PC dropy Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 19 bře 2016 13:13

Mám ještě jednu otázku zkoušeli jsme monitoring DIsku D a vždycky když se to seklo tak byla průměrná doba odezvy třeba 200 až 350 ms

a ten disk je už celkem starý nemohlo by to být tím ?

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod jaro3 » 20 bře 2016 09:29

Stáhni si Memtest:

Políčko , ve kterém je napsáno:
All unused RAM -ponech , jak je.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.


Ještě zkontrolovat HDD na chyby ,popř. zkusit jeho defragmentaci ..


Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 10:51

----------------------------------------------------------------------------
CrystalDiskInfo 6.7.0 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 Enterprise [10.0 Build 10240] (x64)
Date : 2016/03/20 10:51:47

-- Controller Map ----------------------------------------------------------
+ Intel(R) 9 Series Chipset Family SATA AHCI Controller [ATA]
- KINGSTON SHFS37A120G SCSI Disk Device
- WDC WD5000AZRX-00A8LB0
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) KINGSTON SHFS37A120G : 120,0 GB [0/0/0, pd1] - sf
(2) WDC WD5000AZRX-00A8LB0 : 500,1 GB [1/0/0, pd1] - wd

----------------------------------------------------------------------------
(1) KINGSTON SHFS37A120G
----------------------------------------------------------------------------
Model : KINGSTON SHFS37A120G
Firmware : 605ABBF2
Serial Number : 50026B725A0A63BE
Disk Size : 120,0 GB (8,4/120,0/120,0/120,0)
Buffer Size : Neznámy údaj
Queue Depth : 32 # of Sectors : 234441648
Rotation Rate : ---- (SSD)
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ACS-2 Revision 3
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 805 hod.
Power On Count : 191 krát
Host Reads : 1191 GB
Host Writes : 1640 GB
Temperature : 22 C (71 F)
Health Status : Dobrý (100 %)
Features : S.M.A.R.T., APM, 48bit LBA, NCQ, TRIM
APM Level : 00FEh [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr Raw Values (7) Attribute Name
01 _95 _95 _50 000000008E2D45 Raw Read Error Rate
05 100 100 __3 00000000000000 Retired Block Count
09 100 100 __0 0FFB5E00000325 Power-on Hours
0C 100 100 __0 000000000000BF Power Cycle Count
AB 100 100 __0 00000000000000 Program Fail Count
AC 100 100 __0 00000000000000 Erase Fail Count
AE __0 __0 __0 00000000000012 Unexpected Power Loss Count
B1 __0 __0 __0 00000000000001 Wear Range Delta
B5 100 100 __0 00000000000000 Program Fail Count
B6 100 100 __0 00000000000000 Erase Fail Count
BB 100 100 __0 00000000000000 Reported Uncorrectable Errors
BD _22 _31 __0 00000D001F0016 Specifický pro výrobce
C2 _22 _31 __0 00000D001F0016 Temperature
C3 120 120 __0 000000008E2D45 On-the-Fly ECC Uncorrectable Error Count
C4 100 100 __3 00000000000000 Reallocation Event Count
C9 120 120 __0 000000008E2D45 Uncorrectable Soft Read Error Rate
CC 120 120 __0 000000008E2D45 Soft ECC Correction Rate
E6 100 100 __0 00000000000064 Life Curve Status
E7 100 100 _11 00000900000000 SSD Life Left
E9 __0 __0 __0 0000000000082D Specifický pro výrobce
EA __0 __0 __0 00000000000668 Specifický pro výrobce
F1 __0 __0 __0 00000000000668 Lifetime Writes from Host
F2 __0 __0 __0 000000000004A7 Lifetime Reads from Host
F4 100 100 _10 0000000022000E Specifický pro výrobce

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0C5A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 3530 3032 3642 3732 3541 3041 3633 4245 2020 2020
020: 0000 0000 0004 3630 3541 4242 4632 4B49 4E47 5354
030: 4F4E 2053 4846 5333 3741 3132 3047 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8001 4000 2F00
050: 4001 0200 0200 0007 3FFF 0010 003F FC10 00FB 0101
060: 4BB0 0DF9 0000 0007 0003 0078 0078 0078 0078 0F08
070: 0000 0000 0000 0000 0000 001F 950E 0006 004C 004C
080: 01FC 0110 746B 7569 6163 7429 B449 6163 407F 0001
090: 0001 00FE FFFE 0000 0000 0000 0000 0000 0000 0000
100: 4BB0 0DF9 0000 0000 0000 0001 4000 0000 5002 6B72
110: 5A0A 63BE 0000 0000 0000 0000 0000 0000 0000 405A
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 0025 0000 0000 4000
210: 0000 0000 0100 0000 0000 0000 0000 0001 0000 0000
220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 4BB0 0DF9 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 22A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 0A 00 01 32 00 5F 5F 45 2D 8E 00 00 00 00 05 33
010: 00 64 64 00 00 00 00 00 00 00 09 32 00 64 64 25
020: 03 00 00 5E FB 0F 0C 32 00 64 64 BF 00 00 00 00
030: 00 00 AB 0A 00 64 64 00 00 00 00 00 00 00 AC 32
040: 00 64 64 00 00 00 00 00 00 00 AE 30 00 00 00 12
050: 00 00 00 00 00 00 B1 00 00 00 00 01 00 00 00 00
060: 00 00 B5 0A 00 64 64 00 00 00 00 00 00 00 B6 32
070: 00 64 64 00 00 00 00 00 00 00 BB 12 00 64 64 00
080: 00 00 00 00 00 00 BD 00 00 16 1F 16 00 1F 00 0D
090: 00 00 C2 22 00 16 1F 16 00 1F 00 0D 00 00 C3 1C
0A0: 00 78 78 45 2D 8E 00 00 00 00 C4 33 00 64 64 00
0B0: 00 00 00 00 00 00 C9 1C 00 78 78 45 2D 8E 00 00
0C0: 00 00 CC 1C 00 78 78 45 2D 8E 00 00 00 00 E6 13
0D0: 00 64 64 64 00 00 00 00 00 00 E7 00 00 64 64 00
0E0: 00 00 00 09 00 00 E9 32 00 00 00 2D 08 00 00 00
0F0: 00 00 EA 32 00 00 00 68 06 00 00 00 00 00 F1 32
100: 00 00 00 68 06 00 00 00 00 00 F2 32 00 00 00 A7
110: 04 00 00 00 00 00 F4 00 00 64 64 0E 00 22 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 7D
170: 03 00 01 00 01 30 02 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 9B

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 0A 00 01 32 00 00 00 00 00 00 00 00 00 00 05 03
010: 00 00 00 00 00 00 00 00 00 00 09 00 00 00 00 00
020: 00 00 00 00 00 00 0C 00 00 00 00 00 00 00 00 00
030: 00 00 AB 00 00 00 00 00 00 00 00 00 00 00 AC 00
040: 00 00 00 00 00 00 00 00 00 00 AE 00 00 00 00 00
050: 00 00 00 00 00 00 B1 00 00 00 00 00 00 00 00 00
060: 00 00 B5 00 00 00 00 00 00 00 00 00 00 00 B6 00
070: 00 00 00 00 00 00 00 00 00 00 BB 00 00 00 00 00
080: 00 00 00 00 00 00 BD 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C3 00
0A0: 00 00 00 00 00 00 00 00 00 00 C4 03 00 00 00 00
0B0: 00 00 00 00 00 00 C9 00 00 00 00 00 00 00 00 00
0C0: 00 00 CC 00 00 00 00 00 00 00 00 00 00 00 E6 00
0D0: 00 00 00 00 00 00 00 00 00 00 E7 0B 00 00 00 00
0E0: 00 00 00 00 00 00 E9 00 00 00 00 00 00 00 00 00
0F0: 00 00 EA 00 00 00 00 00 00 00 00 00 00 00 F1 00
100: 00 00 00 00 00 00 00 00 00 00 F2 00 00 00 00 00
110: 00 00 00 00 00 00 F4 0A 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A0

----------------------------------------------------------------------------
(2) WDC WD5000AZRX-00A8LB0
----------------------------------------------------------------------------
Model : WDC WD5000AZRX-00A8LB0
Firmware : 01.01A01
Serial Number : WD-WCC1U4584098
Disk Size : 500,1 GB (8,4/137,4/500,1/500,1)
Buffer Size : Neznámy údaj
Queue Depth : 32 # of Sectors : 976771055
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 8171 hod.
Power On Count : 2067 krát
Temperature : 24 C (75 F)
Health Status : Dobrý
Features : S.M.A.R.T., 48bit LBA, NCQ
APM Level : ----
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 159 132 _21 000000000BE1 Čas na roztočení ploten
04 _95 _95 __0 00000000151C Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _89 _89 __0 000000001FEB Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _98 _98 __0 000000000813 Počet cyklů zapnutí zařízení
C0 198 198 __0 00000000086F Počet vypnutí disku
C1 180 180 __0 00000000EDE3 Počet cyklů načítání/vymazání
C2 119 _95 __0 000000000018 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 200 200 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 200 200 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5743 4331 5534 3538 3430 3938
020: 0000 0000 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3530 3030 415A 5258 2D30 3041 384C 4230 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 970E 0006 0044 0044
080: 01FE 0000 746B 7D61 4123 7469 BC41 4123 407F 0029
090: 0029 0000 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 57EF 3A38 0000 0000 0000 0000 6003 0000 5001 4EE2
110: B39E 230A 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0400
130: 0001 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 30B5 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 F1A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 9F 84 E1 0B 00 00 00 00 00 04 32 00 5F 5F 1C
020: 15 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 59 59 EB 1F 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 62 62 13 08 00 00 00 00 00 C0 32
070: 00 C6 C6 6F 08 00 00 00 00 00 C1 32 00 B4 B4 E3
080: ED 00 00 00 00 00 C2 22 00 77 5F 18 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 C8 C8 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 C8 C8 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 82 00 B4 1E 01 7B
170: 03 00 01 00 02 5C 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 02 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 00 00 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 C8 C8 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 11:01

Když chci dát u toho MEMTEST start tak mi to napíše windows limits the amount of contiguous RAM a single program can allocate atd ...

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 12:45

Podle mě to bude diskem D ,je totiž dost starý zkoušel jsem dát LoLko na C a jelo v pohodě tak nevím

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod jaro3 » 20 bře 2016 14:03

000000000BE1 Čas na roztočení ploten
udělej znovu CDI.

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.

Memtest , spusť několik memtestů současně.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 14:07

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Kuba (administrator) on KUBA-PC (20-03-2016 14:07:02)
Running from C:\Users\Kuba\Desktop
Loaded Profiles: Kuba (Available Profiles: Kuba)
Platform: Windows 10 Enterprise (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
() C:\Windows\SysWOW64\ASGT.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Users\Kuba\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-03-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\Run: [WarThunderLauncher] => D:\Games\WarThunder\launcher.exe [6021168 2016-03-10] (Gaijin Entertainment)
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\MountPoints2: {311572c4-ab30-11e5-8d6f-d8cb8aa0c6f3} - "E:\CheckID.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{04c254f7-985b-4381-baf6-fbf35b55fccc}: [DhcpNameServer] 10.0.0.1

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3313306934-2274467357-1670545691-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2016-01-01] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-01] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-02-05] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2016-01-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2016-01-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-08] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-10] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\abs@avira.com.xpi [2016-03-12]
FF Extension: Avira SafeSearch Plus - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\safesearchplus2@avira.com.xpi [2016-03-12]

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR Profile: C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-18]
CHR Extension: (Dokumenty Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-18]
CHR Extension: (Disk Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-18]
CHR Extension: (YouTube) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-18]
CHR Extension: (Tabulky Google) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-18]
CHR Extension: (Gmail) - C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-18]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [48640 2015-05-29] () [File not signed]
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [245544 2016-03-18] (EasyAntiCheat Ltd)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2521440 2016-02-22] (ESET)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2013-11-21] (Futuremark)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-03-08] (NVIDIA Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-02-10] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-03-08] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-03-08] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-03-08] (NVIDIA Corporation)
S3 SandraDataSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Engineer XII.SP1\Win32\RpcDataSrv.exe [213176 2007-12-12] (SiSoftware)
S3 SandraTheSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Engineer XII.SP1\RpcSandraSrv.exe [1865904 2007-12-12] (SiSoftware)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dc1-controller; C:\Windows\system32\DRIVERS\dc1-controller.sys [50688 2015-07-10] (Microsoft Corp.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264552 2016-02-09] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [199680 2016-02-09] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [14976 2016-02-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186784 2016-02-09] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [170792 2016-02-09] (ESET)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-03-17] ()
R3 int0800; C:\Windows\System32\drivers\flashud.sys [51712 2009-09-09] (Intel Corporation)
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [24824 2014-10-23] (ASUSTeK Computer Inc.)
S3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-02-03] ()
R3 Ke2200; C:\Windows\System32\drivers\e22w7x64.sys [125488 2015-03-18] (Qualcomm Atheros, Inc.)
S3 ksapi64; C:\WINDOWS\system32\drivers\ksapi64.sys [56680 2016-01-16] (Kingsoft Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [184608 2015-07-07] (Intel Corporation)
R2 MMCSS; C:\Windows\system32\drivers\mmcss.sys [48128 2015-07-10] (Microsoft Corporation) [File not signed]
S3 Modem; C:\Windows\System32\drivers\modem.sys [41984 2015-07-10] (Microsoft Corporation) [File not signed]
R3 monitor; C:\Windows\System32\drivers\monitor.sys [38400 2015-07-10] (Microsoft Corporation) [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-03-08] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R3 Serenum; C:\Windows\system32\DRIVERS\nuvserenum.sys [23552 2014-01-12] (Windows (R) Win 7 DDK provider)
R3 Serial; C:\Windows\system32\DRIVERS\nuvserial.sys [86016 2014-01-12] (Nuvoton Technology Corp.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-20 14:06 - 2016-03-20 14:07 - 00013888 _____ C:\Users\Kuba\Desktop\FRST.txt
2016-03-20 14:06 - 2016-02-21 21:42 - 00032768 _____ () C:\Users\Kuba\Desktop\memtest.exe
2016-03-20 14:05 - 2016-03-20 14:07 - 00000000 ____D C:\FRST
2016-03-20 14:05 - 2016-03-20 14:05 - 02374144 _____ (Farbar) C:\Users\Kuba\Desktop\FRST64.exe
2016-03-20 10:57 - 2016-03-20 10:57 - 00015612 _____ C:\Users\Kuba\Downloads\MemTest (1).zip
2016-03-20 10:51 - 2016-03-20 10:51 - 04166472 _____ (Crystal Dew World ) C:\Users\Kuba\Downloads\CrystalDiskInfo6_7_0-en.exe
2016-03-20 10:49 - 2016-03-20 10:49 - 00015612 _____ C:\Users\Kuba\Downloads\MemTest.zip
2016-03-20 09:37 - 2016-03-20 09:37 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2016-03-20 09:37 - 2016-03-20 09:37 - 00000000 ____D C:\WINDOWS\LastGood
2016-03-20 07:37 - 2016-03-20 07:37 - 00016148 _____ C:\WINDOWS\system32\KUBA-PC_Kuba_HistoryPrediction.bin
2016-03-19 15:57 - 2016-03-19 15:57 - 00000000 ____D C:\Users\Kuba\AppData\Local\CrashDumps
2016-03-19 13:19 - 2016-03-19 13:19 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-19 13:19 - 2016-03-19 13:19 - 00000000 ____D C:\Riot Games
2016-03-19 13:18 - 2016-03-19 13:18 - 30993712 _____ (Riot Games) C:\Users\Kuba\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe
2016-03-19 12:59 - 2016-03-19 12:59 - 00000000 ____D C:\Users\Kuba\AppData\Local\Adobe
2016-03-19 12:08 - 2016-03-19 12:08 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-19 12:08 - 2016-03-19 12:08 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-19 12:08 - 2016-03-08 07:05 - 00110016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-03-19 12:07 - 2016-03-19 12:07 - 00000000 ____D C:\NVIDIA
2016-03-19 12:04 - 2016-03-19 12:06 - 340696488 _____ (NVIDIA Corporation) C:\Users\Kuba\Downloads\364.51-desktop-win10-64bit-international-whql.exe
2016-03-18 19:27 - 2016-03-18 19:27 - 00000000 ____D C:\Users\Kuba\AppData\LocalLow\Freejam
2016-03-18 19:25 - 2016-03-18 19:25 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\.mono
2016-03-18 19:24 - 2016-03-20 09:09 - 00295160 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2016-03-18 19:24 - 2016-03-18 19:22 - 00245544 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
2016-03-18 17:48 - 2016-03-18 17:55 - 00000000 ____D C:\ProgramData\RogueKiller
2016-03-18 17:48 - 2016-03-18 17:48 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-03-18 17:41 - 2016-03-18 17:41 - 00008640 _____ C:\Users\Kuba\Documents\PC dropy.txt
2016-03-18 14:13 - 2016-03-18 14:13 - 00000000 ____D C:\Users\Kuba\AppData\Local\CEF
2016-03-17 19:58 - 2016-03-17 19:58 - 00000000 _____ C:\autoexec.bat
2016-03-17 19:57 - 2016-03-17 19:57 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-03-17 17:34 - 2016-03-17 17:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-17 17:30 - 2016-03-18 17:32 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
2016-03-17 17:09 - 2016-03-17 17:09 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2016-03-17 17:08 - 2016-03-17 17:08 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-03-17 17:08 - 2016-03-17 17:08 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-03-17 16:58 - 2016-03-17 16:58 - 00007606 _____ C:\Users\Kuba\AppData\Local\Resmon.ResmonCfg
2016-03-16 19:27 - 2016-03-17 17:40 - 00000901 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-03-16 19:27 - 2016-03-16 19:27 - 00002852 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-03-16 19:27 - 2016-03-16 19:27 - 00000000 ____D C:\Program Files\CCleaner
2016-03-16 18:50 - 2016-03-16 18:50 - 00000000 ____D C:\Program Files (x86)\ESET
2016-03-16 17:30 - 2016-03-16 17:30 - 00000000 ___HD C:\ProgramData\CanonIJEGV
2016-03-16 16:36 - 2016-03-16 16:36 - 00000000 ____D C:\Users\Kuba\AppData\Local\VS Revo Group
2016-03-16 16:36 - 2016-03-16 16:36 - 00000000 ____D C:\ProgramData\VS Revo Group
2016-03-16 15:54 - 2016-03-16 17:55 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2016-03-14 20:34 - 2016-03-14 20:34 - 00466456 _____ (Creative Labs) C:\WINDOWS\system32\wrap_oal.dll
2016-03-14 20:34 - 2016-03-14 20:34 - 00444952 _____ (Creative Labs) C:\WINDOWS\SysWOW64\wrap_oal.dll
2016-03-14 20:34 - 2016-03-14 20:34 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\system32\OpenAL32.dll
2016-03-14 20:34 - 2016-03-14 20:34 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\WINDOWS\SysWOW64\OpenAL32.dll
2016-03-14 20:34 - 2016-03-14 20:34 - 00000000 ____D C:\ProgramData\Codemasters
2016-03-14 20:34 - 2016-03-14 20:34 - 00000000 ____D C:\Program Files (x86)\OpenAL
2016-03-14 19:32 - 2016-03-14 19:32 - 00000222 _____ C:\Users\Kuba\Desktop\DiRT 3 Complete Edition.url
2016-03-13 15:25 - 2016-03-14 13:30 - 00001024 _____ C:\Users\Kuba\Desktop\µTorrent.lnk
2016-03-12 20:29 - 2016-03-12 20:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2016-03-12 20:29 - 2016-03-12 20:29 - 00000000 ____D C:\ProgramData\ESET
2016-03-12 20:29 - 2016-03-12 20:29 - 00000000 ____D C:\Program Files\ESET
2016-03-12 20:09 - 2016-03-12 20:26 - 00000000 ____D C:\ProgramData\Avira
2016-03-12 20:09 - 2016-03-12 20:26 - 00000000 ____D C:\Program Files (x86)\Avira
2016-03-12 19:05 - 2016-03-12 19:05 - 00000000 _____ C:\WINDOWS\My Product Name
2016-03-12 13:10 - 2016-03-08 11:27 - 42968120 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 37609528 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 22971960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 21322480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 20863920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 18906048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 17732960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 17368424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 17325400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 10547128 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 08657936 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 02613696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 02257344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00955328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00885184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00786872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00784640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00750016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00692160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00678704 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00632152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00630592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00601752 _____ C:\WINDOWS\system32\nvmcumd.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00545632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00448824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00385080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00379296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00346560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00317656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00175552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-03-12 13:10 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-12 13:10 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-09 18:11 - 2016-02-23 15:53 - 01314496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 18:11 - 2016-02-23 15:52 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-09 18:11 - 2016-02-23 15:51 - 00633184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-03-09 18:11 - 2016-02-23 15:51 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 18:11 - 2016-02-23 15:50 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 18:11 - 2016-02-23 15:48 - 08022368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 18:11 - 2016-02-23 15:48 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-09 18:11 - 2016-02-23 15:48 - 01123952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-09 18:11 - 2016-02-23 15:41 - 01150816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 18:11 - 2016-02-23 15:41 - 00299600 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMASF.DLL
2016-03-09 18:11 - 2016-02-23 15:41 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-03-09 18:11 - 2016-02-23 15:40 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-03-09 18:11 - 2016-02-23 15:38 - 00272752 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 18:11 - 2016-02-23 15:36 - 00080128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-03-09 18:11 - 2016-02-23 15:11 - 00781984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 18:11 - 2016-02-23 15:11 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-09 18:11 - 2016-02-23 15:11 - 00103776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-03-09 18:11 - 2016-02-23 15:08 - 03622272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-09 18:11 - 2016-02-23 15:07 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-09 18:11 - 2016-02-23 14:39 - 00607416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 18:11 - 2016-02-23 14:30 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 18:11 - 2016-02-23 14:25 - 01085632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-03-09 18:11 - 2016-02-23 14:23 - 00952968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 18:11 - 2016-02-23 14:21 - 00529456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 18:11 - 2016-02-23 14:21 - 00141152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 18:11 - 2016-02-23 14:11 - 00249976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMASF.DLL
2016-03-09 18:11 - 2016-02-23 14:11 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-03-09 18:11 - 2016-02-23 14:11 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-03-09 18:11 - 2016-02-23 14:09 - 00229352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 18:11 - 2016-02-23 14:06 - 00069232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-03-09 18:11 - 2016-02-23 13:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-03-09 18:11 - 2016-02-23 13:50 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-09 18:11 - 2016-02-23 13:50 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-03-09 18:11 - 2016-02-23 13:42 - 00658536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 18:11 - 2016-02-23 13:42 - 00467296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-09 18:11 - 2016-02-23 13:42 - 00078176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-03-09 18:11 - 2016-02-23 13:39 - 02879024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-09 18:11 - 2016-02-23 13:38 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-09 18:11 - 2016-02-23 13:35 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 18:11 - 2016-02-23 13:20 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-03-09 18:11 - 2016-02-23 13:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-03-09 18:11 - 2016-02-23 13:16 - 02237952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 18:11 - 2016-02-23 13:15 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 18:11 - 2016-02-23 13:15 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-03-09 18:11 - 2016-02-23 12:59 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2016-03-09 18:11 - 2016-02-23 12:59 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-09 18:11 - 2016-02-23 12:57 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-09 18:11 - 2016-02-23 12:55 - 24592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 18:11 - 2016-02-23 12:45 - 12504576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-09 18:11 - 2016-02-23 12:45 - 06788608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 18:11 - 2016-02-23 12:42 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 18:11 - 2016-02-23 12:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 18:11 - 2016-02-23 12:38 - 02663424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-09 18:11 - 2016-02-23 12:37 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2016-03-09 18:11 - 2016-02-23 12:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-09 18:11 - 2016-02-23 12:25 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 18:11 - 2016-02-23 12:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 18:11 - 2016-02-23 12:17 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-03-09 18:11 - 2016-02-23 12:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-03-09 18:11 - 2016-02-23 12:14 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-03-09 18:11 - 2016-02-23 12:08 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 18:11 - 2016-02-23 12:04 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 18:11 - 2016-02-23 12:03 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 18:11 - 2016-02-23 12:03 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 18:11 - 2016-02-23 12:02 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 18:11 - 2016-02-23 11:55 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 18:11 - 2016-02-23 11:55 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 18:11 - 2016-02-23 11:51 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 18:11 - 2016-02-23 11:51 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 18:11 - 2016-02-23 11:48 - 21859840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 18:11 - 2016-02-23 11:48 - 05157376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 18:11 - 2016-02-23 11:46 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 18:11 - 2016-02-23 11:45 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 18:11 - 2016-02-23 11:45 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-03-09 18:11 - 2016-02-23 11:45 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 18:11 - 2016-02-23 11:45 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 18:11 - 2016-02-23 11:44 - 01821696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-09 18:11 - 2016-02-23 11:38 - 07524864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 18:11 - 2016-02-23 11:29 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-03-09 18:11 - 2016-02-23 11:17 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 18:11 - 2016-02-23 11:17 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-09 18:11 - 2016-02-23 11:11 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 18:11 - 2016-02-23 11:03 - 01495040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 18:11 - 2016-02-23 11:00 - 11263488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-09 18:11 - 2016-02-23 11:00 - 05457408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 18:11 - 2016-02-23 10:58 - 18800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-02 14:45 - 2016-02-24 00:57 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436200.dll
2016-03-02 14:45 - 2016-02-24 00:57 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436200.dll
2016-02-29 20:26 - 2016-03-17 17:40 - 00001220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-02-29 20:26 - 2016-03-17 17:40 - 00001214 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-02-29 20:26 - 2016-03-01 14:13 - 00000000 ____D C:\Users\Kuba\AppData\Local\Mozilla
2016-02-29 20:26 - 2016-02-29 20:26 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Mozilla
2016-02-29 20:26 - 2016-02-29 20:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-29 20:26 - 2016-02-29 20:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-26 19:37 - 2016-02-26 19:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Xbox 360 Accessories
2016-02-26 19:37 - 2016-02-26 19:37 - 00000000 ____D C:\Program Files\Microsoft Xbox 360 Accessories
2016-02-20 23:01 - 2016-02-28 18:13 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\vlc
2016-02-20 23:00 - 2016-03-17 17:40 - 00000843 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-02-20 23:00 - 2016-02-20 23:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-02-20 20:37 - 2016-03-17 17:40 - 00000146 _____ C:\Users\Kuba\Desktop\Zvuk.lnk
2016-02-19 14:16 - 2016-03-08 11:27 - 17320280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-02-19 14:16 - 2016-02-09 09:25 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-19 14:16 - 2016-02-09 09:25 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436191.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-20 14:07 - 2016-01-12 19:52 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-20 14:04 - 2016-01-01 11:08 - 00004194 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{615B282C-818C-4F86-955C-0DA3F7970455}
2016-03-20 07:37 - 2016-01-12 19:52 - 00000972 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-19 23:01 - 2015-12-25 18:58 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Skype
2016-03-19 22:40 - 2015-12-26 19:28 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\.minecraft
2016-03-19 14:26 - 2015-07-30 23:42 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-19 13:19 - 2015-12-26 09:00 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Riot Games
2016-03-19 12:32 - 2015-12-25 18:37 - 01762290 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-19 12:32 - 2015-09-10 06:05 - 00745406 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-19 12:32 - 2015-09-10 06:05 - 00149344 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-19 12:32 - 2015-07-30 23:40 - 00000000 ____D C:\WINDOWS\INF
2016-03-19 12:26 - 2015-12-25 18:46 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-19 12:26 - 2015-07-30 22:52 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-19 12:10 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-19 12:08 - 2015-12-26 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-19 12:08 - 2015-12-25 18:46 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-19 11:40 - 2015-12-28 15:59 - 00000080 _____ C:\Users\Kuba\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2016-03-18 17:41 - 2015-12-26 20:51 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2016-03-18 14:09 - 2015-07-30 23:42 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-17 19:57 - 2015-12-25 18:32 - 00000000 ____D C:\Users\Kuba
2016-03-17 17:40 - 2016-02-12 14:32 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-17 17:40 - 2016-02-06 14:16 - 00000764 _____ C:\Users\Public\Desktop\WarThunder.lnk
2016-03-17 17:40 - 2016-02-02 22:49 - 00000741 _____ C:\Users\Kuba\Desktop\World of tanks.lnk
2016-03-17 17:40 - 2016-01-31 15:24 - 00000746 _____ C:\Users\Public\Desktop\Steam.lnk
2016-03-17 17:40 - 2016-01-23 09:32 - 00001459 _____ C:\Users\Kuba\Desktop\WinRAR.lnk
2016-03-17 17:40 - 2016-01-22 21:32 - 00072192 ___SH C:\Users\Kuba\Desktop\Thumbs.db
2016-03-17 17:40 - 2016-01-12 19:55 - 00002260 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-17 17:40 - 2016-01-12 19:55 - 00002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-17 17:40 - 2016-01-11 16:17 - 00002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-03-17 17:40 - 2016-01-11 16:17 - 00002395 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-03-17 17:40 - 2016-01-11 16:17 - 00002389 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-03-17 17:40 - 2016-01-11 16:17 - 00002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-03-17 17:40 - 2016-01-09 14:51 - 00000811 _____ C:\Users\Kuba\Desktop\The Sims 4.lnk
2016-03-17 17:40 - 2015-12-29 00:06 - 00000998 _____ C:\Users\Public\Desktop\Zoner Photo Studio 13 x64.lnk
2016-03-17 17:40 - 2015-12-26 20:51 - 00001134 _____ C:\Users\Public\Desktop\ASUS GPU TweakII.lnk
2016-03-17 17:40 - 2015-12-26 19:27 - 00000792 _____ C:\Users\Public\Desktop\Minecraft.lnk
2016-03-17 17:40 - 2015-12-25 22:02 - 00001083 _____ C:\Users\Public\Desktop\Grand Theft Auto V.lnk
2016-03-17 17:40 - 2015-12-25 18:58 - 00002652 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-17 17:40 - 2015-12-25 18:42 - 00002425 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-17 17:40 - 2015-12-25 18:42 - 00001051 _____ C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volitelné funkce.lnk
2016-03-17 17:40 - 2015-12-25 18:32 - 00001564 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-03-17 17:40 - 2015-12-24 23:08 - 00001941 _____ C:\Users\Kuba\Desktop\Tento počítač.lnk
2016-03-17 17:38 - 2015-12-28 15:17 - 00000000 ____D C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2016-03-17 17:34 - 2015-12-26 09:31 - 00000000 ____D C:\Users\Kuba\AppData\Local\Comms
2016-03-17 17:17 - 2015-07-30 22:49 - 00442128 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-17 17:16 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini
2016-03-16 17:31 - 2016-01-11 22:19 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-03-16 16:07 - 2016-01-11 22:17 - 00000000 ____D C:\Program Files (x86)\Canon
2016-03-15 15:02 - 2015-12-25 22:05 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-03-15 15:02 - 2015-12-25 22:04 - 00000000 ____D C:\Program Files\Rockstar Games
2016-03-14 20:34 - 2016-02-06 14:16 - 00000000 ____D C:\Users\Kuba\Documents\My Games
2016-03-14 17:40 - 2016-01-06 15:38 - 00000000 ____D C:\Users\Kuba\Desktop\písničky
2016-03-13 09:23 - 2015-12-25 18:40 - 00000000 ____D C:\Users\Kuba\AppData\Local\Packages
2016-03-12 20:29 - 2015-07-30 23:42 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-03-11 20:16 - 2015-07-30 23:25 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-11 18:16 - 2015-09-10 06:43 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-11 18:16 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-11 18:16 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-11 18:16 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-11 18:16 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 04:19 - 2015-12-25 18:46 - 12653504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-09 20:44 - 2015-12-25 21:55 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 20:37 - 2015-12-25 21:55 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-08 11:27 - 2015-12-29 10:07 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-03-08 11:27 - 2015-12-26 20:51 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-03-08 11:27 - 2015-12-26 20:51 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-03-08 11:27 - 2015-12-26 20:51 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-03-08 11:27 - 2015-12-26 20:51 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-03-08 11:27 - 2015-12-26 20:48 - 14226864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-08 11:27 - 2015-12-26 20:48 - 03259176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-08 11:27 - 2015-12-25 18:46 - 20061152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-08 11:27 - 2015-12-25 18:46 - 03681672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-08 11:27 - 2015-12-25 18:46 - 00037702 _____ C:\WINDOWS\system32\nvinfo.pb
2016-03-08 08:10 - 2015-07-30 23:43 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 08:10 - 2015-07-30 23:43 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-08 07:42 - 2015-12-27 20:09 - 00530880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-08 07:42 - 2015-12-27 20:09 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-08 07:42 - 2015-12-25 18:46 - 06371384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-08 07:42 - 2015-12-25 18:46 - 02992576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-08 07:42 - 2015-12-25 18:46 - 02563128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-08 07:42 - 2015-12-25 18:46 - 01264064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-08 07:42 - 2015-12-25 18:46 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-08 07:42 - 2015-12-25 18:46 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-07 13:24 - 2015-12-25 18:58 - 00000000 ____D C:\ProgramData\Skype
2016-03-07 05:22 - 2015-12-25 18:46 - 06203411 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-02-28 18:30 - 2015-07-30 23:42 - 00000000 ____D C:\WINDOWS\system32\spool

==================== Files in the root of some directories =======

2016-03-17 16:58 - 2016-03-17 16:58 - 0007606 _____ () C:\Users\Kuba\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Kuba\AppData\Local\Temp\7za.exe
C:\Users\Kuba\AppData\Local\Temp\DaS_21.exe
C:\Users\Kuba\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Kuba\AppData\Local\Temp\hijackthis.exe
C:\Users\Kuba\AppData\Local\Temp\NirCmd.exe
C:\Users\Kuba\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Kuba\AppData\Local\Temp\nvStInst.exe
C:\Users\Kuba\AppData\Local\Temp\PEVZ.EXE
C:\Users\Kuba\AppData\Local\Temp\remove.exe
C:\Users\Kuba\AppData\Local\Temp\sed.exe
C:\Users\Kuba\AppData\Local\Temp\shortcut.exe
C:\Users\Kuba\AppData\Local\Temp\swreg.exe
C:\Users\Kuba\AppData\Local\Temp\swxcacls.exe
C:\Users\Kuba\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Kuba\AppData\Local\Temp\wget.exe
C:\Users\Kuba\AppData\Local\Temp\zoek-delete.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-03-19 08:32

==================== End of FRST.txt ============================

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 14:07

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Kuba (2016-03-20 14:07:18)
Running from C:\Users\Kuba\Desktop
Windows 10 Enterprise (X64) (2015-12-25 17:40:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3313306934-2274467357-1670545691-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3313306934-2274467357-1670545691-503 - Limited - Disabled)
Guest (S-1-5-21-3313306934-2274467357-1670545691-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3313306934-2274467357-1670545691-1002 - Limited - Enabled)
Kuba (S-1-5-21-3313306934-2274467357-1670545691-1001 - Administrator - Enabled) => C:\Users\Kuba

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET NOD32 Antivirus 9.0.374.1 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 9.0.374.1 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3DMark (HKLM-x32\...\{e1e3b41b-1078-4885-a74f-393ca384b1aa}) (Version: 1.2.250.0 - Futuremark)
3DMark (Version: 1.2.250.0 - Futuremark) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated)
Aktualizace NVIDIA 2.10.2.40 (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
ASUS GPU TweakII (HKLM-x32\...\InstallShield_{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.0.6.9 - ASUSTek COMPUTER INC.)
ASUS GPU TweakII (x32 Version: 1.0.6.9 - ASUSTek COMPUTER INC.) Hidden
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - )
Canon MP Navigator EX 3.0 (HKLM-x32\...\MP Navigator EX 3.0) (Version: - )
Canon MP550 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version: - )
Canon Utilities Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
Canon Utilities My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.15 - Piriform)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
DiRT 3 Complete Edition (HKLM\...\Steam App 321040) (Version: - Codemasters Racing Studio)
ESET NOD32 Antivirus (HKLM\...\{AECC8921-23AC-4056-9953-205D83BFF65E}) (Version: 9.0.374.1 - ESET, spol. s r.o.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Futuremark SystemInfo (HKLM-x32\...\{991C8DEA-3C01-45B8-A62B-1BB69BDC277D}) (Version: 4.23.255 - Futuremark)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4251 - Intel Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{6f962b9e-bb55-4be9-aff3-c4749c546fb9}) (Version: 4.6.81 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Motion Graphics Toolkit for Studio (HKLM-x32\...\InstallShield_{178D71F4-DFB1-40EC-9D95-326FD8A3E7A0}) (Version: 1.00.0000 - Red Giant)
Motion Graphics Toolkit for Studio (x32 Version: 1.00.0000 - Red Giant) Hidden
Mozilla Firefox 44.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 cs)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 44.0.2 - Mozilla)
NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 364.51 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 364.51 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 364.51 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 364.51 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Ovládací panel NVIDIA 364.51 (Version: 364.51 - NVIDIA Corporation) Hidden
Ovladače videa společnosti Pinnacle (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7572 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.7.8 - Rockstar Games)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
SiSoftware Sandra Engineer XII.SP1 (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2096}_is1) (Version: 13.12.2008.1 - SiSoftware)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
The Sims 4 (HKLM-x32\...\The Sims 4_R.G. Mechanics_is1) (Version: - R.G. Mechanics, ProZorg_tm)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
War Thunder Launcher 1.0.1.613 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )
World of Tanks (HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net)
Zoner Photo Studio 13 (HKLM\...\ZonerPhotoStudio13_CZ_is1) (Version: 13.0.1.1 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3313306934-2274467357-1670545691-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Kuba\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02CE4951-D735-435F-927C-6F8DAF6DA3F9} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {079C1515-E668-4D31-83C9-FB46DD4827B6} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {20A3E08C-480C-491C-8B52-0C2A9A3BD822} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {20FF90B8-C916-4736-9FEF-C87A5247DF9A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {343160C6-EA61-4CB6-9CC2-85DC880133D4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-12] (Google Inc.)
Task: {44F09C48-305D-45C4-9780-369825582335} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {51483D08-1C06-4072-AA07-8D6EFBF67417} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {51B6DFF0-3AC0-484D-919F-16B1E5026C67} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {554ADB79-3DEA-4465-AC3D-1C219D1C1346} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {5F4D3C08-CC46-4713-88E6-263D2CF5432C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {646DF488-5376-45DD-830D-F454FA4DD455} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {6EE3AEEF-F8A7-4CB3-AE2B-CD0E9F1B166A} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {70E3EBE3-4E32-4703-8488-F6ACFC45811D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {70E94869-CF3E-4CBC-8A38-9A2F25F962A3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {8328CA0A-9387-47F2-AB3E-E802DE62C267} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {8FA42678-0A11-43EF-B3F5-1D70DFC7EF82} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {A23E0012-CCB9-4779-BEC3-23EC751D006C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {A5D38D2B-2696-4264-99B9-948B8596A751} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {AB5FED39-C910-4F91-B2CF-C5CA79C8CA79} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-02-12] (Piriform Ltd)
Task: {B29208E0-C10C-413C-BE46-4696E82CC5C9} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {B38CE365-24D7-489B-8D7E-B862E69507A3} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {D6FBA69F-6FC9-4B16-9D93-9489728A80AD} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {DD0B3322-AC1B-466A-AEFC-C8DE611FAC4A} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {DEDF7C23-C8ED-4D7E-AA8B-255741F4CA0F} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {E0B6A0F4-BBD6-4BE6-A0AD-8DD7FB42C0B2} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {ED2938E4-8ADB-4BC0-B67C-2EC894C6054F} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {F1299134-4B63-46B1-B74C-656E735D6B3C} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {FE141C8E-ED7D-436D-9199-DC59630232C1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-12] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-09-10 06:08 - 2015-09-10 06:08 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-09-10 06:08 - 2015-09-10 06:08 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-05-29 10:28 - 2015-05-29 10:28 - 00048640 _____ () C:\Windows\SysWOW64\ASGT.exe
2016-02-19 14:12 - 2016-03-08 11:27 - 01416064 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2015-12-29 10:07 - 2016-03-08 11:27 - 00299392 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-02-19 14:12 - 2016-03-08 11:27 - 03613056 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2016-01-11 22:19 - 2009-02-10 16:01 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2015-12-25 18:46 - 2016-03-08 07:42 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-12-25 21:54 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-25 21:54 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-12-25 19:09 - 2006-12-11 02:14 - 00043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2015-12-25 21:53 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 04:13 - 2015-07-10 04:13 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-12-25 21:53 - 2015-09-17 07:04 - 00642048 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2015-12-25 21:54 - 2015-11-25 05:20 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-12-25 21:54 - 2015-11-25 05:17 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-25 21:54 - 2015-11-25 05:17 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-12-25 21:54 - 2015-09-17 06:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 04:13 - 2015-09-10 06:08 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-12-26 20:51 - 2016-03-08 11:27 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2016-03-18 20:48 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kuba\Pictures\Wallpapers-room_com___Dark_Red_by_derekprospero_1920x1200.jpg
DNS Servers: 10.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "CanonMyPrinter"
HKLM\...\StartupApproved\Run: => "CanonSolutionMenu"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "BCSSync"
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_8DE71DA2DA81B795B6ABDB72281EA8CB"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0A64461A-BB34-43A7-A5EF-4B5DEBE4EEE6}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Engineer XII.SP1\RpcSandraSrv.exe
FirewallRules: [{10C1F951-8B2F-43BC-AF33-B34AABDE9C1B}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Engineer XII.SP1\Win32\RpcDataSrv.exe
FirewallRules: [{7550031B-971D-4B0D-887E-4C2913B4D310}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A640CC1F-EBAE-4C46-8DB9-71E9103701DF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5ED51E7D-C5FC-4A68-AC6C-35329E226D72}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B535DA02-BA91-4704-9598-792E970B15ED}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B8B64346-4828-4B58-BEA5-83B1972C39A9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E9ED8683-1410-4F88-AD89-10426B792883}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{7D450FFC-E2E1-43B4-85CF-CC4A6E213727}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [TCP Query User{0D0CD3D9-C999-489A-BE68-B34D169D7849}D:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) D:\program files\rockstar games\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{5FBE2A47-287A-4CE0-A19E-031E6E7BE086}D:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) D:\program files\rockstar games\grand theft auto v\gta5.exe
FirewallRules: [{F4FA410B-A395-418B-9313-6C2C72B70D7B}] => (Allow) D:\WarThunder\bpreport.exe
FirewallRules: [{634890A4-6A58-4A40-9F38-DCF23BE39CB4}] => (Allow) D:\WarThunder\bpreport.exe
FirewallRules: [{416F708B-E5AC-4BCD-A037-6DE95773E188}] => (Allow) LPort=80
FirewallRules: [{5C691684-1C39-4C4C-A340-D296018F3D9D}] => (Allow) LPort=443
FirewallRules: [{441B45D2-6415-41AA-A16A-C390BDEF65D9}] => (Allow) LPort=20010
FirewallRules: [{97F2E3ED-35FF-4648-BA9F-CA493671E294}] => (Allow) LPort=3478
FirewallRules: [{4EAC94A2-420E-4082-AEF3-F3DD96D7203D}] => (Allow) LPort=7850
FirewallRules: [{FC7F44CE-B70F-47B7-9ED1-AF85B31143A6}] => (Allow) LPort=7852
FirewallRules: [{C5B90FFB-C4FE-4173-8B74-C7AD569FE99F}] => (Allow) LPort=7853
FirewallRules: [{C9E592C1-8D3B-4C5E-92F6-ACC2DE813A42}] => (Allow) LPort=27022
FirewallRules: [{0D4820B9-3245-40A0-AF5C-64471EB4A3F1}] => (Allow) LPort=6881
FirewallRules: [{880ED2A1-F908-4755-886B-0FB8201165C4}] => (Allow) LPort=33333
FirewallRules: [{0E3E5A66-1700-48C4-BACA-D8B9ECB09089}] => (Allow) LPort=20443
FirewallRules: [{C594BDAE-FE03-440B-BB59-B4FB26BF0906}] => (Allow) LPort=8090
FirewallRules: [TCP Query User{28CE65FE-6B43-463B-BA32-B4E5736E20A4}D:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Block) D:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{BFA0819B-527C-413D-8A08-99668FC994F0}D:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Block) D:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{A025FD74-519E-4A58-AA4E-43B1B34892FD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{04E1CBD1-F51B-4BE0-9D82-BFBC9AAD88DE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{45B0AB50-A1BD-4737-9279-27E402139EF7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{9F2C1D64-BA8D-4CAD-B118-693C05B0E794}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{967F2286-FDCD-4045-B2E9-B293AFF6140C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{2197C1E9-E5FE-4133-83BE-797B03A7F862}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9007D232-9F02-456D-B49D-20B17B34836D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{25218826-5ACE-455F-A5A4-9988CD69A01B}D:\users\kuba\appdata\roaming\utorrent\utorrent.exe] => (Allow) D:\users\kuba\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{D0674A45-A98D-45C8-B909-7E3E873F7FE2}D:\users\kuba\appdata\roaming\utorrent\utorrent.exe] => (Allow) D:\users\kuba\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{ED75E03A-EF8D-430F-89DC-A44B159A2423}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [UDP Query User{2BB1EA09-1766-40DB-961B-07F8A350C204}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [TCP Query User{B1E37002-FFBF-4BE2-9DCF-4892A5862CDB}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [UDP Query User{C68C96AB-1EE1-4B27-BC4D-8352F0EF9BC6}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [TCP Query User{013C1ECA-44D1-4B7C-B962-EAC72AEF01FB}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe
FirewallRules: [UDP Query User{37CEA344-448E-4B84-90E1-1696E26588B8}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe
FirewallRules: [{BC13DB80-5E0F-47FF-9154-E64BCC298624}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{EA15C672-B364-430B-BDA1-B51D5DF0BD1C}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
FirewallRules: [{4F5C27B9-25D0-4F5A-86D5-639AA06AF9B8}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
FirewallRules: [{474D83ED-FD39-4E67-B437-D6805F123385}] => (Allow) C:\Program Files (x86)\SpringFiles\downloader.exe
FirewallRules: [{4E35D636-26C0-442C-95FF-A0AC946C102B}] => (Allow) C:\Program Files (x86)\SpringFiles\downloader.exe
FirewallRules: [TCP Query User{4ED5F602-86AB-4921-BD03-97C147E18277}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{4E2EE54C-11F9-40EE-BBE9-62AAFAD98351}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [{F6919611-852B-404C-838E-3F2F10FE57DD}] => (Allow) D:\Program Files (x86)\Pinnacle\Studio 16\programs\RM.exe
FirewallRules: [{4CC02990-FDDF-4EA7-A345-BCEC40B42EAB}] => (Allow) D:\Program Files (x86)\Pinnacle\Studio 16\programs\RM.exe
FirewallRules: [{A9E496D7-49C5-4033-81D7-D1A67D891E19}] => (Allow) D:\Program Files (x86)\Pinnacle\Studio 16\programs\NGStudio.exe
FirewallRules: [{B3EB5EA0-D68E-41A2-8520-CE4A35B4D4C5}] => (Allow) D:\Program Files (x86)\Pinnacle\Studio 16\programs\NGStudio.exe
FirewallRules: [{DB199106-4EC3-4DE3-B47C-29641AC0D9B7}] => (Allow) D:\Program Files (x86)\Pinnacle\Studio 16\programs\UMI.exe
FirewallRules: [{5B4168E8-88E8-4536-A8A0-050709819940}] => (Allow) D:\Program Files (x86)\Pinnacle\Studio 16\programs\UMI.exe
FirewallRules: [TCP Query User{936E4B84-75FF-42D4-B33B-1245DCB13551}D:\games\call of duty black ops 3\blackops3.exe] => (Allow) D:\games\call of duty black ops 3\blackops3.exe
FirewallRules: [UDP Query User{467CC4F1-802E-40D8-99E2-CB95D5F9D3E2}D:\games\call of duty black ops 3\blackops3.exe] => (Allow) D:\games\call of duty black ops 3\blackops3.exe
FirewallRules: [TCP Query User{B42D3AB2-73CE-497D-B313-2D120DBE93A9}D:\games\call of duty black ops 3\call of duty black ops 3\blackops3.exe] => (Allow) D:\games\call of duty black ops 3\call of duty black ops 3\blackops3.exe
FirewallRules: [UDP Query User{5E67BFCC-4798-44C7-9EFE-D36AE72DF4B8}D:\games\call of duty black ops 3\call of duty black ops 3\blackops3.exe] => (Allow) D:\games\call of duty black ops 3\call of duty black ops 3\blackops3.exe
FirewallRules: [{0A333495-1DDF-41E2-992D-E960C16AB85C}] => (Allow) LPort=8090
FirewallRules: [{9F0E5122-0C99-47D1-AFA4-B51E290E970A}] => (Allow) C:\Users\Kuba\Desktop\Steam.exe
FirewallRules: [{40B21578-31E0-4A86-9980-939D999054ED}] => (Allow) C:\Users\Kuba\Desktop\Steam.exe
FirewallRules: [{B7490620-D981-4CFC-8101-A6160D772432}] => (Allow) C:\Users\Kuba\Desktop\bin\steamwebhelper.exe
FirewallRules: [{3AFCC182-8745-428D-9D63-71F0FEA52801}] => (Allow) C:\Users\Kuba\Desktop\bin\steamwebhelper.exe
FirewallRules: [{FF7895FF-50B1-43D7-B1B1-C363A9916F24}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{BAE5A3D9-48A1-4CE4-959C-BDBE3F411F3E}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A89111CB-7DD6-417A-920A-330B3B985915}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B0D6E63D-7EB5-4832-B87A-1B924A4E97FD}] => (Allow) D:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{800DC183-B97B-4FC8-B647-E4E5CBA3A641}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{79AC15D9-3AE3-48A7-8B22-0EDAEEDDA4AF}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [TCP Query User{3F94C9DC-7511-4E09-98A9-363A828ADAE7}D:\games\world_of_tanks\wotlauncher.exe] => (Allow) D:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [UDP Query User{C822BC27-65B5-49B4-A115-4EA8D732F431}D:\games\world_of_tanks\wotlauncher.exe] => (Allow) D:\games\world_of_tanks\wotlauncher.exe
FirewallRules: [TCP Query User{293C846D-7611-4A58-94D3-C1B989627A9C}D:\games\world_of_tanks\worldoftanks.exe] => (Allow) D:\games\world_of_tanks\worldoftanks.exe
FirewallRules: [UDP Query User{43046F5D-F7CE-4BAD-AAC1-0CB35369845F}D:\games\world_of_tanks\worldoftanks.exe] => (Allow) D:\games\world_of_tanks\worldoftanks.exe
FirewallRules: [{AB3F124D-54D4-4FE2-AA8B-AAEDC574E7BE}] => (Allow) D:\Games\WarThunder\launcher.exe
FirewallRules: [{971903C5-E5BC-4DD2-888D-631A33DFE769}] => (Allow) D:\Games\WarThunder\launcher.exe
FirewallRules: [{D56940BD-B430-49A3-A56A-3FA1CACBAEDB}] => (Allow) D:\Games\WarThunder\bpreport.exe
FirewallRules: [{E437ED23-BB34-45CD-BC6A-74C5D1EE1C36}] => (Allow) D:\Games\WarThunder\bpreport.exe
FirewallRules: [TCP Query User{31F50766-31C6-4968-BDF3-4E677FA7D3D5}D:\games\warthunder\win64\aces.exe] => (Allow) D:\games\warthunder\win64\aces.exe
FirewallRules: [UDP Query User{35387F9C-62CC-4BA0-BDEB-51D0916A5FF5}D:\games\warthunder\win64\aces.exe] => (Allow) D:\games\warthunder\win64\aces.exe
FirewallRules: [{D321D01F-7AC1-4A36-B82D-66960653A3B9}] => (Allow) C:\Program Files (x86)\Deskshare\WebCam Monitor 6\WebCam Monitor.exe
FirewallRules: [{E5BA969D-8600-4914-B101-C34FE748628E}] => (Allow) C:\Program Files (x86)\Deskshare\WebCam Monitor 6\WebCam Monitor.exe
FirewallRules: [TCP Query User{96FF5F6A-C4EC-4235-A35C-C4AFCD2EDDA6}D:\games\warthunder\aces.exe] => (Allow) D:\games\warthunder\aces.exe
FirewallRules: [UDP Query User{71A4F66F-89EA-4BA8-A942-7296E9990E7C}D:\games\warthunder\aces.exe] => (Allow) D:\games\warthunder\aces.exe
FirewallRules: [{BCE1B04E-10E5-4FF7-9C2B-36A2A1C7A340}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0E8B263B-4F2D-4584-8FAD-1B5470F3FB71}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EF14DC6C-2AEF-4139-8A2B-C31ECA2670A5}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\DiRT 3 Complete Edition\dirt3_game.exe
FirewallRules: [{290CF60C-E12B-4F6C-B8EA-92C75EE5D53D}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\DiRT 3 Complete Edition\dirt3_game.exe
FirewallRules: [{2565B02F-AF93-433B-A832-F6E4ED7262DA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

19-03-2016 10:24:06 End of disinfection

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/20/2016 07:37:32 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0xC004F074
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (03/20/2016 07:37:25 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x8007139F
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (03/19/2016 07:46:56 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0xC004F074
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (03/19/2016 03:57:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: dirt3_game.exe, verze: 1.2.0.0, časové razítko: 0x5530e971
Název chybujícího modulu: gameoverlayrenderer.dll, verze: 1.0.0.1, časové razítko: 0x56e9f278
Kód výjimky: 0xc0000005
Posun chyby: 0x00059b65
ID chybujícího procesu: 0x100c
Čas spuštění chybující aplikace: 0xdirt3_game.exe0
Cesta k chybující aplikaci: dirt3_game.exe1
Cesta k chybujícímu modulu: dirt3_game.exe2
ID zprávy: dirt3_game.exe3
Úplný název chybujícího balíčku: dirt3_game.exe4
ID aplikace související s chybujícím balíčkem: dirt3_game.exe5

Error: (03/19/2016 01:16:19 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_3bccb1ff6bcd1849.manifest.

Error: (03/19/2016 12:43:47 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0xC004F074
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=2

Error: (03/19/2016 12:43:39 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x8007139F
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (03/19/2016 12:26:48 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0xC004F074
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (03/19/2016 12:26:42 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x8007139F
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (03/19/2016 12:10:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KUBA-PC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2144927141. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.


System errors:
=============
Error: (03/20/2016 08:16:00 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:15:48 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:15:48 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:13:14 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:13:14 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:10:43 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:10:41 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:10:41 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:10:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (03/20/2016 08:09:35 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici


CodeIntegrity:
===================================
Date: 2016-03-18 16:46:17.088
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:46:17.030
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:46:16.392
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:46:16.284
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:45:33.920
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:45:33.865
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:45:32.793
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-18 16:45:32.694
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-12 13:21:58.720
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.

Date: 2016-03-12 13:21:58.655
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4590 CPU @ 3.30GHz
Percentage of memory in use: 24%
Total physical RAM: 8140.76 MB
Available physical RAM: 6107.93 MB
Total Virtual: 11966.76 MB
Available Virtual: 9792.98 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.25 GB) (Free:50.94 GB) NTFS
Drive d: (Disk 500 záloha) (Fixed) (Total:465.76 GB) (Free:157.46 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 111.8 GB) (Disk ID: CE8BD8DD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449 MB) - (Type=27)

========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: D904762C)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 14:10

U toho memtestu to furt píše tu chybu a nejde to, když jich spustím víc je to to samé nepíše to chybu a nespustí se

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod jaro3 » 20 bře 2016 14:20

Odinstaluj:
Avira Browser Safety (pokud najdeš)

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
SearchScopes: HKU\S-1-5-21-3313306934-2274467357-1670545691-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
FF Extension: Avira Browser Safety - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\abs@avira.com.xpi [2016-03-12]
FF Extension: Avira SafeSearch Plus - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\safesearchplus2@avira.com.xpi [2016-03-12]
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\ProgramData\Avira
 C:\Program Files (x86)\Avira
C:\Users\Kuba\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
C:\Users\Kuba\AppData\Local\Temp\7za.exe
C:\Users\Kuba\AppData\Local\Temp\DaS_21.exe
C:\Users\Kuba\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Kuba\AppData\Local\Temp\hijackthis.exe
C:\Users\Kuba\AppData\Local\Temp\NirCmd.exe
C:\Users\Kuba\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Kuba\AppData\Local\Temp\nvStInst.exe
C:\Users\Kuba\AppData\Local\Temp\PEVZ.EXE
C:\Users\Kuba\AppData\Local\Temp\remove.exe
C:\Users\Kuba\AppData\Local\Temp\sed.exe
C:\Users\Kuba\AppData\Local\Temp\shortcut.exe
C:\Users\Kuba\AppData\Local\Temp\swreg.exe
C:\Users\Kuba\AppData\Local\Temp\swxcacls.exe
C:\Users\Kuba\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Kuba\AppData\Local\Temp\wget.exe
C:\Users\Kuba\AppData\Local\Temp\zoek-delete.exe
Task: {343160C6-EA61-4CB6-9CC2-85DC880133D4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-12] (Google Inc.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Memtest 86
http://www.memtest86.com/
klikni vlevo na Free Download , vyber:
ISO image for creating bootable CD (Windows - zip) , stáhni , rozbal , otevři , vypal třeba v programu:
http://www.slunecnice.cz/sw/active-iso-burner/
Vlož do mechaniky a nabootuj z něj.
Test udělej alespoň 8h ( přes noc).

http://www.memtest86.com/download.htm
http://www.eopcservis.cz/jak-otestovat-ram.html
http://www.memtest86.com/download.htm
http://www.memtest86.com/downloads/memt ... sb.img.zip
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 14:47

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Kuba (2016-03-20 14:46:07) Run:1
Running from C:\Users\Kuba\Desktop
Loaded Profiles: Kuba (Available Profiles: Kuba)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
SearchScopes: HKU\S-1-5-21-3313306934-2274467357-1670545691-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
FF Extension: Avira Browser Safety - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\abs@avira.com.xpi [2016-03-12]
FF Extension: Avira SafeSearch Plus - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\safesearchplus2@avira.com.xpi [2016-03-12]
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\ProgramData\Avira
C:\Program Files (x86)\Avira
C:\Users\Kuba\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
C:\Users\Kuba\AppData\Local\Temp\7za.exe
C:\Users\Kuba\AppData\Local\Temp\DaS_21.exe
C:\Users\Kuba\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Kuba\AppData\Local\Temp\hijackthis.exe
C:\Users\Kuba\AppData\Local\Temp\NirCmd.exe
C:\Users\Kuba\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Kuba\AppData\Local\Temp\nvStInst.exe
C:\Users\Kuba\AppData\Local\Temp\PEVZ.EXE
C:\Users\Kuba\AppData\Local\Temp\remove.exe
C:\Users\Kuba\AppData\Local\Temp\sed.exe
C:\Users\Kuba\AppData\Local\Temp\shortcut.exe
C:\Users\Kuba\AppData\Local\Temp\swreg.exe
C:\Users\Kuba\AppData\Local\Temp\swxcacls.exe
C:\Users\Kuba\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Kuba\AppData\Local\Temp\wget.exe
C:\Users\Kuba\AppData\Local\Temp\zoek-delete.exe
Task: {343160C6-EA61-4CB6-9CC2-85DC880133D4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-12] (Google Inc.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End
*****************

Processes closed successfully.
"HKU\S-1-5-21-3313306934-2274467357-1670545691-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\abs@avira.com.xpi => moved successfully
C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\a02slw7r.default\Extensions\safesearchplus2@avira.com.xpi => moved successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
Chrome DefaultSuggestURL => removed successfully
"HKLM\SOFTWARE\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk" => key removed successfully
"HKLM\SOFTWARE\Google\Chrome\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp" => key removed successfully
idsvc => service removed successfully
wpcsvc => service removed successfully
C:\ProgramData\Avira => moved successfully
C:\Program Files (x86)\Avira => moved successfully
C:\Users\Kuba\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦 => moved successfully
C:\Users\Kuba\AppData\Local\Temp\7za.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\DaS_21.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\dllnt_dump.dll => moved successfully
C:\Users\Kuba\AppData\Local\Temp\hijackthis.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\NirCmd.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\nvSCPAPI64.dll => moved successfully
C:\Users\Kuba\AppData\Local\Temp\nvStInst.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\PEVZ.EXE => moved successfully
C:\Users\Kuba\AppData\Local\Temp\remove.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\sed.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\shortcut.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\swreg.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\swxcacls.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\vcredist_x86.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\wget.exe => moved successfully
C:\Users\Kuba\AppData\Local\Temp\zoek-delete.exe => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{343160C6-EA61-4CB6-9CC2-85DC880133D4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{343160C6-EA61-4CB6-9CC2-85DC880133D4}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
EmptyTemp: => 792.7 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 14:46:11 ====

Kuba jiřík
nováček
Příspěvky: 47
Registrován: březen 16
Pohlaví: Muž
Stav:
Offline

Re: PC dropy

Příspěvekod Kuba jiřík » 20 bře 2016 14:59

A je to nutný ? protože si na 99 % myslím že to dělá starý dist protože když jsem hru nainstaloval na disk C tak jela v pohodě


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 121 hostů