Stránka 1 z 2

Po startu Windows 10 se otevře CMD

Napsal: 15 led 2016 20:37
od BeFaCZ
Ahoj,

Mám takový problém, po spuštění Windows 10 se mi otevře automaticky "CMD" a nebo když zapojím nabíječku u Notebooku. V CMD to napíše stahuji playlisty, zálohuji playlisty a něco problikne, pak se CMD ukončí a PC běží normálně, ale už mě to štve jak se to furt zapíná. Nějaká rada..? Přikládám log z HJT:

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 20:08:48, on 15. 1. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16603)

FIREFOX: 43.0.4 (x86 en-US)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Users\ErOoR\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 1F63F709C0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [OneDrive] "C:\Users\ErOoR\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Save Serp Now] C:\Users\ErOoR\AppData\Roaming\SSN\updssn.exe
O4 - HKCU\..\Run: [CyberGhost] "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min
O4 - HKCU\..\Run: [Stream Nation] C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stream Nation\Stream Nation.appref-ms
O4 - HKCU\..\Run: [Lync] "C:\Program Files\Microsoft Office\root\Office16\lync.exe" /fromrunkey
O4 - HKCU\..\Run: [Dxtory Update Checker 2.0] C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
O4 - HKCU\..\Run: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Startup: MEGAsync.lnk = ErOoR\AppData\Local\MEGAsync\MEGAsync.exe
O4 - Startup: Send to OneNote.lnk = C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{448dec91-e726-40f1-a5ef-13b1f751a42a}: NameServer = 217.77.165.81,217.77.165.211
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: ggbugreport - Unknown owner - C:\Program Files (x86)\yesforsearchesbnd\bugreport.exe
O23 - Service: GtkFree Update (GtkFree) - Unknown owner - C:\Program Files (x86)\GtkFree\GtkFree Update\GtkFree.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: hide.me VPN Service (hmevpnsvc) - eVenture Limited - C:\Program Files (x86)\hide.me VPN\vpnsvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\WINDOWS\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: wampapache64 - Apache Software Foundation - c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe
O23 - Service: wampmysqld64 - Unknown owner - c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Free Space Decimal Point (wucotusy) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Name Double Spaced (xiketelezbt) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Replicate Exit (zutuzuni) - Unknown owner - C:\Program.exe (file missing)

--
End of file - 14392 bytes

Re: Po startu Windows 10 se otevře CMD

Napsal: 15 led 2016 21:40
od jerabina
Logy prosím pro příště vkládej jako prostý text, mnohem lépe se to čte :-)

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.

Re: Po startu Windows 10 se otevře CMD

Napsal: 15 led 2016 22:27
od BeFaCZ
# AdwCleaner v5.029 - Logfile created 15/01/2016 at 21:58:29
# Updated 11/01/2016 by Xplode
# Database : 2016-01-15.2 [Server]
# Operating system : Windows 10 Home (x64)
# Username : ErOoR - PC-EROOR
# Running from : C:\Users\ErOoR\Desktop\2. AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : MPCKpt
Service Found : wucotusy
Service Found : xiketelezbt
Service Found : zigipyro
Service Found : zutuzuni

***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\MPC Cleaner
Folder Found : C:\ProgramData\pokki
Folder Found : C:\Users\ErOoR\AppData\Local\pokki
Folder Found : C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399
Folder Found : C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399
Folder Found : C:\Users\ErOoR\AppData\Roaming\SSN
Folder Found : C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Folder Found : C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Found : C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

***** [ Files ] *****

File Found : C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
File Found : C:\WINDOWS\SysNative\drivers\MPCKpt.sys

***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : amiupdaterExd
Task Found : amiupdaterExi

***** [ Registry ] *****

Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Save Serp Now]
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_re_021010208]
Key Found : HKCU\Software\distromatic
Key Found : HKCU\Software\TutoTag
Key Found : HKCU\Software\ssn
Key Found : HKCU\Software\DAILYPCCLEAN
Key Found : HKCU\Software\OB
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : HKLM\SOFTWARE\WdsManPro
Key Found : HKLM\SOFTWARE\yessearchesSoftware
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Save Serp Now
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PopupProduct
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages] - hxxp://mystart.lenovo.com
Data Found : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1 ... XXW770SVB1

***** [ Web browsers ] *****

[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "search.mpc.am");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("browser.newtab.url", "hxxp://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("browser.search.defaultenginename", "yessearches");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("browser.search.defaultenginename.US", "data:text/plain,browser.search.defaultenginename.US=yessearches");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("browser.search.selectedEngine", "yessearches");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxp://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "43.0");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=7829e4ff");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", true);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016011519");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1452881117991");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"ja\",\"en\"],\"defaultLocale\":\"en\",\"supportedLo[...]
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "hxxp://www.yessearches.com/chrome.php?uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&ts=AHEpAXUsAH0qBU..&v=20160114&mode=ffexttoolbar&q[...]
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"filesToDelete\":[\"C:\\\\Users\\\\ErOoR\\\\AppData\\\\[...]
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "yourGSearchfinder@GSearch.com");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://www.yessearches.com/chrome.php?uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&ts=AHEpAXUsAH0qBU..&v=20160114&mode=ffexttoolbar&q=");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Found : user_pref("browser.newtab.url", "hxxp://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Found : user_pref("browser.search.defaultenginename", "yessearches");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Found : user_pref("browser.search.selectedEngine", "yessearches");
[C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxp://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");
[C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : istartsurf
[C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : conduit.search
[C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.istartsurf.com/webfavicon.ico

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [10894 bytes] ##########


Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 15. 1. 2016
Čas skenování: 22:03
Protokol: hhhh.txt
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.01.15.07
Databáze rootkitů: v2016.01.09.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 10
CPU: x64
Souborový systém: NTFS
Uživatel: ErOoR

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 408828
Uplynulý čas: 19 min, 20 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 1
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399\qnsj8C85.tmp, 2884, , [678ccf6a6a2f66d00434be127d84f808]

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 24
PUP.Optional.ConvertAd, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\zigipyro, , [678ccf6a6a2f66d00434be127d84f808],
PUP.Optional.ConvertAd, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PopupProduct, , [18db2c0ddebb270f3df2b4fd956e02fe],
PUP.Optional.Yelloader, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Save Serp Now, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, HKLM\SOFTWARE\MICROSOFT\TRACING\updssn_RASAPI32, , [a152ff3a6237f73f624e9d77e51f20e0],
PUP.Optional.Yelloader, HKLM\SOFTWARE\MICROSOFT\TRACING\updssn_RASMANCS, , [9d560c2d2d6c3600cde34fc564a0837d],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExd, , [6e8591a87128db5b6649dccba75c52ae],
PUP.Optional.AmiUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExi, , [c33032070c8deb4b4768961163a0956b],
PUP.Optional.YesSearches, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\GGGUpLoad, , [cb28d663edac92a499270fbc37cb59a7],
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, , [bd36b6838f0a9b9b9df8050f07fdbb45],
PUP.Optional.WdsManPro, HKLM\SOFTWARE\WOW6432NODE\WdsManPro, , [777cf7422574171fd0a74e9e6d962ed2],
PUP.Optional.YesSearches, HKLM\SOFTWARE\WOW6432NODE\yessearchesSoftware, , [53a071c878214aec4369ce60b54ff10f],
PUP.Optional.PCSpeedUp, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\PCSUSpeedTest_RASAPI32, , [f4ff3108d2c7be7893afd718d92a946c],
PUP.Optional.PCSpeedUp, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\PCSUSpeedTest_RASMANCS, , [52a183b6fa9ff5414ff3618e20e3b848],
PUP.Optional.Yelloader, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\ssn_RASAPI32, , [8b6856e3a1f84de9249cca282ad9e51b],
PUP.Optional.Yelloader, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\ssn_RASMANCS, , [7281e1584a4fb284b10f13dfb2510af6],
PUP.Optional.VOPackage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPackage, , [a35003369108ba7c0cc42fb46d962ed2],
PUP.Optional.MySearch123, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}, , [01f2e2573762cc6ac80978a7986cd62a],
PUP.Optional.Tuto4PC, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, , [43b02f0af9a0fc3a11a7528fc43fa25e],
PUP.Optional.MultiPlug, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WUCOTUSY, , [b63d0c2dbfda50e69b4d4586b1521ae6],
PUP.Optional.MultiPlug, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ZUTUZUNI, , [32c1e2570990c37350980cbf39ca3cc4],
PUP.Optional.WindowsProtectionManager, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WdsManPro, , [b83bd267b5e40b2b1609824b38cacd33],
PUP.Optional.Yelloader, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\ssn, , [d320a891b7e2d6601c48ae665ea6629e],
PUP.Optional.Tuto4PC, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\TutoTag, , [648fde5b2673280e902469781fe460a0],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\OB, , [4fa4e7528f0a79bd835de6e8907315eb],

Hodnoty registru: 10
PUP.Optional.Yelloader, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Save Serp Now, C:\Users\ErOoR\AppData\Roaming\SSN\updssn.exe, , [ab480633a1f8e84e0db252a05ea59070]
PUP.Optional.GamesDesktop, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_re_021010208, , [9b581b1e1e7b2c0a3eae6e4edd26f010],
PUP.Optional.Tuto4PC, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, 91025817-7BA1-47E7-99DB-C624346276F5, , [43b02f0af9a0fc3a11a7528fc43fa25e]
PUP.Optional.MultiPlug, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wucotusy|ImagePath, C:\Program Files (x86)\CC0451F2-1452881182-11E4-A961-68F728AE1399\hnse6C2E.tmp, , [b63d0c2dbfda50e69b4d4586b1521ae6]
PUP.Optional.MultiPlug, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\zigipyro|ImagePath, C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399\qnsj8C85.tmp, , [9f54fb3e6a2ffc3afbed6566689bcf31]
PUP.Optional.MultiPlug, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\zutuzuni|ImagePath, C:\Program Files (x86)\CC0451F2-1452881182-11E4-A961-68F728AE1399\jnst5151.tmp, , [32c1e2570990c37350980cbf39ca3cc4]
PUP.Optional.OutBrowse, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\OB|monitype20, 1/15/16 19:6:45, , [4fa4e7528f0a79bd835de6e8907315eb]
PUP.Optional.OutBrowse, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\OB|monitype24, 1/15/16 19:6:45, , [ca293efb712853e3e4fcebe3897a8080]
PUP.Optional.OutBrowse, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\OB|monitype27, 1/15/16 19:6:45, , [3cb777c2f1a80036b729a22ca3606d93]
PUP.Optional.OutBrowse, HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\SOFTWARE\OB|monitype6, 1/15/16 19:9:2, , [36bde158aeebc3730cd4d0fe956e0df3]

Data registru: 2
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... XXW770SVB1, Dobré: (iexplore.exe), Špatné: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... XXW770SVB1),,[906351e88d0c0a2c7ad36941798bec14]
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... XXW770SVB1, Dobré: (iexplore.exe), Špatné: (C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... XXW770SVB1),,[0ce7c079dfba12240e3f604a2bd9bd43]

Složky: 8
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399, , [16dd79c0fe9b46f0bd720ca534cff010],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399, , [18db2c0ddebb270f3df2b4fd956e02fe],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\dictionaries, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\Update, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.VOPackage, C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage, , [2cc74aef8316300681564d74bb47e020],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\gWdsManProg, , [1dd6e653287187afab984d77d52db64a],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\gWdsManProg\update, , [1dd6e653287187afab984d77d52db64a],

Soubory: 66
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399\qnsj8C85.tmp, , [678ccf6a6a2f66d00434be127d84f808],
PUP.Optional.YesSearches, C:\Windows\System32\Tasks\GGGUpLoad, , [876c4aefcccd5fd70cb2b219cd35768a],
PUP.Optional.CrossAd.Gen, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi, , [9c5791a8673235011873b6ef22e1b34d],
PUP.Optional.CrossAd.Gen, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi, , [28cbff3aa8f16bcbed9ee4c143c059a7],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399\Uninstall.exe, , [16dd79c0fe9b46f0bd720ca534cff010],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399\onsi65E2.tmp, , [16dd79c0fe9b46f0bd720ca534cff010],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399\pnsi65E3.exe, , [16dd79c0fe9b46f0bd720ca534cff010],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399\rnss65D1.exe, , [16dd79c0fe9b46f0bd720ca534cff010],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399\snsc64D6.tmp, , [16dd79c0fe9b46f0bd720ca534cff010],
PUP.Optional.ConvertAd, C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399\Uninstall.exe, , [18db2c0ddebb270f3df2b4fd956e02fe],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\log-updater.txt, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\nssckbi.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\AccessibleMarshal.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\breakpadinjector.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\crashreporter.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\crashreporter.ini, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\D3DCompiler_43.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\dependentlibs.list, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\freebl3.chk, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\freebl3.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\Geckofx-Core.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\Geckofx-Winforms.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\gkmedias.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\IA2Marshal.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\install_app.py, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\js-gdb.py, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\js.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\libEGL.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\libGLESv2.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\LICENSE, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\log4net.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\mozalloc.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\mozglue.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\mozjs.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\msvcp100.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\msvcr100.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\nss3.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\nssdbm3.chk, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\nssdbm3.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\omni.ja, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\platform.ini, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\plugin-container.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\plugin-hang-ui.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\precomplete, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\redit.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\softokn3.chk, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\softokn3.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\ssn.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\Uninstall.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\updater.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\updssn.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\version.txt, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\Whois.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\xpcshell.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\xul.dll, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\xulrunner-stub.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\xulrunner.exe, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\dictionaries\en-US.aff, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.Yelloader, C:\Users\ErOoR\AppData\Roaming\SSN\dictionaries\en-US.dic, , [ab480633a1f8e84e0db252a05ea59070],
PUP.Optional.VOPackage, C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\Configure.lnk, , [2cc74aef8316300681564d74bb47e020],
PUP.Optional.ProtectWindowsManager, C:\ProgramData\gWdsManProg\updateconf, , [1dd6e653287187afab984d77d52db64a],
PUP.Optional.YesSearches, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml, , [40b31b1efe9b39fde508f3eb7e8657a9],
PUP.Optional.YesSearches, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Dobré: (), Špatné: (user_pref("browser.newtab.url", "http://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");), ,[d91af4456c2dac8a2cd09b438b799b65]
PUP.Optional.YesSearches, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Dobré: (), Špatné: (user_pref("browser.search.searchengine.url", "http://www.yessearches.com/chrome.php?mode=ffsengext&ptid=wak&q={searchTerms}&ts=AHEpAXUsAH0qBU..&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&v=20160114");), ,[0ce768d1f5a40d2997665f7f8282da26]
PUP.Optional.YesSearches, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js, Dobré: (browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Špatné: (browser.startup.homepage", "http://www.yessearches.com), ,[b63d3aff1f7a89ad718331af37cda45c]
PUP.Optional.YesSearches, C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\searchplugins\DD1B66D4.xml, , [f4ff3bfe2475171f1cd1ab33f014738d],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Re: Po startu Windows 10 se otevře CMD

Napsal: 15 led 2016 22:31
od jerabina
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 00:19
od BeFaCZ
# AdwCleaner v5.029 - Logfile created 15/01/2016 at 23:19:10
# Updated 11/01/2016 by Xplode
# Database : 2016-01-15.2 [Server]
# Operating system : Windows 10 Home (x64)
# Username : ErOoR - PC-EROOR
# Running from : C:\Users\ErOoR\Desktop\2. AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : MPCKpt
[-] Service Deleted : xiketelezbt

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\MPC Cleaner
[-] Folder Deleted : C:\ProgramData\pokki
[-] Folder Deleted : C:\Users\ErOoR\AppData\Local\pokki
[-] Folder Deleted : C:\Users\ErOoR\AppData\Local\CC0451F2-1452889741-11E4-A961-68F728AE1399
[-] Folder Deleted : C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[-] Folder Deleted : C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

***** [ Files ] *****

[-] File Deleted : C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
[-] File Deleted : C:\WINDOWS\SysNative\drivers\MPCKpt.sys

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : amiupdaterExd
[-] Task Deleted : amiupdaterExi

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\distromatic
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKCU\Software\Microsoft\Tinstalls
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages]

***** [ Web browsers ] *****

[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "search.mpc.am");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("browser.search.defaultenginename", "yessearches");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("browser.search.defaultenginename.US", "data:text/plain,browser.search.defaultenginename.US=yessearches");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("browser.search.selectedEngine", "yessearches");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.BUTTON_STRUCTURE", "[{\"b\":224520315,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224520316,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.browser.version.last", "43.0");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.firstKnownVersion", "7.38.8.45986");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.homepage", "/index.jhtml?n=7829e4ff");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.hp.enabled", true);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.initialized", true);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.installation.installDate", "2016011519");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.installation.success", true);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.lastActivePing", "1452881117991");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.lastKnownVersion", "7.38.8.45986");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.lssState", "{\"previousLocales\":[\"en-US\",\"en\"],\"supportedLocales\":[\"de\",\"es\",\"pt\",\"ja\",\"en\"],\"defaultLocale\":\"en\",\"supportedLo[...]
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.options.defaultSearch", false);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.options.homePageEnabled", false);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.options.keywordEnabled", true);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.options.tabEnabled", false);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.language", "en");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.productDeliveryOption.type", "Toolbar");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.successUrl", "hxxp://www.yessearches.com/chrome.php?uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&ts=AHEpAXUsAH0qBU..&v=20160114&mode=ffexttoolbar&q[...]
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.toolbarCollapsed", false);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._brMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._brMembers_.\"],\"filesToDelete\":[\"C:\\\\Users\\\\ErOoR\\\\AppData\\\\[...]
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "yourGSearchfinder@GSearch.com");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "yourGSearchfinder@GSearch.com");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://www.yessearches.com/chrome.php?uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&ts=AHEpAXUsAH0qBU..&v=20160114&mode=ffexttoolbar&q=");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Deleted : user_pref("browser.search.defaultenginename", "yessearches");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Deleted : user_pref("browser.search.selectedEngine", "yessearches");
[-] [C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng");
[-] [C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : istartsurf
[-] [C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : conduit.search
[-] [C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Deleted : hxxp://www.istartsurf.com/webfavicon.ico

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [9264 bytes] ##########

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 15. 1. 2016
Čas skenování: 23:23
Protokol: ghjhh.txt
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.01.15.08
Databáze rootkitů: v2016.01.09.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 10
CPU: x64
Souborový systém: NTFS
Uživatel: ErOoR

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 409330
Uplynulý čas: 17 min, 0 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 0
(Nenalezeny žádné škodlivé položky)

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.2 (01.06.2016)
Operating System: Windows 10 Home x64
Ran by ErOoR (Administrator) on p  15. 01. 2016 at 23:43:12,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 7

Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\ErOoR\AppData\Local\crashrpt (Folder)
Successfully deleted: C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod (Folder)
Successfully deleted: C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bigefpfhnfcobdlfbedofhhaibnlghod_0.localstorage (File)
Successfully deleted: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\extensions\staged (Folder)
Successfully deleted: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\extensions\staged (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)



Registry: 1

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9187EAF6-5E76-4E5D-85EB-502185C90405} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  15. 01. 2016 at 23:45:27,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


RogueKiller V11.0.7.0 (x64) [Jan 11 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.10240) 64 bits version
Spuštěno : Normální režim
Uživatel : ErOoR [Práva správce]
Started from : C:\Users\ErOoR\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 01/16/2016 00:12:56

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 13 ¤¤¤
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Partner -> Nalezeno
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending | (default) : {056D528D-CE28-4194-9BA3-BA2E9197FF8C} (C:\Users\ErOoR\AppData\Local\MEGAsync\ShellExtX64.dll) -> Nalezeno
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced | (default) : {05B38830-F4E9-4329-978B-1DD28605D202} (C:\Users\ErOoR\AppData\Local\MEGAsync\ShellExtX64.dll) -> Nalezeno
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing | (default) : {0596C850-7BDD-4C9D-AFDF-873BE6890637} (C:\Users\ErOoR\AppData\Local\MEGAsync\ShellExtX64.dll) -> Nalezeno
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending | (default) : {056D528D-CE28-4194-9BA3-BA2E9197FF8C} (C:\Users\ErOoR\AppData\Local\MEGAsync\ShellExtX64.dll) -> Nalezeno
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced | (default) : {05B38830-F4E9-4329-978B-1DD28605D202} (C:\Users\ErOoR\AppData\Local\MEGAsync\ShellExtX64.dll) -> Nalezeno
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing | (default) : {0596C850-7BDD-4C9D-AFDF-873BE6890637} (C:\Users\ErOoR\AppData\Local\MEGAsync\ShellExtX64.dll) -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GPU-Z (\??\C:\Users\ErOoR\AppData\Local\Temp\GPU-Z.sys) -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GPU-Z (\??\C:\Users\ErOoR\AppData\Local\Temp\GPU-Z.sys) -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1964906038-3208373991-3138683177-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://lenovo13.msn.com/?pc=LCJB -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1964906038-3208373991-3138683177-1002\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://lenovo13.msn.com/?pc=LCJB -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D771F185-B102-4DC2-B79F-BAC5B308E547} | DhcpNameServer : 43.249.38.68 43.249.38.70 ([X][-]) -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{D771F185-B102-4DC2-B79F-BAC5B308E547} | DhcpNameServer : 43.249.38.68 43.249.38.70 ([X][-]) -> Nalezeno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 1 ¤¤¤
[Hj.Name][Soubor] C:\Program Files (x86)\PSPad editor\Notepad.EXE -> Nalezeno

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 41A66E7E5EE1 : user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser//?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&mode=ffseng"); -> Nalezeno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM014-SSHD-8GB +++++
--- User ---
[MBR] 0acf8dc5b88b9d915b1cbe856bfbc639
[BSP] 29228ac5b66aad8ad3bc609d093d6365 : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1000 MB
1 - [SYSTEM][MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 260 MB
2 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2582528 | Size: 1000 MB
3 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 4630528 | Size: 128 MB
4 - Basic data partition | Offset (sectors): 4892672 | Size: 911223 MB
5 - Basic data partition | Offset (sectors): 1871077376 | Size: 25600 MB
6 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1923506176 | Size: 14657 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: SDHC Card +++++
--- User ---
[MBR] 6607c68f68a38ede577e33394e862c45
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0xb) [VISIBLE] Offset (sectors): 2048 | Size: 7459 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 09:47
od jaro3
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:

- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)


- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir i firewall.
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 14:56
od BeFaCZ
RogueKiller V11.0.7.0 (x64) [Jan 11 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.10240) 64 bits version
Spuštěno : Normální režim
Uživatel : ErOoR [Práva správce]
Started from : C:\Users\ErOoR\Desktop\RogueKillerX64.exe
Mód : Smazat -- Datum : 01/16/2016 13:11:20

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 1 ¤¤¤
[FIREFX:Addon] CCACCBF1-7AB4-4CF5-B32D-668C686A539F : Mozilla Firefox hotfix [firefox-hotfix@mozilla.org] -> Smazáno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM014-SSHD-8GB +++++
--- User ---
[MBR] 0acf8dc5b88b9d915b1cbe856bfbc639
[BSP] 29228ac5b66aad8ad3bc609d093d6365 : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1000 MB
1 - [SYSTEM][MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 260 MB
2 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2582528 | Size: 1000 MB
3 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 4630528 | Size: 128 MB
4 - Basic data partition | Offset (sectors): 4892672 | Size: 911223 MB
5 - Basic data partition | Offset (sectors): 1871077376 | Size: 25600 MB
6 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1923506176 | Size: 14657 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: SDHC Card +++++
--- User ---
[MBR] 6607c68f68a38ede577e33394e862c45
[BSP] 9e3b3c473b1db0daa516427cdae6e1cc : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] FAT32 (0xb) [VISIBLE] Offset (sectors): 2048 | Size: 7459 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 14:56
od BeFaCZ
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by ErOoR on so 16. 01. 2016 at 13:19:34,81.
Microsoft Windows 10 Home 10.0.10240 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\ErOoR\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-01-16-121738.log 1875 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ff-bmboc@bytemobile.com deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\prefs.js:

Added to C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);

Added to C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:

Added to C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344

user.js not found
---- Lines Search removed from prefs.js ----
user_pref("browser.search.searchengine.name", "MPC Safe Search ");
---- Lines search.mpc.am removed from prefs.js ----
user_pref("browser.search.searchengine.url", "http://search.mpc.am?q={searchTerms}&cx=partner-pub-3796753109442372:3837783968");
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.alias", "");
user_pref("browser.search.searchengine.iconURL", "http://download.mpc.am/mpc/www/mpc.ico");
user_pref("browser.search.searchengine.ref", "");
user_pref("browser.search.searchengine.ts", "");
user_pref("browser.search.searchengine.type", "");
user_pref("browser.search.searchengine.uid", "");
---- FireFox user.js and prefs.js backups ----

prefs_201616.01._1331_.backup

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1

user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.hp", "http://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&
user_pref("browser.search.searchengine.sp", "http://www.yessearches.com/chrome.php?mode=ffsengext&ptid=wak&q={searchTerms}&ts=AHEpAXUsAH0qBU..&uid=57A
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- FireFox user.js and prefs.js backups ----

prefs_201616.01._1331_.backup

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F

user.js not found
---- Lines searchengine removed from prefs.js ----
user_pref("browser.search.searchengine.hp", "http://www.yessearches.com/?ts=AHEpAXUsAH0qBU..&v=20160114&uid=57A2CAFB2E9F12DF3F624AC119D9FB26&ptid=wak&
user_pref("browser.search.searchengine.sp", "http://www.yessearches.com/chrome.php?mode=ffsengext&ptid=wak&q={searchTerms}&ts=AHEpAXUsAH0qBU..&uid=57A
user_pref("browser.search.searchengine.url", "http://www.yessearches.com/chrome.php?mode=ffsengext&ptid=wak&q={searchTerms}&ts=AHEpAXUsAH0qBU..&uid=57
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- FireFox user.js and prefs.js backups ----

prefs_201616.01._1331_.backup

==== Deleting Files \ Folders ======================

C:\Users\ErOoR\AppData\Roaming\Seznam Browser deleted
C:\Users\ErOoR\AppData\Roaming\TaiGPro deleted
C:\windows\SysNative\Tasks\WebTV_update_playlist_PoPrihlaseni deleted
C:\PROGRA~3\DAEMON Tools Pro deleted
C:\Users\Public\Pokki deleted
C:\found.000 deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Default\AppData\Local\Pokki deleted
C:\Users\ErOoR\AppData\Local\{A17DB202-A666-4ECC-88B9-E40B88A02A46} deleted
C:\Users\ErOoR\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Public\Documents\dmp deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted
C:\WINDOWS\SysWow64\AI_RecycleBin deleted
C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\YourGSearchFinder_br deleted
"C:\Users\ErOoR\AppData\Roaming\MPC-HC" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
- Undetermined - C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\0imiqqnw.default-1451950143344
B2D023F2C6132BECBF9B0FD967AD5D87 - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL - Microsoft Office 2016
A53E7608DC4CC9F5306E6CBA25887EA8 - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll - Microsoft Office 2016
70858ED7836E5C849D33576A84DC8CCF - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll - Shockwave Flash

Profilepath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
B2D023F2C6132BECBF9B0FD967AD5D87 - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL - Microsoft Office 2016
70858ED7836E5C849D33576A84DC8CCF - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll - Shockwave Flash

Profilepath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
B2D023F2C6132BECBF9B0FD967AD5D87 - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL - Microsoft Office 2016
A53E7608DC4CC9F5306E6CBA25887EA8 - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll - Microsoft Office 2016
70858ED7836E5C849D33576A84DC8CCF - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll - Shockwave Flash


==== Chromium Look ======================

Video Downloader - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc
Auto Clicker - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\daoghdmcjpjomfalbgjonallnfkhdccg
Plex - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpniocchabmgenibceglhnfeimmdhdfm
AdBlock - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Unlimited Free VPN - Betternet - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjknjjomckknofjidppipffbpoekiipm
Linkbucks skip - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjpndobkiolgpnpagkhnknhinnpoajmd
Google Play - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi
Solitaire - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep
Shortcut Manager - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjjeipcdnnjhgodgjpfkffcejoljijf
Plants vs Zombies - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina
Collabim - ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\oinjknlpcckmnnjpodcifmifeghabelo

==== Chromium Fix ======================

C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc deleted successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aiimdkdngfcipjohbjenkahhlhccpdbc_0.localstorage deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130862007067622896&GUID=E08D6B73-CEFE-4A54-8609-341F63F709C0"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{9187EAF6-5E76-4E5D-85EB-502185C90405}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9187EAF6-5E76-4E5D-85EB-502185C90405}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130862007067622896&GUID=E08D6B73-CEFE-4A54-8609-341F63F709C0"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{9187EAF6-5E76-4E5D-85EB-502185C90405}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\SearchScopes\{9187EAF6-5E76-4E5D-85EB-502185C90405} - http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{9187EAF6-5E76-4E5D-85EB-502185C90405}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes\{9187EAF6-5E76-4E5D-85EB-502185C90405} - http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02

==== Reset Google Chrome ======================

C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome SxS\User Data\Default\Preferences was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome SxS\User Data\Default\Preferences.bad was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome SxS\User Data\Default\Secure Preferences was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ErOoR\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ErOoR\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ErOoR\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\ErOoR\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\ErOoR\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\ErOoR\AppData\Local\Google\Chrome SxS\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=13818 folders=1914 4001628945 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\ErOoR\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on so 16. 01. 2016 at 14:20:29,68 ======================

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 14:57
od BeFaCZ
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01
Ran by ErOoR (administrator) on PC-EROOR (16-01-2016 14:40:31)
Running from C:\Users\ErOoR\Desktop
Loaded Profiles: ErOoR (Available Profiles: ErOoR)
Platform: Windows 10 Home (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Windows\System32\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(eVenture Limited) C:\Program Files (x86)\hide.me VPN\vpnsvc.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(REALiX) C:\Program Files\HWiNFO64\HWiNFO64.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer64.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\yesforsearchesbnd\bugreport.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.6020.0_x64__8wekyb3d8bbwe\Calculator.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-02-26] (Intel Corporation)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-14] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2015-03-25] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2015-03-25] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2014-06-19] (Adobe Systems Incorporated)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [5052120 2015-06-01] (Realtek semiconductor)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3945672 2015-09-02] (Synaptics Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-09] (Apple Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492808 2014-09-09] (CyberLink Corp.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-07-20] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3639280 2015-12-27] (Electronic Arts)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.exe [430048 2015-08-10] (CyberGhost S.R.L.)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [Stream Nation] => C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stream Nation\Stream Nation.appref-ms
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [25825472 2016-01-08] (Microsoft Corporation)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [349968 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd)
Startup: C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-01-15]
ShortcutTarget: MEGAsync.lnk -> C:\Users\ErOoR\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)
Startup: C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-01-15]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{448dec91-e726-40f1-a5ef-13b1f751a42a}: [NameServer] 217.77.165.81,217.77.165.211
Tcpip\..\Interfaces\{95f892e4-364e-4179-9bf8-33b9f790e7ca}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{f6c9b2fc-fccd-4b6b-ae93-e9a55bf4cddc}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID= ... 1F63F709C0
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKU\S-1-5-21-1964906038-3208373991-3138683177-1002 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1964906038-3208373991-3138683177-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-11-18] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-01-07] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-11-18] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2016-01-12] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-01-07] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-12] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-1964906038-3208373991-3138683177-1002 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-01-07] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-01-07] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-06-19] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2016-01-12] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2016-01-12] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-01-07] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-06-19] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1964906038-3208373991-3138683177-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-15] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\ErOoR\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [not found]

Chrome:
=======
CHR Profile: C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-15]
CHR Extension: (ViDown FLV downloader helper) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\alhnopeoagjmjfgcbnokcnagkecgdcdh [2016-01-15]
CHR Extension: (Google Docs) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-15]
CHR Extension: (Google Drive) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Poper Blocker) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-11-10]
CHR Extension: (YouTube) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Auto Clicker) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\daoghdmcjpjomfalbgjonallnfkhdccg [2015-11-10]
CHR Extension: (Google Sheets) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-15]
CHR Extension: (Word Online) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2015-11-10]
CHR Extension: (iCloud Bookmarks) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2015-11-10]
CHR Extension: (Plex) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpniocchabmgenibceglhnfeimmdhdfm [2016-01-09]
CHR Extension: (Chrome Remote Desktop) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-11-10]
CHR Extension: (Google Docs Offline) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (AdBlock) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-09]
CHR Extension: (Unlimited Free VPN - Betternet) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjknjjomckknofjidppipffbpoekiipm [2016-01-04]
CHR Extension: (Linkbucks skip) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjpndobkiolgpnpagkhnknhinnpoajmd [2015-11-10]
CHR Extension: (The West) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilkgeioneoemibpddeiamfgiofnpjifm [2015-11-10]
CHR Extension: (Google Play) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2015-11-10]
CHR Extension: (Solitaire) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbhppfbabandkdmgjmifahoabeodiep [2015-11-10]
CHR Extension: (Video Converter) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcjjnhgakghmggnimjkldjmmpabhnhne [2015-11-10]
CHR Extension: (Shortcut Manager) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjjeipcdnnjhgodgjpfkffcejoljijf [2015-11-10]
CHR Extension: (Plants vs Zombies) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2015-11-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR Extension: (Fast Video Downloader) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nocpfkkbaekckhcoekockfbidpcjgkbd [2015-11-10]
CHR Extension: (Collabim) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\oinjknlpcckmnnjpodcifmifeghabelo [2015-09-24]
CHR Extension: (Gmail) - C:\Users\ErOoR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-15]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDevice.exe [55336 2015-09-19] ()
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
S4 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [650680 2015-07-29] (Lenovo)
S4 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [63968 2015-08-10] (CyberGhost S.R.L)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2762936 2016-01-07] (Microsoft Corporation)
S4 GDCAgent; C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe [1155512 2015-07-29] (Lenovo)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-16] (NVIDIA Corporation)
S2 ggbugreport; C:\Program Files (x86)\yesforsearchesbnd\bugreport.exe [1584728 2016-01-14] ()
S2 GtkFree; C:\Program Files (x86)\GtkFree\GtkFree Update\GtkFree.exe [294072 2016-01-13] ()
R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\vpnsvc.exe [184528 2015-11-02] (eVenture Limited)
S4 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-02-26] (Intel Corporation)
S4 ibtsiva; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [150256 2015-07-13] (Intel Corporation)
S4 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-10-07] (Intel Corporation)
S4 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S4 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-23] (Lenovo)
S4 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
S4 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-03-25] (Lenovo(beijing) Limited)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-16] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-16] (NVIDIA Corporation)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-27] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2015-11-26] ()
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2015-11-03] ()
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S4 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-09-02] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
S4 tvMobiliService; C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe [2731520 2015-04-20] () [File not signed]
S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [File not signed]
S4 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-07-20] (Western Digital Technologies, Inc.)
S4 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [306552 2015-07-20] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2015-07-15] (DT Soft Ltd)
S3 FcSerial; C:\Windows\system32\DRIVERS\FcSerial.sys [221568 2013-01-30] (Flash Card.)
R3 HWiNFO32; C:\Users\ErOoR\AppData\Local\Temp\HWiNFO64A.SYS [27552 2016-01-16] (REALiX(tm))
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [255216 2015-07-13] (Intel Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-01-15] (DotC United Inc)
R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3496216 2015-07-10] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-12-16] (NVIDIA Corporation)
S3 pmxdrv; C:\WINDOWS\system32\drivers\pmxdrv.sys [31152 2015-08-03] ()
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-18] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3059416 2015-06-11] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-09-02] (Synaptics Incorporated)
S3 taphss6; C:\Windows\System32\drivers\taphss6.sys [42088 2015-06-04] (Anchorfree Inc.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wmbclass; C:\Windows\System32\drivers\wmbclass.sys [299520 2015-07-29] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 14:57
od BeFaCZ
==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-16 14:40 - 2016-01-16 14:41 - 00029709 _____ C:\Users\ErOoR\Desktop\FRST.txt
2016-01-16 14:40 - 2016-01-16 14:40 - 00000000 ____D C:\FRST
2016-01-16 14:39 - 2016-01-16 14:39 - 00016148 _____ C:\WINDOWS\system32\PC-EROOR_ErOoR_HistoryPrediction.bin
2016-01-16 14:39 - 2016-01-16 14:39 - 00015359 _____ C:\Users\ErOoR\Desktop\zoek-results.txt
2016-01-16 14:39 - 2016-01-16 14:39 - 00000000 ____D C:\ProgramData\DAEMON Tools Pro
2016-01-16 13:38 - 2016-01-16 13:19 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2016-01-16 13:12 - 2016-01-16 13:36 - 00000000 ____D C:\zoek_backup
2016-01-16 13:11 - 2016-01-16 13:11 - 00003924 _____ C:\Users\ErOoR\Desktop\rk_73F2.tmp.txt
2016-01-16 12:41 - 2016-01-16 12:43 - 25044040 _____ C:\Users\ErOoR\Desktop\RogueKillerX64.exe
2016-01-16 12:41 - 2016-01-16 12:41 - 00002289 _____ C:\Users\ErOoR\Desktop\návod.txt
2016-01-16 12:39 - 2016-01-16 14:40 - 02370560 _____ (Farbar) C:\Users\ErOoR\Desktop\FRST64.exe
2016-01-16 12:39 - 2016-01-16 13:12 - 01309184 _____ C:\Users\ErOoR\Desktop\zoek.exe
2016-01-16 03:24 - 2016-01-16 03:28 - 00000000 ____D C:\Users\ErOoR\Documents\The Crew
2016-01-16 02:22 - 2016-01-16 02:24 - 00000000 ____D C:\Users\ErOoR\Documents\Call of Juarez - The Cartel
2016-01-15 23:47 - 2016-01-16 12:43 - 00036608 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-01-15 23:47 - 2016-01-15 23:48 - 00000000 ____D C:\ProgramData\RogueKiller
2016-01-15 22:02 - 2016-01-15 22:02 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-15 21:58 - 2016-01-15 23:19 - 00000000 ____D C:\AdwCleaner
2016-01-15 21:53 - 2016-01-15 21:53 - 00000221 _____ C:\Users\ErOoR\Desktop\Call of Juarez The Cartel.url
2016-01-15 21:21 - 2016-01-15 21:21 - 00000000 ____D C:\Users\ErOoR\Documents\Call of Juarez - Bound in Blood
2016-01-15 20:08 - 2016-01-15 20:08 - 00388608 _____ (Trend Micro Inc.) C:\Users\ErOoR\Downloads\HijackThis.exe
2016-01-15 19:40 - 2016-01-15 19:40 - 00060136 ____N (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCKpt.sys
2016-01-15 19:18 - 2016-01-15 19:18 - 00000233 _____ C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Crew (Worldwide).url
2016-01-15 19:13 - 2016-01-15 19:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-01-15 19:10 - 2016-01-15 19:10 - 00003316 _____ C:\WINDOWS\System32\Tasks\{30A016DA-18BC-46DA-A2D0-960D24A0F1C7}
2016-01-15 19:07 - 2016-01-15 19:05 - 00001224 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2016-01-15 19:06 - 2016-01-15 19:06 - 00002347 _____ C:\Users\Default\Desktop\Google Chrome.lnk
2016-01-15 19:06 - 2016-01-15 19:06 - 00002347 _____ C:\Users\Default User\Desktop\Google Chrome.lnk
2016-01-15 19:05 - 2016-01-16 14:19 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-01-15 19:05 - 2016-01-15 19:07 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Seznam.cz
2016-01-15 19:04 - 2016-01-15 21:04 - 00000000 ____D C:\Program Files (x86)\yesforsearchesbnd
2016-01-15 19:04 - 2016-01-15 19:04 - 00015158 _____ C:\WINDOWS\System32\Tasks\ACGPro Update
2016-01-15 19:04 - 2016-01-15 19:04 - 00014554 _____ C:\WINDOWS\System32\Tasks\GGGMonitor
2016-01-15 19:04 - 2016-01-15 19:04 - 00000000 ____D C:\Program Files (x86)\GtkFree
2016-01-15 19:04 - 2016-01-15 19:04 - 00000000 ____D C:\Program Files (x86)\ACGPro
2016-01-15 18:43 - 2016-01-15 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassins Creed Chronicles China
2016-01-15 18:25 - 2016-01-15 18:25 - 00003302 _____ C:\WINDOWS\System32\Tasks\{9C9D20BA-7947-46F6-91F9-11D2D06B22AF}
2016-01-14 22:59 - 2016-01-15 19:15 - 00000000 ____D C:\Users\ErOoR\Desktop\Vše
2016-01-14 00:19 - 2016-01-14 00:20 - 00000000 ____D C:\Users\ErOoR\.nbi
2016-01-14 00:19 - 2016-01-14 00:19 - 224411528 _____ C:\Users\ErOoR\Downloads\netbeans-8.1-windows.exe
2016-01-13 21:43 - 2016-01-13 21:43 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\VitySoft
2016-01-13 21:43 - 2016-01-13 21:43 - 00000000 ____D C:\Users\ErOoR\.objectdb
2016-01-13 01:15 - 2016-01-05 04:07 - 02463704 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-01-13 01:15 - 2016-01-05 04:07 - 00377592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP4SDECD.DLL
2016-01-13 01:15 - 2016-01-05 04:06 - 08022368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-01-13 01:15 - 2016-01-05 04:06 - 01991120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVENCOD.DLL
2016-01-13 01:15 - 2016-01-05 04:06 - 01270104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-01-13 01:15 - 2016-01-05 04:06 - 01063504 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2016-01-13 01:15 - 2016-01-05 04:06 - 00119800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 02641928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 01591848 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 01150816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00862056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00787720 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00779928 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00772448 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00751992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 00667856 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00250520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPG4DECD.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 00249464 _____ (Microsoft Corporation) C:\WINDOWS\system32\RESAMPLEDMO.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00233992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00115704 _____ (Microsoft Corporation) C:\WINDOWS\system32\VIDRESZR.DLL
2016-01-13 01:15 - 2016-01-05 04:04 - 00090912 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2016-01-13 01:15 - 2016-01-05 04:04 - 00083704 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfvdsp.dll
2016-01-13 01:15 - 2016-01-05 03:59 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-01-13 01:15 - 2016-01-05 03:52 - 00441696 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-13 01:15 - 2016-01-05 03:50 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-01-13 01:15 - 2016-01-05 03:50 - 00723648 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-01-13 01:15 - 2016-01-05 03:50 - 00345080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSDECD.DLL
2016-01-13 01:15 - 2016-01-05 03:50 - 00251544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP43DECD.DLL
2016-01-13 01:15 - 2016-01-05 03:50 - 00205072 _____ (Microsoft Corporation) C:\WINDOWS\system32\COLORCNV.DLL
2016-01-13 01:15 - 2016-01-05 03:31 - 01365576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-01-13 01:15 - 2016-01-05 03:30 - 02459096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2016-01-13 01:15 - 2016-01-05 03:30 - 02162064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVENCOD.DLL
2016-01-13 01:15 - 2016-01-05 03:30 - 02152744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-01-13 01:15 - 2016-01-05 03:30 - 01106872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-01-13 01:15 - 2016-01-05 03:30 - 00882208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2016-01-13 01:15 - 2016-01-05 03:30 - 00368776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP4SDECD.DLL
2016-01-13 01:15 - 2016-01-05 03:30 - 00232896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RESAMPLEDMO.DLL
2016-01-13 01:15 - 2016-01-05 03:30 - 00100712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2016-01-13 01:15 - 2016-01-05 03:29 - 00208688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 02445128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00714808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00696192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2016-01-13 01:15 - 2016-01-05 03:28 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2016-01-13 01:15 - 2016-01-05 03:28 - 00645144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00635312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00497896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00277400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MPG4DECD.DLL
2016-01-13 01:15 - 2016-01-05 03:28 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00107952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VIDRESZR.DLL
2016-01-13 01:15 - 2016-01-05 03:28 - 00082096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devenum.dll
2016-01-13 01:15 - 2016-01-05 03:28 - 00072808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfvdsp.dll
2016-01-13 01:15 - 2016-01-05 03:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-01-13 01:15 - 2016-01-05 03:18 - 21873152 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-01-13 01:15 - 2016-01-05 03:15 - 24592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-01-13 01:15 - 2016-01-05 03:15 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-01-13 01:15 - 2016-01-05 03:15 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-13 01:15 - 2016-01-05 03:15 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
2016-01-13 01:15 - 2016-01-05 03:10 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfh264enc.dll
2016-01-13 01:15 - 2016-01-05 03:10 - 00305776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSDECD.DLL
2016-01-13 01:15 - 2016-01-05 03:10 - 00278424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP43DECD.DLL
2016-01-13 01:15 - 2016-01-05 03:10 - 00188032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\COLORCNV.DLL
2016-01-13 01:15 - 2016-01-05 03:09 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-01-13 01:15 - 2016-01-05 03:09 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-01-13 01:15 - 2016-01-05 03:02 - 01672192 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-13 01:15 - 2016-01-05 03:02 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-01-13 01:15 - 2016-01-05 03:02 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-01-13 01:15 - 2016-01-05 03:01 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-01-13 01:15 - 2016-01-05 03:00 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-01-13 01:15 - 2016-01-05 03:00 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-01-13 01:15 - 2016-01-05 02:59 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-01-13 01:15 - 2016-01-05 02:57 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-01-13 01:15 - 2016-01-05 02:57 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-01-13 01:15 - 2016-01-05 02:57 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-01-13 01:15 - 2016-01-05 02:56 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-01-13 01:15 - 2016-01-05 02:51 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-13 01:15 - 2016-01-05 02:51 - 01009664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-13 01:15 - 2016-01-05 02:51 - 00634368 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVXENCD.DLL
2016-01-13 01:15 - 2016-01-05 02:51 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFWMAAEC.DLL
2016-01-13 01:15 - 2016-01-05 02:51 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVSENCD.DLL
2016-01-13 01:15 - 2016-01-05 02:44 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-01-13 01:15 - 2016-01-05 02:44 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
2016-01-13 01:15 - 2016-01-05 02:43 - 19324928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-01-13 01:15 - 2016-01-05 02:42 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2016-01-13 01:15 - 2016-01-05 02:38 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfh264enc.dll
2016-01-13 01:15 - 2016-01-05 02:32 - 01541632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-13 01:15 - 2016-01-05 02:32 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-01-13 01:15 - 2016-01-05 02:31 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-01-13 01:15 - 2016-01-05 02:31 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-01-13 01:15 - 2016-01-05 02:30 - 18802176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-01-13 01:15 - 2016-01-05 02:29 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-01-13 01:15 - 2016-01-05 02:29 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-01-13 01:15 - 2016-01-05 02:26 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-01-13 01:15 - 2016-01-05 02:24 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-01-13 01:15 - 2016-01-05 02:20 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-01-13 01:15 - 2016-01-05 02:19 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-01-13 01:15 - 2016-01-05 02:19 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVXENCD.DLL
2016-01-13 01:15 - 2016-01-05 02:19 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVSENCD.DLL
2016-01-13 01:15 - 2016-01-05 02:19 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFWMAAEC.DLL
2016-01-13 00:19 - 2016-01-13 00:19 - 00003666 _____ C:\WINDOWS\System32\Tasks\Maxthon Update
2016-01-13 00:19 - 2016-01-13 00:19 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Maxthon3
2016-01-13 00:19 - 2016-01-13 00:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxthon Cloud Browser
2016-01-13 00:19 - 2016-01-13 00:19 - 00000000 ____D C:\Program Files (x86)\Maxthon
2016-01-12 23:32 - 2016-01-12 23:32 - 00000000 ____D C:\Users\ErOoR\Documents\MPC-HC Capture
2016-01-12 15:56 - 2016-01-12 16:04 - 00000000 ____D C:\Users\ErOoR\AppData\Local\NVIDIA
2016-01-12 15:56 - 2016-01-12 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-01-12 15:56 - 2015-12-16 17:59 - 01846016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-01-12 15:56 - 2015-12-16 17:59 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-01-12 15:56 - 2015-12-16 17:59 - 01530240 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-01-12 15:56 - 2015-12-16 17:59 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-01-12 15:56 - 2015-12-16 17:59 - 00111520 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 06359672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 02985264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 01256240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-01-12 15:56 - 2015-12-16 15:54 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 00114808 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 00075056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-01-12 15:56 - 2015-12-16 15:49 - 06090019 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-01-12 15:54 - 2015-12-18 09:48 - 12426896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-01-12 15:54 - 2015-12-16 17:59 - 42976888 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 37608568 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 31098488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 24923768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 21131424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 20672376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 19727624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 17568432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 17164160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 17123736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 17104016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 14103608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 03603368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 03184152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 02560816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 02214192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 01915512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436143.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 01564976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436143.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00938104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00872056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00735024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00681592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00416560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00378784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00370992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00316960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00072504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00069416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-01-12 15:54 - 2015-12-16 17:59 - 00050472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2016-01-12 15:54 - 2015-12-16 17:59 - 00035775 _____ C:\WINDOWS\system32\nvinfo.pb
2016-01-12 15:44 - 2016-01-12 15:44 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Sun
2016-01-12 15:44 - 2016-01-12 15:44 - 00000000 ____D C:\Users\ErOoR\.oracle_jre_usage
2016-01-12 15:43 - 2016-01-12 15:43 - 00000000 ____D C:\Users\ErOoR\AppData\LocalLow\Oracle
2016-01-12 15:14 - 2016-01-12 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin s Creed Chronicles India
2016-01-12 13:51 - 2016-01-12 13:51 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-01-11 20:42 - 2016-01-11 20:42 - 00000000 ____D C:\ProgramData\Caphyon
2016-01-11 20:38 - 2016-01-11 20:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FEAR Combat (SEC2)
2016-01-11 20:38 - 2016-01-11 20:38 - 00000000 ____D C:\Users\Public\Documents\Monolith Productions
2016-01-11 20:35 - 2016-01-11 20:35 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\FEAR-Community.org
2016-01-10 03:36 - 2016-01-10 03:36 - 00000000 ____D C:\plugin.video.befun.cz-master
2016-01-10 03:36 - 2016-01-10 02:39 - 00029877 _____ C:\plugin.video.befun.cz-master.zip
2016-01-10 03:11 - 2016-01-10 03:33 - 00029810 _____ C:\plugin.video.serialy-filmy.online-master.zip
2016-01-10 02:39 - 2016-01-10 02:39 - 00029877 _____ C:\Users\ErOoR\Downloads\plugin.video.befun.cz-master.zip
2016-01-10 02:39 - 2016-01-10 02:39 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
2016-01-10 02:36 - 2016-01-10 02:38 - 71111070 _____ C:\Users\ErOoR\Downloads\kodi-14.2-Helix.exe
2016-01-10 02:13 - 2016-01-10 02:39 - 00000000 ____D C:\Program Files (x86)\Kodi
2016-01-10 00:45 - 2016-01-10 00:45 - 00000000 ____D C:\TempProjekty
2016-01-05 00:28 - 2016-01-15 18:12 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-05 00:28 - 2016-01-15 18:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-05 00:28 - 2016-01-13 21:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-05 00:28 - 2016-01-05 00:28 - 13171424 _____ (Microsoft Corporation) C:\Users\ErOoR\Downloads\Silverlight_x64.exe
2016-01-05 00:27 - 2016-01-05 00:27 - 00000000 ____D C:\Users\ErOoR\AppData\Local\Macromedia
2016-01-05 00:18 - 2016-01-05 00:18 - 00248624 _____ C:\Users\ErOoR\Downloads\Firefox Setup Stub 43.0.3.exe
2016-01-03 22:07 - 2016-01-15 18:36 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\New Technology Studio
2016-01-03 22:07 - 2016-01-03 22:07 - 00000000 ____D C:\Users\ErOoR\AppData\Local\New Technology Studio
2016-01-02 21:53 - 2016-01-02 22:00 - 37342449 _____ ( ) C:\Users\ErOoR\Downloads\GTA_5_CZ_V2.1-socialClub.exe
2015-12-29 01:41 - 2016-01-15 23:22 - 00001115 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2015-12-23 07:30 - 2015-12-23 07:30 - 00677843 _____ C:\Users\ErOoR\Documents\IMG_20151223_0001.pdf
2015-12-21 22:14 - 2015-12-21 22:14 - 00000000 ____D C:\Users\ErOoR\Documents\Adobe Scripts
2015-12-21 19:21 - 2015-12-21 19:21 - 00687146 _____ C:\Users\ErOoR\Downloads\Doklad_157031358PV.pdf
2015-12-18 20:56 - 2015-12-18 20:58 - 00000000 ___HD C:\ProgramData\CanonIJMIG
2015-12-18 20:55 - 2015-12-18 20:56 - 00000000 ___HD C:\ProgramData\CanonIJScan
2015-12-17 22:27 - 2015-12-18 00:44 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Hide.me
2015-12-17 22:27 - 2015-12-17 22:27 - 17892112 _____ (Bitvise Limited) C:\Users\ErOoR\Downloads\BvSshClient-Inst.exe
2015-12-17 22:27 - 2015-12-17 22:27 - 03357000 _____ (eVenture Limited ) C:\Users\ErOoR\Downloads\Hide.me-Setup-1.1.6.exe
2015-12-17 22:27 - 2015-12-17 22:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hide.me VPN
2015-12-17 22:27 - 2015-12-17 22:27 - 00000000 ____D C:\Program Files (x86)\hide.me VPN
2015-12-17 22:26 - 2015-12-17 22:27 - 17242740 _____ C:\Users\ErOoR\Downloads\betternetInstaller.exe
2015-12-17 22:13 - 2016-01-15 23:23 - 00001967 _____ C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2015-12-17 22:12 - 2015-12-17 22:12 - 44218928 _____ C:\Users\ErOoR\Downloads\torbrowser-install-5.0.5_en-US.exe
2015-12-17 20:41 - 2015-12-17 20:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WampServer
2015-12-17 20:29 - 2015-12-17 20:31 - 43507845 _____ (Hervé Leclerc (HeL) ) C:\Users\ErOoR\Downloads\wampserver2.5-Apache-2.4.9-Mysql-5.6.17-php5.5.12-64b.exe
2015-12-17 20:00 - 2015-12-17 20:01 - 11182492 _____ C:\Users\ErOoR\Downloads\d119694_1 (1).sql
2015-12-17 17:20 - 2015-12-17 17:20 - 00001638 _____ C:\Users\ErOoR\Downloads\Category.sql
2015-12-17 00:11 - 2015-12-17 00:11 - 11914514 _____ C:\Users\ErOoR\Downloads\d119694_1.sql

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-01-16 14:40 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2016-01-16 14:37 - 2015-07-15 03:14 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-16 14:32 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-01-16 14:24 - 2015-07-29 18:19 - 00747670 _____ C:\WINDOWS\system32\perfh005.dat
2016-01-16 14:24 - 2015-07-29 18:19 - 00150090 _____ C:\WINDOWS\system32\perfc005.dat
2016-01-16 14:24 - 2015-07-29 08:58 - 01765712 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-16 14:24 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2016-01-16 14:21 - 2015-07-15 03:14 - 00000974 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-16 14:19 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-16 14:18 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-01-16 13:44 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-01-16 13:42 - 2015-10-20 02:28 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-01-16 13:35 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-01-16 13:35 - 2013-08-22 16:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-01-16 13:19 - 2015-07-24 20:41 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2016-01-16 13:16 - 2015-07-24 21:19 - 00003112 _____ C:\WINDOWS\System32\Tasks\RTSS
2016-01-16 12:39 - 2015-07-16 17:15 - 00004198 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{68257F6B-FF21-4A10-B77A-9FC3D65CF82D}
2016-01-16 03:35 - 2015-07-15 10:26 - 00000000 ____D C:\Program Files (x86)\Steam
2016-01-16 03:27 - 2015-08-26 09:57 - 00000000 ____D C:\Users\ErOoR\Documents\ProfileCache
2016-01-16 02:22 - 2015-07-16 18:04 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2016-01-16 00:29 - 2015-07-15 03:26 - 00000000 ____D C:\Program Files (x86)\PSPad editor
2016-01-15 23:23 - 2015-07-29 09:13 - 00002410 _____ C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-01-15 23:22 - 2015-11-07 14:06 - 00000741 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Black Ops III.lnk
2016-01-15 23:22 - 2015-10-24 14:31 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive pro firmy.lnk
2016-01-15 23:22 - 2015-10-24 14:31 - 00002180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002194 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002144 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-01-15 23:22 - 2015-10-24 14:12 - 00002108 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-01-15 23:22 - 2015-09-28 00:15 - 00001945 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-01-15 23:22 - 2015-08-07 09:28 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-01-15 23:22 - 2015-07-29 08:46 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-01-15 23:22 - 2015-07-22 20:34 - 00001134 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
2016-01-15 23:22 - 2015-07-22 20:33 - 00001226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
2016-01-15 23:22 - 2015-07-22 20:32 - 00001096 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2016-01-15 23:22 - 2015-07-22 20:31 - 00001188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
2016-01-15 23:22 - 2015-07-22 20:28 - 00001542 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2016-01-15 23:22 - 2015-07-22 20:28 - 00001372 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2016-01-15 23:22 - 2015-07-15 14:53 - 00001423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
2016-01-15 23:22 - 2015-07-15 13:06 - 00001119 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-01-15 23:22 - 2015-07-15 12:24 - 00000716 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel(R) HD Graphics Control Panel.lnk
2016-01-15 23:22 - 2015-07-15 03:19 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-01-15 23:21 - 2015-09-15 18:08 - 00001961 _____ C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.lnk
2016-01-15 22:24 - 2015-10-24 14:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office 2016
2016-01-15 22:24 - 2015-07-15 15:24 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2016-01-15 21:53 - 2015-07-15 14:29 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-01-15 21:15 - 2015-03-25 20:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-01-15 20:27 - 2015-07-29 21:21 - 00000000 ____D C:\Program Files (x86)\Activision
2016-01-15 19:57 - 2015-07-16 02:46 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-01-15 19:56 - 2015-09-28 00:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-15 19:56 - 2015-07-29 08:40 - 00000000 ____D C:\Users\ErOoR
2016-01-15 19:56 - 2015-07-15 10:27 - 00000000 ____D C:\ProgramData\Origin
2016-01-15 19:40 - 2015-08-27 23:58 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\TeamViewer
2016-01-15 19:39 - 2015-07-15 03:30 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\DAEMON Tools Pro
2016-01-15 19:39 - 2015-07-15 03:29 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\FileZilla
2016-01-15 19:38 - 2015-07-29 21:17 - 00000000 ____D C:\WINDOWS\Minidump
2016-01-15 19:15 - 2015-07-15 15:24 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\uTorrent
2016-01-15 19:15 - 2015-07-15 10:29 - 00000000 ____D C:\Program Files\CCleaner
2016-01-15 19:13 - 2015-07-15 10:29 - 00002856 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-01-15 19:04 - 2015-07-29 22:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-01-15 18:44 - 2015-07-15 15:40 - 00000000 ____D C:\Users\ErOoR\Documents\My Games
2016-01-15 18:35 - 2015-10-24 18:00 - 00000000 ____D C:\Program Files\OBS
2016-01-15 18:35 - 2015-10-24 18:00 - 00000000 ____D C:\Program Files (x86)\OBS
2016-01-15 18:33 - 2015-07-15 03:14 - 00000000 ____D C:\Users\ErOoR\AppData\Local\Google
2016-01-15 18:30 - 2015-07-31 20:26 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\.minecraft
2016-01-15 17:59 - 2015-07-31 22:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Catalyst
2016-01-15 16:57 - 2015-07-15 03:19 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-01-15 01:05 - 2015-07-15 10:58 - 25207808 ___SH C:\Users\ErOoR\Desktop\Thumbs.db
2016-01-14 23:09 - 2015-08-21 21:19 - 00003956 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1436962003
2016-01-14 23:09 - 2015-07-15 13:06 - 00000000 ____D C:\Program Files (x86)\Opera
2016-01-14 01:04 - 2015-07-16 19:10 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-01-14 00:57 - 2015-07-16 19:10 - 143671360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-01-13 23:41 - 2015-09-18 09:46 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Kodi
2016-01-13 21:36 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-13 21:25 - 2015-07-15 14:36 - 00000000 ____D C:\ProgramData\Microsoft Help
2016-01-13 21:23 - 2015-07-15 14:42 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-01-13 21:20 - 2013-08-22 14:25 - 00000254 _____ C:\WINDOWS\win.ini
2016-01-13 00:40 - 2015-07-15 10:45 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\vlc
2016-01-12 16:04 - 2015-07-29 08:34 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-01-12 15:56 - 2015-07-29 10:12 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-12 15:56 - 2015-07-29 08:33 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-01-12 15:56 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Help
2016-01-12 15:56 - 2015-03-25 20:08 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-01-12 15:55 - 2015-07-15 03:46 - 00000000 ____D C:\Users\ErOoR\AppData\Local\NVIDIA Corporation
2016-01-12 15:45 - 2015-07-20 13:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-01-12 15:45 - 2015-07-15 04:04 - 00000000 ____D C:\ProgramData\Oracle
2016-01-12 15:44 - 2015-07-20 13:22 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-01-12 15:44 - 2015-07-20 13:22 - 00000000 ____D C:\Program Files (x86)\Java
2016-01-12 13:51 - 2015-07-10 12:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-01-12 13:51 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-01-12 13:49 - 2015-07-15 14:36 - 00000000 ____D C:\Program Files\Microsoft Office
2016-01-11 18:32 - 2015-10-25 21:42 - 00348360 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2016-01-11 18:32 - 2015-07-20 11:23 - 00348360 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2016-01-10 02:36 - 2015-07-20 03:14 - 00391168 ___SH C:\Users\ErOoR\Downloads\Thumbs.db
2016-01-08 00:13 - 2015-07-16 18:13 - 00348360 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2016-01-07 15:02 - 2015-08-02 14:24 - 00000132 _____ C:\Users\ErOoR\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2016-01-06 20:57 - 2015-07-15 10:28 - 00000000 ____D C:\Users\ErOoR\AppData\Local\Steam
2016-01-06 20:53 - 2015-08-18 00:30 - 00000000 ____D C:\Program Files (x86)\Polda 4
2016-01-05 22:21 - 2015-08-27 20:52 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-01-05 00:25 - 2015-09-28 00:15 - 00000000 ____D C:\Users\ErOoR\AppData\Local\Mozilla
2016-01-05 00:02 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-01-04 00:27 - 2015-09-15 18:08 - 00000000 ____D C:\Users\ErOoR\AppData\Local\Seznam.cz
2016-01-03 22:21 - 2015-10-24 22:54 - 00000000 ____D C:\Program Files (x86)\Grand Theft Auto V
2016-01-03 02:40 - 2015-07-10 12:06 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-01-03 02:40 - 2015-07-10 12:06 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-29 15:38 - 2015-07-10 13:20 - 04971416 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-28 19:11 - 2015-07-15 02:51 - 00000000 ____D C:\Users\ErOoR\AppData\Local\Packages
2015-12-27 17:56 - 2015-07-15 10:27 - 00000000 ____D C:\Program Files (x86)\Origin
2015-12-23 07:28 - 2015-08-08 08:16 - 00000000 ____D C:\Users\ErOoR\AppData\Roaming\Canon
2015-12-23 07:24 - 2015-12-15 05:10 - 00283958 _____ C:\Users\ErOoR\Downloads\Dohoda o provedení práce.pdf
2015-12-22 00:32 - 2015-12-08 03:14 - 00000000 ____D C:\Users\ErOoR\Desktop\GameTip
2015-12-18 21:02 - 2015-08-08 08:16 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-12-17 20:41 - 2015-08-22 16:17 - 00000000 ____D C:\wamp

==================== Files in the root of some directories =======

2015-08-02 14:24 - 2016-01-07 15:02 - 0000132 _____ () C:\Users\ErOoR\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2015-07-29 08:35 - 2015-07-29 08:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-01-06 18:37

==================== End of FRST.txt ============================

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 14:58
od BeFaCZ
Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01
Ran by ErOoR (2016-01-16 14:41:35)
Running from C:\Users\ErOoR\Desktop
Windows 10 Home (X64) (2015-07-29 08:04:42)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1964906038-3208373991-3138683177-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1964906038-3208373991-3138683177-503 - Limited - Disabled)
ErOoR (S-1-5-21-1964906038-3208373991-3138683177-1002 - Administrator - Enabled) => C:\Users\ErOoR
Guest (S-1-5-21-1964906038-3208373991-3138683177-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1964906038-3208373991-3138683177-1004 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 15.05 beta x64 (HKLM\...\7-Zip) (Version: - )
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - )
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.010.20056 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated)
Adobe Flash Player 20 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 20.0.0.285 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Aktualizace NVIDIA 2.8.1.21 (Version: 2.8.1.21 - NVIDIA Corporation) Hidden
Aplikace Intel® PROSet/Wireless (HKLM-x32\...\{795ee3a0-97fa-489a-9543-7564ccc43be4}) (Version: 18.12.0 - Intel Corporation)
Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Assassin s Creed Chronicles India (HKLM-x32\...\Assassin s Creed Chronicles India_is1) (Version: - )
Assassins Creed Chronicles China (HKLM-x32\...\Assassins Creed Chronicles China_is1) (Version: - )
Assassin's Creed Rogue (HKLM-x32\...\Uplay Install 895) (Version: - Ubisoft)
Assassins Creed Syndicate (HKLM-x32\...\Assassins Creed Syndicate_is1) (Version: - )
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.7.2.45672 - Electronic Arts)
Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.3.0.8 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.7.1 - EA Digital Illusions CE AB)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Call of Duty(R) - World at War(TM) (HKLM-x32\...\InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}) (Version: 1.7 - Cenega)
Call of Duty(R) - World at War(TM) (x32 Version: 1.0 - Cenega) Hidden
Call of Duty(R) - World at War(TM) 1.1 Patch (x32 Version: - ) Hidden
Call of Duty(R) - World at War(TM) 1.1 Patch (x32 Version: 1.1 - Activision) Hidden
Call of Duty(R) - World at War(TM) 1.2 Patch (x32 Version: - ) Hidden
Call of Duty(R) - World at War(TM) 1.2 Patch (x32 Version: 1.2 - Activision) Hidden
Call of Duty(R) - World at War(TM) 1.4 Patch (x32 Version: - ) Hidden
Call of Duty(R) - World at War(TM) 1.4 Patch (x32 Version: 1.4 - Activision) Hidden
Call of Duty(R) - World at War(TM) 1.5 Patch (x32 Version: - ) Hidden
Call of Duty(R) - World at War(TM) 1.5 Patch (x32 Version: 1.5 - Activision) Hidden
Call of Duty(R) - World at War(TM) 1.6 Patch (x32 Version: - ) Hidden
Call of Duty(R) - World at War(TM) 1.6 Patch (x32 Version: 1.6 - Activision) Hidden
Call of Duty(R) - World at War(TM) 1.7 Patch (x32 Version: - ) Hidden
Call of Duty(R) - World at War(TM) 1.7 Patch (x32 Version: 1.7 - Activision) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32 Version: - ) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: - ) Hidden
Call of Duty: Black Ops II - Multiplayer (HKLM-x32\...\Steam App 202990) (Version: - Treyarch)
Call of Duty: Black Ops II - Zombies (HKLM-x32\...\Steam App 212910) (Version: - )
Call of Duty: Black Ops II (HKLM-x32\...\Steam App 202970) (Version: - Treyarch)
Call of Duty: Black Ops III (HKLM\...\Q2FsbG9mRHV0eUJsYWNrT3BzSUlJ_is1) (Version: 1 - )
Call of Juarez - Bound in Blood (HKLM-x32\...\InstallShield_{019908AA-79E9-4389-A1AD-8BBEED63CFBA}) (Version: 1.01.0000 - Ubisoft)
Call of Juarez - Bound in Blood (x32 Version: 1.01.0000 - Ubisoft) Hidden
Call of Juarez: The Cartel (HKLM-x32\...\Steam App 33420) (Version: - Techland)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.1.0 - Canon Inc.)
Canon MG2500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.00 - Canon Inc.)
Canon MG2500 series On-screen Manual (HKLM-x32\...\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 2.0.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 2.0.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.2.1 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform)
CCSDK (HKLM-x32\...\{AE75190B-11B4-4F90-8254-DAB275CF2557}_is1) (Version: 1.2.0.13 - Lenovo)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.4.0 - Conexant)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
CyberGhost 5 (HKLM\...\CyberGhost 5_is1) (Version: - CyberGhost S.R.L.)
CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.4505 - CyberLink Corp.)
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.2.0.0348 - DT Soft Ltd)
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.6.5.1 - Dolby Laboratories Inc)
Dxtory version 2.0.132 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.132 - ExKode Co. Ltd.)
EAX4 Unified Redist (HKLM-x32\...\{89661B04-C646-4412-B6D3-5E19F02F1F37}) (Version: 4.001 - Creative Labs)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.35 - Lenovo)
Energy Manager (x32 Version: 1.0.0.35 - Lenovo) Hidden
FEAR Combat (SEC2) (HKLM-x32\...\FEAR Combat (SEC2) 2.0.1) (Version: 2.0.1 - FEAR-Community.org)
FEAR Combat (SEC2) (x32 Version: 2.0.1 - FEAR-Community.org) Hidden
FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto V verze 1.0.350.2 (HKLM-x32\...\{9E0EEBF7-740B-40F0-9C9B-7A93BE7F7A2B}_is1) (Version: 1.0.350.2 - )
hide.me VPN version 1.1.6 (HKLM-x32\...\{0E00BDA5-7998-4889-BE4B-39A4BBD2EDFB}_is1) (Version: 1.1.6 - eVenture Limited)
HWiNFO64 Version 5.02 (HKLM\...\HWiNFO64_is1) (Version: 5.02 - Martin Malík - REALiX)
iCloud (HKLM\...\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
Intel Driver Update Utility (HKLM-x32\...\{ca4bc3a8-b99c-4416-90d8-351a8ceab458}) (Version: 2.2.0.2 - Intel)
Intel(R) Driver Update Utility 2.2 (x32 Version: 2.2.0.1 - Intel) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3910 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.0.1098 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{75A3C5F1-C10C-4EC8-95FA-DD689DAD874F}) (Version: 17.1.1529.1613 - Intel Corporation)
Intel(R) Wireless Bluetooth(R)(patch version 17.1.1431.1) (HKLM\...\{302600C1-6BDF-4FD1-1407-148929CC1385}) (Version: 17.1.1407.0480 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.40 - Irfan Skiljan)
iTunes (HKLM\...\{0D44E3A4-6C3D-45D7-B443-079509E5BE5D}) (Version: 12.3.2.35 - Apple Inc.)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
K-Lite Codec Pack 11.5.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.5.0 - )
Kodi (HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Kodi) (Version: - XBMC-Foundation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11105 - Realtek Semiconductor Corp.)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 7.35.295.2 - Lenovo)
Maxthon Cloud Browser (HKLM-x32\...\Maxthon3) (Version: 4.4.8.1000 - Maxthon International Limited)
MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited)
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProplusRetail - cs-cz) (Version: 16.0.6366.2056 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProplusRetail - en-us) (Version: 16.0.6366.2056 - Microsoft Corporation)
Microsoft Project Professional 2016 - cs-cz (HKLM\...\ProjectProRetail - cs-cz) (Version: 16.0.6366.2056 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM\...\ProjectProRetail - en-us) (Version: 16.0.6366.2056 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 x64 CSY (HKLM\...\{0A8A841B-29C4-4947-BF59-241216B4D904}) (Version: 4.0.8482.1 - Microsoft Corporation)
Microsoft Visio Professional 2016 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 16.0.6366.2056 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM\...\VisioProRetail - en-us) (Version: 16.0.6366.2056 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Mozilla Firefox 43.0.4 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.4 (x86 en-US)) (Version: 43.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.4.5848 - Mozilla)
MPC-HC 1.7.9 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.9 - MPC-HC Team)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.6326.1019 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.6326.1019 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.6326.1019 - Microsoft Corporation) Hidden
Onekey Theater (HKLM-x32\...\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Opera Stable 34.0.2036.47 (HKLM-x32\...\Opera 34.0.2036.47) (Version: 34.0.2036.47 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 9.5.20.5318 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 361.43 (Version: 361.43 - NVIDIA Corporation) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Plánování směn verze 1.0.0.23 (HKLM-x32\...\{51B687AD-E85A-444F-8F36-4C6C98E2DA7F}_is1) (Version: 1.0.0.23 - DUHA system spol. s r.o.)
Podpora aplikací Apple (32bitová) (HKLM-x32\...\{C5815ACF-FD34-4553-8A22-C7411B7E662B}) (Version: 4.1.1 - Apple Inc.)
Podpora aplikací Apple (64bitová) (HKLM\...\{CBF12D2F-CF64-4CB7-858B-2C1F21068E5F}) (Version: 4.1.1 - Apple Inc.)
Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve)
Prohlížeč Seznam.cz (HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\Seznam Browser) (Version: - Seznam.cz a.s.)
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 4.5.8.2500 - Jan Fiala)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
Qualcomm Atheros 61x4 Wireless LAN Installer (HKLM-x32\...\{20CA507E-24AA-4741-87CF-CC1B250790B7}) (Version: 11.0.0.067 - Qualcomm Atheros)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39052 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.213.243 - REALTEK Semiconductor Corp.)
Registrace uživatele zařízení Canon MG2500 series (HKLM-x32\...\Registrace uživatele zařízení Canon MG2500 series) (Version: - ‭Canon Inc.)
RivaTuner Statistics Server 6.4.0 (HKLM-x32\...\RTSS) (Version: 6.4.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.5 - Rockstar Games)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.1.8.0 - Lenovo Group Limited)
SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden
SiteMap Generator 0.975 (beta) (HKLM-x32\...\SiteMap Generator_is1) (Version: - wonderwebware.com)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stream Nation (HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\f2819113ecca712f) (Version: 1.3.5683.0 - Stream Nation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.16.0 - Synaptics Incorporated)
System Requirements Lab Detection (HKLM-x32\...\{441DF767-CC00-4B1B-8D73-33F24A0FC739}) (Version: 6.1.5.0 - Husdawg, LLC)
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.53254 - TeamViewer)
TVMOBiLi (HKLM-x32\...\TVMOBiLi) (Version: - )
UESDK (HKLM-x32\...\{EB3F6640-58AE-4886-B8BA-466B6939A933}_is1) (Version: 1.0.2.7 - Lenovo)
Ulož.to File Manager verze 1.7 (HKLM-x32\...\{8190420D-F4BA-4744-8940-A466F81AF89C}_is1) (Version: 1.7 - Nodus Technologies s.r.o.)
Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0405-1000-0000000FF1CE}_Office15.PROPLUSR_{C224EEBF-D40A-4056-9DD3-EE74666F74AB}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3114502) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{6F47687A-78E9-41B1-8587-ED0CC2677A2A}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3114502) 64-Bit Edition (HKLM\...\{90150000-012B-0405-1000-0000000FF1CE}_Office15.PROPLUSR_{6F47687A-78E9-41B1-8587-ED0CC2677A2A}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3114502) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{6F47687A-78E9-41B1-8587-ED0CC2677A2A}) (Version: - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
Vegas Pro 9.0 (HKLM-x32\...\{DC785DB7-D389-48C3-B146-96FE99BF4E2B}) (Version: 9.0.563 - Sony)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Vypínač na dobrou noc verze 2.0 (HKLM-x32\...\Vypínač na dobrou noc_is1) (Version: - )
WampServer 2.5 (HKLM-x32\...\WampServer 2_is1) (Version: - Hervé Leclerc (HeL))
WD Quick View (HKLM-x32\...\{10E4655D-047D-472A-AE5C-CCEF665B47E8}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.)
WD SmartWare (HKLM\...\{17A76C9D-91D4-4E01-922D-1B3000DEB9F1}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\...\{979a4332-3eb0-4561-9f74-a4fb871cf2bd}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.)
Webshare uploader (HKLM-x32\...\WebshareDLC) (Version: - Webshare)
Windows Driver Package - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1964906038-3208373991-3138683177-1002_Classes\CLSID\{ED90173A-3B4C-4E7E-B9CF-79714425D4B5}\InprocServer32 -> C:\Program Files (x86)\PSPad editor\pspshellx64.dll ()

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01137465-2329-4A83-8D91-CA5DCBB87757} - System32\Tasks\ACGPro Update => C:\Program Files (x86)\ACGPro\ACGPro Update\ACGPro.exe [2016-01-13] ()
Task: {0897AFB0-6C36-4ED1-9B40-9E130A04328C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {08A111D9-CF25-4771-A896-184014AE74E1} - System32\Tasks\HWiNFO => C:\Program Files\HWiNFO64\HWiNFO64.EXE [2015-07-20] (REALiX)
Task: {1C2C9B94-CE70-42BB-BDC3-C5FC175F03F5} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-13] (Adobe Systems Incorporated)
Task: {215545C4-4766-478F-BD13-829A70D94CFC} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {21A52669-4C82-4C62-AF10-55DB91FF47D9} - System32\Tasks\{30A016DA-18BC-46DA-A2D0-960D24A0F1C7} => pcalua.exe -a C:\Users\ErOoR\AppData\Local\CC0451F2-1452884881-11E4-A961-68F728AE1399\Uninstall.exe
Task: {28BB658A-2E85-4E52-979E-9BE52A5C3891} - System32\Tasks\{68ACFB49-CBDC-4F1E-AF17-A3434B6A2A3C} => pcalua.exe -a "C:\Program Files (x86)\Activision\Call of Duty 2\CoD2MP_s.exe" -d "C:\Program Files (x86)\Activision\Call of Duty 2"
Task: {290172E9-2D37-4838-84CA-097886616975} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2DBDFB57-4A92-4F94-B551-A7E5495E6F7D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {2E57F3E4-5429-4F4C-98C0-1D1886970E31} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {3B83BC3B-4AE5-4977-B868-E46BA34AAE9D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15] (Google Inc.)
Task: {5512B9B8-9BF5-4429-BF4E-B071F3C995DE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {58D144FF-3C25-4DB9-8180-ACD0FDF9FBB2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {5B035F41-01AD-4D4A-864B-D1B9E4142293} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-01-07] (Microsoft Corporation)
Task: {66DF47AE-C365-493A-84B5-74BA0019A504} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2016-01-08] (Microsoft Corporation)
Task: {698006C2-0695-40BF-8005-4DCFBD1C2EEC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {6B01ED49-968D-469C-B2A8-B05B1CD105C2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {70DB9B39-3355-4579-A103-D2871943F902} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-08-19] (Lenovo)
Task: {7AE0EA96-8C6A-42CE-8CD0-B12E1E756251} - System32\Tasks\GGGMonitor => C:\Program Files (x86)\yesforsearchesbnd\upkfc.exe
Task: {7AF60EDA-CACD-4A15-B333-EEFDDEA8C016} - System32\Tasks\AutoKMS => C:\windows\AutoKMS\AutoKMS.exe [2015-07-15] ()
Task: {88349B48-69DD-48AD-826E-B4C34F5CDDE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2016-01-08] (Microsoft Corporation)
Task: {90CB5273-302D-4EA2-8FED-7D9B28EF8C4E} - \WebTV_update_playlist_PoPrihlaseni -> No File <==== ATTENTION
Task: {96C9A5EB-CAB5-4954-B5C2-204F09796680} - \GGGUpLoad -> No File <==== ATTENTION
Task: {991460CB-6037-4B4A-A5B4-773D774F7527} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-09-02] (Synaptics Incorporated)
Task: {9F2B8FF0-7FDA-410A-92A8-9CF7E7D3EA11} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [2015-10-27] (Maxthon International ltd.)
Task: {A03207B8-C023-4035-AFA3-FC06C6C4564C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd)
Task: {A16E8E7C-1153-4E4A-8847-8439CD1AEE99} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {A20B2CAE-96B0-4388-B8C9-A8AC43E1FEAA} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {A27925D8-EDFF-4680-9270-8B7B1698E2AA} - System32\Tasks\Trigger KMS Activation => C:\Users\ErOoR\Downloads\aktivator---KMSnano-v19-Final\aktivator - KMSnano v19 Final\TriggerKMS.exe
Task: {B20D85A9-E1BA-4C90-9743-0D28B62FC5E7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {B23948EC-30A7-45E6-9C71-66BB79E1A217} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {BE0B5CBD-31C1-4302-81EE-44865458CFBE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-15] (Google Inc.)
Task: {CADE8C09-D724-4E73-8699-73312EE42DC6} - System32\Tasks\{9C9D20BA-7947-46F6-91F9-11D2D06B22AF} => pcalua.exe -a C:\Users\ErOoR\AppData\Local\Pokki\Engine\HostAppService.exe -c /UNINSTALLMENU
Task: {CC5EF27B-2727-40A2-8906-E9B94342DBBC} - System32\Tasks\Opera scheduled Autoupdate 1436962003 => C:\Program Files (x86)\Opera\launcher.exe [2016-01-08] (Opera Software)
Task: {CCD58525-613A-4E4D-91FD-679B5EF8BC73} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {D1032E7E-790E-407D-93F6-C4E8A8903894} - System32\Tasks\RTSS => C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [2015-10-21] ()
Task: {D2122A06-59BF-4DE5-83F9-E832AC0DD647} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-10] (Lenovo)
Task: {D919108F-B2E3-4B29-B645-7F16CB0559F9} - System32\Tasks\{4C8B9FE2-5B3F-4E5E-A895-33A99728C9DA} => pcalua.exe -a "C:\Program Files (x86)\Vietcong2\vietcong2.exe" -d "C:\Program Files (x86)\Vietcong2"
Task: {D92D7622-C2F8-4CD9-AA99-C1DD2C8F774E} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-01-07] (Microsoft Corporation)
Task: {E3D95517-EF22-4352-B42A-F09F5589BA1C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {E5D41598-2346-499F-A9CE-54C052607D3D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {EBD24381-3CA1-42F0-9500-54795B43CD19} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {EE3A6A3E-4432-4260-ACBF-2B5A2824EED3} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2015-10-05] ()
Task: {EF068ABE-765E-46CF-A4F0-EED904050797} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-14] (Microsoft Corporation)
Task: {EF368A49-14EC-4C2E-8F0D-21D2481C02DC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {FD0B23A8-4E83-4D66-BEDD-D01FED29B2FB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

Re: Po startu Windows 10 se otevře CMD

Napsal: 16 led 2016 14:58
od BeFaCZ
2015-07-29 18:23 - 2015-07-29 18:23 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2016-01-12 15:56 - 2015-12-16 15:54 - 00126256 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-08-19 21:46 - 2015-08-11 10:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-10-24 14:08 - 2016-01-07 06:13 - 00162472 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
2015-05-15 15:26 - 2015-05-15 15:26 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 04:45 - 2015-10-13 04:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-01-12 15:56 - 2015-12-16 17:59 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2015-07-30 00:26 - 2015-11-26 07:03 - 00076152 _____ () C:\WINDOWS\system32\PnkBstrA.exe
2015-10-01 16:59 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 16:59 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-01-12 13:48 - 2016-01-07 15:14 - 08903848 _____ () C:\Program Files\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll
2014-08-30 19:07 - 2015-10-21 19:09 - 00403456 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll
2015-10-21 19:33 - 2015-10-21 19:33 - 00205000 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
2015-10-01 16:59 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-12-09 05:07 - 2015-11-25 05:20 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-12-09 05:07 - 2015-11-25 05:17 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-09 05:07 - 2015-11-25 05:17 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 16:59 - 2015-09-17 06:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-30 16:40 - 2010-10-26 11:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2015-08-25 14:33 - 2012-12-21 19:33 - 00020288 _____ () C:\Program Files\CCleaner\branding.dll
2015-12-08 20:25 - 2015-12-08 20:25 - 00047616 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2015-10-21 19:08 - 2015-10-21 19:08 - 00031232 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer64.exe
2015-10-21 19:08 - 2015-10-21 19:08 - 00088576 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
2016-01-15 19:04 - 2016-01-14 03:41 - 01584728 _____ () C:\Program Files (x86)\yesforsearchesbnd\bugreport.exe
2015-12-10 23:07 - 2015-12-10 23:08 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2015-12-10 23:07 - 2015-12-10 23:08 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2015-11-20 17:03 - 2015-11-20 17:03 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2016-01-11 18:03 - 2016-01-11 18:03 - 03563008 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.6020.0_x64__8wekyb3d8bbwe\Calculator.exe
2015-12-15 01:30 - 2015-12-15 01:31 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.6020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2015-10-21 19:08 - 2015-10-21 19:08 - 00056832 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll
2015-10-21 19:08 - 2015-10-21 19:08 - 00353792 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll
2015-10-21 19:08 - 2015-10-21 19:08 - 00071680 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll
2014-08-30 19:07 - 2015-10-21 19:08 - 00356352 _____ () C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks.dll
2016-01-12 15:56 - 2015-12-16 17:59 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-07-15 03:31 - 2015-07-15 03:31 - 00107520 _____ () C:\Program Files (x86)\DAEMON Tools Pro\BRD.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-15 15:02 - 2016-01-16 13:20 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\ErOoR\Desktop\mBmovie\seriál.png
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Apple Mobile Device => 3
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: CCSDK => 2
MSCONFIG\Services: CGVPNCliService => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: CxAudMsg => 2
MSCONFIG\Services: GDCAgent => 2
MSCONFIG\Services: GfExperienceService => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: ibtsiva => 2
MSCONFIG\Services: igfxCUIService2.0.0.0 => 2
MSCONFIG\Services: IJPLMSVC => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: Lenovo EasyPlus Hotspot => 3
MSCONFIG\Services: Lenovo System Agent Service => 2
MSCONFIG\Services: LenovoWiFiHotspotSvr => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NvNetworkService => 2
MSCONFIG\Services: NvStreamNetworkSvc => 3
MSCONFIG\Services: NvStreamSvc => 2
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: Origin Client Service => 3
MSCONFIG\Services: PnkBstrA => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: SwitchBoard => 3
MSCONFIG\Services: SynTPEnhService => 2
MSCONFIG\Services: TeamViewer => 2
MSCONFIG\Services: tvMobiliService => 2
MSCONFIG\Services: wampapache64 => 3
MSCONFIG\Services: wampmysqld64 => 3
MSCONFIG\Services: WDBackup => 2
MSCONFIG\Services: WDDriveService => 2
HKLM\...\StartupApproved\StartupFolder: => "TVMOBiLiArtworkManager.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "OnekeyStudio"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "AdobeCS6ServiceManager"
HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\...\StartupApproved\Run32: => "CLVirtualDrive"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "PD-Proxy"
HKLM\...\StartupApproved\Run32: => "WD Quick View"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\StartupFolder: => "hide.me VPN.lnk"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "DAEMON Tools Pro Agent"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Zoner Photo Studio Autoupdate"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Zoner Photo Studio Service 16"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Save Serp Now"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "CyberGhost"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "RealtekSoftware"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Stream Nation"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Dxtory Update Checker 2.0"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "iCloudPhotos"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "iCloudDrive"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "iCloudServices"
HKU\S-1-5-21-1964906038-3208373991-3138683177-1002\...\StartupApproved\Run: => "PCSpeedUp"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{2D72D78D-8658-4BA2-BB43-33A5DF652CAC}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\bfh.exe
FirewallRules: [{F1ED5CA9-D546-42BE-8230-E0FEC894BC92}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\bfh.exe
FirewallRules: [{B48929D4-C360-45BF-B4C1-4B0CCAC0DC71}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{7A38A7AA-329B-4AF0-8C5F-D6A8D1B1169C}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{136F35CA-B0FA-4AC4-A5ED-1473A6E300A8}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{60398BB7-50A3-436C-B125-A937BB4A46C5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{3C5C5570-12C9-41BA-8CF8-5CCD67818CCC}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{4E344D6F-5CD9-476A-8945-BB54ADD8B161}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{2E044724-83C9-4CD6-967F-08953C026211}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{9A364D8B-76A9-4C5A-A843-B04587E1F2EF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{29D8DEA2-9C51-4190-86D9-398048148AF4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{D3D933EF-A565-4930-82FA-7010FF10F36D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{1D75A876-850B-422D-BF9B-54101D66651D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6sp.exe
FirewallRules: [{C6344F83-AE09-423F-B1E8-419D19FF5DE9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6sp.exe
FirewallRules: [{C200B467-7353-47F5-945E-76E15C5A3AA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{9F3323DE-7E7E-42E0-AC00-FE02B9A7BEF3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [UDP Query User{47B34805-10EC-4EA1-8FC0-0587A0FA1650}C:\users\eroor\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\eroor\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{A765C018-5309-4283-8313-E1BD3D8BFB30}C:\users\eroor\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\eroor\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{DC30C2D4-0AFE-4039-850D-7BD2C548CFBA}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{7A543A85-8A19-45BF-A62D-F093435D6788}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{BB185ED9-57D6-4FBD-9201-029F94E7C9DB}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{BCC9C59E-C7F2-43BF-9E52-66EC29DEE31A}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0B950A21-4503-4CAA-9EEE-92C2F0B8E9F6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{3C75EE67-727E-47CD-A1A7-1C046483C4E8}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{63248F9A-6EEC-4CC1-9FBA-C7EEB1637B07}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{F36E359F-0691-4070-82C8-58457A0E17F0}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{82150105-F63F-4208-B446-85BB4B545175}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{CF8F1FBB-D592-425D-87B5-6FE635C050CC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5AB16A29-B0BA-4E1C-9B6A-7ADFC4BF24E1}] => (Allow) C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
FirewallRules: [{561446A4-2B15-48F3-B61B-09C4BB5A8E19}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{83BC3D5E-A1FB-428E-822D-EB71D61FF654}] => (Allow) LPort=55100
FirewallRules: [{CE7E959C-A0EA-4F53-823A-DDEF0340D6E9}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{E9E48859-EF1B-40A2-8744-4321CCA03AA5}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{A3D031FE-5481-4710-BD29-84C7F04D97AA}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{777E993C-0331-4ADA-9ED3-31B6EEB62474}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{1941FB57-F6DB-4E5D-8057-0E710535C333}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{9EDCB63A-F186-4AFF-BE35-4302B21B3982}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\BFHWebHelper.exe
FirewallRules: [{BCCFF99E-4670-4708-A3D0-93B7EA908836}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\BFHWebHelper.exe
FirewallRules: [{F30BEB36-7308-4577-9867-F19D86E95668}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{A8FC76EA-5A99-488C-A06F-1CC0A543CA3A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{614F429A-5C78-4EF0-8B02-31DE8BD8529E}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{4AA44DF4-CB2D-48AB-926B-607C1AA34D8A}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{5AD295F6-9F79-474E-922B-B188AA1AAD88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{B380E019-689D-40A5-BA56-CC06FE77FCC2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{9D82C03A-9F97-4AE4-BECB-B3A90DB89BF4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BE80EE46-FA94-4E1F-866F-9D84CDDA3BA8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{08D5399B-7C22-484B-8A3E-9468634E3EA4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AD7883E1-459F-4ED2-AFB0-AF5C24386321}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{460DA062-85C6-49E1-BDC0-860444237611}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Rogue\ACC.exe
FirewallRules: [{247433E1-253D-4B04-82A8-C85101CB5EDF}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Rogue\ACC.exe
FirewallRules: [TCP Query User{706E26CF-6E1F-41B8-A193-8C310BE827F5}C:\program files (x86)\microsoft directx sdk (june 2010)\utilities\bin\x86\audconsole3.exe] => (Allow) C:\program files (x86)\microsoft directx sdk (june 2010)\utilities\bin\x86\audconsole3.exe
FirewallRules: [UDP Query User{E2168D20-36D8-48A2-AA17-C551A64204AA}C:\program files (x86)\microsoft directx sdk (june 2010)\utilities\bin\x86\audconsole3.exe] => (Allow) C:\program files (x86)\microsoft directx sdk (june 2010)\utilities\bin\x86\audconsole3.exe
FirewallRules: [TCP Query User{CDD5D376-213C-41BC-B8FD-F6A8C7341E7A}C:\users\eroor\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\eroor\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{F851B6F9-09F5-4583-BFCC-8E1CFDEC830E}C:\users\eroor\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\eroor\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{6F9DA27E-B0B4-43F6-9EBD-A9F53ED40A76}C:\wamp\bin\apache\apache2.4.9\bin\httpd.exe] => (Allow) C:\wamp\bin\apache\apache2.4.9\bin\httpd.exe
FirewallRules: [UDP Query User{6717715D-F043-4061-BFCD-35630A01FF3F}C:\wamp\bin\apache\apache2.4.9\bin\httpd.exe] => (Allow) C:\wamp\bin\apache\apache2.4.9\bin\httpd.exe
FirewallRules: [TCP Query User{98627401-4F27-4DD3-928A-423CAAB48872}C:\program files (x86)\origin games\bfh\bfh.exe] => (Allow) C:\program files (x86)\origin games\bfh\bfh.exe
FirewallRules: [UDP Query User{ED55E4FA-B4F5-4DB8-A66A-91425CE0035D}C:\program files (x86)\origin games\bfh\bfh.exe] => (Allow) C:\program files (x86)\origin games\bfh\bfh.exe
FirewallRules: [TCP Query User{809B5534-EFB5-4D66-AD45-2EDEB063378B}C:\program files (x86)\origin games\battlefield 3\bf3.exe] => (Allow) C:\program files (x86)\origin games\battlefield 3\bf3.exe
FirewallRules: [UDP Query User{3AA3BF45-BB79-40DD-A915-6E93AC9B29B7}C:\program files (x86)\origin games\battlefield 3\bf3.exe] => (Allow) C:\program files (x86)\origin games\battlefield 3\bf3.exe
FirewallRules: [TCP Query User{20B5905D-EBA9-48EB-8468-3E67A6E829AE}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe
FirewallRules: [UDP Query User{874A27C8-6FA6-4535-98D7-D098838C675E}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe
FirewallRules: [{3494AFFB-85F2-4C48-98AD-0466AE11BF7D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{24DB038D-5C56-4475-8049-D16A3E5BCBE3}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{6AFFD31E-7188-4AE8-A037-90D61020607F}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{C9E0DD33-4DFB-432F-A109-3B292CAC50C6}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{B6283B95-E034-43EA-9EA0-4106E9B9A92D}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{C32ADE32-C0D2-4A80-9F7C-3E8EDEFDEEF4}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{154FC940-AC56-4387-9CC7-9A32DC2A5A91}] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{61295BA0-72A2-4ADF-882F-31C810AF2B41}] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{871C2614-8D24-4E06-AB1E-489636B77A3A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F6024328-02EB-48D4-B3E0-DC7D2D9BB867}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9096B3EC-B789-440A-88DF-F85C4D00D875}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EEC0BB07-348D-4B7C-8127-89857AAED4CB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{71805A0F-0AD7-419A-9EAC-CB63637C0FAB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A7F7D6B4-33BA-4158-9D21-BD0537E8A7E5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{042D78E0-AC92-47A6-87CE-BEC787CB7089}E:\autoplay\docs\dslman.exe] => (Block) E:\autoplay\docs\dslman.exe
FirewallRules: [UDP Query User{F6B2304E-2222-46EC-9400-8B2B1836289B}E:\autoplay\docs\dslman.exe] => (Block) E:\autoplay\docs\dslman.exe
FirewallRules: [TCP Query User{AA6282B8-702B-4249-80B9-5993FCCEAC90}C:\users\eroor\downloads\dslman.exe] => (Allow) C:\users\eroor\downloads\dslman.exe
FirewallRules: [UDP Query User{8A9D3850-0AF0-406D-AC60-A194BDC8CBFA}C:\users\eroor\downloads\dslman.exe] => (Allow) C:\users\eroor\downloads\dslman.exe
FirewallRules: [{5F226DC3-5EED-459B-9234-40646AA85EDA}] => (Block) C:\users\eroor\downloads\dslman.exe
FirewallRules: [{2F16CB42-94F7-43C3-82A8-13E0299F163B}] => (Block) C:\users\eroor\downloads\dslman.exe
FirewallRules: [{E5B3C60A-9063-43BB-831D-1C80AB600B6B}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{8213BB79-9BCB-4125-B53A-4415087E5FC8}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A3733B08-D58F-4AF9-8691-70DC30E74888}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{6C0889A3-8FDA-4D4B-B62E-31032202F2A2}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{04272043-8F77-4581-8CBE-2464EB422C86}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{D1FFDFAB-EFCD-4F67-9976-1D2EB3471C96}C:\program files (x86)\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{738B223A-EBB1-4278-8B88-724AC3F9AA04}C:\program files (x86)\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [{41BFF99E-8E2A-4139-93FE-4F5BF7CA59D2}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{276893C9-2E8D-4782-97AE-223238B8834B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{B04867AF-5C6C-42F5-BB3A-27E98EE433BC}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{9A33B3EE-08AB-454C-9095-56CCC46264CD}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{61BA481B-E53B-4945-BE27-66E9966663A4}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe
FirewallRules: [{BB10018F-5F37-4B91-B464-47DF27FA5389}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe
FirewallRules: [{477188D2-9B3E-488A-A6B8-28969579F19D}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaWmp.exe
FirewallRules: [{851CCB72-BC68-4D8E-BE01-2B0838F35586}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaWmp.exe
FirewallRules: [TCP Query User{B002222D-4822-4C06-A247-08A2AB54F792}C:\program files\call of duty black ops iii\blackops3.exe] => (Allow) C:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [UDP Query User{6D9E2923-0B09-40DD-86E8-E7D0A46B4443}C:\program files\call of duty black ops iii\blackops3.exe] => (Allow) C:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [{81882D56-3B22-4DAB-9DA0-7994336D3FEA}] => (Block) C:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [{6C9F358B-C12A-4747-AE9C-E3A67635A3D9}] => (Block) C:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [{7F408CE3-05DE-40F7-A1AC-2BE6850135F6}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{187033CB-22BC-4E7A-A6C3-CB30D7DA7255}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{B0A07EEA-0F30-40D8-81DB-1E3987663546}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{BF1B00D7-B3FD-4461-9D3D-116255279BC2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{80440EC9-8500-4078-8824-39757E78F918}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{13F52548-EE07-47A2-B14F-7A22F2A1E417}C:\program files (x86)\activision\call of duty - world at war\codwawmp.exe] => (Allow) C:\program files (x86)\activision\call of duty - world at war\codwawmp.exe
FirewallRules: [UDP Query User{1278D56E-4815-4473-9DB9-313BA374F539}C:\program files (x86)\activision\call of duty - world at war\codwawmp.exe] => (Allow) C:\program files (x86)\activision\call of duty - world at war\codwawmp.exe
FirewallRules: [TCP Query User{2C98065C-BF82-4012-A6E2-F9A5E95035D3}C:\program files (x86)\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{75268716-7728-4599-B586-9FF49F39ED72}C:\program files (x86)\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [{BF14D7D5-0341-4E48-B93E-9E36B9935BBF}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [{AFC0BEE0-6BC5-4699-9E41-8CB052A34307}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4WebHelper.exe
FirewallRules: [{1C504B00-E76F-41E9-AF72-0AC7946D8360}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [{BB05E0BA-DAF8-41C3-9430-94CE2EA6A0CC}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BF4X86WebHelper.exe
FirewallRules: [TCP Query User{FC3AB9D9-6494-4186-A780-A1187B5564C9}D:\games\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe] => (Allow) D:\games\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [UDP Query User{479B9CA9-FF5D-4FCE-BF6F-D09D98699924}D:\games\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe] => (Allow) D:\games\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [{9B6AA7D5-7775-4DEC-8A14-65851B98D358}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{45C9DA61-F901-41A5-9606-A04D8A0C4A36}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{CF52E71E-C230-4730-989C-AE146D8658AA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{E76A3F50-43FA-4D0F-B8A0-694A64CAC576}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{25AD620A-23EB-4D95-A481-925F1392D709}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{C9222932-BCE6-4552-A2F8-380493E7E820}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A7BD1FE4-B64C-488E-AA9A-B2780157AF29}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A6691938-8416-4770-A490-FDFB3B3BB19D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{1312BB2A-2D8F-401D-9917-8D6C91390725}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{9B9A1AC5-8808-4C22-A01A-C828E6E159BE}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{2A3F4D8D-A99F-4908-A991-6CBC4A010AC8}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [TCP Query User{4CA36A36-4619-4590-BC77-781F936D942D}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [UDP Query User{6C0AE9CF-A459-4CDD-A41C-49791FCDF3B0}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [{E05A0B58-11C7-4521-B371-BE8E574AD55C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{FFECCC5A-5E82-4AA3-902B-53B882E67029}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\BFHWebHelper.exe
FirewallRules: [{0D83C7E2-A58C-474C-A30A-343A1084768B}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\BFHWebHelper.exe
FirewallRules: [TCP Query User{C386CD07-ACCB-4E1D-B656-3BC4EC9AA9A5}D:\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe] => (Allow) D:\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [UDP Query User{86896D93-9BCE-4222-BD0B-53CCAC738B9A}D:\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe] => (Allow) D:\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [{33EF0CD4-1351-472D-85A4-37E3600D10E0}] => (Allow) C:\Program Files (x86)\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe
FirewallRules: [{6D020BC3-78BC-46B9-BC1E-819F088A3DFF}] => (Allow) C:\Program Files (x86)\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe
FirewallRules: [{0D0CF66A-B447-4838-A2B8-1F5CDAF8DBE8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Juarez - The Cartel\CoJ_TheCartel.exe
FirewallRules: [{0750D0ED-3BEE-4A81-8D61-E9A7A25DDF73}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Juarez - The Cartel\CoJ_TheCartel.exe

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/16/2016 02:21:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AutoKMS.exe, verze: 2.5.2.0, časové razítko: 0x53c9a9a0
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10240.16384, časové razítko: 0x559f38c3
Kód výjimky: 0xe0434352
Posun chyby: 0x000000000002a1c8
ID chybujícího procesu: 0x680
Čas spuštění chybující aplikace: 0xAutoKMS.exe0
Cesta k chybující aplikaci: AutoKMS.exe1
Cesta k chybujícímu modulu: AutoKMS.exe2
ID zprávy: AutoKMS.exe3
Úplný název chybujícího balíčku: AutoKMS.exe4
ID aplikace související s chybujícím balíčkem: AutoKMS.exe5

Error: (01/16/2016 02:21:50 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoKMS.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.FormatException
Stack:
at System.DateTimeParse.Parse(System.String, System.Globalization.DateTimeFormatInfo, System.Globalization.DateTimeStyles)
at ..(.)
at ..(.)
at ..()

Error: (01/16/2016 01:19:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AutoKMS.exe, verze: 2.5.2.0, časové razítko: 0x53c9a9a0
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10240.16384, časové razítko: 0x559f38c3
Kód výjimky: 0xe0434352
Posun chyby: 0x000000000002a1c8
ID chybujícího procesu: 0x13f8
Čas spuštění chybující aplikace: 0xAutoKMS.exe0
Cesta k chybující aplikaci: AutoKMS.exe1
Cesta k chybujícímu modulu: AutoKMS.exe2
ID zprávy: AutoKMS.exe3
Úplný název chybujícího balíčku: AutoKMS.exe4
ID aplikace související s chybujícím balíčkem: AutoKMS.exe5

Error: (01/16/2016 01:19:27 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoKMS.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.FormatException
Stack:
at System.DateTimeParse.Parse(System.String, System.Globalization.DateTimeFormatInfo, System.Globalization.DateTimeStyles)
at ..(.)
at ..(.)
at ..()

Error: (01/16/2016 01:19:16 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC-ErOoR)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2144927141. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (01/16/2016 12:55:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AutoKMS.exe, verze: 2.5.2.0, časové razítko: 0x53c9a9a0
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10240.16384, časové razítko: 0x559f38c3
Kód výjimky: 0xe0434352
Posun chyby: 0x000000000002a1c8
ID chybujícího procesu: 0x2288
Čas spuštění chybující aplikace: 0xAutoKMS.exe0
Cesta k chybující aplikaci: AutoKMS.exe1
Cesta k chybujícímu modulu: AutoKMS.exe2
ID zprávy: AutoKMS.exe3
Úplný název chybujícího balíčku: AutoKMS.exe4
ID aplikace související s chybujícím balíčkem: AutoKMS.exe5

Error: (01/16/2016 12:55:42 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoKMS.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.FormatException
Stack:
at System.DateTimeParse.Parse(System.String, System.Globalization.DateTimeFormatInfo, System.Globalization.DateTimeStyles)
at ..(.)
at ..(.)
at ..()

Error: (01/16/2016 12:36:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AutoKMS.exe, verze: 2.5.2.0, časové razítko: 0x53c9a9a0
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10240.16384, časové razítko: 0x559f38c3
Kód výjimky: 0xe0434352
Posun chyby: 0x000000000002a1c8
ID chybujícího procesu: 0x1780
Čas spuštění chybující aplikace: 0xAutoKMS.exe0
Cesta k chybující aplikaci: AutoKMS.exe1
Cesta k chybujícímu modulu: AutoKMS.exe2
ID zprávy: AutoKMS.exe3
Úplný název chybujícího balíčku: AutoKMS.exe4
ID aplikace související s chybujícím balíčkem: AutoKMS.exe5

Error: (01/16/2016 12:36:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoKMS.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.FormatException
Stack:
at System.DateTimeParse.Parse(System.String, System.Globalization.DateTimeFormatInfo, System.Globalization.DateTimeStyles)
at ..(.)
at ..(.)
at ..()

Error: (01/16/2016 02:23:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AutoKMS.exe, verze: 2.5.2.0, časové razítko: 0x53c9a9a0
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10240.16384, časové razítko: 0x559f38c3
Kód výjimky: 0xe0434352
Posun chyby: 0x000000000002a1c8
ID chybujícího procesu: 0x1a08
Čas spuštění chybující aplikace: 0xAutoKMS.exe0
Cesta k chybující aplikaci: AutoKMS.exe1
Cesta k chybujícímu modulu: AutoKMS.exe2
ID zprávy: AutoKMS.exe3
Úplný název chybujícího balíčku: AutoKMS.exe4
ID aplikace související s chybujícím balíčkem: AutoKMS.exe5


System errors:
=============
Error: (01/16/2016 02:37:15 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (01/16/2016 02:18:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba WWAN AutoConfig byla ukončena s následující chybou:
%%997

Error: (01/16/2016 02:18:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba User Data Access_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (01/16/2016 02:18:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba User Data Storage_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (01/16/2016 02:18:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Contact Data_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (01/16/2016 02:18:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Sync Host_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (01/16/2016 01:31:44 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/16/2016 01:31:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/16/2016 01:31:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (01/16/2016 01:31:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


CodeIntegrity:
===================================
Date: 2016-01-16 13:43:49.656
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 13:43:49.523
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 12:40:42.202
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 12:40:42.170
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 03:32:17.827
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 03:32:17.795
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 03:32:17.732
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 03:32:17.671
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 03:32:09.500
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2016-01-16 03:32:08.600
Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-4510U CPU @ 2.00GHz
Percentage of memory in use: 13%
Total physical RAM: 16276.27 MB
Available physical RAM: 14007.56 MB
Total Virtual: 18708.27 MB
Available Virtual: 16430.14 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:889.87 GB) (Free:193.43 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:14.41 GB) NTFS
Drive f: (ESD-USB) (Removable) (Total:7.27 GB) (Free:4.96 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 113ADB84)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 7.3 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================