Vysoké využití procesoru, prosím o kontrolu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 17 dub 2018 22:25

Vzhledem k objemu logu, vkládám do přílohy
Desktop.zip
logy z FRST
(35.38 KiB) Staženo 24 x

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod jaro3 » 17 dub 2018 22:53

c:\program files (x86)\IpSsiZJ.exe se nesmazalo , smažeme v frst.

ten log sem musíš vložit celý:
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků

zkouknu zítra..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 18 dub 2018 00:26

2018-04-16 17:16 - 2018-01-01 04:18 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistWSDDiscoProv.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-04-16 17:16 - 2018-01-01 04:18 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\vmicres.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistHttpTrans.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-04-16 17:16 - 2018-01-01 04:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-04-16 17:16 - 2018-01-01 04:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-04-16 17:16 - 2018-01-01 04:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-04-16 17:16 - 2018-01-01 04:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-04-16 17:16 - 2018-01-01 04:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-04-16 17:16 - 2018-01-01 03:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-04-16 17:16 - 2018-01-01 03:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-04-16 17:16 - 2018-01-01 03:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-04-16 17:16 - 2018-01-01 03:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-04-16 17:16 - 2018-01-01 03:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-04-16 17:16 - 2018-01-01 03:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-04-16 17:16 - 2018-01-01 03:46 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\IcCoinstall.dll
2018-04-16 17:16 - 2018-01-01 03:46 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\vmictimeprovider.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-04-16 17:16 - 2018-01-01 03:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-04-16 17:16 - 2018-01-01 03:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-04-16 17:16 - 2018-01-01 03:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-04-16 17:16 - 2017-12-05 19:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-04-16 17:16 - 2017-12-05 19:36 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2018-04-16 17:16 - 2017-12-05 19:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-04-16 17:16 - 2017-12-05 19:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-04-16 17:16 - 2017-12-05 19:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-04-16 17:16 - 2017-12-05 17:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-04-16 17:16 - 2017-11-04 17:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-04-16 17:16 - 2017-11-04 17:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-04-16 17:16 - 2017-11-04 17:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2018-04-16 17:16 - 2017-11-04 17:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2018-04-16 17:16 - 2017-11-02 18:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll
2018-04-16 17:16 - 2017-11-02 18:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2018-04-16 17:16 - 2017-11-02 18:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll
2018-04-16 17:16 - 2017-11-02 17:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll
2018-04-16 17:16 - 2017-11-02 17:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2018-04-16 17:16 - 2017-11-02 16:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll
2018-04-16 17:16 - 2017-10-18 04:06 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2018-04-16 17:16 - 2017-10-18 04:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2018-04-16 17:16 - 2017-10-18 04:06 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2018-04-16 17:16 - 2017-10-18 04:06 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2018-04-16 17:16 - 2017-10-12 02:55 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2018-04-16 17:16 - 2017-10-12 02:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2018-04-16 17:16 - 2017-10-12 02:55 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2018-04-16 17:16 - 2017-10-12 02:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2018-04-16 17:16 - 2017-10-12 02:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2018-04-16 17:16 - 2017-10-12 02:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2018-04-16 17:16 - 2017-10-12 02:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2018-04-16 17:16 - 2017-10-12 02:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2018-04-16 17:16 - 2017-10-12 02:37 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2018-04-16 17:16 - 2017-10-12 02:37 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2018-04-16 17:16 - 2017-10-12 02:37 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2018-04-16 17:16 - 2017-10-12 02:37 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2018-04-16 17:16 - 2017-10-12 02:37 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2018-04-16 17:16 - 2017-10-12 02:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2018-04-16 17:16 - 2017-10-12 02:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2018-04-16 17:16 - 2017-10-12 02:24 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2018-04-16 17:16 - 2017-10-12 02:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2018-04-16 17:16 - 2017-10-12 02:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2018-04-16 17:16 - 2017-10-12 02:20 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2018-04-16 17:16 - 2017-09-13 17:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-04-16 17:16 - 2017-09-13 17:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2018-04-16 17:16 - 2017-09-13 17:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2018-04-16 17:16 - 2017-09-13 17:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2018-04-16 17:16 - 2017-09-13 17:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2018-04-16 17:16 - 2017-08-19 17:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-04-16 17:16 - 2017-08-19 17:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2018-04-16 17:16 - 2017-08-19 17:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2018-04-16 17:16 - 2017-08-19 17:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2018-04-16 17:16 - 2017-08-19 17:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-04-16 17:16 - 2017-08-19 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2018-04-16 17:16 - 2017-08-19 17:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2018-04-16 17:16 - 2017-08-19 17:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2018-04-16 17:16 - 2017-08-19 16:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2018-04-16 17:16 - 2017-08-19 16:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2018-04-16 17:16 - 2017-08-14 19:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2018-04-16 17:16 - 2017-08-14 19:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2018-04-16 17:16 - 2017-08-14 19:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2018-04-16 17:16 - 2017-08-14 19:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2018-04-16 17:16 - 2017-08-14 19:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2018-04-16 17:16 - 2017-08-14 19:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2018-04-16 17:16 - 2017-08-13 23:45 - 000162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2018-04-16 17:16 - 2017-08-13 23:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2018-04-16 17:16 - 2017-08-13 23:45 - 000020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2018-04-16 17:16 - 2017-08-11 08:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2018-04-16 17:16 - 2017-08-11 08:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2018-04-16 17:16 - 2017-08-11 08:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2018-04-16 17:16 - 2017-08-11 08:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2018-04-16 17:16 - 2017-08-11 08:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2018-04-16 17:16 - 2017-08-11 08:20 - 000071680 _____ C:\Windows\system32\PrintBrmUi.exe
2018-04-16 17:16 - 2017-08-11 08:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2018-04-16 17:16 - 2017-08-11 08:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2018-04-16 17:16 - 2017-08-11 08:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2018-04-16 17:16 - 2017-08-11 08:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2018-04-16 17:16 - 2017-08-11 08:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2018-04-16 17:16 - 2017-08-11 08:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2018-04-16 17:16 - 2017-08-11 08:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2018-04-16 17:16 - 2017-08-11 08:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2018-04-16 17:16 - 2017-08-11 07:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2018-04-16 17:16 - 2017-07-21 16:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll
2018-04-16 17:16 - 2017-07-21 16:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2018-04-16 17:16 - 2017-07-14 17:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2018-04-16 17:16 - 2017-07-14 16:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2018-04-16 17:16 - 2017-07-14 16:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2018-04-16 17:16 - 2017-07-14 16:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2018-04-16 17:16 - 2017-06-13 00:49 - 000594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2018-04-16 17:16 - 2017-06-13 00:49 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2018-04-16 17:16 - 2017-06-13 00:29 - 000444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2018-04-16 17:16 - 2017-06-13 00:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2018-04-16 17:16 - 2017-06-13 00:14 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2018-04-16 17:16 - 2017-06-13 00:14 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe
2018-04-16 17:16 - 2017-06-13 00:06 - 000157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2018-04-16 17:16 - 2017-06-13 00:06 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe
2018-04-16 17:16 - 2017-05-16 17:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2018-04-16 17:16 - 2017-05-10 17:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2018-04-16 17:16 - 2017-05-10 17:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
2018-04-16 17:16 - 2017-05-10 17:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2018-04-16 17:16 - 2017-05-07 17:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2018-04-16 17:16 - 2017-03-30 17:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2018-04-16 17:16 - 2017-03-30 16:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2018-04-16 17:16 - 2017-03-10 18:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2018-04-16 17:16 - 2017-03-10 18:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2018-04-16 17:16 - 2017-03-10 17:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2018-04-16 17:16 - 2017-03-07 18:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2018-04-16 17:16 - 2017-03-07 18:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2018-04-16 17:16 - 2017-03-04 03:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2018-04-16 17:16 - 2017-03-04 03:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2018-04-16 17:16 - 2017-02-09 18:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2018-04-16 17:16 - 2017-02-09 18:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2018-04-16 17:16 - 2017-01-11 20:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2018-04-16 17:16 - 2017-01-11 19:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2018-04-16 17:16 - 2016-10-11 17:32 - 000069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2018-04-16 17:16 - 2016-10-11 17:31 - 001148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2018-04-16 17:16 - 2016-10-11 17:31 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2018-04-16 17:16 - 2016-10-11 17:31 - 000176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:31 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2018-04-16 17:16 - 2016-10-11 17:18 - 000126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2018-04-16 17:16 - 2016-10-11 17:18 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2018-04-16 17:16 - 2016-10-05 16:54 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2018-04-16 17:16 - 2016-09-12 23:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2018-04-16 17:16 - 2016-09-12 22:49 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2018-04-16 17:16 - 2016-08-06 17:31 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2018-04-16 17:16 - 2016-08-06 17:31 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2018-04-16 17:16 - 2016-08-06 17:15 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2018-04-16 17:16 - 2016-08-06 17:01 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2018-04-16 17:16 - 2016-08-06 16:53 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2018-04-16 17:16 - 2016-08-06 16:53 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2018-04-16 17:16 - 2016-06-14 19:16 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2018-04-16 17:16 - 2016-06-14 19:16 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2018-04-16 17:16 - 2016-06-14 19:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2018-04-16 17:16 - 2016-06-14 19:16 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2018-04-16 17:16 - 2016-06-14 19:16 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2018-04-16 17:16 - 2016-06-14 17:21 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2018-04-16 17:16 - 2016-06-14 17:21 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2018-04-16 17:16 - 2016-06-14 17:21 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2018-04-16 17:16 - 2016-06-14 17:15 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2018-04-16 17:16 - 2016-06-14 17:00 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2018-04-16 17:16 - 2016-06-14 17:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2018-04-16 17:15 - 2015-11-14 01:09 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2018-04-16 17:15 - 2015-11-14 01:09 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2018-04-16 17:15 - 2015-11-14 01:08 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2018-04-16 17:15 - 2015-11-14 00:50 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
2018-04-16 17:15 - 2015-11-14 00:50 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
2018-04-16 17:15 - 2015-11-14 00:49 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
2018-04-16 17:15 - 2015-04-13 05:28 - 000328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2018-04-16 17:15 - 2015-02-03 05:31 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2018-04-16 17:15 - 2015-02-03 05:12 - 000171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2018-04-16 17:14 - 2018-03-14 19:14 - 000135360 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-04-16 17:14 - 2018-03-14 19:09 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-04-16 17:14 - 2018-03-14 15:05 - 001559552 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 000414720 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-04-16 17:14 - 2018-03-14 15:05 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-04-16 17:08 - 2016-04-14 15:49 - 000603648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2018-04-16 17:08 - 2016-04-14 15:21 - 000647680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2018-04-16 17:08 - 2016-01-06 21:02 - 000275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2018-04-16 17:08 - 2016-01-06 20:41 - 000216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2018-04-16 17:08 - 2015-12-08 23:54 - 002285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2018-04-16 17:08 - 2015-12-08 23:54 - 001620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 001568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 001325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2018-04-16 17:08 - 2015-12-08 23:54 - 000739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
2018-04-16 17:08 - 2015-12-08 23:54 - 000154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
2018-04-16 17:08 - 2015-12-08 23:53 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
2018-04-16 17:08 - 2015-12-08 23:53 - 000193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2018-04-16 17:08 - 2015-12-08 23:53 - 000153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
2018-04-16 17:08 - 2015-12-08 23:53 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
2018-04-16 17:08 - 2015-12-08 23:53 - 000053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
2018-04-16 17:08 - 2015-12-08 23:53 - 000004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 002777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 001955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 001888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 001575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 001307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 001232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 001160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 001026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 001010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 000978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 000292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2018-04-16 17:08 - 2015-12-08 21:07 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2018-04-16 17:08 - 2015-12-08 21:07 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll
2018-04-16 17:08 - 2015-12-08 21:06 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2018-04-16 17:08 - 2015-12-08 20:54 - 000116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2018-04-16 17:08 - 2015-12-08 20:12 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2018-04-16 17:08 - 2015-12-08 20:11 - 000005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2018-04-16 17:00 - 2016-07-22 16:58 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2018-04-16 17:00 - 2016-07-22 16:51 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2018-04-16 16:07 - 2018-04-16 16:07 - 000277056 _____ C:\Windows\Minidump\041618-31793-01.dmp
2018-04-16 16:00 - 2018-04-16 16:00 - 000277056 _____ C:\Windows\Minidump\041618-28438-01.dmp
2018-04-15 20:34 - 2018-04-15 20:34 - 000277056 _____ C:\Windows\Minidump\041518-27097-01.dmp
2018-04-15 20:05 - 2018-04-15 20:05 - 000448512 _____ (OldTimer Tools) C:\Users\Lukáš\Downloads\TFC.exe
2018-04-15 19:55 - 2018-04-15 19:55 - 000277056 _____ C:\Windows\Minidump\041518-31949-01.dmp
2018-04-15 13:27 - 2018-04-15 20:38 - 000000934 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2018-04-15 13:27 - 2018-04-15 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2018-04-15 13:27 - 2018-04-15 13:27 - 000000000 ____D C:\Program Files\CPUID
2018-04-15 12:01 - 2011-06-26 08:45 - 000256000 _____ C:\Windows\PEV.exe
2018-04-15 12:01 - 2010-11-07 19:20 - 000208896 _____ C:\Windows\MBR.exe
2018-04-15 12:01 - 2009-04-20 06:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2018-04-15 12:01 - 2000-08-31 02:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2018-04-15 12:01 - 2000-08-31 02:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2018-04-15 12:01 - 2000-08-31 02:00 - 000098816 _____ C:\Windows\sed.exe
2018-04-15 12:01 - 2000-08-31 02:00 - 000080412 _____ C:\Windows\grep.exe
2018-04-15 12:01 - 2000-08-31 02:00 - 000068096 _____ C:\Windows\zip.exe
2018-04-15 11:56 - 2018-04-15 11:57 - 000277056 _____ C:\Windows\Minidump\041518-19344-01.dmp
2018-04-15 11:53 - 2018-04-15 11:53 - 001931969 _____ C:\Users\Lukáš\Downloads\ProcessExplorer.zip
2018-04-15 01:10 - 2018-04-15 01:10 - 000388608 _____ (Trend Micro Inc.) C:\Users\Lukáš\Downloads\HijackThis (1).exe
2018-04-15 00:19 - 2018-04-15 00:19 - 000277056 _____ C:\Windows\Minidump\041518-25552-01.dmp
2018-04-14 23:52 - 2018-04-14 23:53 - 000277056 _____ C:\Windows\Minidump\041418-52197-01.dmp
2018-04-14 23:09 - 2018-04-14 23:09 - 000277056 _____ C:\Windows\Minidump\041418-24601-01.dmp
2018-04-14 22:58 - 2018-04-17 21:41 - 000000000 ____D C:\Qoobox
2018-04-14 22:56 - 2018-04-16 20:18 - 624532164 _____ C:\Windows\MEMORY.DMP
2018-04-14 22:56 - 2018-04-14 22:56 - 000277056 _____ C:\Windows\Minidump\041418-23914-01.dmp
2018-04-14 22:55 - 2018-04-15 12:21 - 000000000 ____D C:\Windows\erdnt
2018-04-14 22:55 - 2018-04-14 22:55 - 005659794 ____R (Swearware) C:\Users\Lukáš\Desktop\ComboFix.exe
2018-04-14 22:43 - 2018-04-18 00:15 - 002023588 _____ C:\Windows\ntbtlog.txt
2018-04-14 22:27 - 2018-04-16 20:06 - 000000000 ____D C:\AdwCleaner
2018-04-14 11:36 - 2018-04-14 11:36 - 000003616 _____ C:\Windows\System32\Tasks\{21083008-5343-9729-A8D3-D1A8478C1836}
2018-04-14 11:36 - 2018-04-14 11:36 - 000003442 _____ C:\Windows\System32\Tasks\{37039AE3-3BC4-B999-CB48-924D3A62B043}
2018-04-14 11:36 - 2018-04-14 11:36 - 000000003 _____ C:\Users\Lukáš\AppData\Local\wbem.ini
2018-04-14 11:14 - 2018-04-14 11:14 - 000000000 ____D C:\Users\Lukáš\AppData\Local\PUSH Entertainment
2018-04-12 22:18 - 2018-04-12 22:17 - 000376536 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-04-12 22:15 - 2018-04-12 22:15 - 000000000 ____D C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-04-05 22:05 - 2018-04-05 22:05 - 000002100 _____ C:\Users\Lukáš\AppData\Local\recently-used.xbel
2018-04-02 12:21 - 2018-04-02 12:21 - 000388608 _____ (Trend Micro Inc.) C:\Users\Lukáš\Downloads\HijackThis.exe
2018-03-29 16:21 - 2018-03-29 16:21 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-03-24 13:55 - 2018-03-24 13:55 - 003942360 _____ (Crystal Dew World ) C:\Users\Lukáš\Downloads\CrystalDiskInfo7_6_0.exe
2018-03-23 15:52 - 2018-04-02 15:42 - 000000000 ____D C:\Users\Lukáš\Downloads\Blade Runner 2049.HDRip.XviD.AC3-EVO
2018-03-19 17:14 - 2018-03-19 17:14 - 008222496 _____ (Malwarebytes) C:\Users\Lukáš\Downloads\adwcleaner_7.0.8.0 (1).exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-18 00:13 - 2017-12-14 22:03 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-04-18 00:13 - 2015-11-26 00:49 - 000000000 _____ C:\Windows\system32\RzSurroundVADAudioDeviceManager_log.txt
2018-04-18 00:13 - 2009-07-14 06:45 - 000014736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-18 00:13 - 2009-07-14 06:45 - 000014736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-17 22:25 - 2015-01-30 18:00 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-04-17 22:25 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-04-17 22:23 - 2015-01-30 18:00 - 000000000 ____D C:\Program Files\Microsoft Office
2018-04-17 22:16 - 2009-07-14 17:18 - 000704018 _____ C:\Windows\system32\perfh005.dat
2018-04-17 22:16 - 2009-07-14 17:18 - 000154692 _____ C:\Windows\system32\perfc005.dat
2018-04-17 22:16 - 2009-07-14 07:13 - 001669688 _____ C:\Windows\system32\PerfStringBackup.INI
2018-04-17 22:16 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-04-17 22:09 - 2017-11-16 17:20 - 000000000 ____D C:\ProgramData\NVIDIA
2018-04-17 22:09 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-17 21:39 - 2009-07-14 04:34 - 000000215 _____ C:\Windows\system.ini
2018-04-17 21:26 - 2018-02-18 14:39 - 000000000 ____D C:\Windows\Minidump
2018-04-17 21:26 - 2015-01-29 18:41 - 000289436 ____N C:\Windows\Minidump\041718-25240-01.dmp
2018-04-17 19:26 - 2015-01-29 19:09 - 000000000 ____D C:\Users\Lukáš
2018-04-17 17:54 - 2015-01-29 19:47 - 000000000 ____D C:\Users\Lukáš\AppData\Local\ElevatedDiagnostics
2018-04-17 17:54 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\rescache
2018-04-17 16:35 - 2015-01-29 19:35 - 000000000 ____D C:\Program Files (x86)\Steam
2018-04-16 21:05 - 2015-01-29 19:29 - 000000000 ____D C:\Users\Lukáš\AppData\Local\Google
2018-04-16 21:04 - 2015-08-17 10:21 - 000003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-04-16 21:04 - 2015-08-17 10:21 - 000003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-04-16 21:04 - 2015-01-29 19:29 - 000000000 ____D C:\Program Files (x86)\Google
2018-04-16 20:22 - 2015-04-23 09:36 - 000000000 __SHD C:\Users\Lukáš\AppData\Local\EmieUserList
2018-04-16 20:22 - 2015-04-23 09:36 - 000000000 __SHD C:\Users\Lukáš\AppData\Local\EmieSiteList
2018-04-16 19:03 - 2017-09-29 16:43 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-04-16 18:07 - 2009-07-14 07:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2018-04-16 18:06 - 2009-07-14 06:57 - 000001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-04-16 18:01 - 2009-07-14 06:45 - 000446280 _____ C:\Windows\system32\FNTCACHE.DAT
2018-04-16 17:56 - 2015-01-31 11:29 - 000000000 ___SD C:\Windows\system32\CompatTel
2018-04-16 17:56 - 2015-01-31 11:29 - 000000000 ____D C:\Windows\system32\appraiser
2018-04-16 17:56 - 2009-07-14 17:37 - 000000000 ____D C:\Program Files\Windows Journal
2018-04-16 17:56 - 2009-07-14 07:32 - 000000000 ____D C:\Program Files\DVD Maker
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\Setup
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\migwiz
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\Dism
2018-04-16 17:56 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2018-04-16 17:50 - 2015-01-30 14:23 - 000000000 ____D C:\Windows\system32\MRT
2018-04-16 17:45 - 2015-01-30 14:23 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-04-16 17:25 - 2015-02-09 12:53 - 001644402 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-04-15 20:16 - 2017-09-29 23:01 - 000001762 _____ C:\Users\Lukáš\Desktop\mbam.txt
2018-04-15 12:23 - 2017-04-15 11:48 - 000000000 ____D C:\Users\Lukáš
2018-04-15 12:12 - 2009-07-14 04:34 - 094109696 _____ C:\Windows\system32\config\SOFTWARE.bak
2018-04-15 12:12 - 2009-07-14 04:34 - 038010880 _____ C:\Windows\system32\config\SYSTEM.bak
2018-04-15 12:12 - 2009-07-14 04:34 - 001572864 _____ C:\Windows\system32\config\DEFAULT.bak
2018-04-15 12:12 - 2009-07-14 04:34 - 000262144 _____ C:\Windows\system32\config\SECURITY.bak
2018-04-15 12:12 - 2009-07-14 04:34 - 000262144 _____ C:\Windows\system32\config\SAM.bak
2018-04-15 12:04 - 2016-03-25 20:54 - 000000000 ____D C:\Users\Lukáš\AppData\Roaming\vlc
2018-04-15 11:32 - 2017-04-15 11:48 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-04-14 15:18 - 2009-07-14 07:08 - 000032518 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-14 13:50 - 2017-11-16 17:20 - 000000000 ____D C:\Users\UpdatusUser
2018-04-14 13:13 - 2015-01-30 14:21 - 000000000 ____D C:\Users\Lukáš\AppData\Roaming\uTorrent
2018-04-14 11:34 - 2018-02-18 14:51 - 000000000 ____D C:\Users\Lukáš\AppData\LocalLow\uTorrent
2018-04-14 11:14 - 2017-06-02 14:58 - 000000000 ____D C:\ProgramData\PUSH Entertainment
2018-04-12 22:18 - 2017-12-19 20:15 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2018-04-12 22:18 - 2017-12-19 20:14 - 000147224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-04-12 22:17 - 2017-12-22 18:39 - 000227784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000460520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000380528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000205976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000196640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000111352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-04-12 22:17 - 2017-12-19 20:14 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-04-12 22:15 - 2015-02-21 19:57 - 000000000 ____D C:\Users\Lukáš\AppData\Roaming\Dropbox
2018-04-10 19:31 - 2018-02-07 20:31 - 005252608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2018-04-10 19:31 - 2017-05-01 23:47 - 000804864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-04-10 19:31 - 2017-05-01 23:47 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-04-10 19:31 - 2017-05-01 23:47 - 000004540 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-04-10 19:31 - 2017-05-01 23:47 - 000004408 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-04-10 19:31 - 2017-05-01 23:47 - 000000000 ____D C:\Windows\system32\Macromed
2018-04-08 13:19 - 2018-01-06 23:53 - 000000000 ____D C:\Users\Lukáš\AppData\Local\Spotify
2018-04-08 13:19 - 2018-01-06 23:52 - 000000000 ____D C:\Users\Lukáš\AppData\Roaming\Spotify
2018-04-08 12:37 - 2016-12-12 15:57 - 000000000 ____D C:\Users\Lukáš\Documents\UPCE
2018-04-05 22:06 - 2015-11-09 21:28 - 000000000 ____D C:\Users\Lukáš\.gimp-2.8
2018-04-05 22:05 - 2015-11-09 21:29 - 000000000 ____D C:\Users\Lukáš\AppData\Local\gtk-2.0
2018-04-05 20:35 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2018-03-31 17:59 - 2016-03-25 21:12 - 000000000 ____D C:\Users\Lukáš\AppData\Roaming\MPC-HC
2018-03-30 11:33 - 2015-01-29 22:00 - 000000000 ____D C:\Program Files\CCleaner
2018-03-29 21:39 - 2015-06-16 07:18 - 000000000 ____D C:\Users\Lukáš\AppData\Local\Dropbox
2018-03-22 18:30 - 2015-04-18 18:57 - 000000000 ____D C:\ProgramData\Package Cache

==================== Files in the root of some directories =======

1601-01-03 21:33 - 1601-01-03 21:33 - 000073216 ____N (Microsoft Corporation) C:\Users\Lukáš\YIuooyIaaY.exe
1601-01-03 21:33 - 1601-01-03 21:33 - 000186368 ____N (Microsoft Corporation) C:\Program Files (x86)\IpSsiZJ.exe
2015-06-19 16:27 - 2015-08-04 01:05 - 000000024 _____ () C:\Users\Lukáš\AppData\Roaming\appdataFr25.bin
2002-08-29 19:33 - 2002-08-29 19:33 - 000319488 ____R () C:\Users\Lukáš\AppData\Roaming\MafiaSetup.exe
2017-01-28 15:11 - 2017-01-28 15:15 - 000000772 _____ () C:\Users\Lukáš\AppData\Roaming\Ping Monitor_Settings.ini
2015-03-13 12:18 - 2015-03-13 12:19 - 000000154 _____ () C:\Users\Lukáš\AppData\Roaming\settings.xml
2017-10-05 23:47 - 2017-10-05 23:49 - 000000003 _____ () C:\Users\Lukáš\AppData\Roaming\splitterdirectorys.txt
2017-11-16 17:12 - 2017-11-16 17:12 - 000000000 _____ () C:\Users\Lukáš\AppData\Local\Driver_LOM_8161Present.flag
1601-01-03 21:33 - 1601-01-03 21:33 - 000073216 ____N (Microsoft Corporation) C:\Users\Lukáš\AppData\Local\OHyYhj.exe
2018-04-05 22:05 - 2018-04-05 22:05 - 000002100 _____ () C:\Users\Lukáš\AppData\Local\recently-used.xbel
2018-04-14 11:36 - 2018-04-14 11:36 - 000000003 _____ () C:\Users\Lukáš\AppData\Local\wbem.ini

Some files in TEMP:
====================
2018-04-17 21:50 - 2018-03-31 03:38 - 001665336 _____ (Microsoft Corporation) C:\Users\Lukáš\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-04-17 17:46

==================== End of FRST.txt ============================

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 18 dub 2018 00:31

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.04.2018
Ran by Lukáš (18-04-2018 00:18:51)
Running from C:\Users\Lukáš\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-01-29 16:54:10)
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-639372863-3589611575-3710821846-500 - Administrator - Disabled)
Guest (S-1-5-21-639372863-3589611575-3710821846-501 - Limited - Disabled)
Lukáš (S-1-5-21-639372863-3589611575-3710821846-1000 - Administrator - Enabled) => C:\Users\Lukáš
UpdatusUser (S-1-5-21-639372863-3589611575-3710821846-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-639372863-3589611575-3710821846-1000\...\uTorrent) (Version: 3.5.3.44358 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.3.0.256 - Adobe Systems Incorporated)
Adobe Flash Player 29 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 29.0.0.140 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.7 - Adobe Systems Incorporated)
AHD ID3 Tag Editor (HKLM-x32\...\{0EDDBA14-C1D8-4962-9C7B-72683E8248CB}) (Version: 2.1.4920.38207 - AHD)
Aktualizace NVIDIA 1.12.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.12.12 - NVIDIA Corporation)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 17.11.4 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\...\{AA7D90D2-2387-4FA5-A3AF-96811BE49BFD}) (Version: 11.0.5.14 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{19589375-5C58-4AFA-842F-8B34744CCEAD}) (Version: 2.5.0.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.3.2333 - AVAST Software)
AviSynth (HKLM-x32\...\AviSynth) (Version: 2.6.0 MT - )
Battlefield 2(TM) (HKLM-x32\...\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}) (Version: - )
BitLord 2.5 (HKLM-x32\...\BitLord) (Version: 2.4.5-316 - House of Life)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.68.1077 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.41 - Piriform)
Counter-Strike Source verze 3398447 (HKLM\...\{28659B67-FC49-49DB-9DAC-1AD52203D75A}_is1) (Version: 3398447 - Strogino CS Portal)
CPUID HWMonitor 1.34 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.34 - )
CyberLink PowerDirector 12 (HKLM\...\{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.2109.0 - CyberLink Corp.) Hidden
CyberLink PowerDirector 12 (HKLM-x32\...\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.2109.0 - CyberLink Corp.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.40.2.0131 - DT Soft Ltd)
Dropbox (HKU\S-1-5-21-639372863-3589611575-3710821846-1000\...\Dropbox) (Version: 47.4.74 - Dropbox, Inc.)
EAX Unified (HKLM-x32\...\EAX Unified) (Version: - )
EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
F.3.A.R. 1.0 (HKLM-x32\...\F.3.A.R._is1) (Version: 1.0 - Íîâűé Äčńę)
FlatOut2 (HKLM-x32\...\{D4006E71-FF32-44FF-AD5A-B5EE4389B825}_is1) (Version: 1.0 - US - ACTION, s.r.o.)
FormApps Signing Extension (HKLM-x32\...\{ACA43D91-8B42-4D42-8C8B-A893BD6AA40D}) (Version: 2.8.2.28 - Software602 a.s.)
GIMP 2.8.22 (HKLM\...\GIMP-2_is1) (Version: 2.8.22 - The GIMP Team)
GOG.com Tzar (HKLM\...\{28210e66-3392-4e9c-a085-6e186cedf3a1}.sdb) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd)
Chrome Remote Desktop Host (HKLM-x32\...\{FBB43A99-0B72-461A-A6D2-2F1B54D36B69}) (Version: 66.0.3359.12 - Google Inc.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3650 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\...\{20F70BB1-9240-43D2-985C-A8F5C6AAA1C7}) (Version: 5.0.10.2907 - Intel Corporation)
iTunes (HKLM\...\{30771861-1BBF-4BE2-8CD2-FB282C58C3ED}) (Version: 12.7.3.46 - Apple Inc.)
Java 8 Update 111 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180111F0}) (Version: 8.0.1110.14 - Oracle Corporation)
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
K-Lite Mega Codec Pack 12.0.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.0.5 - KLCP)
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Mafia Game (HKLM-x32\...\Mafia Game) (Version: - )
Malwarebytes verze 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 365 ProPlus - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.8431.2242 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-639372863-3589611575-3710821846-1000\...\OneDriveSetup.exe) (Version: 17.3.5951.0827 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Need for Speed Underground 2 (HKLM-x32\...\Need for Speed Underground 2) (Version: - )
NewBlue Video Essentials for PowerDirector (HKLM\...\NewBlue Video Essentials for Cyberlink) (Version: 3.0 - NewBlue)
NVIDIA Ovladač 3D Vision 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.23.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.23.1 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 314.22 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Ovládací panel NVIDIA 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 314.22 - NVIDIA Corporation) Hidden
PDFsam Basic (HKLM-x32\...\{96ABFF50-88F5-426E-96CC-80C98F198C4D}) (Version: 3.0.20.0 - Andrea Vacondio)
Podpora aplikací Apple (32bitová) (HKLM-x32\...\{D4C80B0C-CF67-43A7-90C3-466853543B54}) (Version: 6.3 - Apple Inc.)
Podpora aplikací Apple (64bitová) (HKLM\...\{B2A2E8AF-BC48-4191-B2C4-3846A19835CA}) (Version: 6.3 - Apple Inc.)
Qualcomm Atheros Bandwidth Control Filter Driver (HKLM\...\{C80C9B28-CF99-431C-88C8-8B1F9B6A182F}) (Version: 1.1.39.1040 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (HKLM\...\{DD2A85B3-64C5-4263-A7AF-4F61FA5F369A}) (Version: 1.1.39.1040 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.39.1040 - Qualcomm Atheros)
Qualcomm Atheros Network Manager (HKLM\...\{7364C716-1212-4EAE-B0C9-A31D1E797BF8}) (Version: 1.1.39.1040 - Qualcomm Atheros) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Razer Surround (HKLM-x32\...\Razer Surround) (Version: 1.05.18 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.27748 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.89.716.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7293 - Realtek Semiconductor Corp.)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.151 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-639372863-3589611575-3710821846-1000\...\Spotify) (Version: 1.0.77.338.g758ebd78 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1258 - SUPERAntiSpyware.com)
SWAT 4 (HKLM-x32\...\{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}) (Version: 1.0.31763 - Sierra Entertainment, Inc.) Hidden
SWAT 4 (HKLM-x32\...\InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}) (Version: 1.0.31763 - Sierra Entertainment, Inc.)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Tony Hawk's Pro Skater 2 (HKLM-x32\...\Activision_THPS2UninstallKey) (Version: - )
Trillian (HKLM-x32\...\Trillian) (Version: - Cerulean Studios, LLC)
Tzar - The Burden of the Crown (HKLM-x32\...\GOGPACKTZAR_is1) (Version: 2.0.0.8 - GOG.com)
Vectir 4.1.0.0 (HKLM-x32\...\Vectir_is1) (Version: - Incendo Technology)
Vegas Pro 13.0 (64-bit) (HKLM\...\{D0360940-CCC6-11E3-B9C6-F04DA23A5C58}) (Version: 13.0.310 - Sony)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.8 - VideoLAN)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WinRAR 5.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
Wise Auto Shutdown 1.6.5 (HKLM-x32\...\Wise Auto Shutdown_is1) (Version: 1.6.5 - WiseCleaner.com, Inc.)
X-Mouse Button Control 2.10 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.10 - Highresolution Enterprises)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-639372863-3589611575-3710821846-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [2017-08-14] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [2017-08-14] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [2017-08-14] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-12] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-04-17] ()
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [2017-08-14] ()
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-12] (AVAST Software)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-12-02] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-12-02] (Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-12] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-11-27] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-01-29] (Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2015-01-29] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2013-03-15] (NVIDIA Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-04-17] ()
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll [2017-08-14] ()
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-12] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-12-02] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-12-02] (Alexander Roshal)
ContextMenuHandlers1_S-1-5-21-639372863-3589611575-3710821846-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-639372863-3589611575-3710821846-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-639372863-3589611575-3710821846-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\DropboxExt64.19.0.dll [2018-04-09] (Dropbox, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01E856B9-662C-4CB6-883A-AAFA2DA178F2} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-04-17] (Microsoft Corporation)
Task: {0B09B843-8FE9-4DFB-90B8-63EC7FFE699C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-04-17] ()
Task: {0B222E30-3264-4C9D-98C3-C66FEA2886FA} - System32\Tasks\{37039AE3-3BC4-B999-CB48-924D3A62B043} => C:\Users\Lukáš\AppData\Local\OHyYhj.exe [1601-01-03] (Microsoft Corporation)
Task: {12005E1A-5682-41B3-82A6-8CE932523787} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-11-27] (Advanced Micro Devices, Inc.)
Task: {1EE96253-F296-49B2-865C-5BEAECCD3690} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-03-29] (Piriform Ltd)
Task: {210CA66E-0DE2-4F23-B946-D36FEF231E9F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-04-10] (Adobe Systems Incorporated)
Task: {285F77D9-EA05-4BAB-9F1A-E4851CFC8469} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-04-17] ()
Task: {29495E17-03B5-4165-8E25-536CB2D0043E} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-04-12] (AVAST Software)
Task: {2B721288-D1F4-4167-841A-CB84F5CB492A} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {2C227485-ABDD-422A-B32C-89A63A313645} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-03-31] (Microsoft Corporation)
Task: {33FF61FD-83E5-44D0-87F6-2B0A758B3799} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_140_pepper.exe [2018-04-10] (Adobe Systems Incorporated)
Task: {4C561519-3402-4CB9-B0C7-DAB31DCAD0B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-17] (Google Inc.)
Task: {5CECB93B-82FE-47BD-B2E6-6882C56A2C9A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-03-31] (Microsoft Corporation)
Task: {7B3A4494-2919-49B7-9C2F-D6109DB612D0} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-03-29] (Piriform Ltd)
Task: {7F5E59CD-9FDF-4107-849A-22FFCD7D607E} - System32\Tasks\{5736A9E1-5DB0-4EB8-832A-4CB9616DF571} => C:\Windows\system32\pcalua.exe -a "C:\Users\Lukáš\Downloads\Battlefield - CX\Battlefield 2\setup.exe" -d "C:\Users\Lukáš\Downloads\Battlefield - CX\Battlefield 2"
Task: {957FDB2B-D5AA-4589-A05F-BC826EBEC097} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-04-14] (AVAST Software)
Task: {A5822BF7-DF4B-4149-B375-2661C46681B9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-17] (Google Inc.)
Task: {B0FA410C-6D78-4C13-BFE4-EFD9A567164A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-04-17] (Microsoft Corporation)
Task: {B1825191-E5C0-4936-B27C-2D30C873EC5D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-04-17] (Microsoft Corporation)
Task: {B2DA6AB5-16A3-4E4B-814D-51DBA0DD3109} - System32\Tasks\{21083008-5343-9729-A8D3-D1A8478C1836} => C:\Users\Lukáš\YIuooyIaaY.exe [1601-01-03] (Microsoft Corporation)
Task: {B5646DC1-8308-4EFC-871B-0DB31DF46145} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-10-12] (Apple Inc.)
Task: {F212ECB5-DDD8-4179-A050-70155AFE9C04} - System32\Tasks\AdobeGCInvoker-1.0-Lukáš-PC-Lukáš => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {FBF64408-B15C-4936-A005-64C43919CCDF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Vzdálená plocha Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp

==================== Loaded Modules (Whitelisted) ==============

2017-08-14 03:48 - 2017-08-14 03:48 - 000491600 _____ () C:\Program Files (x86)\Adobe\Adobe Sync\CoreSyncExtension\CoreSync_x64.dll
2018-04-17 16:37 - 2018-04-17 16:37 - 000155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2018-04-16 21:05 - 2018-03-20 08:00 - 002683224 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\swiftshader\libglesv2.dll
2018-04-16 21:05 - 2018-03-20 08:00 - 000127832 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\swiftshader\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Program Files (x86)\Vectir:{7A004600-3600-4100-3800-520058003400} [728]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-06-10 14:25 - 2018-04-17 21:39 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-639372863-3589611575-3710821846-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Universal Media Server.lnk => C:\Windows\pss\Universal Media Server.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Lukáš^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Lukáš\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: Plex Media Server => "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Razer Synapse => "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => C:\Users\Lukáš\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized
MSCONFIG\startupreg: Spotify Web Helper => C:\Users\Lukáš\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: ZAM => "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /minimized

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{83CA7E38-E999-47F4-A6F5-3F6059C60520}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9EE4714D-C3BD-4022-BD51-45758F0678F3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{4837975F-9744-47D4-A823-96766749015F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{5DF5E703-E7BD-4F0C-BFCA-A715788C1562}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{0A9D6975-692E-496C-A967-001867C2648B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{3CB65F28-C6AF-45A4-A762-E5EB73D8B3BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{D227AAA3-2C7E-43DA-9754-9E9FB22E7AF0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{68F6002B-659A-4D8C-934F-686299831CEB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Trine 2\trine2_launcher.exe
FirewallRules: [{2482DCB8-9BE4-4149-B1DC-6BCBA7883939}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Trine 2\trine2_launcher.exe
FirewallRules: [{40591A08-0751-4EFD-9833-6B947AB178FF}] => (Allow) C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{DADB9C9E-FFEC-4557-8C85-53F5301A843A}] => (Allow) C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{E3352E30-D719-4A62-B528-F7EC68A6D20B}C:\users\lukáš\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\lukáš\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{A91D0A19-F650-4116-929F-880B1EACDA77}C:\users\lukáš\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\lukáš\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{B0D5BF8E-56B5-4F7B-AE1F-56FC62345F52}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [UDP Query User{D869867B-A196-4E8C-B573-52395FABBEBE}C:\windows\syswow64\dplaysvr.exe] => (Allow) C:\windows\syswow64\dplaysvr.exe
FirewallRules: [{FAE001FE-9684-4D09-AF74-A19C62DF5D8C}] => (Allow) C:\Program Files (x86)\Trillian\trillian.exe
FirewallRules: [{E459158B-7716-4FAC-A178-616DF9935DF3}] => (Allow) C:\Program Files (x86)\Trillian\trillian.exe
FirewallRules: [{F688FB21-5378-4DE8-88AE-9C2CC6C55C2E}] => (Allow) C:\Program Files (x86)\Trillian\trillian.exe
FirewallRules: [{B28ABA0D-F9F8-48AF-A4E7-59F9F5CB9FEB}] => (Allow) C:\Program Files (x86)\Trillian\trillian.exe
FirewallRules: [{28C4C9C9-FEAF-49CC-B10F-027B6FE5A230}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Heroes of Might & Magic III - HD Edition\HOMM3Launcher.exe
FirewallRules: [{570A35E4-7885-4DDE-BAB3-31243275DA33}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Heroes of Might & Magic III - HD Edition\HOMM3Launcher.exe
FirewallRules: [{5E8A07AD-AFE9-49DA-A132-EC0DF9E241FD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{9C1CAD18-2B22-4DDB-B6B0-1B672650431C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe
FirewallRules: [{5BA95522-FF20-483B-AF03-F568A6CB10AD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{90DD66A4-FB51-4811-A04D-B21E322434A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe
FirewallRules: [{DB7A5CEE-552C-4D34-A2E6-11D0198C4867}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Audiosurf\engine\QuestViewer.exe
FirewallRules: [{334F884D-EFF4-47E5-B282-235FDDD169FC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Audiosurf\engine\QuestViewer.exe
FirewallRules: [{FBB66A17-6EFD-41FC-B3B9-4D26EDA9E132}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{7E45AC8E-C02B-465E-AC21-326C81A9F904}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{EB3B0BEB-E0DE-4988-B677-981E938A1425}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tropico 4\Tropico4.exe
FirewallRules: [{CA562CBF-519D-4E78-9F9B-25AFE1584205}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tropico 4\Tropico4.exe
FirewallRules: [{74CC3424-3EA8-4640-AE4B-DD445F38C757}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Magicka\Magicka.exe
FirewallRules: [{B9A58B2C-E479-4D9E-B8C7-0D4B0E245D51}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Magicka\Magicka.exe
FirewallRules: [{8CC9D131-847B-4094-9407-3BB752F9E450}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dust An Elysian Tail\DustAET.exe
FirewallRules: [{C44C388B-5B74-47A9-BABE-85A762870B95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dust An Elysian Tail\DustAET.exe
FirewallRules: [{4D2B562C-85CE-4D22-A295-CFF2900E9C88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Faeria\Faeria.exe
FirewallRules: [{4CF1AB11-CCAE-48A9-ADCC-59C01ECE67CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Faeria\Faeria.exe
FirewallRules: [TCP Query User{5E83C0D4-A145-4720-AB8E-FED4B757D634}C:\program files (x86)\steam\steamapps\common\heroes of might & magic iii - hd edition\homm3 2.0.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\heroes of might & magic iii - hd edition\homm3 2.0.exe
FirewallRules: [UDP Query User{C646A701-1269-4E57-85D5-C31B74CB7198}C:\program files (x86)\steam\steamapps\common\heroes of might & magic iii - hd edition\homm3 2.0.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\heroes of might & magic iii - hd edition\homm3 2.0.exe
FirewallRules: [{956FB2C8-9776-4A0C-B0FD-7ACBD082699F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{18550BDD-8F79-44D7-A4AE-5349D6146398}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [TCP Query User{9A6739B7-574F-4D52-B586-FA2925CC2065}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{9A8AAA0D-EFFB-4222-BFC6-1BC4881E5A0C}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [TCP Query User{7D536A1D-D375-4BDE-979E-4A97488DB359}C:\program files (x86)\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [UDP Query User{12ACCD07-1873-43B7-ADF5-A078E1D0496E}C:\program files (x86)\java\jre1.8.0_111\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_111\bin\javaw.exe
FirewallRules: [{064A54AE-C0CF-4655-B92F-E64FFCE4DF74}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{C8AD5043-D04C-4FF5-B132-48088CF91001}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{D59769FF-C5EA-45C4-8174-9C7E145E9AAE}] => (Allow) C:\Program Files (x86)\Mr DJ\Need for Speed Carbon Collectors Edition\NFSC.exe
FirewallRules: [{09CE060D-E034-4A39-9FD2-553225AB3CE5}] => (Allow) C:\Program Files (x86)\Mr DJ\Need for Speed Carbon Collectors Edition\NFSC.exe
FirewallRules: [{8CE15B92-285D-4C96-B054-15BF1A626C53}] => (Allow) C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2.exe
FirewallRules: [{598012A7-217E-4665-AE16-26D7B3DDCCB8}] => (Allow) C:\Program Files (x86)\EA GAMES\Battlefield 2\BF2.exe
FirewallRules: [TCP Query User{EE7EF813-E9F4-4A2A-B4FE-DC8069D5B65B}C:\program files\strogino cs portal\counter-strike source\hl2.exe] => (Allow) C:\program files\strogino cs portal\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{842424C1-B0C8-4C57-A84E-138C7BB732F5}C:\program files\strogino cs portal\counter-strike source\hl2.exe] => (Allow) C:\program files\strogino cs portal\counter-strike source\hl2.exe
FirewallRules: [TCP Query User{214A4406-46DB-4CFB-841B-083AC5E05916}C:\program files\flatout2\flatout2.exe] => (Allow) C:\program files\flatout2\flatout2.exe
FirewallRules: [UDP Query User{8BA3AC9B-573B-435F-858C-1EDEA8E84C12}C:\program files\flatout2\flatout2.exe] => (Allow) C:\program files\flatout2\flatout2.exe
FirewallRules: [TCP Query User{789F2FFA-C209-4428-8DCC-D5F27289B831}C:\program files\strogino cs portal\counter-strike source\garrys mod\hl2.exe] => (Allow) C:\program files\strogino cs portal\counter-strike source\garrys mod\hl2.exe
FirewallRules: [UDP Query User{5EE2770F-AE26-4325-8E5C-EA031DDEA5D5}C:\program files\strogino cs portal\counter-strike source\garrys mod\hl2.exe] => (Allow) C:\program files\strogino cs portal\counter-strike source\garrys mod\hl2.exe
FirewallRules: [TCP Query User{31DE61BC-72F6-4ED5-B922-C0E0E5E8478F}C:\program files (x86)\ea games\battlefield 2\bf2.exe] => (Allow) C:\program files (x86)\ea games\battlefield 2\bf2.exe
FirewallRules: [UDP Query User{838E5F94-EF27-4E91-A32A-B238331208BB}C:\program files (x86)\ea games\battlefield 2\bf2.exe] => (Allow) C:\program files (x86)\ea games\battlefield 2\bf2.exe
FirewallRules: [{3A777139-089C-4C64-8632-89CAB4C606A2}] => (Allow) C:\Users\Lukáš\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7500409B-D6C1-474C-A3EC-4AF2D0E19E85}] => (Allow) C:\Users\Lukáš\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5C47F0B3-6F3B-4934-966E-78E14E68A2F3}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{122CE920-FD2A-485B-83FC-154B6477615C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{55EE1146-356B-4294-9D81-7F87902850ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cosmo's Cosmic Adventure\Cosmo Cosmic Adventure\Dosbox\dosbox.exe
FirewallRules: [{E97A1830-6468-45E3-AE40-5E7355B02503}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cosmo's Cosmic Adventure\Cosmo Cosmic Adventure\Dosbox\dosbox.exe
FirewallRules: [TCP Query User{B33D8F11-57D4-4558-84F4-20F905B87AB9}C:\program files (x86)\ea games\need for speed underground 2\speed2.exe] => (Allow) C:\program files (x86)\ea games\need for speed underground 2\speed2.exe
FirewallRules: [UDP Query User{504AC997-771D-4999-86AB-EA61CF0A408B}C:\program files (x86)\ea games\need for speed underground 2\speed2.exe] => (Allow) C:\program files (x86)\ea games\need for speed underground 2\speed2.exe
FirewallRules: [TCP Query User{01DE15E3-DCF7-49EE-A0DA-E0CBF87F032E}C:\program files\strogino cs portal\counter-strike source\hl2.exe] => (Allow) C:\program files\strogino cs portal\counter-strike source\hl2.exe
FirewallRules: [UDP Query User{AE33A0D1-FB0E-41DF-81F2-CD45BA7B1CEE}C:\program files\strogino cs portal\counter-strike source\hl2.exe] => (Allow) C:\program files\strogino cs portal\counter-strike source\hl2.exe
FirewallRules: [{0DBDE19D-D3C1-4622-8443-6772E390D539}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{1CF7CD70-B7DF-424A-BD07-D23E71A38B70}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [TCP Query User{6CE77FF0-87B8-4F10-9E46-2A59B3DF0C8E}C:\program files (x86)\vectir\vectir.exe] => (Allow) C:\program files (x86)\vectir\vectir.exe
FirewallRules: [UDP Query User{9D44E6FD-E038-4EF8-9DA4-E1B77B319389}C:\program files (x86)\vectir\vectir.exe] => (Allow) C:\program files (x86)\vectir\vectir.exe
FirewallRules: [TCP Query User{0D795617-90D2-4311-8212-9235C5CD8105}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{4B4FD52B-4839-44BE-8C0A-E313C6A3F519}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{C7F7EE9E-295A-4EC5-BEE6-91A7D690496A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II\pc\mafia2.exe
FirewallRules: [{F2F3AB2F-2EC2-43BA-9FF7-EFFFEA6DE7E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II\pc\mafia2.exe
FirewallRules: [TCP Query User{9FFC0494-4C40-4C53-94F8-3F40FA3B1A8C}C:\program files (x86)\vectir\vectir.exe] => (Block) C:\program files (x86)\vectir\vectir.exe
FirewallRules: [UDP Query User{D6219F15-7004-49E7-AB37-036BA2255719}C:\program files (x86)\vectir\vectir.exe] => (Block) C:\program files (x86)\vectir\vectir.exe
FirewallRules: [{05B26E60-D92C-4735-9BBC-D9F11676391D}] => (Allow) LPort=10011
FirewallRules: [{22A56711-AB7F-4EC1-904E-927092F36AAB}] => (Allow) LPort=30033
FirewallRules: [{D4A4B37C-8D99-4C1F-87DA-B1D757C5700D}] => (Allow) LPort=9987
FirewallRules: [{1BCDE21B-99DA-45A7-9FDC-574833C7A929}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{8243CEEF-2B95-4491-BEE9-2D4AA21D502C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [{E8497356-C856-4DAD-9FC5-9C497D6F3895}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [TCP Query User{58DBEAA2-1CB9-421D-B4E8-551BC4691516}C:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [UDP Query User{7E918A4B-E04B-48DD-96C0-6B7691CC7FCF}C:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [TCP Query User{FA479612-115C-4131-AB73-7958E15CB7E7}C:\users\lukáš\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\lukáš\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{09E60642-6A44-4BFA-A0D2-1A7212FF2860}C:\users\lukáš\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\lukáš\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{19A71DEF-2F02-4C47-9B59-37FCA1939A0F}C:\users\lukáš\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\lukáš\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{3808F035-0738-4195-96D4-740B33BAE7B7}C:\users\lukáš\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\lukáš\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{99B168A7-D64D-42E9-B35E-F8CBDCA3E622}C:\program files\quake 3 arena\quake3 arena\quake3\quake3.exe] => (Allow) C:\program files\quake 3 arena\quake3 arena\quake3\quake3.exe
FirewallRules: [UDP Query User{DE1D12F0-B765-4C9E-BA1E-6D1F897B4C50}C:\program files\quake 3 arena\quake3 arena\quake3\quake3.exe] => (Allow) C:\program files\quake 3 arena\quake3 arena\quake3\quake3.exe
FirewallRules: [{7C6570DA-A244-47B1-A254-1E042EC006FC}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{D71C8AC2-0B26-47AA-B6DF-A98314FC3FDB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{FB62EC0C-BE3A-499C-8837-852879D76D4C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{514B9304-0005-49C7-9D2A-B293069EE63B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6FFE0AAB-6085-4D27-A33D-82B747A38874}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{31C03665-E479-4034-9955-D8F7E05E2D06}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{AB8382BF-FF34-4790-844E-271A0B9F77EB}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe
FirewallRules: [UDP Query User{948541C4-69D0-4E73-A18A-9408E6EB793E}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.129\deploy\leagueclient.exe
FirewallRules: [{C9686DA1-4513-43F1-B125-5D32CA03F632}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1\H1Z1_BE.exe
FirewallRules: [{7FDAD595-2509-4875-9B76-1CDE365B60EF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\H1Z1\H1Z1_BE.exe
FirewallRules: [{7D1F0102-78EB-42C4-80E8-DE80D3530B1D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
FirewallRules: [{29EDB145-C5D8-43DD-A253-017F1DE5B29F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
FirewallRules: [{AE37BF3E-072F-48B3-80D2-9FB549EAC11A}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\66.0.3359.12\remoting_host.exe
FirewallRules: [TCP Query User{93DB5974-9E6F-4211-ADA7-921EDEB7B65B}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.138\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.138\deploy\leagueclient.exe
FirewallRules: [UDP Query User{9677606E-6267-4AF3-B5D1-E868F58A006C}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.138\deploy\leagueclient.exe] => (Allow) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.138\deploy\leagueclient.exe
FirewallRules: [TCP Query User{6CA520E1-FB82-4D0E-86EE-7086CED59966}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.139\deploy\leagueclient.exe] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.139\deploy\leagueclient.exe
FirewallRules: [UDP Query User{D60B0F62-BAC9-42D2-95CA-F70774CA4921}C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.139\deploy\leagueclient.exe] => (Block) C:\riot games\league of legends\rads\projects\league_client\releases\0.0.0.139\deploy\leagueclient.exe
FirewallRules: [{07E6610C-A689-4AA3-9CEE-149FDA4C91D0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 18 dub 2018 00:32

==================== Restore Points =========================

16-04-2018 18:08:47 Windows Update
16-04-2018 21:56:48 Removed LogMeIn Hamachi
17-04-2018 18:00:13 Windows Update

==================== Faulty Device Manager Devices =============

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Řadič sběrnice SM
Description: Řadič sběrnice SM
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: aswRvrt
Description: aswRvrt
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswRvrt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: aswVmm
Description: aswVmm
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: aswVmm
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Řadič USB (Universal Serial Bus)
Description: Řadič USB (Universal Serial Bus)
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/18/2018 12:14:51 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktivace licence systému Windows se nezdařila. Chyba 0x80070005.

Error: (04/18/2018 12:01:01 AM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: Plánovač aktivace licence (sppuinotify.dll) byl ukončen s následujícím kódem chyby:
0x80070005

Error: (04/17/2018 11:01:01 PM) (Source: Software Protection Platform Service) (EventID: 8193) (User: )
Description: Plánovač aktivace licence (sppuinotify.dll) byl ukončen s následujícím kódem chyby:
0x80070005

Error: (04/17/2018 10:24:56 PM) (Source: MsiInstaller) (EventID: 11704) (User: NT AUTHORITY)
Description: Produkt: Office 16 Click-to-Run Extensibility Component - Chyba 1704 Instalace produktu IC__iPackage je pozastavena. Chcete-li pokračovat, je nutné vrátit zpět změny provedené při instalaci. Chcete tyto změny vrátit zpět?

Error: (04/17/2018 10:13:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: igfxCUIService.exe, verze: 6.15.10.3650, časové razítko: 0x539f21a7
Název chybujícího modulu: igfxCUIService.exe, verze: 6.15.10.3650, časové razítko: 0x539f21a7
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000171a9
ID chybujícího procesu: 0x4e4
Čas spuštění chybující aplikace: 0x01d3d68807f74d27
Cesta k chybující aplikaci: C:\Windows\system32\igfxCUIService.exe
Cesta k chybujícímu modulu: C:\Windows\system32\igfxCUIService.exe
ID zprávy: c002356a-427b-11e8-9516-d8cb8a196ec3

Error: (04/17/2018 10:09:47 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktivace licence systému Windows se nezdařila. Chyba 0x80070005.

Error: (04/17/2018 10:02:12 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktivace licence systému Windows se nezdařila. Chyba 0x80070005.

Error: (04/17/2018 09:45:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: igfxCUIService.exe, verze: 6.15.10.3650, časové razítko: 0x539f21a7
Název chybujícího modulu: igfxCUIService.exe, verze: 6.15.10.3650, časové razítko: 0x539f21a7
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000171a9
ID chybujícího procesu: 0x4e4
Čas spuštění chybující aplikace: 0x01d3d684360d4ad8
Cesta k chybující aplikaci: C:\Windows\system32\igfxCUIService.exe
Cesta k chybujícímu modulu: C:\Windows\system32\igfxCUIService.exe
ID zprávy: dc0a50ca-4277-11e8-bde8-d8cb8a196ec3


System errors:
=============
Error: (04/18/2018 12:17:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
Nepodařilo se zahájit závislou službu nebo skupinu.

Error: (04/18/2018 12:17:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
Nepodařilo se zahájit závislou službu nebo skupinu.

Error: (04/18/2018 12:17:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
Nepodařilo se zahájit závislou službu nebo skupinu.

Error: (04/18/2018 12:17:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
Nepodařilo se zahájit závislou službu nebo skupinu.

Error: (04/18/2018 12:17:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
Nepodařilo se zahájit závislou službu nebo skupinu.

Error: (04/18/2018 12:17:01 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
Nepodařilo se zahájit závislou službu nebo skupinu.

Error: (04/18/2018 12:15:00 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Služba DCOM zjistila chybu %%1084 = Tuto službu nelze spustit v nouzovém režimu. při pokusu o spuštění služby WSearch s argumenty za účelem spuštění serveru:
{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (04/18/2018 12:15:00 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Služba DCOM zjistila chybu %%1084 = Tuto službu nelze spustit v nouzovém režimu. při pokusu o spuštění služby WSearch s argumenty za účelem spuštění serveru:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}


CodeIntegrity:
===================================

Date: 2018-04-17 21:38:44.239
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-04-17 21:38:44.208
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-04-17 21:38:44.177
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-04-17 21:38:44.161
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-04-16 16:08:31.362
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-04-16 16:07:26.809
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\hamachi.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-04-16 16:07:26.809
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\hamachi.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-04-16 16:07:26.809
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\hamachi.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
Percentage of memory in use: 17%
Total physical RAM: 8120 MB
Available physical RAM: 6677.06 MB
Total Virtual: 16238.17 MB
Available Virtual: 14858.63 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:499.32 GB) NTFS
Drive d: () (Removable) (Total:3.74 GB) (Free:3.74 GB) FAT32
Drive z: (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]


==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: FC325D5D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 3.8 GB) (Disk ID: 741909D2)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0B)

==================== End of Addition.txt ============================

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 18 dub 2018 00:33

Přidal jsem zbytek logu z FRST, odstranil daný soubor a hodil addition z frst. Případně jsou oba soubory v zipu výše

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod jaro3 » 18 dub 2018 10:45

ten soubor je tam zpátky..

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
ShortcutTarget: Dropbox.lnk -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
SearchScopes: HKU\S-1-5-21-639372863-3589611575-3710821846-1000 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz145; \??\C:\Windows\temp\cpuz145\cpuz145_x64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Lukáš\YIuooyIaaY.exe
C:\Program Files (x86)\IpSsiZJ.exe
C:\Users\Lukáš\AppData\Roaming\appdataFr25.bin
C:\Users\Lukáš\AppData\Local\Temp\dllnt_dump.dll
Task: {4C561519-3402-4CB9-B0C7-DAB31DCAD0B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-17] (Google Inc.)
Task: {A5822BF7-DF4B-4149-B375-2661C46681B9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-17] (Google Inc.)
ShortcutWithArgument: C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Vzdálená plocha Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
AlternateDataStreams: C:\Program Files (x86)\Vectir:{7A004600-3600-4100-3800-520058003400} [728]

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Podívej se do správce zařízení , zda tam nemáš otazník nebo vykřičník.


C:\Users\Lukáš\Desktop\rk_586C.tmp.txt tohle znáš?

Máš tam dost BSOD:
Stáhni si a nainstaluj WhoCrashed
otevři ho a klikni na [b]Analyze
.
Program vytvoří zprávu , zkopíruj celou a vlož prosím sem.

[/b]
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 18 dub 2018 16:35

Logy níže, také přikládám screen ze správce zařízení. Pár vykřičníků tam je..

C:\Users\Lukáš\Desktop\rk_586C.tmp.txt je log, který mi včera vyhodil RogueKiller


Fix result of Farbar Recovery Scan Tool (x64) Version: 15.04.2018
Ran by Lukáš (18-04-2018 16:25:35) Run:2
Running from C:\Users\Lukáš\Desktop
Loaded Profiles: Lukáš (Available Profiles: Lukáš & UpdatusUser)
Boot Mode: Safe Mode (with Networking)
==============================================

fixlist content:
*****************
Start
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
ShortcutTarget: Dropbox.lnk -> C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL =
SearchScopes: HKU\S-1-5-21-639372863-3589611575-3710821846-1000 -> {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz145; \??\C:\Windows\temp\cpuz145\cpuz145_x64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Lukáš\YIuooyIaaY.exe
C:\Program Files (x86)\IpSsiZJ.exe
C:\Users\Lukáš\AppData\Roaming\appdataFr25.bin
C:\Users\Lukáš\AppData\Local\Temp\dllnt_dump.dll
Task: {4C561519-3402-4CB9-B0C7-DAB31DCAD0B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-17] (Google Inc.)
Task: {A5822BF7-DF4B-4149-B375-2661C46681B9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-17] (Google Inc.)
ShortcutWithArgument: C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Vzdálená plocha Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
AlternateDataStreams: C:\Program Files (x86)\Vectir:{7A004600-3600-4100-3800-520058003400} [728]

EmptyTemp:
End
*****************

Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" => removed successfully
C:\Users\Lukáš\AppData\Roaming\Dropbox\bin\Dropbox.exe => moved successfully
"HKLM\SOFTWARE\Policies\Google" => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} => not found
"HKU\S-1-5-21-639372863-3589611575-3710821846-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}" => removed successfully
HKLM\Software\Classes\CLSID\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} => not found
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki" => removed successfully
"HKLM\System\CurrentControlSet\Services\catchme" => removed successfully
catchme => service removed successfully
"HKLM\System\CurrentControlSet\Services\cpuz145" => removed successfully
cpuz145 => service removed successfully
"HKLM\System\CurrentControlSet\Services\NTIOLib_1_0_C" => removed successfully
NTIOLib_1_0_C => service removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\Users\Lukáš\YIuooyIaaY.exe => moved successfully
"C:\Program Files (x86)\IpSsiZJ.exe" => not found
C:\Users\Lukáš\AppData\Roaming\appdataFr25.bin => moved successfully
C:\Users\Lukáš\AppData\Local\Temp\dllnt_dump.dll => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4C561519-3402-4CB9-B0C7-DAB31DCAD0B5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C561519-3402-4CB9-B0C7-DAB31DCAD0B5}" => removed successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A5822BF7-DF4B-4149-B375-2661C46681B9}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A5822BF7-DF4B-4149-B375-2661C46681B9}" => removed successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Vzdálená plocha Chrome.lnk => Shortcut argument removed successfully
C:\Program Files (x86)\Vectir => ":{7A004600-3600-4100-3800-520058003400}" ADS removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 20465345 B
Java, Flash, Steam htmlcache => 385735343 B
Windows/system/drivers => 503273 B
Edge => 0 B
Chrome => 388769594 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 33186 B
systemprofile32 => 33058 B
LocalService => 33058 B
NetworkService => 33058 B
Lukáš => 1115115 B
UpdatusUser => 0 B

RecycleBin => 0 B
EmptyTemp: => 759.8 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 16:25:56 ====




System Information (local)
--------------------------------------------------------------------------------

Computer name: LUKÁŠ-PC
Windows version: Windows 7 Service Pack 1, 6.1, build: 7601
Windows dir: C:\Windows
Hardware: MS-7816, MSI, B85-G43 (MS-7816)
CPU: GenuineIntel Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz Intel586, level: 6
4 logical processors, active mask: 15
RAM: 8514437120 bytes total




--------------------------------------------------------------------------------
Crash Dump Analysis
--------------------------------------------------------------------------------

Crash dumps are enabled on your computer. This system is not configured for complete or automatic crash dumps. For best results, configure your system to write out complete or automatic crash dumps. Select Tools->Crash Dump Configuration from the main menu to configure your system to write out complete memory dumps.

Crash dump directories:
C:\Windows
C:\Windows\Minidump

On Mon 16.4.2018 20:18:11 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041618-26629-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0xA44A0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA80068709A0, 0xFFFFFA8006870C80, 0xFFFFF800045C0190)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Mon 16.4.2018 20:18:11 your computer crashed or a problem was reported
crash dump file: C:\Windows\MEMORY.DMP
This was probably caused by the following module: ntkrnlmp.exe (nt!PsSetCurrentThreadPrefetching+0x6E2)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA80068709A0, 0xFFFFFA8006870C80, 0xFFFFF800045C0190)
Error: CRITICAL_OBJECT_TERMINATION
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Mon 16.4.2018 15:59:12 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041618-28438-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x6, 0xFFFFFA80090433D0, 0xFFFFFA8009013BF0, 0xFFFFF800045D6100)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sun 15.4.2018 20:32:58 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041518-27097-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA8009FCB6A0, 0xFFFFFA8009FCB980, 0xFFFFF800045CB130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sun 15.4.2018 19:53:44 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041518-31949-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA8009F65B30, 0xFFFFFA8009F65E10, 0xFFFFF800045DD130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sun 15.4.2018 11:55:58 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041518-19344-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA8006862B30, 0xFFFFFA8006862E10, 0xFFFFF800045D1130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sun 15.4.2018 0:18:48 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041518-25552-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA8006E83B30, 0xFFFFFA8006E83E10, 0xFFFFF8000457D130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sat 14.4.2018 23:51:38 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041418-52197-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA8006966060, 0xFFFFFA8006966340, 0xFFFFF800045D9130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sat 14.4.2018 23:08:26 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041418-24601-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA800A16CB30, 0xFFFFFA800A16CE10, 0xFFFFF80004599130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.



On Sat 14.4.2018 22:55:37 your computer crashed or a problem was reported
crash dump file: C:\Windows\Minidump\041418-23914-01.dmp
This was probably caused by the following module: ntoskrnl.exe (nt+0x74EC0)
Bugcheck code: 0xF4 (0x3, 0xFFFFFA80067F52E0, 0xFFFFFA80067F55C0, 0xFFFFF800045C7130)
Error: CRITICAL_OBJECT_TERMINATION
file path: C:\Windows\system32\ntoskrnl.exe
product: Microsoft® Windows® Operating System
company: Microsoft Corporation
description: NT Kernel & System
Bug check description: This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated. This bug check is typically caused by a thermal issue. It's suggested that you do temperature checking on your CPUs and hardware.
This is likely to be caused by a hardware problem. This problem might also be caused because of overheating (thermal issue).
The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.





--------------------------------------------------------------------------------
Conclusion
--------------------------------------------------------------------------------

On your computer a total of 12 crash dumps have been found. Only 10 have been analyzed. No offending third party drivers have been found. Connsider using WhoCrashed Professional which offers more detailed analysis using symbol resolution. Also configuring your system to produce a full memory dump may help you.


Read the topic general suggestions for troubleshooting system crashes for more information.

Note that it's not always possible to state with certainty whether a reported driver is responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.
Přílohy
správce zařízení.jpg

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 19 dub 2018 00:05

Vypadá to, že se toho sajrajtu jen tak nezbavím, tak se chci zeptat. Dnes mi přišlo SSDčko, když nainstaluju Windows na něj a budu si pak chtít překopírovat soubory ze starého disku, je tam riziko, že se vir dostane i na nový disk? Nemám jak jinak data zálohovat. Ovšem za předpokladu, že zůstane připojení k internetu zakázané..

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod jaro3 » 19 dub 2018 09:41

Podívej se , zda tam nemáš zpátky tyto soubory:
C:\Users\Lukáš\YIuooyIaaY.exe
C:\Program Files (x86)\IpSsiZJ.exe
C:\Users\Lukáš\AppData\Roaming\appdataFr25.bin

Měl by si nainstalovat ovladače chipsetu ( na CD k základní desce). Jer tam ale i Teredo , a to je ve windows..

K těm virům , ještě udělej tohle:
Stáhni Kaspersky VRT
na svojí plochu.
Spusť program Kaspersky VRT, .Program se nainstaluje.
Potvrď licenci a klikni na „Start“ . Pokud program nabídne aktualizaci , klikni dole na na „Download Now“.
- Klikni na ozubené kolečko v pravém horním rohu. V okně vyber kromě již zatržených , svojí jednotku disku , pokud jich máš víc , můžeš zatrhnout všechny.
- zvol „Automatic Scan“ nahoře vlevo. a stiskni tlačítko „Start Scanning
- Program začne skenovat zatržené jednotky

Zaškrtnuté :
Hidden startup objects
System Memory
Disk boot sectors

Počítač
Místní disk C

Nezašrkrtnuté:
Dokumenty
My email
Místní disk D
Jednotka DVD-Rom (E)
Jednotka BD-ROM (G)
Disketová jednotka

A jiné , např. Flash disky , které máš připojeny.

- povol programu Virus Removal Tool odstranit všechny nalezené infekce
- jakmile sken skončí ,zvol záložku „Report“ , vpravo nahoře (vedle ozubeného kolečka)
- klikni na „Detected Threads“ a klikni na obrázek diskety („Save“)
- ulož do počítače zprávu a vložit ji sem do příspěvku


Pak uvidíme , jestli se dá vše zálohovat..

Stáhni si Memtest:

Políčko , ve kterém je napsáno:
All unused RAM , změň na 2048.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.
poklepej na Memtest , pak znovu a znovu , do políček všech Memtestů napiš 2048 , pak dej u všech Memtestů "Start".

Nebo lépe:
Memtest 86
http://www.memtest86.com/
klikni vlevo na Free Download , vyber:
ISO image for creating bootable CD (Windows - zip) , stáhni , rozbal , otevři , vypal třeba v programu:
http://www.slunecnice.cz/sw/active-iso-burner/
Vlož do mechaniky a nabootuj z něj.
Test udělej alespoň 8h ( přes noc).

http://www.memtest86.com/download.htm
http://www.eopcservis.cz/jak-otestovat-ram.html
http://www.memtest86.com/download.htm
http://www.memtest86.com/downloads/memt ... sb.img.zip
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

spawnex
nováček
Příspěvky: 21
Registrován: duben 18
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod spawnex » 20 dub 2018 11:20

Žádný z výše uvedených souborů jsem v počítači nenašel.
Ovladače jsem doinstaloval a projel počítač přes Kaspersky. Log má asi 400 MB, tak jsem hodil do zipu a dávám odkaz: http://leteckaposta.cz/346446728

Memtest běžel taky a opět bez výsledku..

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vysoké využití procesoru, prosím o kontrolu

Příspěvekod jaro3 » 20 dub 2018 17:41

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

pak ještě jednou zkontroluj ty soubory:
C:\Users\Lukáš\YIuooyIaaY.exe
C:\Program Files (x86)\IpSsiZJ.exe
C:\Users\Lukáš\AppData\Roaming\appdataFr25.bin

Memtest tedy bez chyb?

Zkoušel si nainstalovat usb drivery?
A to druhé si zkoušel? Oco se jedná?

Ten Kaspersky je dlouhý , měl si dát jen nákazy , ne celý log.. Byly nějaké nákazy?
Co PC?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 3 hosti