Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-07-2016
Ran by Hrstka (2016-07-31 17:00:33)
Running from C:\Users\Hrstka\Desktop
Windows 8.1 Connected (X64) (2015-05-09 23:28:57)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-553964673-1622739263-2049447999-500 - Administrator - Disabled)
Guest (S-1-5-21-553964673-1622739263-2049447999-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-553964673-1622739263-2049447999-1003 - Limited - Enabled)
Hrstka (S-1-5-21-553964673-1622739263-2049447999-1001 - Administrator - Enabled) => C:\Users\Hrstka
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: ESET Smart Security 9.0.385.1 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.385.1 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
CCleaner (HKLM\...\CCleaner) (Version: 5.20 - Piriform)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.38.00 - Lenovo Inc.) Hidden
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.21 - Lenovo)
Energy Manager (x32 Version: 1.5.0.21 - Lenovo) Hidden
ESET Smart Security (HKLM\...\{D94B5945-22DD-47C9-9CA4-ED784C9B2427}) (Version: 9.0.385.1 - ESET, spol. s r.o.)
Google Chrome (HKU\S-1-5-21-553964673-1622739263-2049447999-1001\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1347.2) (HKLM\...\{302600C1-6BDF-4FD1-1312-148929CC1385}) (Version: 17.0.1312.0414 - Intel Corporation)
Intel(R) Sideband Fabric Device Driver (HKLM-x32\...\C5A8BC6E-723A-4C0F-96E1-C426D1A4BCA9) (Version: 1.0.0.1002 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{2f4d8103-e601-4d48-b81d-d508d760aaba}) (Version: 17.0.3 - Intel Corporation)
Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.25.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10264 - Realtek Semiconductor Corp.)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2326 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2326 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.43.4 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
Malwarebytes Anti-Malware verze 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office Klikni a spusť 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1011 - Microsoft Corporation)
Microsoft Office Starter 2010 - čeština (HKLM-x32\...\{90140011-0066-0405-0000-0000000FF1CE}) (Version: 14.0.4763.1011 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0405-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-553964673-1622739263-2049447999-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Hrstka\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-553964673-1622739263-2049447999-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Hrstka\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-553964673-1622739263-2049447999-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-553964673-1622739263-2049447999-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Hrstka\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5A277F2E-A817-463E-8170-88C269D35293} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
Task: {5D390007-DEA3-4EF9-A244-3084868682B6} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2014-05-22] ()
Task: {B592A570-0062-40D6-B1DF-2C19006B5648} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {D34748F1-668B-4F52-B5C9-0FAE3B262190} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-09] (CyberLink Corp.)
Task: {D99D39A2-0E3C-4A4A-82BA-DD8BAA377C0F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-13] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-10-13 22:11 - 2012-04-24 12:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-553964673-1622739263-2049447999-1001\...\mojebanka.cz ->
hxxps://etrading.mojebanka.czIE trusted site: HKU\S-1-5-21-553964673-1622739263-2049447999-1001\...\mojeplatba.cz ->
hxxps://www.mojeplatba.cz==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2016-07-31 12:30 - 00000753 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-553964673-1622739263-2049447999-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme1\img2.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: Bluetooth Device Monitor => 2
MSCONFIG\Services: Bluetooth OBEX Service => 2
MSCONFIG\Services: iBtSiva => 2
HKLM\...\StartupApproved\Run: => "Lenovo Utility"
HKLM\...\StartupApproved\Run: => "SmartAudio"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{41A49E03-7947-40AF-913A-D7093BDE730A}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{C01CE014-910C-4139-8905-3A91B328612D}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{1B6B53A5-39C7-4D76-9BD5-66E7A28DE783}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{C84838CE-073F-4BCD-AAFA-DC75E7D9689C}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{F4E5AA18-D912-465B-ABF9-5631BE8B0E25}] => (Allow) LPort=55100
FirewallRules: [{45D4E69B-4FFD-4E02-A629-2712AF45E2DD}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
==================== Restore Points =========================
29-07-2016 16:58:49 Configured Lenovo Updates
30-07-2016 10:37:20 JRT Pre-Junkware Removal
31-07-2016 12:29:44 zoek.exe restore point
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/31/2016 01:48:22 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/31/2016 12:58:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/30/2016 12:48:35 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/29/2016 04:10:44 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/29/2016 03:19:10 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/29/2016 10:10:04 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/28/2016 01:42:06 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database
Error: (07/28/2016 12:53:29 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Pouze informace
(Patch task for {90140011-0066-0405-0000-0000000FF1CE}): DownloadLatest Failed: V tuto chvíli není aktivní žádné připojení k síti. Jakmile bude připojen adaptér, bude Služba inteligentního přenosu na pozadí (BITS) akci opakovat.
Error: (07/27/2016 06:13:09 PM) (Source: Application Virtualization Client) (EventID: 3079) (User: )
Description: {hap=12:app=Microsoft Excel Starter 2010 9014006604050000:tid=1514:usr=Hrstka}
Klient nemohl spustit aplikaci Q:\140066.csy\Office14\EXCELC.EXE (návratový kód 22400B24-00000057, poslední chyba: 87).
Error: (07/27/2016 06:13:09 PM) (Source: Application Virtualization Client) (EventID: 6001) (User: )
Description: {tid=1514:usr=Hrstka}
Nelze vytvořit proces (CreateProcess) (návratový kód 22400B24-00000057).
System errors:
=============
Error: (07/31/2016 01:38:16 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 40. Stav chyby Windows SChannel: 252
Error: (07/31/2016 12:48:00 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 40. Stav chyby Windows SChannel: 252
Error: (07/31/2016 12:44:28 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.
Error: (07/31/2016 12:44:28 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.
Error: (07/31/2016 12:44:27 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.
Error: (07/31/2016 12:44:27 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.
Error: (07/31/2016 12:44:26 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.
Error: (07/30/2016 10:31:17 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 40. Stav chyby Windows SChannel: 252
Error: (07/30/2016 10:30:39 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.
Cesta k modulu: C:\windows\System32\IWMSSvc.dll
Error: (07/30/2016 10:30:39 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.
Cesta k modulu: C:\windows\System32\IWMSSvc.dll
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU N3540 @ 2.16GHz
Percentage of memory in use: 42%
Total physical RAM: 3979.21 MB
Available physical RAM: 2271.65 MB
Total Virtual: 5899.21 MB
Available Virtual: 3845.43 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:425.14 GB) (Free:162.69 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:10.89 GB) NTFS
Drive f: () (Removable) (Total:14.54 GB) (Free:7.25 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 97D2FFE3)
Partition: GPT.
========================================================
Disk: 1 (Size: 14.6 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2016
Ran by Hrstka (administrator) on LENOVO-PC (31-07-2016 16:58:07)
Running from C:\Users\Hrstka\Desktop
Loaded Profiles: Hrstka (Available Profiles: Hrstka)
Platform: Windows 8.1 Connected (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(ESET) C:\Users\Hrstka\Desktop\ESETTeslaCryptDecryptor.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3276104 2014-05-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2014-02-27] (Realtek semiconductor)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-10-13] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10841584 2014-10-13] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKU\S-1-5-21-553964673-1622739263-2049447999-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8891608 2016-07-13] (Piriform Ltd)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{1BC11AB7-748D-4B3A-9D6C-A4ACD01C018D}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-553964673-1622739263-2049447999-1001\Software\Microsoft\Internet Explorer\Main,Search Bar =
hxxp://search.msn.com/spbasic.htmSearchScopes: HKU\S-1-5-21-553964673-1622739263-2049447999-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-553964673-1622739263-2049447999-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-553964673-1622739263-2049447999-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-28] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Hrstka\AppData\Roaming\Mozilla\Firefox\Profiles\obxm5qhk.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-553964673-1622739263-2049447999-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Hrstka\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-553964673-1622739263-2049447999-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Hrstka\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-29]
CHR Extension: (Google Drive) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-29]
CHR Extension: (YouTube) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-29]
CHR Extension: (Google Search) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-29]
CHR Extension: (Gmail) - C:\Users\Hrstka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-29]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2542216 2016-06-10] (ESET)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2013-10-15] (ELAN Microelectronics Corp.)
S4 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [130008 2014-01-22] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-02] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-02] (Intel(R) Corporation)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-10-13] (Lenovo(beijing) Limited)
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-18] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-18] (Intel® Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-11-07] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1411384 2013-11-07] (Motorola Solutions, Inc.)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [263336 2016-06-28] (ESET)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2016-06-28] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [197288 2016-06-28] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [153248 2016-06-28] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [208552 2016-06-28] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [61608 2016-06-28] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [84640 2016-06-28] (ESET)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [149448 2014-01-22] (Intel Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-10] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3443680 2014-06-01] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9109720 2014-02-27] (Realtek Semiconductor Corp.)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-07-31] ()
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 CnxtHdAudService; \SystemRoot\system32\drivers\CHDRT64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-31 16:58 - 2016-07-31 16:59 - 00012360 _____ C:\Users\Hrstka\Desktop\FRST.txt
2016-07-31 16:57 - 2016-07-31 16:58 - 00000000 ____D C:\FRST
2016-07-31 16:48 - 2016-07-31 16:43 - 02394112 _____ (Farbar) C:\Users\Hrstka\Desktop\FRST64.exe
2016-07-31 13:45 - 2016-07-31 13:45 - 00019968 ___SH C:\Users\Public\Documents\Thumbs.db
2016-07-31 12:47 - 2016-07-31 12:20 - 00024064 _____ C:\windows\zoek-delete.exe
2016-07-31 12:20 - 2016-07-31 12:44 - 00000000 ____D C:\zoek_backup
2016-07-31 12:20 - 2016-07-31 12:17 - 01309184 _____ C:\Users\Hrstka\Desktop\zoek.exe
2016-07-30 10:41 - 2016-07-31 12:49 - 00028272 _____ C:\windows\system32\Drivers\TrueSight.sys
2016-07-30 10:40 - 2016-07-30 10:40 - 00000000 ____D C:\ProgramData\RogueKiller
2016-07-30 10:38 - 2016-07-30 10:35 - 25355848 _____ C:\Users\Hrstka\Desktop\RogueKillerX64.exe
2016-07-30 10:36 - 2016-07-30 10:34 - 01610560 _____ (Malwarebytes) C:\Users\Hrstka\Desktop\JRT.exe
2016-07-29 17:44 - 2016-07-30 10:13 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-07-29 17:43 - 2016-07-29 17:43 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-07-29 17:43 - 2016-07-29 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-07-29 17:43 - 2016-07-29 17:43 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-07-29 17:43 - 2016-07-29 17:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-07-29 17:43 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-07-29 17:43 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-07-29 17:43 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-07-29 17:38 - 2016-07-29 17:26 - 03712064 _____ C:\Users\Hrstka\Desktop\AdwCleaner.exe
2016-07-29 17:37 - 2016-07-30 10:29 - 00000000 ____D C:\AdwCleaner
2016-07-29 17:30 - 2016-07-31 16:56 - 00000000 ____D C:\Users\Hrstka\Desktop\backups
2016-07-29 15:20 - 2016-07-28 16:06 - 00388608 _____ (Trend Micro Inc.) C:\Users\Hrstka\Desktop\hijackthis.exe
2016-07-29 14:40 - 2016-07-29 14:39 - 149365520 _____ (Microsoft Corporation) C:\Users\Hrstka\Desktop\msert.exe
2016-07-29 12:11 - 2016-07-28 13:58 - 00862368 _____ (ESET) C:\Users\Hrstka\Desktop\ESETTeslaCryptDecryptor.exe
2016-07-29 12:02 - 2016-07-29 13:35 - 00000000 ____D C:\Users\Hrstka\AppData\Local\ElevatedDiagnostics
2016-07-29 11:55 - 2016-07-29 14:40 - 00134664 _____ C:\windows\ntbtlog.txt
2016-07-28 13:44 - 2016-07-28 13:44 - 00000000 ____D C:\Users\Hrstka\AppData\Roaming\Sun
2016-07-28 13:44 - 2016-07-28 13:44 - 00000000 ____D C:\Users\Hrstka\.oracle_jre_usage
2016-07-28 13:23 - 2016-07-28 13:23 - 00000000 ____D C:\Users\Hrstka\AppData\Local\ESET
2016-07-28 13:21 - 2016-07-28 13:21 - 00002054 _____ C:\Users\Public\Desktop\ESET Ochrana bankovnictví a online plateb.lnk
2016-07-28 13:21 - 2016-07-28 13:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2016-07-28 13:21 - 2016-07-28 13:21 - 00000000 ____D C:\ProgramData\ESET
2016-07-28 13:20 - 2016-07-28 13:20 - 00000000 ____D C:\Program Files\ESET
2016-07-28 12:49 - 2016-07-28 12:49 - 00002794 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2016-07-28 12:49 - 2016-07-28 12:49 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-07-28 12:49 - 2016-07-28 12:49 - 00000000 ____D C:\Program Files\CCleaner
2016-07-17 10:00 - 2016-07-17 10:00 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-31 17:00 - 2015-05-10 03:57 - 00000000 ____D C:\Users\Hrstka\Documents\KINGSTON
2016-07-31 16:54 - 2015-05-10 04:03 - 66486503 _____ C:\Users\Hrstka\Desktop\Zverejneno-Bystřice.zip.backup_by_eset
2016-07-31 16:54 - 2015-05-10 04:03 - 51498842 _____ C:\Users\Hrstka\Desktop\ZD-Mořina.zip.backup_by_eset
2016-07-31 16:54 - 2015-05-10 04:03 - 00041050 _____ C:\Users\Hrstka\Desktop\S-com-PD.rtf.backup_by_eset
2016-07-31 16:11 - 2015-05-10 02:42 - 00000000 ____D C:\Data z IBM
2016-07-31 14:33 - 2015-05-10 03:07 - 00000000 ____D C:\Data z IBM2
2016-07-31 13:43 - 2014-10-13 22:06 - 00740368 _____ C:\windows\system32\perfh005.dat
2016-07-31 13:43 - 2014-10-13 22:06 - 00151796 _____ C:\windows\system32\perfc005.dat
2016-07-31 13:43 - 2014-03-18 11:53 - 01747496 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-31 13:43 - 2013-08-22 15:36 - 00000000 ____D C:\windows\Inf
2016-07-31 13:38 - 2013-08-22 16:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-07-31 13:37 - 2015-05-10 02:13 - 00000000 ____D C:\Users\Hrstka\AppData\Roaming\SoftGrid Client
2016-07-30 11:14 - 2015-05-10 01:34 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-553964673-1622739263-2049447999-1001
2016-07-29 18:09 - 2013-08-22 17:20 - 00000000 ____D C:\windows\CbsTemp
2016-07-29 18:08 - 2014-10-13 22:29 - 00000000 ____D C:\ProgramData\LU
2016-07-29 16:59 - 2014-10-13 22:09 - 00001957 _____ C:\Users\Public\Desktop\Lenovo Updates.lnk
2016-07-29 16:58 - 2015-06-22 12:12 - 00001279 _____ C:\Users\Hrstka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-07-29 15:05 - 2015-05-19 21:37 - 00000000 ____D C:\Users\Hrstka\AppData\Roaming\Mozilla
2016-07-29 15:04 - 2015-05-10 01:28 - 00000000 ____D C:\Users\Hrstka
2016-07-29 14:54 - 2014-10-13 22:22 - 03035314 _____ C:\windows\MFGSTAT.zip
2016-07-29 14:53 - 2015-06-27 10:57 - 03425193 _____ C:\Users\Hrstka\Downloads\prilohy_540.zip
2016-07-29 14:53 - 2015-06-14 20:36 - 00000000 ____D C:\Users\Hrstka\Downloads\řeporyje
2016-07-29 14:53 - 2015-06-11 06:26 - 00359123 _____ C:\Users\Hrstka\Downloads\prilohy_364.zip
2016-07-29 14:53 - 2015-06-10 22:13 - 00004621 _____ C:\Users\Hrstka\Downloads\HRSTKA VÁCLAV(2).p12
2016-07-29 14:53 - 2015-05-19 21:52 - 00004621 _____ C:\Users\Hrstka\Downloads\HRSTKA VÁCLAV(1).p12
2016-07-29 14:53 - 2015-05-10 04:04 - 00583108 _____ C:\Users\Hrstka\Downloads\výpis 03-14 (1).pdf
2016-07-29 14:53 - 2015-05-10 04:04 - 00582956 _____ C:\Users\Hrstka\Downloads\vypis_4-2014.pdf
2016-07-29 14:53 - 2015-05-10 04:04 - 00366945 _____ C:\Users\Hrstka\Downloads\prilohy_318.zip
2016-07-29 14:53 - 2015-05-10 04:04 - 00362496 _____ C:\Users\Hrstka\Downloads\mosty Děčín-Rumburk UL DOPLNIT.xls
2016-07-29 14:53 - 2015-05-10 04:04 - 00189440 _____ C:\Users\Hrstka\Downloads\cast-vseobecna.xls
2016-07-29 14:53 - 2015-05-10 04:04 - 00110579 _____ C:\Users\Hrstka\Downloads\141027_sever_plany_podzim.xlsx
2016-07-29 14:53 - 2015-05-10 04:04 - 00106648 _____ C:\Users\Hrstka\Downloads\P1000 03_2015.pdf
2016-07-29 14:53 - 2015-05-10 04:04 - 00073795 _____ C:\Users\Hrstka\Downloads\cast-technicka.xlsx
2016-07-29 14:53 - 2015-05-10 04:04 - 00061284 _____ C:\Users\Hrstka\Downloads\zadost-vyplatu-z-pp.pdf
2016-07-29 14:53 - 2015-05-10 04:04 - 00032575 _____ C:\Users\Hrstka\Downloads\cast-dopravni.xlsx
2016-07-29 14:53 - 2015-05-10 04:04 - 00004621 _____ C:\Users\Hrstka\Downloads\HRSTKA VÁCLAV.p12
2016-07-29 14:50 - 2015-05-10 04:04 - 00625350 _____ C:\Users\Hrstka\Documents\kontakty 05_2013.csv
2016-07-29 14:50 - 2015-05-10 04:01 - 00000000 ____D C:\Users\Hrstka\Documents\Vyměnitelný disk
2016-07-29 14:40 - 2015-05-10 04:03 - 66486503 _____ C:\Users\Hrstka\Desktop\Zverejneno-Bystřice.zip
2016-07-29 14:40 - 2015-05-10 04:03 - 51498842 _____ C:\Users\Hrstka\Desktop\ZD-Mořina.zip
2016-07-29 09:55 - 2013-08-22 15:25 - 00262144 ___SH C:\windows\system32\config\BBI
2016-07-28 14:36 - 2016-03-25 06:01 - 00000000 ____D C:\Users\Hrstka\AppData\Local\KiyEsdu
2016-07-28 14:30 - 2015-06-04 04:22 - 00000000 ____D C:\ProgramData\KabexAsxoj
2016-07-28 13:59 - 2015-05-10 04:16 - 00000000 ____D C:\ProgramData\Oracle
2016-07-28 13:45 - 2015-05-10 04:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-07-28 13:45 - 2015-05-10 04:16 - 00000000 ____D C:\Program Files (x86)\Java
2016-07-28 13:44 - 2015-05-10 04:16 - 00097856 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2016-07-28 13:22 - 2013-08-22 17:36 - 00000000 ___HD C:\windows\ELAMBKUP
2016-07-28 13:05 - 2014-04-02 19:34 - 00000000 ____D C:\windows\Panther
2016-07-28 12:43 - 2014-10-13 22:04 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-07-28 12:43 - 2013-08-22 16:44 - 00345256 _____ C:\windows\system32\FNTCACHE.DAT
2016-07-28 12:41 - 2014-10-13 22:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-07-28 12:40 - 2015-05-19 21:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-28 12:39 - 2015-07-31 15:09 - 00000000 ____D C:\Program Files (x86)\LibreOffice 4
2016-07-28 12:29 - 2014-10-13 21:32 - 00000000 ____D C:\ProgramData\Conexant
2016-07-27 18:25 - 2016-03-30 07:37 - 00113152 ___SH C:\Users\Hrstka\Thumbs.db
2016-07-16 05:33 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppReadiness
2016-07-12 23:37 - 2016-04-10 21:21 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-07-12 23:37 - 2015-08-04 19:28 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
==================== Files in the root of some directories =======
2016-03-30 04:26 - 2016-03-30 05:28 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\+REcovER+bnevw+.png
2016-03-31 20:27 - 2016-03-31 21:06 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\+REcovER+gwyfd+.png
2016-03-30 07:59 - 2016-03-30 08:36 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\+REcovER+qoynb+.png
2016-03-31 12:29 - 2016-03-31 13:06 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\+REcovER+vkmgi+.png
2013-10-02 04:55 - 2013-10-02 04:55 - 0000210 _____ () C:\Users\Hrstka\AppData\Roaming\15.gif
2013-10-02 04:55 - 2013-10-02 04:55 - 0001074 _____ () C:\Users\Hrstka\AppData\Roaming\admon.textlabel.xml
2014-05-08 07:44 - 2014-05-08 07:44 - 0004218 _____ () C:\Users\Hrstka\AppData\Roaming\Adobe-CNS1-1
2014-05-08 06:05 - 2014-05-08 06:05 - 0000524 _____ () C:\Users\Hrstka\AppData\Roaming\BMY brown 3.ADO
2014-05-08 07:44 - 2014-05-08 07:44 - 0000197 _____ () C:\Users\Hrstka\AppData\Roaming\bn_IN.aff
2014-05-08 07:44 - 2014-05-08 07:44 - 0004389 _____ () C:\Users\Hrstka\AppData\Roaming\da.pak
2015-02-26 18:00 - 2015-02-26 18:00 - 0002460 _____ () C:\Users\Hrstka\AppData\Roaming\DDVClean.mof
2015-05-20 03:28 - 2015-05-20 03:28 - 0000579 _____ () C:\Users\Hrstka\AppData\Roaming\dell_connect.png
2013-10-02 04:56 - 2013-10-02 04:56 - 0000923 _____ () C:\Users\Hrstka\AppData\Roaming\ebnf.table.border.xml
2015-05-20 03:28 - 2015-05-20 03:28 - 0000778 _____ () C:\Users\Hrstka\AppData\Roaming\email.png
2013-10-02 04:56 - 2013-10-02 04:56 - 0001079 _____ () C:\Users\Hrstka\AppData\Roaming\emphasis.propagates.style.xml
2015-05-20 03:28 - 2015-05-20 03:28 - 0000382 _____ () C:\Users\Hrstka\AppData\Roaming\EngineLoggerConfig.xml
2013-10-02 04:55 - 2013-10-02 04:55 - 0000071 _____ () C:\Users\Hrstka\AppData\Roaming\external-link.gif
2014-05-08 07:44 - 2014-05-08 07:44 - 0001820 _____ () C:\Users\Hrstka\AppData\Roaming\f3.png
1998-06-12 01:00 - 1998-06-12 01:00 - 0004988 _____ () C:\Users\Hrstka\AppData\Roaming\FootmanBioecology.e
2013-10-02 04:56 - 2013-10-02 04:56 - 0001461 _____ () C:\Users\Hrstka\AppData\Roaming\footnote.sep.leader.properties.xml
2014-05-08 07:44 - 2014-05-08 07:44 - 0002642 _____ () C:\Users\Hrstka\AppData\Roaming\grmphon.env
2015-05-20 03:28 - 2015-05-20 03:28 - 0001684 _____ () C:\Users\Hrstka\AppData\Roaming\help_disabled.png
2013-10-02 04:56 - 2013-10-02 04:56 - 0000944 _____ () C:\Users\Hrstka\AppData\Roaming\html.stylesheet.type.xml
2013-10-02 04:56 - 2013-10-02 04:56 - 0000937 _____ () C:\Users\Hrstka\AppData\Roaming\htmlhelp.title.xml
1992-11-17 02:00 - 1992-11-17 02:00 - 1776947 _____ () C:\Users\Hrstka\AppData\Roaming\Introvert.U
2015-05-20 03:28 - 2015-05-20 03:28 - 0004345 _____ () C:\Users\Hrstka\AppData\Roaming\irda.png
2015-03-24 07:39 - 2015-03-24 07:39 - 0001109 _____ () C:\Users\Hrstka\AppData\Roaming\LICENSE.md
2013-10-02 04:56 - 2013-10-02 04:56 - 0001828 _____ () C:\Users\Hrstka\AppData\Roaming\man.output.lang.in.name.enabled.xml
2013-10-02 04:56 - 2013-10-02 04:56 - 0001536 _____ () C:\Users\Hrstka\AppData\Roaming\man.subheading.divider.xml
2009-06-10 23:06 - 2009-06-10 23:06 - 0002899 _____ () C:\Users\Hrstka\AppData\Roaming\Memories_buttonClear.png
2015-05-20 03:28 - 2015-05-20 03:28 - 0004576 _____ () C:\Users\Hrstka\AppData\Roaming\memory-reader.png
2015-05-20 03:28 - 2015-05-20 03:28 - 0004355 _____ () C:\Users\Hrstka\AppData\Roaming\mouse.png
2009-06-10 23:06 - 2009-06-10 23:06 - 0004515 _____ () C:\Users\Hrstka\AppData\Roaming\nav_rightarrow.png
2013-10-02 04:56 - 2013-10-02 04:56 - 0000888 _____ () C:\Users\Hrstka\AppData\Roaming\no.up.image.xml
2013-10-02 04:55 - 2013-10-02 04:55 - 0003157 _____ () C:\Users\Hrstka\AppData\Roaming\package-frame.html
2015-05-20 03:28 - 2015-05-20 03:28 - 0001264 _____ () C:\Users\Hrstka\AppData\Roaming\pcdrantenna.p5m
2015-05-20 03:28 - 2015-05-20 03:28 - 0002611 _____ () C:\Users\Hrstka\AppData\Roaming\pcdrbattery.p5m
2015-05-20 03:28 - 2015-05-20 03:28 - 0002510 _____ () C:\Users\Hrstka\AppData\Roaming\pcdrscsi2.p5m
2015-05-20 03:28 - 2015-05-20 03:28 - 0000193 _____ () C:\Users\Hrstka\AppData\Roaming\PCDR_HUD_4_3.scheme
2013-10-02 04:55 - 2013-10-02 04:55 - 0001172 _____ () C:\Users\Hrstka\AppData\Roaming\PlanDrawer.java
2014-05-08 06:08 - 2014-05-08 06:08 - 0001630 _____ () C:\Users\Hrstka\AppData\Roaming\Plastic - Polished Alumide.3PP
2013-10-02 04:56 - 2013-10-02 04:56 - 0001024 _____ () C:\Users\Hrstka\AppData\Roaming\procedure.properties.xml
2013-10-02 04:55 - 2013-10-02 04:55 - 0000101 _____ () C:\Users\Hrstka\AppData\Roaming\r1.m
2015-05-20 03:28 - 2015-05-20 03:28 - 0003993 _____ () C:\Users\Hrstka\AppData\Roaming\RB_Disabled.png
2015-05-20 03:28 - 2015-05-20 03:28 - 0001720 _____ () C:\Users\Hrstka\AppData\Roaming\redshd.png
2015-05-20 03:28 - 2015-05-20 03:28 - 0003111 _____ () C:\Users\Hrstka\AppData\Roaming\refresh_12.png
2015-05-20 03:28 - 2015-05-20 03:28 - 0003983 _____ () C:\Users\Hrstka\AppData\Roaming\RF_Enabled.png
2013-10-02 04:56 - 2013-10-02 04:56 - 0002707 _____ () C:\Users\Hrstka\AppData\Roaming\SequenceFrequency.mm
2012-02-22 22:54 - 2012-02-22 22:54 - 0002388 _____ () C:\Users\Hrstka\AppData\Roaming\settings.xml
2013-10-02 04:56 - 2013-10-02 04:56 - 0001068 _____ () C:\Users\Hrstka\AppData\Roaming\shade.verbatim.xml
2013-10-02 04:55 - 2013-10-02 04:55 - 0000104 _____ () C:\Users\Hrstka\AppData\Roaming\SimpleDocument.xml
2013-10-02 04:56 - 2013-10-02 04:56 - 0000975 _____ () C:\Users\Hrstka\AppData\Roaming\subscript.properties.xml
2015-05-20 03:28 - 2015-05-20 03:28 - 0002786 _____ () C:\Users\Hrstka\AppData\Roaming\sysinfofilter_ax_dell.xml
2015-05-20 03:28 - 2015-05-20 03:28 - 0001769 _____ () C:\Users\Hrstka\AppData\Roaming\systemTools.png
2015-05-20 03:28 - 2015-05-20 03:28 - 0000816 _____ () C:\Users\Hrstka\AppData\Roaming\toast_good.png
2013-10-02 04:56 - 2013-10-02 04:56 - 0000840 _____ () C:\Users\Hrstka\AppData\Roaming\toc.image.xml
2015-05-20 03:28 - 2015-05-20 03:28 - 0004090 _____ () C:\Users\Hrstka\AppData\Roaming\tutorials_icon.png
2015-05-20 03:14 - 2015-05-20 03:14 - 0000095 _____ () C:\Users\Hrstka\AppData\Roaming\tweakChkDsk_pt-pt.p5p
2015-05-20 03:14 - 2015-05-20 03:14 - 0001933 _____ () C:\Users\Hrstka\AppData\Roaming\tweakNetworkingManual_de.p5p
2015-05-20 03:28 - 2015-05-20 03:28 - 0000415 _____ () C:\Users\Hrstka\AppData\Roaming\VertexOutputTexturelessInstanced.hlsli
2013-10-02 04:56 - 2013-10-02 04:56 - 0001366 _____ () C:\Users\Hrstka\AppData\Roaming\wordml.template.xml
2016-04-02 02:14 - 2016-04-02 02:14 - 0009238 _____ () C:\Users\Hrstka\AppData\Roaming\{RecOveR}-vhlln__.Htm
2016-04-02 02:14 - 2016-04-02 02:14 - 0082893 _____ () C:\Users\Hrstka\AppData\Roaming\{RecOveR}-vhlln__.Png
2016-04-10 07:00 - 2016-04-10 07:00 - 0009238 _____ () C:\Users\Hrstka\AppData\Roaming\{RecOveR}-yjdwn__.Htm
2016-04-10 07:00 - 2016-04-10 07:00 - 0081953 _____ () C:\Users\Hrstka\AppData\Roaming\{RecOveR}-yjdwn__.Png
2016-03-30 04:26 - 2016-03-30 05:28 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+bnevw+.png
2016-03-30 04:26 - 2016-03-30 05:28 - 0001046 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+bnevw+.txt
2016-03-31 20:27 - 2016-03-31 21:06 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+gwyfd+.png
2016-03-31 20:27 - 2016-03-31 21:06 - 0001046 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+gwyfd+.txt
2016-03-30 07:59 - 2016-03-30 08:36 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+qoynb+.png
2016-03-30 07:59 - 2016-03-30 08:36 - 0001046 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+qoynb+.txt
2016-03-31 12:29 - 2016-03-31 13:06 - 0038534 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+vkmgi+.png
2016-03-31 12:29 - 2016-03-31 13:06 - 0001046 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\+REcovER+vkmgi+.txt
2016-04-02 02:14 - 2016-04-02 02:14 - 0009238 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\{RecOveR}-vhlln__.Htm
2016-04-02 02:14 - 2016-04-02 02:14 - 0082893 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\{RecOveR}-vhlln__.Png
2016-04-02 02:14 - 2016-04-02 02:14 - 0002818 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\{RecOveR}-vhlln__.Txt
2016-04-10 07:00 - 2016-04-10 07:00 - 0009238 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\{RecOveR}-yjdwn__.Htm
2016-04-10 07:00 - 2016-04-10 07:00 - 0081953 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\{RecOveR}-yjdwn__.Png
2016-04-10 07:00 - 2016-04-10 07:00 - 0002818 _____ () C:\Users\Hrstka\AppData\Roaming\Microsoft\{RecOveR}-yjdwn__.Txt
2016-04-02 02:05 - 2016-04-02 02:17 - 0009238 _____ () C:\Users\Hrstka\AppData\Local\{RecOveR}-vhlln__.Htm
2016-04-02 02:05 - 2016-04-02 02:17 - 0082893 _____ () C:\Users\Hrstka\AppData\Local\{RecOveR}-vhlln__.Png
2016-04-02 02:05 - 2016-04-02 02:17 - 0002818 _____ () C:\Users\Hrstka\AppData\Local\{RecOveR}-vhlln__.Txt
2016-04-10 06:51 - 2016-04-10 06:58 - 0009238 _____ () C:\Users\Hrstka\AppData\Local\{RecOveR}-yjdwn__.Htm
2016-04-10 06:51 - 2016-04-10 06:58 - 0081953 _____ () C:\Users\Hrstka\AppData\Local\{RecOveR}-yjdwn__.Png
2016-04-10 06:51 - 2016-04-10 06:58 - 0002818 _____ () C:\Users\Hrstka\AppData\Local\{RecOveR}-yjdwn__.Txt
2016-03-30 02:35 - 2016-03-30 02:35 - 0038534 _____ () C:\ProgramData\+REcovER+bnevw+.png
2016-04-05 06:40 - 2016-04-05 06:41 - 0038534 _____ () C:\ProgramData\+REcovER+crmkj+.png
2016-03-31 19:57 - 2016-03-31 19:58 - 0038534 _____ () C:\ProgramData\+REcovER+gwyfd+.png
2016-03-30 07:32 - 2016-03-30 07:32 - 0038534 _____ () C:\ProgramData\+REcovER+qoynb+.png
2016-03-31 12:01 - 2016-03-31 12:01 - 0038534 _____ () C:\ProgramData\+REcovER+vkmgi+.png
2014-10-13 21:32 - 2014-10-13 21:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-04-02 02:04 - 2016-04-02 02:05 - 0009238 _____ () C:\ProgramData\{RecOveR}-vhlln__.Htm
2016-04-02 02:04 - 2016-04-02 02:05 - 0082893 _____ () C:\ProgramData\{RecOveR}-vhlln__.Png
2016-04-10 06:50 - 2016-04-10 06:50 - 0009238 _____ () C:\ProgramData\{RecOveR}-yjdwn__.Htm
2016-04-10 06:50 - 2016-04-10 06:50 - 0081953 _____ () C:\ProgramData\{RecOveR}-yjdwn__.Png
Some files in TEMP:
====================
C:\Users\Hrstka\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-24 01:30
==================== End of FRST.txt ============================