Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 21:57:11, on 12. 7. 2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.19036)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE
C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
C:\moje programy\avg pc tuneup\Antivirus\AVGUI.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
C:\Users\lenovo\Desktop\HijackThis.exe
C:\windows\SysWOW64\DllHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkI ... id=UE12DHPR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe" /R
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote -
res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Antivirus - AVG Technologies CZ, s.r.o. - C:\moje programy\avg pc tuneup\Antivirus\AVGSvc.exe
O23 - Service: avgbIDSAgent - AVG Technologies CZ, s.r.o. - C:\moje programy\avg pc tuneup\Antivirus\x64\aswidsagenta.exe
O23 - Service: @oem15.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: CCSDK - Unknown owner - C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
O23 - Service: @C:\windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VeriFaceSrv - Unknown owner - C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAM Controller Service (ZAMSvc) - Copyright 2017. - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
--
End of file - 7916 bytes
____________________________________________________________________________________________________________
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by lenovo (administrator) on LENOVO-PC (12-07-2018 22:00:04)
Running from C:\Users\lenovo\Desktop
Loaded Profiles: lenovo (Available Profiles: lenovo)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVG Technologies CZ, s.r.o.) C:\moje programy\avg pc tuneup\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(AVG Technologies CZ, s.r.o.) C:\moje programy\avg pc tuneup\Antivirus\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
(AVG Technologies CZ, s.r.o.) C:\moje programy\avg pc tuneup\Antivirus\AVGUI.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
() C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LU.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2856616 2014-12-22] (Synaptics Incorporated)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [4060376 2014-10-22] (Realtek semiconductor)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2015-02-26] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2015-02-26] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2015-02-26] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated)
HKLM\...\Run: [AVGUI.exe] => C:\moje programy\avg pc tuneup\Antivirus\AvLaunch.exe [291568 2018-07-11] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492808 2014-09-09] (CyberLink Corp.)
HKU\S-1-5-21-1288416228-618668501-294838459-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27250144 2016-12-20] (Skype Technologies S.A.)
HKU\S-1-5-21-1288416228-618668501-294838459-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd)
HKU\S-1-5-21-1288416228-618668501-294838459-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1288416228-618668501-294838459-1001\...\MountPoints2: {7abf1e26-3765-11e8-8509-68f728762374} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1288416228-618668501-294838459-1001\...\MountPoints2: {c0b76895-e54a-11e6-8312-68f728762374} - "F:\autorun.exe"
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-02-26]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 83.240.0.214 83.240.0.135
Tcpip\..\Interfaces\{A8E7AD9D-D0EB-4E24-BEF8-D3A5E9DDC9F1}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{CD7C5C94-B32F-47E6-9818-D58DB930A9FC}: [DhcpNameServer] 83.240.0.214 83.240.0.135
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
hxxp://www.msn.com/HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1288416228-618668501-294838459-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhomeSearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1288416228-618668501-294838459-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
FireFox:
========
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
Chrome:
=======
CHR Profile: C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default [2018-07-12]
CHR Extension: (Prezentace) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-12]
CHR Extension: (Dokumenty) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-12]
CHR Extension: (Disk Google) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-12]
CHR Extension: (YouTube) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-12]
CHR Extension: (Tabulky) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-12]
CHR Extension: (Dokumenty Google offline) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-12]
CHR Extension: (AVG SafePrice) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-07-12]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-12]
CHR Extension: (Gmail) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-12]
CHR Extension: (Chrome Media Router) - C:\Users\lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-12]
CHR HKU\S-1-5-21-1288416228-618668501-294838459-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] -
hxxps://clients2.google.com/service/update2/crx==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVG Antivirus; C:\moje programy\avg pc tuneup\Antivirus\AVGSvc.exe [323512 2018-07-11] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\moje programy\avg pc tuneup\Antivirus\x64\aswidsagenta.exe [7829784 2018-07-11] (AVG Technologies CZ, s.r.o.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [976088 2014-03-15] (Broadcom Corporation.)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-10] ()
R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin Ltd. or its subsidiaries)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-18] (Lenovo(beijing) Limited)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S3 npggsvc; C:\windows\SysWOW64\GameMon.des [4362656 2016-02-24] (INCA Internet Co., Ltd.) [File not signed]
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2015-02-26] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2015-02-26] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [220840 2014-12-22] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10885360 2017-05-31] (TeamViewer GmbH)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2015-02-26] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\windows\System32\drivers\amdkmpfd.sys [36608 2013-12-13] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R1 avgArPot; C:\windows\System32\drivers\avgArPot.sys [189544 2018-07-11] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\windows\System32\drivers\avgbidsdrivera.sys [222288 2018-07-11] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\windows\System32\drivers\avgbidsha.sys [194224 2018-07-11] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\windows\System32\drivers\avgbloga.sys [339048 2018-07-11] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\windows\System32\drivers\avgbuniva.sys [51952 2018-07-11] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\windows\System32\drivers\avgHwid.sys [39352 2018-07-11] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\windows\System32\drivers\avgMonFlt.sys [152016 2018-07-11] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\windows\System32\drivers\avgRdr2.sys [104256 2018-07-11] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\windows\System32\drivers\avgRvrt.sys [78352 2018-07-11] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\windows\System32\drivers\avgSnx.sys [1020112 2018-07-11] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\windows\System32\drivers\avgSP.sys [455464 2018-07-11] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\windows\System32\drivers\avgStm.sys [203544 2018-07-11] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\windows\System32\drivers\avgVmm.sys [373944 2018-07-11] (AVG Technologies CZ, s.r.o.)
R1 CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-13] (CyberLink)
S3 NETwNe64; C:\windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 rtsuvc; C:\windows\system32\DRIVERS\rtsuvc.sys [2584280 2014-10-22] (Realtek Semiconductor Corp.)
S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 wsvd; C:\windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
R1 ZAM; C:\windows\System32\drivers\zam64.sys [203680 2018-07-12] (Zemana Ltd.)
R1 ZAM_Guard; C:\windows\System32\drivers\zamguard64.sys [203680 2018-07-12] (Zemana Ltd.)
S2 APXACC; \SystemRoot\system32\DRIVERS\appexDrv.sys [X]
S3 cpuz136; \??\C:\Users\lenovo\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-12 22:00 - 2018-07-12 22:00 - 000015403 _____ C:\Users\lenovo\Desktop\FRST.txt
2018-07-12 21:59 - 2018-07-12 22:00 - 000000000 ____D C:\FRST
2018-07-12 21:58 - 2018-07-12 21:58 - 002412544 _____ (Farbar) C:\Users\lenovo\Desktop\FRST64.exe
2018-07-12 21:56 - 2018-07-12 21:56 - 000000000 ____D C:\Users\lenovo\Desktop\backups
2018-07-12 20:03 - 2014-02-13 23:59 - 000024064 _____ C:\windows\zoek-delete.exe
2018-07-12 18:30 - 2018-07-12 19:40 - 000000000 ____D C:\zoek_backup
2018-07-12 18:29 - 2018-07-12 18:29 - 002038755 _____ C:\Users\lenovo\Desktop\zoek.exe
2018-07-12 14:42 - 2018-07-12 14:42 - 000203680 _____ (Zemana Ltd.) C:\windows\system32\Drivers\zamguard64.sys
2018-07-12 14:42 - 2018-07-12 14:42 - 000203680 _____ (Zemana Ltd.) C:\windows\system32\Drivers\zam64.sys
2018-07-12 14:42 - 2018-07-12 14:42 - 000001171 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2018-07-12 14:42 - 2018-07-12 14:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2018-07-12 12:51 - 2018-07-12 12:51 - 027086392 _____ (Adlice Software) C:\Users\lenovo\Desktop\RogueKiller_portable64.exe
2018-07-12 12:48 - 2018-07-12 12:48 - 000000037 _____ C:\Users\lenovo\Downloads\file-not-found (1).txt
2018-07-12 10:42 - 2018-07-12 10:42 - 000002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2018-07-12 10:42 - 2018-07-12 10:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-07-12 10:41 - 2018-07-12 10:41 - 000000000 ____D C:\Program Files (x86)\Sophos
2018-07-12 10:36 - 2018-07-12 10:39 - 195958672 _____ (Sophos Limited) C:\Users\lenovo\Downloads\Sophos Virus Removal Tool (1).exe
2018-07-12 10:33 - 2018-07-12 10:34 - 000000830 _____ C:\Users\lenovo\Desktop\JRT.txt
2018-07-12 10:21 - 2018-07-12 10:21 - 001790024 _____ (Malwarebytes) C:\Users\lenovo\Desktop\JRT.exe
2018-07-12 10:15 - 2018-07-12 10:15 - 000001767 _____ C:\Users\lenovo\Desktop\mbamb.txt
2018-07-12 10:08 - 2018-07-12 10:08 - 000001894 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-07-12 10:08 - 2018-07-12 10:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-07-12 10:08 - 2018-06-19 14:09 - 000152688 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-07-12 10:07 - 2018-07-12 10:07 - 000000000 ____D C:\Program Files\Malwarebytes
2018-07-12 10:06 - 2018-07-12 10:06 - 000001360 _____ C:\Users\lenovo\Desktop\AdwCleaner[S01].txt
2018-07-12 10:02 - 2018-07-12 10:02 - 000000000 ____D C:\Users\lenovo\AppData\Local\Adobe
2018-07-12 09:57 - 2018-07-12 09:58 - 075378680 _____ (Malwarebytes ) C:\Users\lenovo\Desktop\mb3-setup-consumer-3.5.1.2522-1.0.391-1.0.5867.exe
2018-07-12 09:56 - 2018-07-12 09:56 - 007395536 _____ (Malwarebytes) C:\Users\lenovo\Desktop\AdwCleaner.exe
2018-07-12 09:56 - 2018-07-12 09:56 - 000448512 _____ (OldTimer Tools) C:\Users\lenovo\Desktop\TFC.exe
2018-07-12 09:55 - 2018-07-12 09:55 - 000050688 _____ (Atribune.org) C:\Users\lenovo\Desktop\ATF-Cleaner (1).exe
2018-07-12 09:47 - 2018-07-12 09:47 - 000388608 _____ (Trend Micro Inc.) C:\Users\lenovo\Desktop\HijackThis.exe
2018-07-12 08:12 - 2018-07-12 22:00 - 000083626 _____ C:\windows\ZAM.krnl.trace
2018-07-12 08:12 - 2018-07-12 22:00 - 000058343 _____ C:\windows\ZAM_Guard.krnl.trace
2018-07-12 08:12 - 2018-07-12 14:42 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-07-12 08:11 - 2018-07-12 08:11 - 000000000 ____D C:\Users\lenovo\AppData\Local\Zemana
2018-07-12 08:10 - 2018-07-12 08:10 - 006625600 _____ (Zemana Ltd. ) C:\Users\lenovo\Downloads\Zemana.AntiMalware.Setup (1).exe
2018-07-12 07:59 - 2018-06-29 00:07 - 000835064 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2018-07-12 07:59 - 2018-06-29 00:07 - 000179704 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-07-11 21:21 - 2018-07-12 12:54 - 000028272 _____ C:\windows\system32\Drivers\TrueSight.sys
2018-07-11 21:20 - 2018-07-11 21:21 - 000000000 ____D C:\ProgramData\RogueKiller
2018-07-11 20:57 - 2018-07-11 20:57 - 000000037 _____ C:\Users\lenovo\Downloads\file-not-found.txt
2018-07-11 20:55 - 2018-07-11 20:55 - 000000000 ____D C:\ProgramData\Sophos
2018-07-11 20:11 - 2018-07-11 20:12 - 075160280 _____ (Malwarebytes ) C:\Users\lenovo\Downloads\mb3-setup-consumer-3.5.1.2522-1.0.391-1.0.5849.exe
2018-07-11 19:56 - 2018-06-20 22:01 - 007398232 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-07-11 19:56 - 2018-06-15 05:01 - 004169216 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2018-07-11 19:56 - 2018-06-12 10:00 - 022374248 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2018-07-11 19:56 - 2018-06-12 09:57 - 019790760 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2018-07-11 19:56 - 2018-06-11 18:55 - 025744896 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-07-11 19:56 - 2018-06-11 18:36 - 003119616 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2018-07-11 19:56 - 2018-06-11 18:06 - 005779968 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-07-11 19:56 - 2018-06-11 17:36 - 015283200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-07-11 19:56 - 2018-06-09 18:40 - 020286976 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-07-11 19:56 - 2018-06-09 17:37 - 004496384 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-07-11 19:56 - 2018-06-09 17:36 - 013680128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-07-11 19:55 - 2018-07-11 19:54 - 000379120 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\avgBoot.exe
2018-07-11 19:55 - 2018-06-20 21:44 - 001676064 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-07-11 19:55 - 2018-06-20 21:44 - 001536120 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2018-07-11 19:55 - 2018-06-20 20:48 - 000095744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdk8.sys
2018-07-11 19:55 - 2018-06-20 20:48 - 000027136 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fxppm.sys
2018-07-11 19:55 - 2018-06-20 18:58 - 000098816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\intelppm.sys
2018-07-11 19:55 - 2018-06-20 18:58 - 000098816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdppm.sys
2018-07-11 19:55 - 2018-06-20 18:58 - 000092672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\processr.sys
2018-07-11 19:55 - 2018-06-11 18:14 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-07-11 19:55 - 2018-06-11 18:04 - 000794624 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-07-11 19:55 - 2018-06-11 17:39 - 001033216 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2018-07-11 19:55 - 2018-06-11 17:31 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-07-11 19:55 - 2018-06-11 17:22 - 003241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-07-11 19:55 - 2018-06-11 17:11 - 001545216 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-07-11 19:55 - 2018-06-11 16:59 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-07-11 19:55 - 2018-06-09 18:26 - 002712064 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2018-07-11 19:55 - 2018-06-09 18:09 - 000498176 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-07-11 19:55 - 2018-06-09 17:59 - 000662016 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-07-11 19:55 - 2018-06-09 17:37 - 000880640 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2018-07-11 19:55 - 2018-06-09 17:32 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-07-11 19:55 - 2018-06-09 17:11 - 002767872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-07-11 19:55 - 2018-06-09 17:08 - 001313792 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-07-11 19:55 - 2018-06-09 17:06 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-07-11 19:55 - 2018-06-09 04:47 - 002176072 _____ (Microsoft Corporation) C:\windows\system32\combase.dll
2018-07-11 19:55 - 2018-06-09 03:44 - 001565528 _____ (Microsoft Corporation) C:\windows\SysWOW64\combase.dll
2018-07-11 19:55 - 2018-06-08 20:26 - 000440832 _____ (Microsoft Corporation) C:\windows\system32\zipfldr.dll
2018-07-11 19:55 - 2018-06-08 19:54 - 000656384 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll
2018-07-11 19:55 - 2018-06-08 19:53 - 000252416 _____ (Microsoft Corporation) C:\windows\system32\dnsrslvr.dll
2018-07-11 19:55 - 2018-06-08 19:07 - 000404992 _____ (Microsoft Corporation) C:\windows\SysWOW64\zipfldr.dll
2018-07-11 19:55 - 2018-06-08 18:44 - 000499200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll
2018-07-11 19:55 - 2018-06-07 20:51 - 000074240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mpsdrv.sys
2018-07-11 19:55 - 2018-05-24 23:29 - 002449752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2018-07-11 19:55 - 2018-05-24 23:29 - 000428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2018-07-11 19:55 - 2018-05-15 10:42 - 000590680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys
2018-07-11 19:55 - 2018-05-04 01:02 - 000439640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2018-07-11 19:55 - 2018-05-04 01:02 - 000325456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS
2018-07-11 19:55 - 2018-05-04 01:02 - 000187728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\UCX01000.SYS
2018-07-11 19:55 - 2018-04-26 15:43 - 000918296 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000065880 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000021848 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000018776 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000017240 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000017240 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000015704 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000015192 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000013656 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000013152 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000012120 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000012120 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000011608 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000011608 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000011608 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:43 - 000011608 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000998912 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000063832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000020824 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000019288 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000017752 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000017752 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000016216 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000015704 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000014168 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000013656 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000012632 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000012120 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000012120 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000012120 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-07-11 19:55 - 2018-04-26 15:19 - 000012120 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-07-11 19:55 - 2018-04-25 19:38 - 000243200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2018-07-11 19:49 - 2018-06-12 21:01 - 000149632 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2018-07-11 19:49 - 2018-06-08 15:15 - 002860032 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2018-07-11 19:49 - 2018-06-08 15:15 - 001602048 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000783872 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000680960 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000612352 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000470016 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000443392 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000301056 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2018-07-11 19:49 - 2018-06-08 15:15 - 000246272 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2018-07-11 19:33 - 2018-07-11 19:33 - 000050688 _____ (Atribune.org) C:\Users\lenovo\Downloads\ATF-Cleaner.exe
2018-07-11 19:29 - 2018-07-11 19:29 - 000000845 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-07-11 19:25 - 2018-07-11 19:26 - 015989160 _____ (Piriform Ltd) C:\Users\lenovo\Downloads\ccsetup544.exe
2018-07-11 19:21 - 2018-07-11 19:24 - 008458415 _____ (Piriform Ltd) C:\Users\lenovo\Downloads\Nepotvrzeno 403184.crdownload
2018-06-15 19:48 - 2018-05-25 05:56 - 000381440 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-06-15 19:48 - 2018-05-25 05:55 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-06-15 19:48 - 2018-05-25 05:53 - 002135552 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-06-15 19:48 - 2018-05-25 05:38 - 002060288 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-06-15 19:48 - 2018-05-25 05:38 - 000333312 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-06-15 19:48 - 2018-05-23 07:45 - 000027480 ____C (Microsoft Corporation) C:\windows\system32\Drivers\uefi.sys
2018-06-15 19:48 - 2018-05-15 07:47 - 002334624 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2018-06-15 19:48 - 2018-05-15 07:47 - 000244304 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2018-06-15 19:48 - 2018-05-15 07:33 - 001308352 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-06-15 19:48 - 2018-05-15 06:57 - 002324752 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2018-06-15 19:48 - 2018-05-15 06:17 - 000032640 ____C (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2018-06-15 19:48 - 2018-05-15 06:04 - 000240128 _____ (Microsoft Corporation) C:\windows\system32\vdsbas.dll
2018-06-15 19:48 - 2018-05-15 05:05 - 000517120 _____ (Microsoft Corporation) C:\windows\system32\wimserv.exe
2018-06-15 19:48 - 2018-05-15 04:57 - 000672768 _____ (Microsoft Corporation) C:\windows\system32\wimgapi.dll
2018-06-15 19:48 - 2018-05-15 04:51 - 000561152 _____ (Microsoft Corporation) C:\windows\SysWOW64\wimgapi.dll
2018-06-15 19:48 - 2018-05-12 23:11 - 000532664 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2018-06-15 19:48 - 2018-05-12 23:06 - 000567152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2018-06-15 19:48 - 2018-05-12 22:51 - 002014040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2018-06-15 19:48 - 2018-05-12 22:51 - 000923480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\refs.sys
2018-06-15 19:48 - 2018-05-12 21:08 - 000445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-06-15 19:48 - 2018-05-11 05:04 - 000324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-06-15 19:48 - 2018-05-05 21:05 - 001543800 _____ (Microsoft Corporation) C:\windows\system32\webservices.dll
2018-06-15 19:48 - 2018-05-05 20:15 - 001178136 _____ (Microsoft Corporation) C:\windows\SysWOW64\webservices.dll
2018-06-15 19:48 - 2018-05-05 18:38 - 000358912 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll
2018-06-15 19:48 - 2018-05-05 18:23 - 000324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll
2018-06-15 19:48 - 2018-04-07 18:43 - 000243200 _____ (Microsoft Corporation) C:\windows\system32\WinSCard.dll
2018-06-15 19:48 - 2018-04-07 18:09 - 000170496 _____ (Microsoft Corporation) C:\windows\SysWOW64\WinSCard.dll
2018-06-15 19:48 - 2018-04-07 17:34 - 002255360 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2018-06-15 19:48 - 2018-04-07 17:15 - 001942016 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2018-06-15 19:48 - 2018-04-05 19:47 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netvsc63.sys
2018-06-15 19:48 - 2018-04-05 19:38 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\NetVscCoinstall.dll
2018-06-15 19:48 - 2018-03-29 03:33 - 000070656 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2018-06-15 19:48 - 2018-03-29 03:06 - 002608640 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2018-06-15 19:48 - 2018-03-29 03:05 - 000285184 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2018-06-15 19:48 - 2018-03-29 02:26 - 002170880 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2018-06-15 19:48 - 2018-03-29 02:24 - 000236032 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2018-06-15 19:47 - 2018-05-23 06:13 - 000251392 _____ (Microsoft Corporation) C:\windows\system32\microsoft-windows-system-events.dll
2018-06-15 19:47 - 2018-03-29 03:21 - 000015872 _____ (Microsoft Corporation) C:\windows\system32\wsmplpxy.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-12 20:55 - 2015-10-14 04:44 - 000003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1288416228-618668501-294838459-1001
2018-07-12 20:37 - 2015-12-31 14:44 - 000000000 __RDO C:\Users\lenovo\OneDrive
2018-07-12 20:36 - 2015-02-26 18:47 - 000065536 _____ C:\windows\system32\spu_storage.bin
2018-07-12 20:36 - 2013-08-22 16:45 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-07-12 20:35 - 2015-02-26 20:10 - 000018944 _____ C:\windows\system32\VfService.trf
2018-07-12 19:43 - 2017-05-14 07:51 - 000000000 ____D C:\Users\Default\AppData\Local\Google
2018-07-12 19:43 - 2017-05-14 07:51 - 000000000 ____D C:\Users\Default User\AppData\Local\Google
2018-07-12 19:40 - 2013-08-22 17:36 - 000000000 ___HD C:\windows\system32\GroupPolicy
2018-07-12 16:27 - 2013-08-22 15:25 - 000262144 ___SH C:\windows\system32\config\BBI
2018-07-12 14:45 - 2015-10-14 04:36 - 000000000 ____D C:\Users\lenovo
2018-07-12 10:08 - 2013-08-22 15:36 - 000000000 ____D C:\windows\Inf
2018-07-12 10:07 - 2017-07-12 18:31 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-07-12 09:50 - 2015-12-25 21:47 - 000384000 ___SH C:\Users\lenovo\Desktop\Thumbs.db
2018-07-12 09:38 - 2015-02-26 19:53 - 000000000 ____D C:\windows\System32\Tasks\Lenovo
2018-07-12 09:38 - 2015-02-26 19:05 - 000000000 ____D C:\Program Files\Lenovo
2018-07-12 09:37 - 2015-10-14 04:37 - 000000000 ____D C:\Users\lenovo\AppData\Local\Packages
2018-07-12 09:37 - 2013-08-22 17:36 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-12 09:37 - 2013-08-22 17:36 - 000000000 ____D C:\windows\AppReadiness
2018-07-12 09:32 - 2016-01-12 17:02 - 000000034 _____ C:\Users\lenovo\AppData\Roaming\AdobeWLCMCache.dat
2018-07-12 09:32 - 2016-01-12 17:00 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2018-07-12 09:31 - 2016-01-12 17:21 - 000001720 _____ C:\Users\lenovo\Desktop\Adobe Illustrator CC 2015.lnk
2018-07-12 09:30 - 2015-12-31 14:34 - 000000000 ____D C:\moje programy
2018-07-12 08:04 - 2015-02-26 18:54 - 000734510 _____ C:\windows\system32\perfh005.dat
2018-07-12 08:04 - 2015-02-26 18:54 - 000148820 _____ C:\windows\system32\perfc005.dat
2018-07-12 08:04 - 2014-03-18 11:53 - 001739092 _____ C:\windows\system32\PerfStringBackup.INI
2018-07-12 08:02 - 2015-02-26 20:15 - 000000000 ____D C:\ProgramData\Energy Manager
2018-07-12 07:57 - 2013-08-22 16:44 - 000494112 _____ C:\windows\system32\FNTCACHE.DAT
2018-07-12 07:50 - 2013-08-22 17:36 - 000000000 ___RD C:\windows\ToastData
2018-07-11 22:58 - 2013-08-22 17:20 - 000000000 ____D C:\windows\CbsTemp
2018-07-11 20:35 - 2015-12-27 02:57 - 000000000 ____D C:\windows\system32\appraiser
2018-07-11 20:03 - 2017-06-01 20:17 - 000003924 _____ C:\windows\System32\Tasks\Antivirus Emergency Update
2018-07-11 19:54 - 2018-02-10 09:52 - 000189544 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgArPot.sys
2018-07-11 19:54 - 2017-07-12 19:02 - 000000000 ____D C:\AdwCleaner
2018-07-11 19:54 - 2017-06-01 20:17 - 000455464 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgSP.sys
2018-07-11 19:54 - 2017-06-01 20:17 - 000373944 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgVmm.sys
2018-07-11 19:54 - 2017-06-01 20:17 - 000203544 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgStm.sys
2018-07-11 19:54 - 2017-06-01 20:17 - 000152016 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgMonFlt.sys
2018-07-11 19:54 - 2017-06-01 20:17 - 000104256 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgRdr2.sys
2018-07-11 19:54 - 2017-06-01 20:17 - 000078352 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgRvrt.sys
2018-07-11 19:54 - 2017-06-01 20:17 - 000039352 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgHwid.sys
2018-07-11 19:52 - 2017-06-01 20:17 - 001020112 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgSnx.sys
2018-07-11 19:51 - 2017-06-01 20:17 - 000339048 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbloga.sys
2018-07-11 19:51 - 2017-06-01 20:17 - 000222288 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbidsdrivera.sys
2018-07-11 19:51 - 2017-06-01 20:17 - 000194224 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbidsha.sys
2018-07-11 19:51 - 2017-06-01 20:17 - 000051952 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbuniva.sys
2018-07-11 19:43 - 2015-12-27 00:04 - 000000000 ____D C:\windows\system32\MRT
2018-07-11 19:39 - 2015-12-27 00:04 - 134675576 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-07-11 19:37 - 2018-04-08 08:44 - 000000000 ____D C:\Users\lenovo\Desktop\bezobalu
2018-07-11 19:31 - 2018-05-10 18:58 - 000685568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2018-07-11 19:31 - 2015-12-27 16:27 - 000002255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-07-11 19:31 - 2015-12-27 16:27 - 000002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-07-11 19:29 - 2018-04-13 18:42 - 000003870 _____ C:\windows\System32\Tasks\CCleaner Update
2018-07-01 22:09 - 2016-01-03 18:34 - 000000000 ____D C:\Users\lenovo\Desktop\fotky
2018-06-16 10:55 - 2013-08-22 17:36 - 000000000 ____D C:\windows\rescache
2018-06-16 10:46 - 2017-10-12 11:30 - 133315992 ____C (Microsoft Corporation) C:\windows\system32\MRT-KB890830.exe
2018-06-16 08:42 - 2015-12-30 00:52 - 002851840 ___SH C:\Users\lenovo\Downloads\Thumbs.db
==================== Files in the root of some directories =======
2016-01-12 17:02 - 2018-07-12 09:32 - 000000034 _____ () C:\Users\lenovo\AppData\Roaming\AdobeWLCMCache.dat
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-07-11 20:34
==================== End of FRST.txt ============================