Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by zdenda (administrator) on FLANDELLKA (21-09-2015 14:10:54)
Running from C:\Users\zdenda\Downloads
Loaded Profiles: zdenda (Available Profiles: zdenda)
Platform: Windows 10 Home (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(InterVideo Inc.) C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
() C:\Program Files\AutoHotkey\AutoHotkey.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [396688 2015-07-18] ()
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848 2015-07-08] (ESET)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3015408 2013-03-05] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557984 2014-08-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [UVS11 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [341488 2007-03-03] (InterVideo Digital Technology Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2006-09-01] (Apple Computer, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-2292692883-487480938-3015334422-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-2292692883-487480938-3015334422-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53729824 2015-08-07] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\test.ahk.ahk [2015-08-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\XAMPP Control Panel.lnk [2015-08-20]
ShortcutTarget: XAMPP Control Panel.lnk -> C:\xampp\xampp-control.exe ()
Startup: C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2015-09-14]
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon INC.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{b6673560-0908-4de2-b30e-47e0d5be3142}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-2292692883-487480938-3015334422-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
hxxp://windows.microsoft.com/cs-cz/hotm ... ?ocid=iehpSearchScopes: HKU\S-1-5-21-2292692883-487480938-3015334422-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-07] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-07] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\zdenda\AppData\Roaming\Mozilla\Firefox\Profiles\tdyeim5r.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-11] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-11] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-07] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2292692883-487480938-3015334422-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\zdenda\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
Chrome:
=======
CHR Profile: C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-17]
CHR Extension: (Dokumenty Google) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-17]
CHR Extension: (Disk Google) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-17]
CHR Extension: (YouTube) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-17]
CHR Extension: (Vyhledávání Google) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-17]
CHR Extension: (Tabulky Google) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-17]
CHR Extension: (Dokumenty Google offline) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-17]
CHR Extension: (Gmail) - C:\Users\zdenda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor13.0; C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe [231120 2014-08-31] (Adobe Systems Incorporated)
R2 Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720 2015-07-08] (ESET)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-18] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-11] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2013-09-13] (arvato digital services llc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [237568 2015-07-10] (Microsoft Corporation)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [251632 2015-07-14] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET)
R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [231520 2015-07-14] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [53360 2015-07-14] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [72400 2015-07-14] (ESET)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [263952 2015-07-14] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-11] (Intel Corporation)
R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3496216 2015-07-10] (Intel Corporation)
R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation)
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402960 2015-05-14] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31984 2013-03-05] (Synaptics Incorporated)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-09-08] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146072 2015-09-08] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-21 14:10 - 2015-09-21 14:11 - 00015040 _____ C:\Users\zdenda\Downloads\FRST.txt
2015-09-21 14:06 - 2015-09-21 14:10 - 00000000 ____D C:\FRST
2015-09-21 14:05 - 2015-09-21 14:06 - 02191360 _____ (Farbar) C:\Users\zdenda\Downloads\FRST64.exe
2015-09-21 13:59 - 2015-09-21 13:59 - 00016148 _____ C:\WINDOWS\system32\FLANDELLKA_zdenda_HistoryPrediction.bin
2015-09-21 13:56 - 2015-09-21 13:35 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2015-09-21 13:43 - 2015-09-21 13:59 - 00006683 _____ C:\zoek-results.log
2015-09-21 13:35 - 2015-09-21 13:54 - 00000000 ____D C:\zoek_backup
2015-09-21 13:34 - 2015-09-21 13:34 - 01308672 _____ C:\Users\zdenda\Desktop\zoek.exe
2015-09-21 13:16 - 2015-09-21 13:16 - 22748744 _____ C:\Users\zdenda\Desktop\RogueKillerX64.exe
2015-09-21 13:08 - 2015-09-21 13:08 - 00000000 ____D C:\Users\zdenda\AppData\Local\CrashDumps
2015-09-20 13:36 - 2015-09-21 13:16 - 00037624 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-09-20 13:36 - 2015-09-20 13:36 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-20 13:23 - 2015-09-20 13:23 - 00000000 ____D C:\Users\zdenda\AppData\Local\Canon_INC
2015-09-19 17:31 - 2015-09-19 17:31 - 00001146 _____ C:\Users\zdenda\Desktop\JRT.txt
2015-09-19 17:26 - 2015-09-19 17:27 - 01798976 _____ (Malwarebytes) C:\Users\zdenda\Desktop\JRT.exe
2015-09-19 17:09 - 2015-09-19 17:09 - 00002913 _____ C:\Users\zdenda\Desktop\mal.txt
2015-09-19 16:19 - 2015-09-20 12:56 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-19 16:19 - 2015-09-19 16:19 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-19 16:19 - 2015-09-19 16:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-19 16:19 - 2015-09-19 16:19 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-19 16:19 - 2015-09-19 16:19 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-19 16:19 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-19 16:19 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-19 16:19 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-18 20:59 - 2015-09-18 20:59 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\zdenda\Desktop\mbam-setup-2.1.8.1057.exe
2015-09-18 20:53 - 2015-09-20 12:50 - 00000000 ____D C:\AdwCleaner
2015-09-18 20:52 - 2015-09-18 20:52 - 01662976 _____ C:\Users\zdenda\Desktop\AdwCleaner.exe
2015-09-18 20:50 - 2015-09-18 20:50 - 00000000 ____D C:\Users\zdenda\AppData\Local\CEF
2015-09-18 20:49 - 2015-09-21 10:32 - 00000000 ____D C:\Users\zdenda\AppData\Local\Adobe
2015-09-18 20:42 - 2015-09-18 20:42 - 00448512 _____ (OldTimer Tools) C:\Users\zdenda\Desktop\TFC.exe
2015-09-18 17:47 - 2015-09-18 17:47 - 00050688 _____ (Atribune.org) C:\Users\zdenda\Desktop\ATF-Cleaner.exe
2015-09-18 15:16 - 2015-09-18 15:16 - 00011089 _____ C:\Users\zdenda\Desktop\hijackthis.log
2015-09-18 15:09 - 2015-09-18 15:10 - 00388608 _____ (Trend Micro Inc.) C:\Users\zdenda\Desktop\HijackThis.exe
2015-09-17 13:12 - 2015-09-17 13:14 - 00019164 _____ C:\Users\zdenda\Documents\ikony.dst
2015-09-17 13:10 - 2015-09-17 13:10 - 00000000 ____D C:\Users\zdenda\Desktop\Nová složka (3)
2015-09-17 13:09 - 2015-09-17 13:09 - 02432384 _____ C:\Users\zdenda\Desktop\DragStrip---Parádní-panel-s-přetahováním-a-plno-funkcemi.zip
2015-09-16 11:34 - 2015-09-16 11:35 - 96996227 _____ C:\Users\zdenda\Desktop\chrome-win32.zip
2015-09-16 09:11 - 2015-09-16 09:11 - 00111371 _____ C:\Users\zdenda\Desktop\DesktopOK_Unicode.zip
2015-09-16 08:58 - 2015-09-16 08:58 - 00002658 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-16 08:58 - 2015-09-16 08:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-09-15 17:14 - 2015-09-15 20:44 - 00000000 ____D C:\Users\zdenda\VirtualBox VMs
2015-09-15 17:13 - 2015-09-15 20:44 - 00000000 ____D C:\Users\zdenda\.VirtualBox
2015-09-15 17:13 - 2015-09-15 17:13 - 00001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2015-09-15 17:13 - 2015-09-15 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-09-15 17:13 - 2015-09-08 11:48 - 00964392 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
2015-09-15 17:13 - 2015-09-08 11:47 - 00138904 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
2015-09-15 17:12 - 2015-09-15 17:12 - 00000000 ____D C:\Program Files\Oracle
2015-09-15 17:09 - 2015-09-15 17:11 - 116662984 _____ (Oracle Corporation) C:\Users\zdenda\Desktop\VirtualBox-5.0.4-102546-Win.exe
2015-09-15 15:11 - 2015-09-15 15:20 - 00249856 ____N (Microsoft Corporation) C:\WINDOWS\Setup1.exe
2015-09-15 15:11 - 2015-09-15 15:20 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\ST6UNST.EXE
2015-09-15 10:53 - 2015-09-15 10:53 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\.mono
2015-09-15 10:38 - 2015-09-15 10:53 - 00000000 ____D C:\Users\zdenda\Desktop\Kerbal.Space.Program.v1.0.4.861
2015-09-14 14:21 - 2015-09-14 14:21 - 00000000 ____D C:\Users\zdenda\Documents\Adobe
2015-09-14 13:56 - 2015-09-14 13:56 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Canon_Inc_IC
2015-09-14 13:55 - 2015-09-14 13:56 - 00000000 ____D C:\Users\zdenda\Desktop\ovládání foto
2015-09-14 13:46 - 2015-09-14 13:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-09-14 13:46 - 2015-09-14 13:48 - 00000000 ____D C:\Program Files (x86)\Canon
2015-09-14 13:46 - 2015-09-14 13:46 - 00000000 ____D C:\Program Files\Canon
2015-09-14 13:39 - 2015-09-14 13:39 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\canon
2015-09-14 13:39 - 2015-09-14 13:39 - 00000000 ____D C:\ProgramData\Canon_Inc_IC
2015-09-13 16:04 - 2015-09-13 16:04 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Downloaded Installations
2015-09-13 15:20 - 2015-09-13 15:29 - 00000000 ____D C:\Users\zdenda\Documents\Knihovna Calibre
2015-09-13 14:35 - 2015-09-13 14:36 - 00000000 ____D C:\Users\zdenda\.cr3
2015-09-13 14:22 - 2015-09-13 14:22 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\PDM
2015-09-13 14:14 - 2015-09-13 14:16 - 00000000 ____D C:\ProgramData\AllMyBooks
2015-09-13 14:14 - 2015-09-13 14:14 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Obsidium
2015-09-12 22:43 - 2015-09-12 22:45 - 00000000 ____D C:\Users\zdenda\AppData\Local\Seznam.cz
2015-09-12 22:43 - 2015-09-12 22:43 - 00001976 _____ C:\Users\zdenda\Desktop\Seznam.cz.lnk
2015-09-12 22:43 - 2015-09-12 22:43 - 00001956 _____ C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.lnk
2015-09-12 11:05 - 2015-09-12 11:05 - 00002233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-09-12 11:04 - 2015-09-12 11:04 - 00929360 _____ (Google Inc.) C:\Users\zdenda\Desktop\GoogleEarthSetup.exe
2015-09-10 14:21 - 2015-09-02 03:20 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-10 14:21 - 2015-09-02 02:25 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-10 14:21 - 2015-09-02 02:25 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-10 14:21 - 2015-08-27 08:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-10 14:21 - 2015-08-27 08:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-10 14:21 - 2015-08-27 08:04 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-10 14:21 - 2015-08-27 07:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-10 14:21 - 2015-08-27 07:55 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-10 14:21 - 2015-08-27 07:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-10 14:21 - 2015-08-27 07:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-10 14:21 - 2015-08-27 07:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-10 14:21 - 2015-08-27 07:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-10 14:21 - 2015-08-27 07:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-10 14:21 - 2015-08-27 07:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-10 14:21 - 2015-08-27 07:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-10 14:21 - 2015-08-27 07:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-10 14:21 - 2015-08-27 07:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-10 14:21 - 2015-08-27 07:42 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-10 14:21 - 2015-08-27 07:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-10 14:21 - 2015-08-27 07:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-10 14:21 - 2015-08-27 07:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-10 14:21 - 2015-08-27 07:23 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-10 14:21 - 2015-08-27 07:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-10 14:21 - 2015-08-27 07:16 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-10 14:21 - 2015-08-27 07:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-10 14:21 - 2015-08-27 07:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-10 14:21 - 2015-08-27 07:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-10 14:21 - 2015-08-27 07:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-10 14:21 - 2015-08-27 07:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-10 14:21 - 2015-08-27 07:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-10 14:21 - 2015-08-27 07:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-10 14:21 - 2015-08-27 07:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-08 17:36 - 2015-09-08 17:36 - 00000000 ____D C:\Users\zdenda\Documents\Ulead VideoStudio
2015-09-08 17:33 - 2015-09-08 17:37 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Ulead Systems
2015-09-08 17:30 - 2015-09-08 17:30 - 00001914 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-09-08 17:30 - 2015-09-08 17:30 - 00000000 ____D C:\ProgramData\SmartSound Software Inc
2015-09-08 17:30 - 2015-09-08 17:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-09-08 17:30 - 2015-09-08 17:30 - 00000000 ____D C:\Program Files (x86)\SmartSound Software
2015-09-08 17:30 - 2015-09-08 17:30 - 00000000 ____D C:\Program Files (x86)\QuickTime
2015-09-08 17:29 - 2015-09-08 17:29 - 00000000 ____D C:\ProgramData\InterVideo
2015-09-08 17:28 - 2015-09-08 17:28 - 00002253 _____ C:\Users\Public\Desktop\Ulead VideoStudio 11.lnk
2015-09-08 17:28 - 2015-09-08 17:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ulead VideoStudio 11
2015-09-08 17:28 - 2007-03-06 11:58 - 00210456 _____ C:\WINDOWS\SysWOW64\IVIresizeW7.dll
2015-09-08 17:28 - 2007-03-06 11:58 - 00206360 _____ C:\WINDOWS\SysWOW64\IVIresizeA6.dll
2015-09-08 17:28 - 2007-03-06 11:58 - 00198168 _____ C:\WINDOWS\SysWOW64\IVIresizeP6.dll
2015-09-08 17:28 - 2007-03-06 11:58 - 00198168 _____ C:\WINDOWS\SysWOW64\IVIresizeM6.dll
2015-09-08 17:28 - 2007-03-06 11:58 - 00194072 _____ C:\WINDOWS\SysWOW64\IVIresizePX.dll
2015-09-08 17:28 - 2007-03-06 11:58 - 00026136 _____ C:\WINDOWS\SysWOW64\IVIresize.dll
2015-09-08 17:27 - 2015-09-08 17:33 - 00000000 ____D C:\ProgramData\Ulead Systems
2015-09-08 17:27 - 2015-09-08 17:27 - 00000000 ____D C:\Program Files (x86)\Ulead Systems
2015-09-08 17:20 - 2015-09-08 17:23 - 00000000 ____D C:\Users\zdenda\Desktop\Nová složka (2)
2015-09-08 16:33 - 2015-09-08 17:16 - 783898424 _____ C:\Users\zdenda\Desktop\Ulead-Video-Studio-v11-+-Keygen.rar
2015-09-08 16:21 - 2015-09-08 16:21 - 00001883 _____ C:\Users\zdenda\Desktop\Programy a funkce.lnk
2015-09-08 16:21 - 2015-09-08 16:21 - 00000405 _____ C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programy a funkce.lnk
2015-09-08 15:46 - 2015-09-08 16:07 - 00000000 ____D C:\Users\zdenda\Documents\Polda III
2015-09-08 15:45 - 2015-09-08 16:22 - 00000000 ____D C:\Program Files (x86)\Polda 3
2015-09-08 11:47 - 2015-09-08 11:47 - 00146072 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxNetLwf.sys
2015-09-08 11:47 - 2015-09-08 11:47 - 00117768 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxNetAdp6.sys
2015-09-07 21:52 - 2015-09-07 21:52 - 00000000 ____D C:\Users\zdenda\Desktop\Nová složka
2015-09-07 21:51 - 2015-09-07 21:51 - 01908225 _____ C:\Users\zdenda\Desktop\VirtualDub-1.10.4.zip
2015-09-07 20:50 - 2015-09-07 20:50 - 00001845 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Start Art of Illusion.lnk
2015-09-07 20:50 - 2015-09-07 20:50 - 00001839 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Start Art of Illusion.lnk
2015-09-07 20:50 - 2015-09-07 20:50 - 00001833 _____ C:\Users\Public\Desktop\Start Art of Illusion.lnk
2015-09-07 20:50 - 2015-09-07 20:50 - 00000000 ____D C:\Users\zdenda\.artofillusion
2015-09-07 20:50 - 2015-09-07 20:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Art of Illusion
2015-09-07 20:50 - 2015-09-07 20:50 - 00000000 ____D C:\Program Files\ArtOfIllusion
2015-09-07 20:28 - 2015-09-07 20:28 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-09-07 20:28 - 2015-09-07 20:28 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Sun
2015-09-07 20:28 - 2015-09-07 20:28 - 00000000 ____D C:\Users\zdenda\.oracle_jre_usage
2015-09-07 20:28 - 2015-09-07 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-07 20:27 - 2015-09-07 20:49 - 00000000 ____D C:\ProgramData\Oracle
2015-09-07 20:27 - 2015-09-07 20:27 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-07 20:26 - 2015-09-07 20:26 - 06900074 _____ () C:\Users\zdenda\Desktop\ArtOfIllusion272-Windows.exe
2015-09-07 20:26 - 2015-09-07 20:26 - 00584288 _____ (Oracle Corporation) C:\Users\zdenda\Desktop\JavaSetup8u60.exe
2015-09-07 20:18 - 2015-09-07 20:22 - 00000000 ____D C:\ProgramData\TEMP
2015-09-07 20:09 - 2015-09-07 20:09 - 00000000 ____D C:\Users\Public\Documents\PhotoModeler
2015-09-07 20:03 - 2015-09-07 20:09 - 188887485 _____ C:\Users\zdenda\Desktop\PM6DemoSetup.exe
2015-09-07 19:54 - 2015-09-07 19:54 - 08211457 _____ (Delgine ) C:\Users\zdenda\Desktop\deledlitesetup.exe
2015-09-07 19:54 - 2015-09-07 19:54 - 00001003 _____ C:\Users\zdenda\Desktop\DeleD.lnk
2015-09-07 19:54 - 2015-09-07 19:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeleD LITE
2015-09-07 19:54 - 2015-09-07 19:54 - 00000000 ____D C:\Program Files (x86)\DeleD LITE
2015-09-07 19:50 - 2015-09-07 19:50 - 00000000 ____D C:\Users\zdenda\Documents\My Palettes
2015-09-07 19:49 - 2015-09-07 19:49 - 00000000 ____D C:\Users\zdenda\Documents\Corel
2015-09-07 18:52 - 2015-09-07 19:49 - 00000000 ____D C:\ProgramData\Protexis
2015-09-07 18:52 - 2015-09-07 18:52 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Corel
2015-09-07 18:51 - 2015-09-07 18:51 - 00000000 ____D C:\Users\zdenda\Desktop\kuchyň
2015-09-07 18:44 - 2015-09-07 18:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7
2015-09-07 18:44 - 2015-09-07 18:44 - 00000000 ____D C:\Users\Public\Documents\Corel
2015-09-07 18:43 - 2015-09-07 19:49 - 00000000 ____D C:\ProgramData\Corel
2015-09-07 18:43 - 2015-09-07 18:44 - 00000000 ____D C:\Program Files (x86)\Corel
2015-09-07 15:59 - 2015-09-07 15:59 - 00000000 ____D C:\Users\zdenda\eTeks
2015-09-07 15:58 - 2015-09-07 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eTeks Sweet Home 3D
2015-09-07 15:58 - 2015-09-07 15:58 - 00000000 ____D C:\Program Files\Sweet Home 3D
2015-09-07 14:34 - 2015-09-07 14:34 - 00001112 _____ C:\Users\zdenda\Desktop\Safari.exe – zástupce.lnk
2015-09-07 11:04 - 2015-09-07 11:42 - 00009152 _____ C:\Users\zdenda\Desktop\Hagia Sophia.xlsx
2015-09-07 10:46 - 2015-09-07 10:46 - 00000000 ___RD C:\Users\zdenda\3D Objects
2015-09-05 14:23 - 2015-09-05 14:23 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\AMD
2015-09-04 13:38 - 2015-09-08 17:30 - 00000000 ____D C:\ProgramData\Apple Computer
2015-09-04 13:38 - 2015-09-04 13:38 - 00002529 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
2015-09-04 13:38 - 2015-09-04 13:38 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Apple Computer
2015-09-04 13:37 - 2015-09-04 13:37 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-04 13:37 - 2015-09-04 13:37 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-09-04 13:37 - 2015-09-04 13:37 - 00000000 ____D C:\ProgramData\Apple
2015-09-04 13:37 - 2015-09-04 13:37 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-09-04 13:35 - 2015-09-17 11:38 - 00003944 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1441366492
2015-09-04 13:35 - 2015-09-17 11:38 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-09-04 13:35 - 2015-09-04 13:35 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Opera Software
2015-09-04 13:35 - 2015-09-04 13:35 - 00000000 ____D C:\Users\zdenda\AppData\Local\Opera Software
2015-09-04 13:35 - 2015-09-04 13:34 - 00001204 _____ C:\Users\zdenda\Desktop\Opera.lnk
2015-09-04 13:34 - 2015-09-17 11:38 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-04 13:30 - 2015-09-15 21:16 - 00000000 ____D C:\Users\zdenda\Desktop\prohlížeče
2015-09-02 12:43 - 2015-09-02 12:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenSSL
2015-09-02 12:43 - 2015-09-02 12:43 - 00000000 ____D C:\OpenSSL-Win64
2015-09-02 12:43 - 2015-07-09 19:21 - 00379392 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\WINDOWS\system32\ssleay32.dll
2015-09-02 12:43 - 2015-07-09 19:21 - 00379392 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\WINDOWS\system32\libssl32.dll
2015-09-02 12:43 - 2015-07-09 19:20 - 02077184 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\WINDOWS\system32\libeay32.dll
2015-09-02 12:43 - 2013-10-04 23:58 - 00963232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120.dll
2015-09-02 12:27 - 2015-09-02 12:43 - 00000000 ____D C:\totalcmd
2015-09-02 12:27 - 2015-09-02 12:31 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\GHISLER
2015-09-02 12:27 - 2015-09-02 12:27 - 06391640 _____ (Ghisler Software GmbH) C:\Users\zdenda\Downloads\tcmd852x32_64.exe
2015-09-02 12:27 - 2015-09-02 12:27 - 00000683 _____ C:\Users\zdenda\Desktop\Total Commander 64 bit.lnk
2015-09-02 12:27 - 2015-09-02 12:27 - 00000669 _____ C:\Users\zdenda\Desktop\Total Commander.lnk
2015-09-02 12:27 - 2015-09-02 12:27 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2015-09-01 12:56 - 2015-09-01 12:56 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\WinRAR
2015-09-01 12:51 - 2015-09-01 12:51 - 00001042 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2015-09-01 12:51 - 2015-09-01 12:51 - 00001036 _____ C:\Users\Public\Desktop\WinRAR.lnk
2015-09-01 12:51 - 2015-09-01 12:51 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-01 12:51 - 2015-09-01 12:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-01 12:51 - 2015-09-01 12:51 - 00000000 ____D C:\Program Files\WinRAR
2015-09-01 12:50 - 2015-09-01 12:50 - 02129208 _____ C:\Users\zdenda\Desktop\winrar-x64-521cz.exe
2015-08-29 18:22 - 2015-08-29 18:22 - 00003618 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-flanDellka-zdenda
2015-08-29 18:19 - 2015-08-29 18:19 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 13.lnk
2015-08-29 18:19 - 2015-08-29 18:19 - 00001039 _____ C:\Users\Public\Desktop\Adobe Photoshop Elements 13.lnk
2015-08-29 18:19 - 2015-08-29 18:19 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-08-29 18:06 - 2015-08-29 18:18 - 00000000 ____D C:\Program Files\Adobe
2015-08-29 18:03 - 2015-08-29 18:10 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-08-29 18:03 - 2013-09-03 12:01 - 00056336 ____N (Corel Corporation) C:\WINDOWS\system32\Drivers\PxHlpa64.sys
2015-08-29 18:03 - 2012-04-24 12:01 - 00011376 ____N (Corel Corporation) C:\WINDOWS\system32\Drivers\cdralw2k.sys
2015-08-29 18:03 - 2012-04-24 12:01 - 00010864 ____N (Corel Corporation) C:\WINDOWS\system32\Drivers\cdr4_xp.sys
2015-08-29 17:53 - 2015-08-29 17:53 - 00000000 ____D C:\Users\zdenda\Desktop\Adobe Photoshop Elements 13 (64 bit) [Uploaded by Damo33]
2015-08-29 11:28 - 2015-08-29 11:34 - 00000000 ____D C:\Users\zdenda\Desktop\30_1_21ML_00
2015-08-29 11:22 - 2015-08-20 08:07 - 08019296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-29 11:22 - 2015-08-20 08:06 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-29 11:22 - 2015-08-20 08:02 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-29 11:22 - 2015-08-20 07:26 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-29 11:22 - 2015-08-20 07:21 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-29 11:22 - 2015-08-20 07:16 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-29 11:22 - 2015-08-20 07:13 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-29 11:22 - 2015-08-20 07:09 - 00929280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-08-29 11:22 - 2015-08-18 09:56 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-29 11:22 - 2015-08-18 09:55 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-08-29 11:22 - 2015-08-18 09:54 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-29 11:22 - 2015-08-18 09:27 - 01771592 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-29 11:22 - 2015-08-18 09:24 - 00963920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-29 11:22 - 2015-08-18 09:13 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-08-29 11:22 - 2015-08-18 09:13 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-08-29 11:22 - 2015-08-18 09:12 - 02225664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-29 11:22 - 2015-08-18 09:07 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-08-29 11:22 - 2015-08-18 09:04 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-08-29 11:22 - 2015-08-18 09:04 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-29 11:22 - 2015-08-18 08:59 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-08-29 11:22 - 2015-08-18 08:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-08-29 11:22 - 2015-08-18 08:58 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-08-29 11:22 - 2015-08-18 08:58 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-08-29 11:22 - 2015-08-18 08:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-08-29 11:22 - 2015-08-18 08:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-08-29 11:22 - 2015-08-18 08:57 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-08-29 11:22 - 2015-08-18 08:56 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-08-29 11:22 - 2015-08-18 08:55 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-29 11:22 - 2015-08-18 08:54 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-08-29 11:22 - 2015-08-18 08:54 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-29 11:22 - 2015-08-18 08:52 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-29 11:22 - 2015-08-18 08:50 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-29 11:22 - 2015-08-18 08:49 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-29 11:22 - 2015-08-18 08:49 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-08-29 11:22 - 2015-08-18 08:49 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-08-29 11:22 - 2015-08-18 08:36 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-08-29 11:22 - 2015-08-18 08:35 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-08-29 11:22 - 2015-08-18 08:35 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-08-29 11:22 - 2015-08-18 08:34 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-08-29 11:22 - 2015-08-18 08:29 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-29 11:22 - 2015-08-18 08:26 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-08-29 11:22 - 2015-08-18 06:44 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-08-28 11:14 - 2015-08-28 11:16 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Ulozto File Manager
2015-08-28 11:14 - 2015-08-28 11:14 - 00000000 ____D C:\Users\zdenda\Documents\Ulozto
2015-08-23 21:56 - 2015-08-23 22:05 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-08-23 21:55 - 2015-08-23 22:06 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-08-23 21:55 - 2015-08-23 21:55 - 00002124 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-08-23 21:55 - 2015-08-23 21:55 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-08-23 21:54 - 2015-08-29 19:07 - 00000000 ____D C:\ProgramData\Adobe
2015-08-23 21:04 - 2015-08-23 21:04 - 00000000 ____D C:\ProgramData\UniqueId
2015-08-23 20:56 - 2015-09-15 21:19 - 00000000 ____D C:\Users\zdenda\Desktop\knihy
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-21 14:07 - 2015-08-19 10:49 - 00000000 ____D C:\Users\zdenda\OneDrive
2015-09-21 14:07 - 2015-08-17 12:15 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-21 14:07 - 2015-08-16 22:12 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Skype
2015-09-21 13:59 - 2015-08-18 22:12 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-09-21 13:59 - 2015-08-17 10:41 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-21 13:59 - 2015-07-10 14:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-21 13:58 - 2015-08-18 22:07 - 00035226 _____ C:\WINDOWS\PFRO.log
2015-09-21 13:58 - 2015-07-10 14:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-21 13:57 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-21 13:57 - 2015-07-10 11:05 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2015-09-21 12:58 - 2015-08-17 10:41 - 00000982 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-21 10:33 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-20 23:12 - 2015-08-21 10:09 - 00000600 _____ C:\Users\zdenda\AppData\Roaming\winscp.rnd
2015-09-20 23:02 - 2015-08-20 15:03 - 00000000 ____D C:\Users\zdenda\Desktop\lovi-zs
2015-09-20 23:01 - 2015-08-17 12:00 - 00011622 _____ C:\Users\zdenda\Desktop\hesla.xlsx
2015-09-20 13:24 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-09-20 12:40 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-19 16:08 - 2015-08-19 10:45 - 00000000 ____D C:\Users\zdenda\AppData\Local\Comms
2015-09-18 10:16 - 2015-08-16 14:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-17 21:53 - 2015-08-17 10:41 - 00004040 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-17 21:53 - 2015-08-17 10:41 - 00003808 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-17 13:11 - 2015-08-16 14:39 - 00000000 ____D C:\Users\zdenda\AppData\Local\VirtualStore
2015-09-16 09:01 - 2015-08-16 14:39 - 00000000 ____D C:\Users\zdenda\AppData\Local\Packages
2015-09-16 08:58 - 2015-08-16 22:12 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-16 08:58 - 2015-08-16 22:12 - 00000000 ____D C:\ProgramData\Skype
2015-09-15 21:10 - 2015-08-18 22:16 - 00000000 ____D C:\Users\zdenda
2015-09-15 12:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\rescache
2015-09-15 11:20 - 2015-08-17 10:41 - 00000000 ____D C:\Users\zdenda\AppData\Local\Google
2015-09-15 00:18 - 2015-08-17 11:44 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-09-14 14:22 - 2015-08-16 14:40 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Adobe
2015-09-14 14:21 - 2015-07-10 12:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-14 14:20 - 2015-07-10 12:59 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2015-09-14 14:20 - 2015-07-10 12:59 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2015-09-14 14:20 - 2015-07-10 12:59 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2015-09-14 14:20 - 2015-07-10 12:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2015-09-14 14:20 - 2015-07-10 12:59 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2015-09-14 14:01 - 2015-07-10 14:20 - 00014898 _____ C:\WINDOWS\setupact.log
2015-09-14 11:03 - 2015-08-21 10:37 - 00000000 ____D C:\Users\zdenda\Desktop\filmy
2015-09-13 15:00 - 2015-08-18 19:48 - 00000000 ____D C:\Users\zdenda\.FBReader
2015-09-12 11:05 - 2015-08-17 10:41 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-11 14:06 - 2015-08-18 22:24 - 01762290 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-11 14:06 - 2015-07-10 18:02 - 00746648 _____ C:\WINDOWS\system32\perfh005.dat
2015-09-11 14:06 - 2015-07-10 18:02 - 00149550 _____ C:\WINDOWS\system32\perfc005.dat
2015-09-11 14:04 - 2015-08-19 10:49 - 00002401 _____ C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-11 13:59 - 2015-07-10 14:20 - 00460656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-11 13:57 - 2015-07-10 18:05 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-11 13:57 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-09-10 18:46 - 2015-08-19 18:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-10 18:44 - 2013-08-22 15:25 - 00000167 _____ C:\WINDOWS\win.ini
2015-09-10 18:43 - 2015-08-16 17:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-07 21:52 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\System
2015-09-07 18:47 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-02 11:39 - 2015-08-18 22:26 - 00002332 _____ C:\Users\zdenda\Desktop\Google Chrome.lnk
2015-09-01 13:14 - 2015-08-19 17:22 - 00001965 _____ C:\Users\zdenda\Desktop\PSPad.lnk
2015-08-29 18:45 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-08-29 14:33 - 2015-02-14 14:04 - 00000000 ____D C:\Users\zdenda\Desktop\Karty
2015-08-28 11:49 - 2015-08-21 10:35 - 00000000 ___RD C:\Users\zdenda\Desktop\hudba
2015-08-27 17:36 - 2015-08-17 15:18 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\BSplayer
2015-08-26 18:37 - 2015-08-16 17:31 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-25 09:58 - 2015-08-20 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XAMPP
2015-08-23 20:57 - 2015-08-17 15:00 - 00001954 _____ C:\Users\zdenda\Desktop\FBReader.lnk
2015-08-23 20:57 - 2015-08-17 15:00 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FBReader for Windows
2015-08-23 11:11 - 2015-08-21 14:06 - 00000000 ____D C:\Users\zdenda\AppData\Roaming\Audacity
==================== Files in the root of some directories =======
2015-08-21 10:09 - 2015-09-20 23:12 - 0000600 _____ () C:\Users\zdenda\AppData\Roaming\winscp.rnd
2015-08-18 22:12 - 2015-08-18 22:12 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-12 23:22
==================== End of FRST.txt ============================