.) -- C:\WINDOWS\SysNative\drivers\idmwfp.sys
[2017.02.11 09:53:38 | 000,000,000 | ---D | C] -- C:\ProgramData\SuperBoost
[2017.02.11 09:53:34 | 000,128,288 | ---- | C] (IObit) -- C:\WINDOWS\SysNative\IObitSmartDefragExtension.dll
[2017.02.11 09:53:34 | 000,036,824 | ---- | C] (IObit) -- C:\WINDOWS\SysNative\SmartDefragBootTime.exe
[2017.02.11 09:53:34 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Roaming\SuperBoost
[2017.02.11 09:53:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SuperBoost
[2017.02.11 09:51:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\IObit
[2017.02.11 09:43:00 | 000,091,272 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\SysNative\RtNicProp64.dll
[2017.02.11 09:42:45 | 000,795,640 | ---- | C] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaStorA.sys
[2017.02.11 09:41:23 | 000,184,632 | ---- | C] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaLPSS2_I2C.sys
[2017.02.11 09:41:23 | 000,089,912 | ---- | C] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaLPSS2_GPIO2.sys
[2017.02.11 09:40:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\IObit
[2017.02.11 09:39:16 | 000,027,552 | ---- | C] (REALiX(tm)) -- C:\WINDOWS\SysWow64\drivers\HWiNFO64A.SYS
[2017.02.11 09:39:16 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2017.02.11 09:39:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2017.02.11 09:39:00 | 000,000,000 | ---D | C] -- C:\Users\FanEts\AppData\Roaming\IObit
[2017.02.07 08:04:08 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_6.dll
[2017.02.07 08:04:08 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_6.dll
[2017.02.07 08:04:08 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_6.dll
[2017.02.07 08:04:08 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_6.dll
[2017.02.07 08:04:08 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_4.dll
[2017.02.07 08:04:08 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_4.dll
[2017.02.07 08:04:08 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_7.dll
[2017.02.07 08:04:08 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_7.dll
[2017.02.07 08:04:07 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_5.dll
[2017.02.07 08:04:07 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_5.dll
[2017.02.07 08:04:07 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_5.dll
[2017.02.07 08:04:07 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_5.dll
[2017.02.07 08:04:06 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dcsx_42.dll
[2017.02.07 08:04:06 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dcsx_42.dll
[2017.02.07 08:04:06 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_42.dll
[2017.02.07 08:04:06 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_42.dll
[2017.02.07 08:04:05 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_42.dll
[2017.02.07 08:04:05 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_42.dll
[2017.02.07 08:04:05 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_42.dll
[2017.02.07 08:04:05 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_42.dll
[2017.02.07 08:04:05 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx11_42.dll
[2017.02.07 08:04:05 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx11_42.dll
[2017.02.07 08:04:04 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_41.dll
[2017.02.07 08:04:04 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_41.dll
[2017.02.07 08:04:04 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_41.dll
[2017.02.07 08:04:04 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_41.dll
[2017.02.07 08:04:03 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_41.dll
[2017.02.07 08:04:03 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_41.dll
[2017.02.07 08:04:03 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_3.dll
[2017.02.07 08:04:03 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_3.dll
[2017.02.07 08:04:02 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_4.dll
[2017.02.07 08:04:02 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_4.dll
[2017.02.07 08:04:02 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_4.dll
[2017.02.07 08:04:02 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_4.dll
[2017.02.07 08:04:02 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_6.dll
[2017.02.07 08:04:02 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_6.dll
[2017.02.07 08:04:01 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_40.dll
[2017.02.07 08:04:01 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_40.dll
[2017.02.07 08:04:01 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_40.dll
[2017.02.07 08:04:01 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_40.dll
[2017.02.07 08:04:00 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_40.dll
[2017.02.07 08:04:00 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_40.dll
[2017.02.07 08:04:00 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_3.dll
[2017.02.07 08:04:00 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_3.dll
[2017.02.07 08:04:00 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_3.dll
[2017.02.07 08:04:00 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_3.dll
[2017.02.07 08:04:00 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_2.dll
[2017.02.07 08:04:00 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_2.dll
[2017.02.07 08:03:59 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_2.dll
[2017.02.07 08:03:59 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_2.dll
[2017.02.07 08:03:59 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_2.dll
[2017.02.07 08:03:59 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_2.dll
[2017.02.07 08:03:59 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_1.dll
[2017.02.07 08:03:59 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_1.dll
[2017.02.07 08:03:59 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_5.dll
[2017.02.07 08:03:59 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_5.dll
[2017.02.07 08:03:58 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_39.dll
[2017.02.07 08:03:58 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_39.dll
[2017.02.07 08:03:58 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_39.dll
[2017.02.07 08:03:58 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_39.dll
[2017.02.07 08:03:56 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_39.dll
[2017.02.07 08:03:56 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_39.dll
[1 C:\WINDOWS\SysNative\drivers\*.tmp files -> C:\WINDOWS\SysNative\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2017.03.05 22:49:16 | 000,068,416 | ---- | M] () -- C:\WINDOWS\ZAM.krnl.trace
[2017.03.05 22:49:16 | 000,041,149 | ---- | M] () -- C:\WINDOWS\ZAM_Guard.krnl.trace
[2017.03.05 22:44:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\FanEts\Desktop\OTL.exe
[2017.03.05 22:17:37 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2017.03.05 22:15:43 | 000,251,840 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2017.03.05 22:15:36 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2017.03.05 22:15:35 | 3420,839,936 | -HS- | M] () -- C:\hiberfil.sys
[2017.03.05 20:34:12 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2017.03.05 17:08:56 | 000,041,712 | ---- | M] () -- C:\bootsqm.dat
[2017.03.05 08:52:31 | 002,019,276 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2017.03.05 08:52:31 | 000,849,980 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2017.03.05 08:52:31 | 000,737,084 | ---- | M] () -- C:\WINDOWS\SysNative\perfh005.dat
[2017.03.05 08:52:31 | 000,248,578 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2017.03.05 08:52:31 | 000,173,094 | ---- | M] () -- C:\WINDOWS\SysNative\perfc005.dat
[2017.03.04 00:05:40 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\WINDOWS\SysNative\drivers\zamguard64.sys
[2017.03.04 00:05:40 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\WINDOWS\SysNative\drivers\zam64.sys
[2017.03.03 23:53:54 | 000,000,753 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\etc\hosts
[2017.03.03 23:51:25 | 000,024,064 | ---- | M] () -- C:\WINDOWS\zoek-delete.exe
[2017.03.03 21:34:38 | 000,028,272 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\TrueSight.sys
[2017.03.03 12:19:38 | 001,002,605 | ---- | M] () -- C:\Users\FanEts\Desktop\2017 NASCAR.pdf
[2017.03.03 09:54:04 | 000,092,088 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2017.03.03 09:52:44 | 000,186,304 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMChameleon.sys
[2017.03.03 09:52:44 | 000,111,544 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2017.03.03 09:52:39 | 000,043,968 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2017.03.03 09:42:34 | 000,230,376 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2017.02.24 06:23:20 | 000,077,408 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\mbae64.sys
[2017.02.23 19:35:22 | 001,880,512 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspcap64.dll
[2017.02.23 19:35:21 | 001,755,072 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspbridge64.dll
[2017.02.23 19:35:21 | 001,468,864 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspcap.dll
[2017.02.23 19:35:21 | 001,317,312 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspbridge.dll
[2017.02.23 19:35:21 | 000,120,256 | ---- | M] () -- C:\WINDOWS\SysNative\NvRtmpStreamer64.dll
[2017.02.23 19:35:18 | 000,057,792 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvvhci.sys
[2017.02.23 15:32:00 | 000,001,951 | ---- | M] () -- C:\WINDOWS\NvContainerRecovery.bat
[2017.02.23 15:30:51 | 000,001,951 | ---- | M] () -- C:\WINDOWS\NvTelemetryContainerRecovery.bat
[2017.02.17 19:30:05 | 000,327,680 | ---- | M] () -- C:\Users\FanEts\Desktop\GWZ053053739_Výpověď smlouvy o vedení účtů.pdf
[2017.02.17 19:29:57 | 000,327,680 | ---- | M] () -- C:\Users\FanEts\Desktop\GWZ053053739_Výpověď smlouvy o povoleném přečerpání.pdf
[2017.02.11 09:43:00 | 000,955,424 | ---- | M] (Realtek ) -- C:\WINDOWS\SysNative\drivers\rt640x64.sys
[2017.02.11 09:43:00 | 000,091,272 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\SysNative\RtNicProp64.dll
[2017.02.11 09:42:45 | 000,795,640 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaStorA.sys
[2017.02.11 09:42:02 | 000,204,896 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\TeeDriverW8x64.sys
[2017.02.11 09:41:23 | 000,282,424 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaLPSS2_UART2.sys
[2017.02.11 09:41:23 | 000,184,632 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaLPSS2_I2C.sys
[2017.02.11 09:41:23 | 000,089,912 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SysNative\drivers\iaLPSS2_GPIO2.sys
[2017.02.11 09:39:16 | 000,027,552 | ---- | M] (REALiX(tm)) -- C:\WINDOWS\SysWow64\drivers\HWiNFO64A.SYS
[2017.02.10 03:33:54 | 040,192,056 | ---- | M] () -- C:\WINDOWS\SysNative\nvcompiler.dll
[2017.02.10 03:33:54 | 035,272,760 | ---- | M] () -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2017.02.10 03:33:54 | 034,979,384 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2017.02.10 03:33:54 | 028,242,488 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglv32.dll
[2017.02.10 03:33:54 | 019,007,016 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2017.02.10 03:33:54 | 014,674,896 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2017.02.10 03:33:54 | 011,122,728 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2017.02.10 03:33:54 | 011,019,704 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvptxJitCompiler.dll
[2017.02.10 03:33:54 | 009,305,984 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2017.02.10 03:33:54 | 008,990,072 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvptxJitCompiler.dll
[2017.02.10 03:33:54 | 004,078,008 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvapi64.dll
[2017.02.10 03:33:54 | 003,597,128 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvapi.dll
[2017.02.10 03:33:54 | 003,168,192 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2017.02.10 03:33:54 | 002,717,752 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2017.02.10 03:33:54 | 001,983,424 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6437866.dll
[2017.02.10 03:33:54 | 001,589,696 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6437866.dll
[2017.02.10 03:33:54 | 001,052,096 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2017.02.10 03:33:54 | 000,991,288 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2017.02.10 03:33:54 | 000,959,424 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2017.02.10 03:33:54 | 000,946,456 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncMFTH264.dll
[2017.02.10 03:33:54 | 000,910,784 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2017.02.10 03:33:54 | 000,721,952 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncMFTH264.dll
[2017.02.10 03:33:54 | 000,687,224 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvfatbinaryLoader.dll
[2017.02.10 03:33:54 | 000,618,416 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmcumd.dll
[2017.02.10 03:33:54 | 000,609,728 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2017.02.10 03:33:54 | 000,605,120 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvDecMFTMjpeg.dll
[2017.02.10 03:33:54 | 000,576,192 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvfatbinaryLoader.dll
[2017.02.10 03:33:54 | 000,573,448 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2017.02.10 03:33:54 | 000,499,136 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2017.02.10 03:33:54 | 000,483,384 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvDecMFTMjpeg.dll
[2017.02.10 03:33:54 | 000,447,984 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2017.02.10 03:33:54 | 000,043,556 | ---- | M] () -- C:\WINDOWS\SysNative\nvinfo.pb
[2017.02.09 23:57:14 | 006,403,640 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcpl.dll
[2017.02.09 23:57:14 | 002,477,504 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvc64.dll
[2017.02.09 23:57:12 | 001,764,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvcr.dll
[2017.02.09 23:57:12 | 000,548,288 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshext.dll
[2017.02.09 23:57:12 | 000,393,784 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmctray.dll
[2017.02.09 23:57:12 | 000,083,512 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshextr.dll
[2017.02.09 23:57:12 | 000,071,224 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvshext.dll
[2017.02.09 23:57:04 | 007,791,217 | ---- | M] () -- C:\WINDOWS\SysNative\nvcoproc.bin
[2017.02.09 23:39:48 | 000,134,592 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2017.02.06 20:48:07 | 000,835,576 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2017.02.06 20:48:07 | 000,177,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[1 C:\WINDOWS\SysNative\drivers\*.tmp files -> C:\WINDOWS\SysNative\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2017.03.05 17:08:56 | 000,041,712 | ---- | C] () -- C:\bootsqm.dat
[2017.03.05 14:57:46 | 000,000,214 | ---- | C] () -- C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
[2017.03.04 00:05:45 | 000,068,416 | ---- | C] () -- C:\WINDOWS\ZAM.krnl.trace
[2017.03.04 00:05:45 | 000,041,149 | ---- | C] () -- C:\WINDOWS\ZAM_Guard.krnl.trace
[2017.03.04 00:02:12 | 000,024,064 | ---- | C] () -- C:\WINDOWS\zoek-delete.exe
[2017.03.03 20:14:49 | 000,028,272 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\TrueSight.sys
[2017.03.03 12:19:38 | 001,002,605 | ---- | C] () -- C:\Users\FanEts\Desktop\2017 NASCAR.pdf
[2017.03.03 09:50:49 | 000,077,408 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\mbae64.sys
[2017.03.03 09:42:28 | 000,230,376 | ---- | C] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2017.02.18 17:22:44 | 000,000,797 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TapinRadio.lnk
[2017.02.18 17:19:32 | 000,000,675 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\davar3.lnk
[2017.02.18 17:19:24 | 000,001,015 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ulead VideoStudio SE DVD.lnk
[2017.02.18 17:19:04 | 000,000,671 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\dopdf.lnk
[2017.02.18 17:18:40 | 000,001,221 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDFormatter.lnk
[2017.02.18 16:48:29 | 000,326,656 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1.dll
[2017.02.18 16:48:29 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo.exe
[2017.02.18 16:48:28 | 000,322,560 | ---- | C] () -- C:\WINDOWS\SysNative\vulkan-1.dll
[2017.02.18 16:48:28 | 000,118,272 | ---- | C] () -- C:\WINDOWS\SysNative\vulkaninfo.exe
[2017.02.18 16:44:59 | 040,192,056 | ---- | C] () -- C:\WINDOWS\SysNative\nvcompiler.dll
[2017.02.18 16:44:59 | 035,272,760 | ---- | C] () -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2017.02.17 19:30:04 | 000,327,680 | ---- | C] () -- C:\Users\FanEts\Desktop\GWZ053053739_Výpověď smlouvy o vedení účtů.pdf
[2017.02.17 19:29:57 | 000,327,680 | ---- | C] () -- C:\Users\FanEts\Desktop\GWZ053053739_Výpověď smlouvy o povoleném přečerpání.pdf
[2017.01.26 01:13:16 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo-1-1-0-39-1.exe
[2017.01.26 01:12:46 | 000,326,656 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1-1-0-39-1.dll
[2017.01.18 12:42:38 | 000,010,370 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\TheHunterSettings_live.bin
[2017.01.17 18:08:43 | 000,000,043 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\TheHunterSettings_steam_live.cfg
[2017.01.17 17:59:15 | 000,000,097 | ---- | C] () -- C:\Users\FanEts\AppData\Roaming\LauncherSettings_live.cfg
[2016.12.14 16:32:15 | 002,048,496 | ---- | C] () -- C:\WINDOWS\SysWow64\CoreUIComponents.dll
[2016.09.30 11:29:08 | 000,265,728 | ---- | C] () -- C:\WINDOWS\SysWow64\Windows.Perception.Stub.dll
[2016.09.10 06:29:53 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2016.08.13 06:35:18 | 002,502,240 | ---- | C] () -- C:\WINDOWS\SysWow64\BootMan.exe
[2016.08.13 06:35:18 | 000,088,160 | ---- | C] () -- C:\WINDOWS\SysWow64\setupempdrv03.exe
[2016.08.13 06:35:18 | 000,021,088 | ---- | C] () -- C:\WINDOWS\SysWow64\EuEpmGdi.dll
[2016.08.13 06:35:18 | 000,014,944 | ---- | C] () -- C:\WINDOWS\SysWow64\epmntdrv.sys
[2016.08.13 06:35:18 | 000,010,208 | ---- | C] () -- C:\WINDOWS\SysWow64\EuGdiDrv.sys
[2016.07.16 12:47:57 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2016.07.16 12:47:57 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2016.07.16 12:43:04 | 000,055,296 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2016.07.16 12:43:00 | 000,019,968 | ---- | C] () -- C:\WINDOWS\SysWow64\GamePanelExternalHook.dll
[2016.07.16 12:42:55 | 000,167,640 | ---- | C] () -- C:\WINDOWS\SysWow64\chs_singlechar_pinyin.dat
[2016.07.16 12:42:53 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2016.07.16 12:42:49 | 000,304,640 | ---- | C] () -- C:\WINDOWS\SysWow64\HrtfApo.dll
[2016.07.16 12:42:48 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2016.07.16 12:42:43 | 000,002,307 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2016.07.16 12:42:12 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin

========== ZeroAccess Check ==========

[2017.01.29 16:49:03 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2016.11.11 11:01:16 | 007,219,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2016.11.11 08:47:14 | 005,722,832 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2016.07.16 12:42:31 | 000,977,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2016.07.16 12:42:56 | 000,779,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2016.07.16 12:42:31 | 000,518,656 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2016.11.09 09:47:21 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\.mono
[2016.08.13 08:21:16 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\AVG
[2016.09.17 09:43:25 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\Canon
[2017.03.05 22:45:21 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\DMCache
[2017.02.18 13:06:18 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\IDM
[2017.02.11 09:53:27 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\IObit
[2017.01.24 07:14:06 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\Lonely Troops
[2017.01.23 18:07:04 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\MMFApplications
[2017.01.09 19:57:43 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\Origin
[2017.03.03 22:06:08 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\ProductData
[2017.01.05 11:10:27 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\Rainbow
[2017.01.29 16:51:26 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\Red Alert 3
[2017.02.11 09:53:34 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\SuperBoost
[2017.01.17 18:04:17 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\theHunter
[2017.01.17 17:58:41 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\theHunterSteam
[2017.01.30 14:26:58 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\TheLastDreamDemo
[2016.08.13 08:20:35 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\TuneUp Software
[2016.08.13 14:53:25 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\Ulead Systems
[2016.08.13 14:05:54 | 000,000,000 | ---D | M] -- C:\Users\FanEts\AppData\Roaming\CENZURA

========== Purity Check ==========



< End of report >
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 05 bře 2017 23:01

OTL Extras logfile created on: 05.03.2017 22:49:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\FanEts\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.14393.0)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: dd.MM.yyyy

7,96 Gb Total Physical Memory | 5,62 Gb Available Physical Memory | 70,57% Memory free
16,96 Gb Paging File | 14,55 Gb Available in Paging File | 85,76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 261,93 Gb Total Space | 206,33 Gb Free Space | 78,77% Space Free | Partition Type: NTFS
Drive F: | 46,46 Gb Total Space | 46,35 Gb Free Space | 99,77% Space Free | Partition Type: NTFS
Drive G: | 151,43 Gb Total Space | 151,31 Gb Free Space | 99,92% Space Free | Partition Type: NTFS
Drive P: | 10,25 Gb Total Space | 9,06 Gb Free Space | 88,43% Space Free | Partition Type: NTFS
Drive T: | 400,39 Gb Total Space | 333,98 Gb Free Space | 83,41% Space Free | Partition Type: NTFS

Computer Name: TOMÁŠ | User Name: FanEts | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Powershell] -- powershell.exe -noexit -command Set-Location '%V' (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Powershell] -- powershell.exe -noexit -command Set-Location '%V' (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = A6 66 56 35 27 0B D2 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = [binary data]
"DontEnumerateCommonFilesUpgradeExe" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A1BADED-024B-4A94-8E75-03DFE8B18463}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvcontainer\nvcontainer.exe |
"{1CCB3F51-DDC8-4DBC-8D41-7AE12349FBBD}" = lport=47998 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamuseragent.exe |
"{A31BCEA8-CE53-49D4-B26E-49666FB6F55A}" = lport=35043 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{B051D6D2-2A4A-4985-828C-2193F7262FE7}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{B454967B-54C9-428C-A4D5-CA3C9503CC72}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\root\office16\outlook.exe |
"{EA78525A-8B06-4B9A-B62F-D07E9BAAF0B2}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvcontainer\nvcontainer.exe |
"{ED57423D-9E52-4BDE-ACE4-2CAD458AC951}" = lport=47995 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00D6256E-E737-4EF2-ABA2-E752F5B15385}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{0175FA84-2F18-43FC-B807-BE8BB1F40D57}" = dir=out | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{059D2A0B-FE5F-4936-8C89-3D41D1B7C776}" = dir=out | name=@{microsoft.bingweather_4.18.37.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{061D7A5B-F564-4591-AE70-FBC8805D6033}" = dir=in | name=@{microsoft.zunemusic_10.17012.10301.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{077444CC-33DC-4682-B080-6BFF9E186B9E}" = dir=out | name=xbox |
"{0CCCBC86-4D47-45D8-8D6E-223151F7EAC4}" = dir=out | name=twitter |
"{0D21AB31-F270-4CAD-9944-CD7386F6BF73}" = dir=in | name=microsoft solitaire collection |
"{0EBE9190-5EC5-43A3-8016-656B1DDDA88E}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{0FE18B4D-DA51-4C29-B150-270ADCCE8404}" = dir=in | name=@{microsoft.windows.cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} |
"{10C9A19D-D204-44ED-B4A7-E571849A641D}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{1390A890-6762-42DA-85C1-FC1E193FC3E3}" = dir=out | name=@{windows.purchasedialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.purchasedialog/resources/displayname} |
"{13DCD4D5-24B9-48D4-8E73-EF573460727A}" = dir=in | name=@{microsoft.windows.photos_17.214.10010.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |
"{1446BCB7-FC55-4EE8-B4E9-AFE3C0781E61}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{147906AD-BF2B-4F98-B08A-3B2C6F5A7006}" = dir=out | name=@{microsoft.microsoftofficehub_17.7909.7600.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} |
"{16E2EB3F-6722-4DEF-8AD3-24E87B58E22A}" = dir=in | name=onenote |
"{17C1EA0D-C629-44C7-9F0C-C8F1F3164021}" = dir=out | name=@{microsoft.windows.cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} |
"{1AD77318-4C5B-4D1C-9DE1-D4DD99840222}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\av\avgemca.exe |
"{1D458FBB-7C7C-4E89-8B9C-FBE7D05863DD}" = dir=out | name=microsoft solitaire collection |
"{1DDCC2DA-2C91-4D73-9EE5-6946641AD98D}" = dir=in | name=@{microsoft.bingfinance_4.18.37.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} |
"{2772C452-1A4B-4A0B-A602-F40821C5FAB9}" = dir=in | name=@{microsoft.microsoftedge_38.14393.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{27D4C01B-1B98-4AE3-9E56-CC7EBD241C1D}" = dir=in | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{2864B58E-98EF-43C0-9E0A-21215EB7E2A2}" = dir=out | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{2B047621-4B3F-4158-88B2-6ABA28E7BB94}" = dir=out | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{2B6C7DB0-BC08-4339-BD32-985C88894005}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\av\avgnsa.exe |
"{2D8188E8-8EFD-4603-8CBC-B1FDA1D487BD}" = dir=in | name=xbox |
"{2DE2B866-B046-4498-AEAF-BF2507D5D03F}" = dir=out | name=@{windows.contactsupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{2E2F173C-B375-4B55-82B9-CBF737A95C98}" = dir=in | name=@{microsoft.microsoftedge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{305FBCD2-37B7-4625-8795-9A4DEA765B87}" = dir=in | name=@{microsoft.zunevideo_10.17012.10301.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{31E8A11E-495F-4921-8E4B-27633B6D7564}" = dir=out | name=@{microsoft.xboxidentityprovider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxidentityprovider/resources/pkgdisplayname} |
"{3268E267-77DE-4EDC-ABAB-2C79BDDC15E5}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.7922.42017.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} |
"{32A49014-DE10-4F4A-A264-2B958F46887D}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{350E83E4-77F6-409A-A91A-BE3EB63531CB}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{359B236D-8C06-4DB5-B2FC-C16487BF263C}" = dir=out | name=microsoft sticky notes |
"{38562883-A82B-4D1E-A162-7BCE5B31DC08}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{397729FC-FB23-429F-8470-6456CF679EC5}" = dir=out | name=@{windows.contactsupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{39A35218-6629-4609-B1A0-641E5165CB74}" = dir=out | name=@{microsoft.microsoftedge_38.14393.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{3A6439E5-FB69-451C-B878-0D7BE01D80BE}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{3F0204DC-4538-45C7-A75D-D1A85745D86A}" = dir=out | name=@{microsoft.xboxidentityprovider_11.19.19003.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxidentityprovider/resources/displayname} |
"{404C8D5A-8DA9-48BE-8B4A-BA252462E505}" = dir=out | name=@{microsoft.zunemusic_10.17012.10301.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{41C500ED-FB2F-4876-954E-4BE8D6328B92}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{438B6DF6-52E9-40B4-9052-9ACACB244AD0}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\av\avgnsa.exe |
"{438E3DA5-CD54-41B3-A554-114E9E9617FE}" = dir=out | name=@{microsoft.accountscontrol_10.0.14393.693_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{44180D8D-D533-4B6E-A63F-E58063344D8D}" = dir=in | app=p:\formatfactory\formatfactory.exe |
"{44CEF4A0-61FD-4D10-8D1E-BFEA769D7187}" = dir=in | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{47E087B5-7D9B-4A6A-9184-343791CBCC13}" = dir=out | name=@{microsoft.appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.appconnector/resources/connectorstubtitle} |
"{494E8843-B2AA-4872-B4EF-258A1E928E88}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{4B1050CB-2A79-4322-B96A-EAEFA36C7FEA}" = dir=in | name=sway |
"{4BF4EBB3-5D44-44D1-A20C-A5A03EEF56B7}" = dir=in | name=@{windows.contactsupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{4EE6008C-C83D-4CAE-B4E3-20298EB6C572}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{4F7DDA50-DD47-4B3E-A008-E3FAA6E080A4}" = dir=out | name=@{microsoft.windowsstore_11610.1001.25.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{5113CD3A-577A-41FF-A13E-168610F823F8}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{543EC2DE-5CED-4DDD-82AA-BCF4BF065708}" = dir=in | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{547B2DC1-0ACE-4140-8F97-36F1872AE713}" = dir=out | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{54B23DDC-C273-4FA4-852A-56AB3AEE09D0}" = dir=in | name=@{microsoft.bingsports_4.18.37.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} |
"{559D02D7-9CC2-4BA2-B137-E771EF750B4A}" = dir=out | name=@{microsoft.zunevideo_10.17012.10301.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{5AEE6938-43EB-4897-A85E-1ACDF11274E1}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{60B85833-AB05-481D-9A90-CF068DB514FB}" = dir=in | name=@{microsoft.bingnews_4.18.41.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} |
"{62E16D89-DDD0-4D6A-BBEF-7FF2F0D11187}" = dir=out | name=sway |
"{63303D9C-3794-4F25-B643-6C1DCC89CCAF}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{644468C8-43DF-4860-B702-32CF1E0AB8DE}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} |
"{6C072061-1418-455F-BF34-4CD73550E8DD}" = dir=in | name=@{windows.contactsupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{6DBC3263-1237-4FED-B9BA-678CEEF82D8B}" = dir=out | name=@{windows.contactsupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{71264576-796C-4293-BA8E-5C95018EEF8C}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\av\avgemca.exe |
"{740D138D-82AA-4245-8239-1D70BE010718}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\av\avgnsa.exe |
"{746C4A7F-A381-4896-AB42-DFA4A1380645}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} |
"{756A57A4-EE9D-4533-B488-EC23CC17B0A7}" = dir=out | name=@{microsoft.bingfinance_4.18.37.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} |
"{75A09D46-0DD5-4558-A46A-F4839E6F99C1}" = dir=in | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{77A88D6C-82E2-41CA-85E6-2B6E848F78BE}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\av\avgnsa.exe |
"{78FBBE0E-0986-4915-850D-F7613C9952F2}" = dir=out | name=@{microsoft.windowsmaps_5.1611.3342.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} |
"{7C1D5EFC-5372-481F-BC91-E6CBA3FC0EA3}" = dir=out | name=candy crush soda saga |
"{80255AF9-3FA6-4E76-B0DE-B3D220D9DCAC}" = dir=out | name=@{microsoft.lockapp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{811CBAA7-A898-4E9E-9D5C-6F8237B4546D}" = dir=out | name=@{microsoft.windowsfeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windowsfeedback/feedbackapp.resources/appname/text} |
"{83662D12-AD3A-4E92-853F-8102E48BD8DE}" = protocol=17 | dir=in | app=c:\program files (x86)\intel\intel(r) small business advantage next\sba.exe |
"{840AF0E2-BBA6-477B-AE87-8B0DE03AE38D}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{850CC777-EB40-412D-8781-CBC9F1897680}" = dir=in | name=@{microsoft.messaging_3.19.1001.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} |
"{867D2727-E008-46A7-BC5E-186CF7BA7656}" = dir=out | name=@{microsoft.accountscontrol_10.0.14393.693_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{8A7C650C-B863-4ECA-B018-5AE012A75AE8}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{8B1BA837-6CF7-4CE8-8C7B-26588CD47428}" = dir=out | name=@{microsoft.commsphone_1.10.15000.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.commsphone/resources/appstorename} |
"{8BA3880F-C9B1-4D4F-B8FC-1B13FE3A9E63}" = dir=out | name=onenote |
"{8CC471AF-8DE9-436B-BE6A-003B7484CCE5}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{8DFE8C63-E5E8-4661-99B5-14321CB8593F}" = dir=in | app=p:\formatfactory\formatfactory.exe |
"{8FAE6101-A253-4C15-95BC-33BFEB5D8E39}" = dir=in | name=@{microsoft.bingweather_4.18.37.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} |
"{928B37F0-1E70-4F34-8D4D-0F265137E8D1}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} |
"{9528F916-5113-4226-B81C-55BF10C23F36}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{96F60E4A-B74A-442C-8D5C-C3B7E590EB30}" = dir=out | name=@{microsoft.microsoftedge_38.14393.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{9A1FD38D-A6AE-443D-AE22-451B768BA6C2}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{9A6128EE-524F-4D04-B44E-AE77B053F14B}" = dir=out | name=@{microsoft.accountscontrol_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} |
"{9F5508A5-E652-4991-8F55-4252322E4FB2}" = dir=in | name=@{microsoft.oneconnect_1.1607.6.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnect/appstorename} |
"{A0D16CF7-3CA1-4C49-A59C-63CC0FA40504}" = dir=out | name=@{microsoft.skypeapp_11.11.110.0_x64__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/skypevideo_productname} |
"{A0DFB6F6-3A20-43AA-AF91-1DB80C9576DA}" = dir=out | name=@{microsoft.messaging_3.19.1001.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} |
"{A3FDBB65-AC36-4B25-9524-3E78FE6A13F1}" = dir=out | name=@{microsoft.getstarted_4.5.6.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} |
"{A6366805-E90B-4C3A-AF23-7D7002B1B021}" = dir=out | name=@{microsoft.connectivitystore_1.1604.4.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.connectivitystore/mswifiresources/appstorename} |
"{A6E11B61-223C-43E9-8EEF-E36B2A814C40}" = dir=in | name=microsoft sticky notes |
"{A89EBBF6-1C6F-4555-B92D-B479529B7096}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} |
"{AB56C263-ABC2-4C83-9D6B-1D58910E889F}" = dir=in | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{AD222F3A-7D2B-4668-BFCA-F21F9080D846}" = dir=out | name=@{microsoft.people_10.1.3410.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} |
"{AE6730F2-B836-4484-9FE6-71672333F4F1}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} |
"{B0F87D54-2147-434A-8685-2752655783DC}" = dir=out | name=@{microsoft.oneconnect_1.1607.6.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnect/appstorename} |
"{B168633E-9419-4159-8666-F34BD5CE5D07}" = dir=out | name=store purchase app |
"{B3219AFF-E94B-4F63-A77A-D468C047FF94}" = dir=out | name=@{microsoft.microsoftedge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{B66D5E34-E214-45A3-9AF8-401A80AFBC2C}" = dir=in | name=@{microsoft.microsoftofficehub_17.7909.7600.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} |
"{BAED6DDB-C0C9-404A-8349-AC532F4A7A97}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\av\avgemca.exe |
"{BB5B3C4F-CEB5-431F-AD6D-B286FADF59E8}" = dir=out | name=windows_ie_ac_001 |
"{BC2BE9B3-07BD-493E-9D36-6AF7F73C0219}" = dir=in | name=@{microsoft.skypeapp_11.11.110.0_x64__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/skypevideo_productname} |
"{BE0D8BFF-8C53-4BD9-A10D-51E3C0EF3D7D}" = dir=out | name=@{microsoft.windows.photos_17.214.10010.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} |
"{C35EDB5C-A70F-4442-812A-3DAD9035000B}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{C4E8E810-DD6C-465C-9963-D376AF6BAB3D}" = dir=in | app=p:\formatfactory\ffmodules\encoder\doc\ebookcodec.exe |
"{C727DA0F-B989-4CFA-9AB6-758A4F481285}" = dir=in | app=p:\formatfactory\ffmodules\encoder\doc\ebookcodec.exe |
"{C7DD336D-4113-4444-A5BA-23D2068D59B4}" = dir=in | name=@{windows.contactsupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} |
"{C8CBF4FC-3AB6-4C26-B578-67A908B8E1A6}" = dir=in | name=@{microsoft.commsphone_1.10.15000.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.commsphone/resources/appstorename} |
"{CE82BE95-7EAD-4FBD-AC65-FD40571CD99D}" = dir=out | name=@{microsoft.lockapp_10.0.14393.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{D06816DD-4989-4A10-88A6-9069E08E8C7A}" = dir=out | name=@{microsoft.lockapp_10.0.14393.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} |
"{D332FD15-62A5-4A76-A889-1EC0235C8E16}" = dir=out | name=@{microsoft.windowsfeedbackhub_1.1612.10312.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsfeedbackhub/resources/appstorename} |
"{D369274B-FAAD-4240-BFA9-79BED785BF7D}" = dir=out | name=windows_ie_ac_001 |
"{D3C8F9B7-E629-4FA0-852C-060A9E8F0239}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\av\avgemca.exe |
"{D7079E25-E9CF-46A7-8D26-4C682B2E8695}" = dir=out | name=@{microsoft.windowsphone_10.1609.2561.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphone/resources/appstorename} |
"{D9396261-6666-4B60-96B0-2E32F2D62614}" = dir=out | name=@{microsoft.windows.cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} |
"{DEA1A635-CC3A-4533-A2C7-B0C8C665D2C0}" = dir=out | name=@{microsoft.3dbuilder_12.0.3131.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.3dbuilder/resources/appstorename} |
"{E14DA19B-E7C5-4247-BB62-88C017EF4A23}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.7922.42017.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} |
"{E1D93054-8B66-4792-9E08-2C8C15806AF4}" = dir=in | name=@{microsoft.microsoftedge_38.14393.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} |
"{E5F9F0ED-0733-4847-94D0-15B6D619656A}" = dir=in | name=@{microsoft.windowsfeedbackhub_1.1612.10312.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsfeedbackhub/resources/appstorename} |
"{E9724B6F-EBE3-41D7-9433-90FB9AF359A0}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} |
"{EF4CBA94-3C3C-47E3-B96F-077D33A7EFC4}" = dir=in | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |
"{F05C5890-BBEF-4013-B102-C6BE4F95FB48}" = dir=in | name=@{microsoft.windowsstore_11610.1001.25.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} |
"{F3B73D26-E75E-4615-87EE-4A81DDA9BB3B}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{F46E9106-BFC9-4C70-9479-077EC90EE097}" = dir=out | name=@{microsoft.bingnews_4.18.41.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} |
"{F6571047-5E0F-421B-B7C4-50BAC5D58122}" = dir=out | name=@{microsoft.bingsports_4.18.37.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} |
"{F9C49C8A-4F92-450C-ABF2-ADDCBFB29AE9}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} |
"{FC64E34E-22A4-4DB0-96D7-EAE560B4D64C}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} |
"{FD608F27-BC03-45C0-B31E-3D10AACA8D31}" = dir=out | name=@{microsoft.ppiprojection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG4200_series" = Canon MG4200 series MP Drivers
"{1CEAC85D-2590-4760-800F-8DE5E91F3700}" = Intel(R) Management Engine Components
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.7.10 (64-bit)
"{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes verze 3.0.6.1469
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{3DF3AC42-174D-4915-9ED2-448AD4338B83}" = Intel(R) ME UninstallLegacy
"{52CF40B9-7FAF-450D-845E-95CF495CF0B7}" = Intel(R) Management Engine Components
"{55398EAC-F58E-4F19-B553-BDF8B9EFD839}" = Intel(R) Chipset Device Software
"{62260D0F-633D-4B77-B394-BB57DF7223D9}" = Intel(R) Management Engine Components
"{6E400AF1-567B-4832-A92D-0302535110AA}" = AVG 2016
"{7A96D540-38DD-4D02-88E0-139B8074653A}" = AVG
"{7D84E343-A23D-451C-B123-0195B2D903A6}" = Intel® Trusted Connect Service Client
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{90160000-007E-0000-1000-0000000FF1CE}" = Office 16 Click-to-Run Licensing Component
"{90160000-008C-0000-1000-0000000FF1CE}" = Office 16 Click-to-Run Extensibility Component
"{90160000-008C-0405-1000-0000000FF1CE}" = Office 16 Click-to-Run Localization Component
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}" = Intel(R) Serial IO
"{A227B892-C548-4490-9C5D-DB341F8194A6}_is1" = TruckersMP 0.2.1.2.1 Alpha
"{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1" = Revo Uninstaller 2.0.2
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel" = Ansel
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 3.4.0.70
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Ovladač řídící jednotky 3D Vision 369.04
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus Update 23.23.30.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.16.0318
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 23.23.30.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA Wireless Controller Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Ovladač HD audia 1.3.34.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend" = NVIDIA Backend
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer" = NVIDIA Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem" = NVIDIA LocalSystem Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus" = NVIDIA Message Bus for NvContainer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService" = NVIDIA NetworkService Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session" = NVIDIA Session Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User" = NVIDIA User Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer" = NVIDIA Display Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS" = NVIDIA Display Container LS
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs" = NvNodejs
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog" = NVIDIA Watchdog Plugin for NvContainer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry" = NvTelemetry
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetryContainer" = NVIDIA Telemetry Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci" = NvvHci
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC" = Nvidia Share
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 3.4.0.70
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 3.51.2
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{DC2A8E3D-D5E1-4837-A2E0-C308100AC412}" = FMW 1
"{EA30CEC3-9CC5-4C80-AE8E-209A6F894961}" = Intel(R) Management Engine Components
"{F94944A8-7BF1-4D63-935D-DAE36FAA3072}" = Intel(R) Serial IO
"AVG" = AVG Protection
"CCleaner" = CCleaner
"MediaInfo" = MediaInfo 0.7.86
"O365HomePremRetail - cs-cz" = Microsoft Office 365 - cs-cz
"VulkanRT1.0.39.1" = Vulkan Run Time Libraries 1.0.39.1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1" = MSI Kombustor 2.5.9
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{23170F69-40C1-2701-1604-000001000000}" = 7-Zip 16.04
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{4B230374-6475-4A73-BA6E-41015E9C5013}" = Intel® Security Assist
"{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1" = MSI Live Update 6
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}" = Intel(R) Update Manager
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1" = Zemana AntiMalware
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1029-7B44-A94000000001}" = Adobe Reader 9.4.0 - Czech
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B829E117-D072-41EA-9606-9826A38D34C1}" = Sophos Virus Removal Tool
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{C7A82877-2365-4A03-B23F-DFDD629B7F3A}" = Intel® Small Business Advantage
"{c7f54569-0018-439c-809a-48046a4d4ebc}" = Intel® Chipset Device Software
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"7-Zip" = 7-Zip 15.14
"Adobe Flash Player NPAPI" = Adobe Flash Player 24 NPAPI
"Canon_IJ_Scan_Utility" = Canon IJ Scan Utility
"CrystalDiskInfo_is1" = CrystalDiskInfo 7.0.5
"EaseUS Partition Master_is1" = EaseUS Partition Master 10.2
"FormatFactory" = FormatFactory 3.9.5.0
"Freemake Video Converter_is1" = Freemake Video Converter verze 4.1.9
"Freemore MP3 Cutter_is1" = Freemore MP3 Cutter 3.8.1
"Google Chrome" = Google Chrome
"HappyFoto-Designer_is1" = HappyFoto-Designer 5.4
"Internet Download Manager" = Internet Download Manager
"MozBackup" = MozBackup 1.5.1
"Mozilla Firefox 51.0.1 (x86 cs)" = Mozilla Firefox 51.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"SpeedFan" = SpeedFan (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"cuties" = cuties
"OneDriveSetup.exe" = Microsoft OneDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 03.03.2017 13:52:01 | Computer Name = Tomáš | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Služba Šifrování selhala při volání OnIdentity() v objektu System
Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Protokol
Microsoft LLDP (Link-Layer Discovery Protocol). System Error: Přístup byl odepřen.
.

Error - 03.03.2017 15:35:16 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 15:35:16 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 15:35:33 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 15:35:33 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 16:50:55 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 16:50:55 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 16:51:10 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 16:51:10 | Computer Name = Tomáš | Source = Microsoft Security Client | ID = 5000
Description =

Error - 03.03.2017 17:05:35 | Computer Name = Tomáš | Source = .NET Runtime | ID = 1026
Description =

Error - 03.03.2017 17:05:37 | Computer Name = Tomáš | Source = Application Error | ID = 1000
Description = Název chybující aplikace: FreemakeUtilsService.exe, verze: 1.0.0.0,
časové razítko: 0x5833fc4e Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.14393.479,
časové razítko: 0x58256d37 Kód výjimky: 0xe0434352 Posun chyby: 0x000da832 ID chybujícího
procesu: 0x93c Čas spuštění chybující aplikace: 0x01d29461d552d54d Cesta k chybující
aplikaci: C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
Cesta
k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll ID zprávy: 72fd665c-7477-4246-9de5-7891aeec585b
Úplný
název chybujícího balíčku: ID aplikace související s chybujícím balíčkem:

[ isaAgentLog Events ]
Error - 25.12.2016 14:56:10 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 02.01.2017 2:26:14 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 09.01.2017 2:26:15 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 16.01.2017 5:57:13 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 23.01.2017 5:57:15 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 30.01.2017 9:43:56 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 06.02.2017 9:44:00 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 13.02.2017 11:12:42 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 20.02.2017 11:12:45 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

Error - 27.02.2017 11:12:49 | Computer Name = Tomáš | Source = isaAgent | ID = 1135
Description = 1.0.0.532: Unexpected error: Vzdálený server vrátil chybu: (404) Nenalezeno.

[ System Events ]
Error - 05.03.2017 17:17:54 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:02 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:04 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:11 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:11 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:18 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:20 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:18:24 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:24:30 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =

Error - 05.03.2017 17:24:36 | Computer Name = Tomáš | Source = DCOM | ID = 10010
Description =


< End of report >
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 bře 2017 23:33

TuneUp Software si odinstaloval? Pokud ne , udělej

Dávám smazat některé doplňky FF , ty bez jména , je těžké určit , co je špatné. Případně si doinstaluj.

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {012E1000-F331-11DB-8314-0800200C9A66}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - prefs.js..extensions.enabledAddons: %7Ba0faa0a4-f1a7-4098-9a74-21efc3a92372%7D:45.0.0
FF - prefs.js..extensions.enabledAddons: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.6.3.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7B6e84150a-d526-41f1-a480-a67d3fed910d%7D:1.5.6.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: extended.copy.menu%40fix.version:1.6.1c.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7BA4732521-77D9-447E-A557-B279AC923F06%7D:0.6.18
FF - prefs.js..extensions.enabledAddons: superstart%40enjoyfreeware.org:7.4.0.1-signed
FF - prefs.js..extensions.enabledAddons: screenshotlink%40screenshotlink.ru:2.2.1.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:51.0.1
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll File not found
[2016.08.12 20:33:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Extensions
[2017.03.04 00:19:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\blockfall
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (Super Start) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org
[2017.01.07 14:32:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\tabbin
[2017.03.04 00:00:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\temp
[2015.04.13 09:45:26 | 002,813,104 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\bearbluebaby@loic.com.xpi
[2017.02.01 22:26:01 | 000,626,157 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\check4change-owner@mozdev.org.xpi
[2015.04.13 09:45:26 | 002,430,017 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\ecolo@loic.com.xpi
[2016.04.28 14:43:04 | 000,025,898 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\extended.copy.menu@fix.version.xpi
[2015.04.13 09:45:28 | 003,443,846 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\penguin@loic.com.xpi
[2016.10.19 14:36:08 | 000,379,658 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\s3google@translator.xpi
[2017.03.03 17:48:15 | 000,030,288 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\screenshotlink@screenshotlink.ru.xpi
[2017.02.20 13:04:52 | 000,595,958 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
[2016.04.28 14:43:04 | 000,103,645 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi
[2016.04.28 14:43:04 | 000,124,838 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}.xpi
[2015.08.22 06:24:28 | 004,110,416 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi
[2016.03.14 07:21:38 | 000,117,253 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}.xpi
[2016.05.10 08:45:40 | 000,109,711 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{A4732521-77D9-447E-A557-B279AC923F06}.xpi
[2017.03.03 17:24:38 | 000,088,616 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi
[2016.11.24 20:37:04 | 001,055,311 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.05.24 08:11:20 | 001,493,384 | R--- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi
[2017.03.04 00:19:26 | 000,007,704 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\aushelper@mozilla.org.xpi
[2017.03.04 00:19:26 | 000,005,527 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\diagnostics@mozilla.org.xpi
[2017.03.04 00:19:26 | 000,008,857 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\disableSHA1rollout@mozilla.org.xpi
[2017.03.04 00:19:26 | 000,005,336 | ---- | M] () (No name found) -- C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\hsts-priming@mozilla.org.xpi
[2017.01.27 21:09:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2017.01.26 11:35:54 | 000,030,383 | ---- | M] () (No name found) -- C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMMZCC2.XPI
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O13 - gopher Prefix: missing
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2017.01.29 16:49:03 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2016.11.11 11:01:16 | 007,219,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2016.11.11 08:47:14 | 005,722,832 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2016.07.16 12:42:31 | 000,977,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2016.07.16 12:42:56 | 000,779,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2016.07.16 12:42:31 | 000,518,656 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job
C:\Users\FanEts\AppData\Roaming\C:\Users\FanEts\AppData\Roaming\TuneUp Software

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
""=""%1" %*"

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

pokud nebude zlepšení , zkus odinstalovat AVG.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 06 bře 2017 07:20

Aha... ty jsi předtím myslel dopňky do Firefoxu.
Nemyslíme každý něco jiného ? Já měl na mysli panel nástrojů ve Windows.

AVG PC tuneup jsem odinstaloval hned jak jsi řekl.
Potom jsem to ještě zkoušel REVO uninstallerem a ten nic nenašel.

Udělal jsem OTL. Nepomohlo

AVG jsem odinstaloval a ještě jsem použil AVG Remover
Chtěl jsem to zkusit ještě jinak, třeba přidat dalšího uživatele, že bych šel přes něj.
Ale při přidání dalšího účtu vyskočí jen černá tabulka a nic. Nejde přidat ani další účet.

Ale co se vyřešilo je, že se můžu přihlásit přes Firefox do internet banky. Moc díky.Hurá...



All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Prefs.js: %7Ba0faa0a4-f1a7-4098-9a74-21efc3a92372%7D:45.0.0 removed from extensions.enabledAddons
Prefs.js: %7B1A2D0EC4-75F5-4c91-89C4-3656F6E44B68%7D:0.6.3.1-signed.1-signed removed from extensions.enabledAddons
Prefs.js: %7B6e84150a-d526-41f1-a480-a67d3fed910d%7D:1.5.6.1-signed.1-signed removed from extensions.enabledAddons
Prefs.js: extended.copy.menu%40fix.version:1.6.1c.1-signed.1-signed removed from extensions.enabledAddons
Prefs.js: %7BA4732521-77D9-447E-A557-B279AC923F06%7D:0.6.18 removed from extensions.enabledAddons
Prefs.js: superstart%40enjoyfreeware.org:7.4.0.1-signed removed from extensions.enabledAddons
Prefs.js: screenshotlink%40screenshotlink.ru:2.2.1.1-signed.1-signed removed from extensions.enabledAddons
Prefs.js: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:51.0.1 removed from extensions.enabledAddons
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Extensions folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{f57f9be0-5281-11d9-9669-0800200c9a664}\uninstall folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{f57f9be0-5281-11d9-9669-0800200c9a664}\chrome folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{f57f9be0-5281-11d9-9669-0800200c9a664} folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\temp\0 folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\temp folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\tabbin\uninstall folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\tabbin\chrome folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\tabbin folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes\simple folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes\silverlight folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes\launchpad folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes\full folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes\default folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes\basic folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\themes folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\modules folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\META-INF folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\defaults\preferences folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\defaults folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\components folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\chrome folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\cs@dictionaries.addons.mozilla.org\META-INF folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\cs@dictionaries.addons.mozilla.org\dictionaries folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\cs@dictionaries.addons.mozilla.org folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\blockfall\uninstall folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\blockfall\chrome folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\blockfall folder moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions folder moved successfully.
Folder C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\blockfall\ not found.
Folder C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\superstart@enjoyfreeware.org\ not found.
Folder C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\tabbin\ not found.
Folder C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\temp\ not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\bearbluebaby@loic.com.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\check4change-owner@mozdev.org.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\ecolo@loic.com.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\extended.copy.menu@fix.version.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\penguin@loic.com.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\s3google@translator.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\screenshotlink@screenshotlink.ru.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{A4732521-77D9-447E-A557-B279AC923F06}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi not found.
File C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi not found.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\aushelper@mozilla.org.xpi moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\diagnostics@mozilla.org.xpi moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\disableSHA1rollout@mozilla.org.xpi moved successfully.
C:\Users\FanEts\AppData\Roaming\Mozilla\Firefox\Profiles\c6d9e7cs.default\features\{94663438-06f9-487a-a7f1-ae771abec695}\hsts-priming@mozilla.org.xpi moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions folder moved successfully.
C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\WINDOWS\assembly\Desktop.ini moved successfully.
File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\CreateExplorerShellUnelevatedTask.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Program Files\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\Windows\SysNative\drivers\SET826B.tmp moved successfully.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job not found.
File\Folder C:\Users\FanEts\AppData\Roaming\C:\Users\FanEts\AppData\Roaming\TuneUp Software not found.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command\\""|""%1" %*" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default.migrated

User: FanEts
->Temp folder emptied: 17494162 bytes
->Temporary Internet Files folder emptied: 57781 bytes
->FireFox cache emptied: 109769767 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1325 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11461030 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 93120 bytes

Total Files Cleaned = 132,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03062017_064122

Files\Folders moved on Reboot...
C:\Users\FanEts\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File\Folder C:\WINDOWS\temp\officeclicktorun.exe_streamserver(201703052215398CC).log not found!
C:\WINDOWS\temp\TOMÁŠ-20170305-2215.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 06 bře 2017 09:20

Tak ještě:
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

:Files
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt  /c
ipconfig /release /c
ipconfig /renew /c
netsh winsock reset all /c
netsh int ip reset all /c

:Reg
:Commands
[resethosts]
[purity]
[EMPTYFLASH]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.


Možná by sis měl zadat nové téma do sekcí problém s HW ( černá obrazovka) a windows. Kolegové Ti poradí.
Buď je problém s HW nebo problém s windows. Viry vylučuji , i když zkusíme ještě:

Stáhni Kaspersky VRT
na svojí plochu.
Spusť program Kaspersky VRT, .Program se nainstaluje.
Potvrď licenci a klikni na „Start“ . Pokud program nabídne aktualizaci , klikni dole na na „Download Now“.
- Klikni na ozubené kolečko v pravém horním rohu. V okně vyber kromě již zatržených , svojí jednotku disku , pokud jich máš víc , můžeš zatrhnout všechny.
- zvol „Automatic Scan“ nahoře vlevo. a stiskni tlačítko „Start Scanning
- Program začne skenovat zatržené jednotky

Zaškrtnuté :
Hidden startup objects
System Memory
Disk boot sectors

Počítač
Místní disk C

Nezašrkrtnuté:
Dokumenty
My email
Místní disk D
Jednotka DVD-Rom (E)
Jednotka BD-ROM (G)
Disketová jednotka

A jiné , např. Flash disky , které máš připojeny.

- povol programu Virus Removal Tool odstranit všechny nalezené infekce
- jakmile sken skončí ,zvol záložku „Report“ , vpravo nahoře (vedle ozubeného kolečka)
- klikni na „Detected Threads“ a klikni na obrázek diskety („Save“)
- ulož do počítače zprávu a vložit ji sem do příspěvku
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

kimamia
Level 1.5
Level 1.5
Příspěvky: 127
Registrován: květen 15
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod kimamia » 06 bře 2017 15:34

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\FanEts\Desktop\cmd.bat deleted successfully.
C:\Users\FanEts\Desktop\cmd.txt deleted successfully.
< netsh int ip reset c:\resetlog.txt /c >
Resetting Global, OK!
Resetting Interface, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting , failed.
Pýˇstup byl odepýen.
Resetting , OK!
Restart the computer to complete this action.
C:\Users\FanEts\Desktop\cmd.bat deleted successfully.
C:\Users\FanEts\Desktop\cmd.txt deleted successfully.
< ipconfig /release /c >
Windows IP Configuration
Tunnel adapter isatap.{D750FE37-8660-4591-9A5D-1C01525E302F}:
Media State . . . . . . . . . . . : Media unoperational
Connection-specific DNS Suffix . :
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::9d27:126b:8a0:1d7e%12
Default Gateway . . . . . . . . . :
Tunnel adapter Pýipojenˇ k mˇstnˇ sˇti* 10:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
C:\Users\FanEts\Desktop\cmd.bat deleted successfully.
C:\Users\FanEts\Desktop\cmd.txt deleted successfully.
< ipconfig /renew /c >
Windows IP Configuration
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::9d27:126b:8a0:1d7e%12
IPv4 Address. . . . . . . . . . . : 192.168.0.105
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.1
Tunnel adapter Pýipojenˇ k mˇstnˇ sˇti* 10:
Connection-specific DNS Suffix . :
IPv6 Address. . . . . . . . . . . : 2001:0:34ac:b067:24f5:1664:465f:2ce5
Link-local IPv6 Address . . . . . : fe80::24f5:1664:465f:2ce5%3
Default Gateway . . . . . . . . . : ::
Tunnel adapter isatap.{D750FE37-8660-4591-9A5D-1C01525E302F}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
C:\Users\FanEts\Desktop\cmd.bat deleted successfully.
C:\Users\FanEts\Desktop\cmd.txt deleted successfully.
< netsh winsock reset all /c >
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
C:\Users\FanEts\Desktop\cmd.bat deleted successfully.
C:\Users\FanEts\Desktop\cmd.txt deleted successfully.
< netsh int ip reset all /c >
Resetting Interface, OK!
Resetting , failed.
Pýˇstup byl odepýen.
Restart the computer to complete this action.
C:\Users\FanEts\Desktop\cmd.bat deleted successfully.
C:\Users\FanEts\Desktop\cmd.txt deleted successfully.
========== REGISTRY ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Default.migrated

User: FanEts
->Flash cache emptied: 713 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default.migrated

User: FanEts
->Temp folder emptied: 1245263 bytes
->Temporary Internet Files folder emptied: 12126 bytes
->FireFox cache emptied: 148534735 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3850400 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 1106544 bytes

Total Files Cleaned = 148,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03062017_092311

Files\Folders moved on Reboot...
File\Folder C:\Users\FanEts\AppData\Local\Temp\etilqs_rPnNj17jCrZxQ6w not found!
C:\Users\FanEts\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File\Folder C:\WINDOWS\temp\officeclicktorun.exe_streamserver(2017030607460689C).log not found!
C:\WINDOWS\temp\TOMÁŠ-20170306-0746.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...



Kaspersky nic asi nenašel. Žádná zpráva tam není.
To PC jsem kupoval 10.8.2016 v CZC.cz. Nemám to dát k reklamaci ?
Nepomůže tovární nastavení ?
OS Win 10 Home
Základní deska MSI H110M PRO-VD,
2jádrový procesor Intel Core i3-6098P (3.6GHz, HyperThreading), 8GB operační paměti DDR4 2133 MHz TEAM Elite,
Pevný disk 1TB Seagate Barracuda,
Grafická karta NVIDIA GeForce GTX 750 Ti 2GB GDDR5,
DVD±RW mechanika LG,
Zdroj CHIEFTEC GPB-350S, 350 W
Skříň AIO Virtuo TAB04 Champagne

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 06 bře 2017 18:42

Tovární nastavení u PC?
No můžeš zkusit , i záruční opravu. Co psali v jiných sekcích?
Viry to není , možná to Tune Up , nebo ASC ty dodrbávají registry.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 13 hostů