Výkyvy ve výkonu notebooku Vyřešeno
Re: Výkyvy ve výkonu notebooku
Dotaz... jak na ten memtest? Když ho spustim, vyskočí okno, že windows omezuje kolik se může najednou testovat, že mám spustit více testů, atd... v tomto bodě to mám nechat být? Protože když dám OK, tak se to vrátí do výchozího okna a dole je hláška, že nemůže lokalizovat 4095 MB
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Výkyvy ve výkonu notebooku
Spusť memtest dvakrát.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Výkyvy ve výkonu notebooku
Memtest ukázal nula chyb. Tady jsou logy. A jen tak mimochodem. Po těchto testech se mi i text vypisuje zpomaleně. Restartuju a jdu na defregmentaci
----------------------------------------------------------------------------
CrystalDiskInfo 7.0.0 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 8.1 [6.3 Build 9600] (x64)
Date : 2016/07/11 14:34:44
-- Controller Map ----------------------------------------------------------
+ Intel(R) 8 Series Chipset Family SATA AHCI Controller [ATA]
- WDC WD10S21X-24R1BT0-SSHD-8GB
- Řadič prostorů úložišť [SCSI]
- DAEMON Tools Lite Virtual SCSI Bus [SCSI]
-- Disk List ---------------------------------------------------------------
(1) WDC WD10S21X-24R1BT0-SSHD-8GB : 1000,2 GB [0/0/0, pd1] - wd
----------------------------------------------------------------------------
(1) WDC WD10S21X-24R1BT0-SSHD-8GB
----------------------------------------------------------------------------
Model : WDC WD10S21X-24R1BT0-SSHD-8GB
Firmware : 03.01A02
Serial Number : WD-WXD1A154TLV0
Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ACS-2
Minor Version : ----
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 4962 hod.
Power On Count : 953 krát
Temperature : 40 C (104 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ, TRIM
APM Level : 0060h [ON]
AAM Level : ----
Drive Letter : C: D:
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 192 187 _21 00000000055F Čas na roztočení ploten
04 _78 _78 __0 000000005624 Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 _51 000000000000 Počet chybných hledání
09 _94 _94 __0 000000001362 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C 100 100 __0 0000000003B9 Počet cyklů zapnutí zařízení
C0 200 200 __0 00000000003F Počet vypnutí disku
C1 163 163 __0 00000001B7FE Počet cyklů načítání/vymazání
C2 107 _90 __0 000000000028 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů
F0 _94 _94 __0 0000000012FF Čas nastavování hlaviček - v hodinách
-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 4431 4131 3534 544C 5630
020: 0000 0000 0000 3033 2E30 3141 3032 5744 4320 5744
030: 3130 5332 3158 2D32 3452 3142 5430 2D53 5348 442D
040: 3847 4220 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F FF0E 0066 024C 02CC
080: 03FE 0000 346B 7D09 6123 3469 BC09 6123 407F 005F
090: 005F 0060 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5001 4EE6
110: B041 83C7 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 2800 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 E4A5
-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 C0 BB 5F 05 00 00 00 00 00 04 32 00 4E 4E 24
020: 56 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2F 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5E 5E 62 13 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 64 64 B9 03 00 00 00 00 00 C0 32
070: 00 C8 C8 3F 00 00 00 00 00 00 C1 32 00 A3 A3 FE
080: B7 01 00 00 00 00 C2 22 00 6B 5A 28 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 64 FD 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 64 FD 00 00 00 00 00 00 00 F0 32
0D0: 00 5E 5E FF 12 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 9C 45 01 7B
170: 03 00 01 00 02 C6 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55
-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 33 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 00 00 00 00 00 00 00 00 00 00 F0 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5A

----------------------------------------------------------------------------
CrystalDiskInfo 7.0.0 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 8.1 [6.3 Build 9600] (x64)
Date : 2016/07/11 14:34:44
-- Controller Map ----------------------------------------------------------
+ Intel(R) 8 Series Chipset Family SATA AHCI Controller [ATA]
- WDC WD10S21X-24R1BT0-SSHD-8GB
- Řadič prostorů úložišť [SCSI]
- DAEMON Tools Lite Virtual SCSI Bus [SCSI]
-- Disk List ---------------------------------------------------------------
(1) WDC WD10S21X-24R1BT0-SSHD-8GB : 1000,2 GB [0/0/0, pd1] - wd
----------------------------------------------------------------------------
(1) WDC WD10S21X-24R1BT0-SSHD-8GB
----------------------------------------------------------------------------
Model : WDC WD10S21X-24R1BT0-SSHD-8GB
Firmware : 03.01A02
Serial Number : WD-WXD1A154TLV0
Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ACS-2
Minor Version : ----
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 4962 hod.
Power On Count : 953 krát
Temperature : 40 C (104 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ, TRIM
APM Level : 0060h [ON]
AAM Level : ----
Drive Letter : C: D:
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 192 187 _21 00000000055F Čas na roztočení ploten
04 _78 _78 __0 000000005624 Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 _51 000000000000 Počet chybných hledání
09 _94 _94 __0 000000001362 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C 100 100 __0 0000000003B9 Počet cyklů zapnutí zařízení
C0 200 200 __0 00000000003F Počet vypnutí disku
C1 163 163 __0 00000001B7FE Počet cyklů načítání/vymazání
C2 107 _90 __0 000000000028 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů
F0 _94 _94 __0 0000000012FF Čas nastavování hlaviček - v hodinách
-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 4431 4131 3534 544C 5630
020: 0000 0000 0000 3033 2E30 3141 3032 5744 4320 5744
030: 3130 5332 3158 2D32 3452 3142 5430 2D53 5348 442D
040: 3847 4220 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0000 0000 0007 3FFF 0010 003F FC10 00FB 0100
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F FF0E 0066 024C 02CC
080: 03FE 0000 346B 7D09 6123 3469 BC09 6123 407F 005F
090: 005F 0060 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5001 4EE6
110: B041 83C7 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 7035 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 2800 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 E4A5
-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 00 00 00 00 00 00 00 03 27
010: 00 C0 BB 5F 05 00 00 00 00 00 04 32 00 4E 4E 24
020: 56 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2F 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 5E 5E 62 13 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 64 64 B9 03 00 00 00 00 00 C0 32
070: 00 C8 C8 3F 00 00 00 00 00 00 C1 32 00 A3 A3 FE
080: B7 01 00 00 00 00 C2 22 00 6B 5A 28 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 64 FD 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 64 FD 00 00 00 00 00 00 00 F0 32
0D0: 00 5E 5E FF 12 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 9C 45 01 7B
170: 03 00 01 00 02 C6 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55
-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 33 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 00 00 00 00 00 00 00 00 00 00 F0 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5A

Re: Výkyvy ve výkonu notebooku
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-07-2016 01
Ran by User (administrator) on LENOVO-PC (11-07-2016 14:36:12)
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Disc Soft Ltd) D:\Programy\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Windows\System32\igfxTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
() C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\windows\system32\rundll32.exe" C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2014-06-10] (Realtek semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3276104 2014-03-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1379544 2014-03-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1379544 2014-03-05] (Realtek Semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16093512 2015-06-09] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [8235848 2015-06-09] (Lenovo(beijing) Limited)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [8897712 2016-06-30] (AVAST Software)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [26424960 2016-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [DAEMON Tools Lite Automount] => D:\Programy\DAEMON Tools Lite\DTAgent.exe [4299968 2016-06-22] (Disc Soft Ltd)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [Steam] => C:\Data\Hry\Steam\steam.exe [2851408 2016-07-09] (Valve Corporation)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8810200 2016-06-10] (Piriform Ltd)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\MountPoints2: {8abe9851-43ac-11e6-826e-acd1b8debeb8} - "E:\startme.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-30] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-06-09]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{441B73A4-BE7A-4658-B79B-DE84D983B2C4}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{855ACFB7-ED75-4EC0-AE80-412E4C3E9443}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-06-30] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-06-30] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-29] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-10] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-30]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-06-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Chrome:
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-06]
CHR Extension: (Dokumenty Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-06]
CHR Extension: (Disk Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-06]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-06]
CHR Extension: (Tabulky Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-06]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-06]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-10]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-10]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-10]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-10]
CHR Extension: (Google Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-10]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-10]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-10]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-10]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-06-10]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-10]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-06-30] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1362464 2016-07-09] ()
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [980224 2014-12-05] (Broadcom Corporation.)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-10] ()
R3 Disc Soft Lite Bus Service; D:\Programy\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-06-22] (Disc Soft Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2013-10-15] (ELAN Microelectronics Corp.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328296 2014-11-21] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-23] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
R2 LenovoSetSvr; C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe [389680 2015-06-09] (Lenovo(beijing) Limited)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-06-09] (Lenovo(beijing) Limited)
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-06-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-06-14] (NVIDIA Corporation)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-26] (PointGrab LTD)
R2 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-26] (PointGrab LTD)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2015-06-09] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-06-30] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-06-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108304 2016-06-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-06-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-06-30] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-06-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [473592 2016-06-30] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162904 2016-06-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [290088 2016-06-30] (AVAST Software)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-11-14] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7592664 2014-12-04] (Broadcom Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-06-10] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-06-10] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [24904 2014-03-11] (ELAN Microelectronic Corp.)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-06-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [444632 2013-10-24] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9121496 2014-06-10] (Realtek Semiconductor Corp.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-07-06] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 mfeaack01; \Device\mfeaack01.sys [X]
U3 aswMBR; \??\C:\Users\User\AppData\Local\Temp\aswMBR.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-11 14:36 - 2016-07-11 14:36 - 00022263 _____ C:\Users\User\Desktop\FRST.txt
2016-07-11 14:35 - 2016-07-11 14:36 - 00000000 ____D C:\FRST
2016-07-11 06:44 - 2016-07-11 06:44 - 02390528 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2016-07-11 06:42 - 2016-07-11 06:42 - 03889464 _____ (Crystal Dew World ) C:\Users\User\Downloads\CrystalDiskInfo7_0_0-en.exe
2016-07-11 06:42 - 2016-07-11 06:42 - 00001227 _____ C:\Users\User\Desktop\CrystalDiskInfo.lnk
2016-07-11 06:42 - 2016-07-11 06:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2016-07-11 06:42 - 2016-07-11 06:42 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2016-07-10 16:28 - 2016-05-26 16:25 - 00032768 _____ () C:\Users\User\Desktop\memtest.exe
2016-07-10 16:27 - 2016-07-10 16:27 - 00015654 _____ C:\Users\User\Downloads\MemTest.zip
2016-07-10 12:57 - 2016-07-10 12:58 - 00000000 ____D C:\Users\User\Documents\Larian Studios
2016-07-10 12:57 - 2016-07-10 12:57 - 00001976 _____ C:\Users\Public\Desktop\Divinity - Original Sin.lnk
2016-07-10 12:57 - 2016-07-10 12:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Divinity - Original Sin [GOG.com]
2016-07-10 10:41 - 2016-07-10 10:41 - 00000000 ____D C:\ProgramData\Package Cache
2016-07-09 20:31 - 2016-06-29 20:02 - 00111552 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvStreaming.exe
2016-07-09 20:31 - 2016-05-04 04:23 - 00129824 _____ C:\windows\SysWOW64\vulkan-1.dll
2016-07-09 20:31 - 2016-05-04 04:22 - 00130848 _____ C:\windows\system32\vulkan-1.dll
2016-07-09 20:31 - 2016-05-04 04:22 - 00045344 _____ C:\windows\system32\vulkaninfo.exe
2016-07-09 20:31 - 2016-05-04 04:22 - 00040224 _____ C:\windows\SysWOW64\vulkaninfo.exe
2016-07-09 20:30 - 2016-07-09 20:30 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-07-09 20:29 - 2016-07-09 20:29 - 00000000 ____D C:\windows\LastGood
2016-07-09 20:27 - 2016-06-30 00:44 - 39979576 _____ C:\windows\system32\nvcompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 35115968 _____ C:\windows\SysWOW64\nvcompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 31626808 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 25402424 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 19199216 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 17302264 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 16774904 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 14356952 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 13523392 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2016-07-09 20:27 - 2016-06-30 00:44 - 10672752 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 10656296 _____ C:\windows\system32\nvptxJitCompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 10214760 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 09006760 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 08742032 _____ C:\windows\SysWOW64\nvptxJitCompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 08600904 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 03513400 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 03067448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 01922616 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6436869.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 01571776 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6436869.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00984000 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00909248 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00771640 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00707520 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00669952 _____ C:\windows\system32\nvfatbinaryLoader.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00565392 _____ C:\windows\SysWOW64\nvfatbinaryLoader.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00502080 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00425016 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00422752 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00379448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00178136 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00155768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2016-07-09 14:15 - 2016-07-09 14:56 - 730093569 _____ C:\Users\User\Downloads\Big--Lebowski-CZ.avi
2016-07-07 19:15 - 2016-07-07 19:47 - 00000000 ____D C:\Users\User\Desktop\Images
2016-07-06 20:41 - 2016-07-06 20:42 - 00000000 ____D C:\Users\User\Downloads\backups
2016-07-06 20:40 - 2016-07-06 20:40 - 05200384 _____ (AVAST Software) C:\Users\User\Downloads\aswmbr.exe
2016-07-06 18:11 - 2016-07-06 18:11 - 00000000 ____D C:\Users\User\AppData\Roaming\DAEMON Tools Lite
2016-07-06 18:10 - 2016-07-06 18:14 - 00000000 ____D C:\Users\User\AppData\Local\VirtualStore
2016-07-06 18:06 - 2016-07-06 17:53 - 00024064 _____ C:\windows\zoek-delete.exe
2016-07-06 17:53 - 2016-07-06 18:05 - 00000000 ____D C:\zoek_backup
2016-07-06 17:53 - 2016-07-06 17:53 - 01309184 _____ C:\Users\User\Downloads\zoek.exe
2016-07-04 20:37 - 2016-07-06 17:20 - 00028272 _____ C:\windows\system32\Drivers\TrueSight.sys
2016-07-04 20:36 - 2016-07-04 20:36 - 00000000 ____D C:\ProgramData\RogueKiller
2016-07-04 20:20 - 2016-07-04 20:20 - 01610816 _____ (Malwarebytes) C:\Users\User\Downloads\JRT.exe
2016-07-03 12:06 - 2016-07-06 19:59 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-07-03 12:06 - 2016-07-03 12:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-07-03 12:06 - 2016-07-03 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-07-03 12:06 - 2016-07-03 12:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-07-03 12:06 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-07-03 12:06 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-07-03 12:06 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-07-03 12:05 - 2016-07-03 12:05 - 22851472 _____ (Malwarebytes ) C:\Users\User\Downloads\mbam-setup-2.2.1.1043.exe
2016-07-03 12:03 - 2016-07-03 12:03 - 03712064 _____ C:\Users\User\Downloads\adwcleaner_5.201.exe
2016-07-03 12:00 - 2016-07-04 20:25 - 00000000 ____D C:\AdwCleaner
2016-07-03 11:26 - 2016-07-03 11:26 - 00448512 _____ (OldTimer Tools) C:\Users\User\Downloads\TFC.exe
2016-07-02 22:48 - 2016-07-02 22:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis.exe
2016-07-02 15:12 - 2016-07-02 16:24 - 631222750 _____ C:\Users\User\Downloads\Game-of-Thrones----S06E09---Cz-tit-vloženy.avi
2016-07-02 14:23 - 2016-07-02 15:09 - 415590400 _____ C:\Users\User\Downloads\Game-of-Thrones-S06E10-cz.tit..avi
2016-07-01 14:29 - 2016-07-01 15:09 - 364900352 _____ C:\Users\User\Downloads\Vikings.S04E10.cz-tit.avi
2016-07-01 13:43 - 2016-07-01 14:23 - 365955072 _____ C:\Users\User\Downloads\Vikings.S04E09.cz-tit.avi
2016-07-01 11:03 - 2016-07-01 11:03 - 00000000 ____D C:\Users\User\Documents\My Games
2016-07-01 11:03 - 2016-07-01 11:03 - 00000000 ____D C:\Users\User\AppData\LocalLow\Twice Circled
2016-07-01 10:11 - 2016-07-01 10:43 - 299797604 _____ C:\Users\User\Downloads\Big.Pharma.v0.42.00.zip
2016-07-01 02:12 - 2016-07-01 02:12 - 00007597 _____ C:\Users\User\AppData\Local\Resmon.ResmonCfg
2016-07-01 00:31 - 2016-06-03 19:11 - 00472576 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2016-07-01 00:31 - 2016-06-03 15:38 - 01413120 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-07-01 00:31 - 2016-06-02 19:51 - 00050352 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-07-01 00:31 - 2016-05-29 17:04 - 01204224 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00569856 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00544256 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-07-01 00:31 - 2016-05-21 19:28 - 25802752 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-07-01 00:31 - 2016-05-21 18:57 - 20341248 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-07-01 00:31 - 2016-05-21 00:09 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-07-01 00:31 - 2016-05-21 00:08 - 02895360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-07-01 00:31 - 2016-05-21 00:02 - 06051328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-07-01 00:31 - 2016-05-20 23:57 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-07-01 00:31 - 2016-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-07-01 00:31 - 2016-05-20 23:54 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-07-01 00:31 - 2016-05-20 23:50 - 02287104 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-07-01 00:31 - 2016-05-20 23:44 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-07-01 00:31 - 2016-05-20 23:29 - 13815808 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-07-01 00:31 - 2016-05-20 23:27 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-07-01 00:31 - 2016-05-20 23:25 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-07-01 00:31 - 2016-05-20 23:25 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2016-07-01 00:31 - 2016-05-20 23:21 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-07-01 00:31 - 2016-05-20 23:21 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2016-07-01 00:31 - 2016-05-20 23:19 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2016-07-01 00:31 - 2016-05-20 23:16 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2016-07-01 00:31 - 2016-05-20 23:14 - 04610048 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-07-01 00:31 - 2016-05-20 23:12 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-07-01 00:31 - 2016-05-20 23:11 - 15420928 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-07-01 00:31 - 2016-05-20 23:11 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-07-01 00:31 - 2016-05-20 23:09 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-07-01 00:31 - 2016-05-20 23:09 - 00379392 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-07-01 00:31 - 2016-05-20 23:08 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-07-01 00:31 - 2016-05-20 23:08 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-07-01 00:31 - 2016-05-20 23:06 - 02131968 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-07-01 00:31 - 2016-05-20 22:46 - 02597888 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-07-01 00:31 - 2016-05-20 22:42 - 02121216 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-07-01 00:31 - 2016-05-20 22:38 - 01310208 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-07-01 00:31 - 2016-05-20 22:38 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-07-01 00:31 - 2016-05-20 22:34 - 01544192 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-07-01 00:31 - 2016-05-20 22:23 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-07-01 00:31 - 2016-05-19 01:15 - 01379040 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2016-07-01 00:31 - 2016-05-18 22:35 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2016-07-01 00:31 - 2016-05-18 07:31 - 00372568 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-07-01 00:31 - 2016-05-18 07:31 - 00315224 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-07-01 00:31 - 2016-05-16 23:13 - 00563016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2016-07-01 00:31 - 2016-05-16 23:13 - 00397224 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2016-07-01 00:31 - 2016-05-16 23:13 - 00340872 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2016-07-01 00:31 - 2016-05-16 23:13 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-07-01 00:31 - 2016-05-14 22:01 - 00363104 _____ (Microsoft Corporation) C:\windows\system32\ws2_32.dll
2016-07-01 00:31 - 2016-05-14 22:01 - 00320720 _____ (Microsoft Corporation) C:\windows\SysWOW64\ws2_32.dll
2016-07-01 00:31 - 2016-05-14 01:09 - 04169216 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-07-01 00:31 - 2016-05-14 01:07 - 00675328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2016-07-01 00:31 - 2016-05-14 01:07 - 00416768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2016-07-01 00:31 - 2016-05-14 01:07 - 00281088 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbt.sys
2016-07-01 00:31 - 2016-05-14 01:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2016-07-01 00:31 - 2016-05-14 01:04 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-07-01 00:31 - 2016-05-14 00:34 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2016-07-01 00:31 - 2016-05-14 00:19 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-07-01 00:31 - 2016-05-13 23:58 - 00339456 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2016-07-01 00:31 - 2016-05-13 23:58 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2016-07-01 00:31 - 2016-05-13 23:45 - 00802816 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
2016-07-01 00:31 - 2016-05-13 23:35 - 00286208 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2016-07-01 00:31 - 2016-05-13 23:26 - 00631808 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
2016-07-01 00:31 - 2016-05-12 20:38 - 00135336 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll
2016-07-01 00:31 - 2016-05-12 19:43 - 00115704 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll
2016-07-01 00:31 - 2016-05-12 18:17 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\polstore.dll
2016-07-01 00:31 - 2016-05-12 18:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\FwRemoteSvr.dll
2016-07-01 00:31 - 2016-05-12 18:07 - 01360896 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll
2016-07-01 00:31 - 2016-05-12 17:59 - 00398848 _____ (Microsoft Corporation) C:\windows\system32\IPSECSVC.DLL
2016-07-01 00:31 - 2016-05-12 17:43 - 00291328 _____ (Microsoft Corporation) C:\windows\SysWOW64\polstore.dll
2016-07-01 00:31 - 2016-05-12 17:37 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\FwRemoteSvr.dll
2016-07-01 00:31 - 2016-05-09 23:35 - 07075328 _____ (Microsoft Corporation) C:\windows\system32\glcndFilter.dll
2016-07-01 00:31 - 2016-05-09 22:56 - 05270016 _____ (Microsoft Corporation) C:\windows\SysWOW64\glcndFilter.dll
2016-07-01 00:31 - 2016-05-09 22:45 - 07793152 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2016-07-01 00:31 - 2016-05-09 22:23 - 05265920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2016-07-01 00:31 - 2016-05-06 17:45 - 00748544 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
2016-07-01 00:31 - 2016-05-06 17:23 - 00503808 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
2016-07-01 00:31 - 2016-04-14 17:25 - 02778624 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2016-07-01 00:31 - 2016-04-14 17:11 - 02464768 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2016-07-01 00:31 - 2016-04-12 17:46 - 14467584 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2016-07-01 00:31 - 2016-04-12 17:30 - 12879872 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2016-07-01 00:31 - 2016-01-31 21:17 - 00118624 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2016-07-01 00:31 - 2016-01-31 20:07 - 00110080 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2016-07-01 00:31 - 2016-01-31 19:42 - 03320832 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2016-07-01 00:31 - 2016-01-31 19:14 - 03607040 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2016-07-01 00:19 - 2016-07-01 00:19 - 00002790 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2016-07-01 00:19 - 2016-07-01 00:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-07-01 00:19 - 2016-07-01 00:19 - 00000000 ____D C:\Program Files\CCleaner
2016-06-30 23:22 - 2016-06-30 23:22 - 00390984 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-06-30 23:22 - 2016-06-30 23:22 - 00053208 _____ (AVAST Software) C:\windows\avastSS.scr
2016-06-29 22:47 - 2016-06-29 23:26 - 365948928 _____ C:\Users\User\Downloads\Vikings.S04E08.cz-tit.avi
2016-06-29 19:45 - 2016-06-29 21:06 - 364900352 _____ C:\Users\User\Downloads\Vikings.S04E07.cz-tit.avi
2016-06-28 23:04 - 2016-06-28 23:24 - 365948928 _____ C:\Users\User\Downloads\Vikings.S04E06.cz-tit.avi
2016-06-26 16:56 - 2016-06-16 12:49 - 00044040 _____ C:\Users\Public\[CzT]Total_War_Rome_II_Emperor_Edition_2014_CZ_.torrent
2016-06-26 15:47 - 2016-06-26 15:52 - 00000000 ____D C:\Users\Public\Total.War.ROME.II.Emperor.Edition.MULTi9-PROPHET
2016-06-26 14:17 - 2016-06-27 07:20 - 00000000 ____D C:\ProgramData\Steam
2016-06-24 17:47 - 2016-06-24 17:47 - 00495694 _____ C:\Users\User\Downloads\DENNÍ DISPOZICE, 26.6..pdf
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\Users\User\AppData\Roaming\.mono
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\Users\User\AppData\Local\Blizzard
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\ProgramData\.mono
2016-06-21 17:49 - 2016-06-21 17:49 - 00515936 _____ C:\Users\User\Downloads\TECHNICKÝ SCÉNÁŘ - SOUKROMÉ LEKCE.pdf
2016-06-21 12:09 - 2016-06-21 12:09 - 00216790 _____ C:\Users\User\Downloads\SOUKROMÉ LEKCE - natáčecí plán.pdf
2016-06-18 18:46 - 2016-06-19 22:22 - 00000000 ____D C:\Users\User\Documents\Overwatch
2016-06-18 18:45 - 2016-06-18 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch
2016-06-18 13:35 - 2016-06-18 13:40 - 00000000 ____D C:\Users\User\Documents\DayZ
2016-06-18 13:35 - 2016-06-18 13:40 - 00000000 ____D C:\Users\User\AppData\Local\DayZ
2016-06-16 13:31 - 2016-06-16 13:31 - 00032256 _____ C:\Users\User\Downloads\ZTP_2017 (1).xls
2016-06-15 22:47 - 2016-06-15 22:47 - 00031232 _____ C:\Users\User\Downloads\ZTP_2017.xls
2016-06-15 00:40 - 2016-06-15 05:44 - 201340585 _____ C:\Users\User\Downloads\Elysium-2013-(R)-akční,-scifi-cz-dabing_xvid.avi.crdownload
2016-06-14 23:20 - 2016-06-14 23:20 - 00000000 ____D C:\Users\User\Documents\League of Legends
2016-06-14 23:05 - 2016-06-14 23:05 - 00000000 ____D C:\Users\User\AppData\Roaming\LolClient
2016-06-14 00:02 - 2016-07-09 15:41 - 00000000 ____D C:\Users\User\AppData\Roaming\vlc
2016-06-14 00:02 - 2016-06-14 00:02 - 00071755 _____ C:\Users\User\Downloads\Elysium(0000227835).srt
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-06-13 11:46 - 2016-06-13 11:46 - 00000000 ____D C:\windows\PCHEALTH
2016-06-13 11:46 - 2016-06-13 11:46 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
2016-06-13 11:46 - 2016-06-13 11:46 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2016-06-13 11:45 - 2016-06-13 11:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2016-06-13 11:44 - 2016-06-13 11:46 - 00000000 ____D C:\Program Files\Microsoft Office
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 __RHD C:\MSOCache
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2016-06-13 10:41 - 2016-06-14 08:35 - 00000000 ____D C:\Users\User\Downloads\Elysium (2013) [1080p]
2016-06-12 17:22 - 2016-06-12 18:39 - 710028459 _____ C:\Users\User\Downloads\Microsoft-Office-2010-Profesional-64-bit-CZ-+-key.rar
2016-06-12 17:21 - 2016-06-12 17:21 - 00168448 _____ C:\Users\User\Downloads\iivos.xls
2016-06-12 11:59 - 2016-06-12 11:59 - 00000000 ____D C:\Users\User\AppData\Roaming\WinRAR
2016-06-12 11:59 - 2016-04-18 15:40 - 00000000 ____D C:\Users\User\Desktop\Literatura a film - houska
2016-06-12 11:57 - 2016-06-12 11:57 - 02120008 _____ C:\Users\User\Downloads\Literatura a film - houska.rar
2016-06-11 22:11 - 2016-07-11 14:35 - 00310784 ___SH C:\Users\User\Downloads\Thumbs.db
2016-06-11 22:11 - 2016-06-11 22:11 - 00000000 ____D C:\Users\User\AppData\Roaming\FastStone
2016-06-11 20:54 - 2016-07-10 12:57 - 00084480 ___SH C:\Users\User\Desktop\Thumbs.db
2016-06-11 12:58 - 2016-06-11 12:58 - 00000000 ____D C:\ProgramData\Riot Games
2016-06-11 12:56 - 2016-06-11 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-06-11 12:56 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_39.dll
2016-06-11 12:56 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_39.dll
2016-06-11 12:56 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_39.dll
2016-06-11 12:52 - 2016-06-11 12:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Riot Games
2016-06-11 11:39 - 2016-06-11 11:39 - 00000000 ____D C:\Users\User\Documents\Diablo III
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-11 13:11 - 2016-06-10 11:41 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2016-07-11 10:46 - 2016-06-02 11:24 - 00003970 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{D4D1F84D-9AA4-4E87-842B-3909A9629ABA}
2016-07-11 08:04 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppReadiness
2016-07-11 06:49 - 2016-06-02 16:00 - 00003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2130949904-3043617627-3509382821-1001
2016-07-11 05:24 - 2016-06-10 12:27 - 00000000 ____D C:\Users\User\AppData\Local\Battle.net
2016-07-11 04:24 - 2016-06-10 11:12 - 00000000 ___RD C:\Users\User\OneDrive
2016-07-10 01:22 - 2013-08-22 15:36 - 00000000 ____D C:\windows\Inf
2016-07-10 00:07 - 2016-06-10 16:33 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2016-07-09 20:31 - 2015-06-09 17:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-07-09 20:31 - 2015-06-09 17:01 - 00000000 ____D C:\ProgramData\NVIDIA
2016-07-09 18:10 - 2016-06-10 12:32 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-07-09 15:46 - 2015-06-09 16:34 - 00739924 _____ C:\windows\system32\perfh005.dat
2016-07-09 15:46 - 2015-06-09 16:34 - 00151610 _____ C:\windows\system32\perfc005.dat
2016-07-09 15:46 - 2014-11-21 06:44 - 01745984 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-06 18:20 - 2016-06-02 16:59 - 00001283 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-07-06 18:20 - 2016-06-02 16:59 - 00000000 ____D C:\ProgramData\LU
2016-07-06 18:09 - 2013-08-22 16:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-07-06 18:08 - 2015-06-09 17:27 - 00002560 _____ C:\windows\system32\VfService.trf
2016-07-06 18:08 - 2013-08-22 15:25 - 00262144 ___SH C:\windows\system32\config\BBI
2016-07-05 18:34 - 2016-06-10 11:41 - 00000000 ____D C:\ProgramData\Skype
2016-07-05 18:33 - 2016-06-10 11:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-07-05 05:00 - 2015-06-09 17:36 - 00000000 ____D C:\ProgramData\Energy Manager
2016-07-02 13:39 - 2013-08-22 17:36 - 00000000 ____D C:\windows\rescache
2016-07-01 10:50 - 2016-06-10 11:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-01 10:50 - 2016-06-10 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-01 02:09 - 2015-06-09 16:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-07-01 02:08 - 2015-06-09 17:31 - 00000000 ____D C:\Program Files\Lenovo PhoneCompanion
2016-07-01 00:53 - 2016-06-10 11:30 - 00003892 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1465551034
2016-07-01 00:53 - 2016-06-10 11:30 - 00001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-07-01 00:52 - 2013-08-22 16:44 - 00491760 _____ C:\windows\system32\FNTCACHE.DAT
2016-07-01 00:49 - 2016-06-10 15:40 - 00000000 ____D C:\windows\system32\appraiser
2016-07-01 00:49 - 2013-08-22 17:36 - 00000000 ___RD C:\windows\ToastData
2016-07-01 00:40 - 2013-08-22 17:20 - 00000000 ____D C:\windows\CbsTemp
2016-07-01 00:36 - 2016-06-10 13:58 - 00000000 ____D C:\windows\system32\MRT
2016-07-01 00:32 - 2016-06-10 13:58 - 142482544 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-07-01 00:23 - 2016-06-02 15:55 - 00000000 ____D C:\Users\User\AppData\Local\Packages
2016-07-01 00:23 - 2015-06-09 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Photo Master
2016-07-01 00:23 - 2015-06-09 17:08 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-07-01 00:23 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-07-01 00:22 - 2015-06-09 17:35 - 00000000 ____D C:\ProgramData\CyberLink
2016-07-01 00:20 - 2014-12-10 03:49 - 00000000 ____D C:\windows\Panther
2016-06-30 23:23 - 2016-06-10 11:28 - 00473592 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00473592 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys.146732178325002
2016-06-30 23:22 - 2016-06-10 11:28 - 00290088 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00162904 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00108304 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00003922 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-06-30 23:21 - 2016-06-10 11:30 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-06-30 23:21 - 2016-06-10 11:28 - 01070904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-06-30 00:44 - 2015-06-09 17:00 - 03828968 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2016-06-30 00:44 - 2015-06-09 17:00 - 03387080 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2016-06-30 00:44 - 2015-06-09 17:00 - 00039124 _____ C:\windows\system32\nvinfo.pb
2016-06-29 20:36 - 2015-06-09 17:01 - 06364728 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 02455608 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 01762752 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 01352760 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2016-06-29 20:36 - 2015-06-09 17:01 - 00532416 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00124984 _____ (NVIDIA Corporation) C:\windows\SysWOW64\oemdspif.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00083512 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00069568 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2016-06-26 16:38 - 2016-06-10 16:04 - 00000000 ____D C:\Users\User\AppData\Roaming\The Creative Assembly
2016-06-26 16:34 - 2016-06-10 11:11 - 00000000 __SHD C:\Users\User\AppData\LocalLow\EmieUserList
2016-06-26 16:34 - 2016-06-10 11:11 - 00000000 __SHD C:\Users\User\AppData\LocalLow\EmieSiteList
2016-06-26 16:34 - 2016-06-10 11:11 - 00000000 __SHD C:\Users\User\AppData\LocalLow\EmieBrowserModeList
2016-06-23 10:04 - 2015-06-09 17:01 - 07208075 _____ C:\windows\system32\nvcoproc.bin
2016-06-18 02:34 - 2016-06-10 11:20 - 00002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-14 22:01 - 2016-06-10 12:02 - 00112216 _____ C:\windows\system32\NvRtmpStreamer64.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01767944 _____ (NVIDIA Corporation) C:\windows\system32\nvspcap64.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01756424 _____ (NVIDIA Corporation) C:\windows\system32\nvspbridge64.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01377800 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspcap.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01316184 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspbridge.dll
2016-06-14 19:13 - 2016-06-10 15:49 - 00828408 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-06-14 19:13 - 2016-06-10 15:49 - 00176632 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-06-14 16:58 - 2016-06-10 12:04 - 00000000 ____D C:\ProgramData\Origin
2016-06-13 11:47 - 2014-11-21 06:20 - 00000000 ____D C:\windows\ShellNew
2016-06-13 11:47 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-06-13 11:46 - 2014-12-10 03:57 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-06-13 11:44 - 2015-06-09 17:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-06-13 11:44 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\System
2016-06-13 11:44 - 2013-08-22 15:25 - 00000167 _____ C:\windows\win.ini
2016-06-12 12:50 - 2016-06-10 11:54 - 00000000 ____D C:\Users\User\AppData\Roaming\Winamp
2016-06-11 10:12 - 2015-06-09 17:26 - 00000000 ____D C:\windows\System32\Tasks\Lenovo
2016-06-11 00:28 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppCompat
==================== Files in the root of some directories =======
2016-06-02 12:51 - 2016-06-02 12:51 - 0000041 _____ () C:\Program Files\smaple.txt
2016-07-01 02:12 - 2016-07-01 02:12 - 0007597 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
2015-06-09 17:08 - 2015-06-09 17:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\User\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-06 17:30
==================== End of FRST.txt ============================
Ran by User (administrator) on LENOVO-PC (11-07-2016 14:36:12)
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Disc Soft Ltd) D:\Programy\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Windows\System32\igfxTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
() C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\windows\system32\rundll32.exe" C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2014-06-10] (Realtek semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3276104 2014-03-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1379544 2014-03-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1379544 2014-03-05] (Realtek Semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16093512 2015-06-09] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [8235848 2015-06-09] (Lenovo(beijing) Limited)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [8897712 2016-06-30] (AVAST Software)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [26424960 2016-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [DAEMON Tools Lite Automount] => D:\Programy\DAEMON Tools Lite\DTAgent.exe [4299968 2016-06-22] (Disc Soft Ltd)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [Steam] => C:\Data\Hry\Steam\steam.exe [2851408 2016-07-09] (Valve Corporation)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8810200 2016-06-10] (Piriform Ltd)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\MountPoints2: {8abe9851-43ac-11e6-826e-acd1b8debeb8} - "E:\startme.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-30] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-06-09]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{441B73A4-BE7A-4658-B79B-DE84D983B2C4}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{855ACFB7-ED75-4EC0-AE80-412E4C3E9443}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-06-30] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-06-30] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-29] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-10] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-30]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-06-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Chrome:
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-06]
CHR Extension: (Dokumenty Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-06]
CHR Extension: (Disk Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-06]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-06]
CHR Extension: (Tabulky Google) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-06]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-06]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-10]
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-10]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-10]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-10]
CHR Extension: (Google Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-10]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-10]
CHR Extension: (Avast Online Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-10]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-10]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-06-10]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-10]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-06-30] (AVAST Software)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1362464 2016-07-09] ()
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [980224 2014-12-05] (Broadcom Corporation.)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-10] ()
R3 Disc Soft Lite Bus Service; D:\Programy\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-06-22] (Disc Soft Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101680 2013-10-15] (ELAN Microelectronics Corp.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328296 2014-11-21] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-23] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
R2 LenovoSetSvr; C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe [389680 2015-06-09] (Lenovo(beijing) Limited)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-06-09] (Lenovo(beijing) Limited)
S2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [37624 2014-04-21] (Lenovo(beijing) Limited)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-06-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-06-14] (NVIDIA Corporation)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-26] (PointGrab LTD)
R2 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-26] (PointGrab LTD)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2015-06-09] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-06-30] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-06-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108304 2016-06-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-06-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-06-30] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-06-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [473592 2016-06-30] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162904 2016-06-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [290088 2016-06-30] (AVAST Software)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-11-14] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7592664 2014-12-04] (Broadcom Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-06-10] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-06-10] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [24904 2014-03-11] (ELAN Microelectronic Corp.)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-06-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [444632 2013-10-24] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9121496 2014-06-10] (Realtek Semiconductor Corp.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-07-06] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 mfeaack01; \Device\mfeaack01.sys [X]
U3 aswMBR; \??\C:\Users\User\AppData\Local\Temp\aswMBR.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-11 14:36 - 2016-07-11 14:36 - 00022263 _____ C:\Users\User\Desktop\FRST.txt
2016-07-11 14:35 - 2016-07-11 14:36 - 00000000 ____D C:\FRST
2016-07-11 06:44 - 2016-07-11 06:44 - 02390528 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2016-07-11 06:42 - 2016-07-11 06:42 - 03889464 _____ (Crystal Dew World ) C:\Users\User\Downloads\CrystalDiskInfo7_0_0-en.exe
2016-07-11 06:42 - 2016-07-11 06:42 - 00001227 _____ C:\Users\User\Desktop\CrystalDiskInfo.lnk
2016-07-11 06:42 - 2016-07-11 06:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2016-07-11 06:42 - 2016-07-11 06:42 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2016-07-10 16:28 - 2016-05-26 16:25 - 00032768 _____ () C:\Users\User\Desktop\memtest.exe
2016-07-10 16:27 - 2016-07-10 16:27 - 00015654 _____ C:\Users\User\Downloads\MemTest.zip
2016-07-10 12:57 - 2016-07-10 12:58 - 00000000 ____D C:\Users\User\Documents\Larian Studios
2016-07-10 12:57 - 2016-07-10 12:57 - 00001976 _____ C:\Users\Public\Desktop\Divinity - Original Sin.lnk
2016-07-10 12:57 - 2016-07-10 12:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Divinity - Original Sin [GOG.com]
2016-07-10 10:41 - 2016-07-10 10:41 - 00000000 ____D C:\ProgramData\Package Cache
2016-07-09 20:31 - 2016-06-29 20:02 - 00111552 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvStreaming.exe
2016-07-09 20:31 - 2016-05-04 04:23 - 00129824 _____ C:\windows\SysWOW64\vulkan-1.dll
2016-07-09 20:31 - 2016-05-04 04:22 - 00130848 _____ C:\windows\system32\vulkan-1.dll
2016-07-09 20:31 - 2016-05-04 04:22 - 00045344 _____ C:\windows\system32\vulkaninfo.exe
2016-07-09 20:31 - 2016-05-04 04:22 - 00040224 _____ C:\windows\SysWOW64\vulkaninfo.exe
2016-07-09 20:30 - 2016-07-09 20:30 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-07-09 20:29 - 2016-07-09 20:29 - 00000000 ____D C:\windows\LastGood
2016-07-09 20:27 - 2016-06-30 00:44 - 39979576 _____ C:\windows\system32\nvcompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 35115968 _____ C:\windows\SysWOW64\nvcompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 31626808 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 25402424 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 19199216 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 17302264 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 16774904 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 14356952 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 13523392 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2016-07-09 20:27 - 2016-06-30 00:44 - 10672752 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 10656296 _____ C:\windows\system32\nvptxJitCompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 10214760 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 09006760 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 08742032 _____ C:\windows\SysWOW64\nvptxJitCompiler.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 08600904 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 03513400 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 03067448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 01922616 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6436869.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 01571776 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6436869.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00984000 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00909248 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00771640 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00707520 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00669952 _____ C:\windows\system32\nvfatbinaryLoader.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00565392 _____ C:\windows\SysWOW64\nvfatbinaryLoader.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00502080 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00425016 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00422752 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00379448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00178136 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2016-07-09 20:27 - 2016-06-30 00:44 - 00155768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2016-07-09 14:15 - 2016-07-09 14:56 - 730093569 _____ C:\Users\User\Downloads\Big--Lebowski-CZ.avi
2016-07-07 19:15 - 2016-07-07 19:47 - 00000000 ____D C:\Users\User\Desktop\Images
2016-07-06 20:41 - 2016-07-06 20:42 - 00000000 ____D C:\Users\User\Downloads\backups
2016-07-06 20:40 - 2016-07-06 20:40 - 05200384 _____ (AVAST Software) C:\Users\User\Downloads\aswmbr.exe
2016-07-06 18:11 - 2016-07-06 18:11 - 00000000 ____D C:\Users\User\AppData\Roaming\DAEMON Tools Lite
2016-07-06 18:10 - 2016-07-06 18:14 - 00000000 ____D C:\Users\User\AppData\Local\VirtualStore
2016-07-06 18:06 - 2016-07-06 17:53 - 00024064 _____ C:\windows\zoek-delete.exe
2016-07-06 17:53 - 2016-07-06 18:05 - 00000000 ____D C:\zoek_backup
2016-07-06 17:53 - 2016-07-06 17:53 - 01309184 _____ C:\Users\User\Downloads\zoek.exe
2016-07-04 20:37 - 2016-07-06 17:20 - 00028272 _____ C:\windows\system32\Drivers\TrueSight.sys
2016-07-04 20:36 - 2016-07-04 20:36 - 00000000 ____D C:\ProgramData\RogueKiller
2016-07-04 20:20 - 2016-07-04 20:20 - 01610816 _____ (Malwarebytes) C:\Users\User\Downloads\JRT.exe
2016-07-03 12:06 - 2016-07-06 19:59 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-07-03 12:06 - 2016-07-03 12:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-07-03 12:06 - 2016-07-03 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-07-03 12:06 - 2016-07-03 12:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-07-03 12:06 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-07-03 12:06 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-07-03 12:06 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-07-03 12:05 - 2016-07-03 12:05 - 22851472 _____ (Malwarebytes ) C:\Users\User\Downloads\mbam-setup-2.2.1.1043.exe
2016-07-03 12:03 - 2016-07-03 12:03 - 03712064 _____ C:\Users\User\Downloads\adwcleaner_5.201.exe
2016-07-03 12:00 - 2016-07-04 20:25 - 00000000 ____D C:\AdwCleaner
2016-07-03 11:26 - 2016-07-03 11:26 - 00448512 _____ (OldTimer Tools) C:\Users\User\Downloads\TFC.exe
2016-07-02 22:48 - 2016-07-02 22:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\User\Downloads\HijackThis.exe
2016-07-02 15:12 - 2016-07-02 16:24 - 631222750 _____ C:\Users\User\Downloads\Game-of-Thrones----S06E09---Cz-tit-vloženy.avi
2016-07-02 14:23 - 2016-07-02 15:09 - 415590400 _____ C:\Users\User\Downloads\Game-of-Thrones-S06E10-cz.tit..avi
2016-07-01 14:29 - 2016-07-01 15:09 - 364900352 _____ C:\Users\User\Downloads\Vikings.S04E10.cz-tit.avi
2016-07-01 13:43 - 2016-07-01 14:23 - 365955072 _____ C:\Users\User\Downloads\Vikings.S04E09.cz-tit.avi
2016-07-01 11:03 - 2016-07-01 11:03 - 00000000 ____D C:\Users\User\Documents\My Games
2016-07-01 11:03 - 2016-07-01 11:03 - 00000000 ____D C:\Users\User\AppData\LocalLow\Twice Circled
2016-07-01 10:11 - 2016-07-01 10:43 - 299797604 _____ C:\Users\User\Downloads\Big.Pharma.v0.42.00.zip
2016-07-01 02:12 - 2016-07-01 02:12 - 00007597 _____ C:\Users\User\AppData\Local\Resmon.ResmonCfg
2016-07-01 00:31 - 2016-06-03 19:11 - 00472576 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2016-07-01 00:31 - 2016-06-03 15:38 - 01413120 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-07-01 00:31 - 2016-06-02 19:51 - 00050352 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-07-01 00:31 - 2016-05-29 17:04 - 01204224 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00569856 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00544256 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2016-07-01 00:31 - 2016-05-29 17:04 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-07-01 00:31 - 2016-05-21 19:28 - 25802752 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-07-01 00:31 - 2016-05-21 18:57 - 20341248 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-07-01 00:31 - 2016-05-21 00:09 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-07-01 00:31 - 2016-05-21 00:08 - 02895360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-07-01 00:31 - 2016-05-21 00:02 - 06051328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-07-01 00:31 - 2016-05-20 23:57 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-07-01 00:31 - 2016-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-07-01 00:31 - 2016-05-20 23:54 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-07-01 00:31 - 2016-05-20 23:50 - 02287104 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-07-01 00:31 - 2016-05-20 23:44 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-07-01 00:31 - 2016-05-20 23:29 - 13815808 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-07-01 00:31 - 2016-05-20 23:27 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-07-01 00:31 - 2016-05-20 23:25 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-07-01 00:31 - 2016-05-20 23:25 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2016-07-01 00:31 - 2016-05-20 23:21 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-07-01 00:31 - 2016-05-20 23:21 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2016-07-01 00:31 - 2016-05-20 23:19 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2016-07-01 00:31 - 2016-05-20 23:16 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2016-07-01 00:31 - 2016-05-20 23:14 - 04610048 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-07-01 00:31 - 2016-05-20 23:12 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-07-01 00:31 - 2016-05-20 23:11 - 15420928 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-07-01 00:31 - 2016-05-20 23:11 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-07-01 00:31 - 2016-05-20 23:09 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-07-01 00:31 - 2016-05-20 23:09 - 00379392 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-07-01 00:31 - 2016-05-20 23:08 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-07-01 00:31 - 2016-05-20 23:08 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-07-01 00:31 - 2016-05-20 23:06 - 02131968 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-07-01 00:31 - 2016-05-20 22:46 - 02597888 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-07-01 00:31 - 2016-05-20 22:42 - 02121216 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-07-01 00:31 - 2016-05-20 22:38 - 01310208 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-07-01 00:31 - 2016-05-20 22:38 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-07-01 00:31 - 2016-05-20 22:34 - 01544192 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-07-01 00:31 - 2016-05-20 22:23 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-07-01 00:31 - 2016-05-19 01:15 - 01379040 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2016-07-01 00:31 - 2016-05-18 22:35 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2016-07-01 00:31 - 2016-05-18 07:31 - 00372568 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-07-01 00:31 - 2016-05-18 07:31 - 00315224 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-07-01 00:31 - 2016-05-16 23:13 - 00563016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2016-07-01 00:31 - 2016-05-16 23:13 - 00397224 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
2016-07-01 00:31 - 2016-05-16 23:13 - 00340872 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
2016-07-01 00:31 - 2016-05-16 23:13 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-07-01 00:31 - 2016-05-14 22:01 - 00363104 _____ (Microsoft Corporation) C:\windows\system32\ws2_32.dll
2016-07-01 00:31 - 2016-05-14 22:01 - 00320720 _____ (Microsoft Corporation) C:\windows\SysWOW64\ws2_32.dll
2016-07-01 00:31 - 2016-05-14 01:09 - 04169216 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-07-01 00:31 - 2016-05-14 01:07 - 00675328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2016-07-01 00:31 - 2016-05-14 01:07 - 00416768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2016-07-01 00:31 - 2016-05-14 01:07 - 00281088 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbt.sys
2016-07-01 00:31 - 2016-05-14 01:06 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2016-07-01 00:31 - 2016-05-14 01:04 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-07-01 00:31 - 2016-05-14 00:34 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2016-07-01 00:31 - 2016-05-14 00:19 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-07-01 00:31 - 2016-05-13 23:58 - 00339456 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll
2016-07-01 00:31 - 2016-05-13 23:58 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2016-07-01 00:31 - 2016-05-13 23:45 - 00802816 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
2016-07-01 00:31 - 2016-05-13 23:35 - 00286208 _____ (Microsoft Corporation) C:\windows\SysWOW64\mswsock.dll
2016-07-01 00:31 - 2016-05-13 23:26 - 00631808 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
2016-07-01 00:31 - 2016-05-12 20:38 - 00135336 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll
2016-07-01 00:31 - 2016-05-12 19:43 - 00115704 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll
2016-07-01 00:31 - 2016-05-12 18:17 - 00331776 _____ (Microsoft Corporation) C:\windows\system32\polstore.dll
2016-07-01 00:31 - 2016-05-12 18:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\FwRemoteSvr.dll
2016-07-01 00:31 - 2016-05-12 18:07 - 01360896 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll
2016-07-01 00:31 - 2016-05-12 17:59 - 00398848 _____ (Microsoft Corporation) C:\windows\system32\IPSECSVC.DLL
2016-07-01 00:31 - 2016-05-12 17:43 - 00291328 _____ (Microsoft Corporation) C:\windows\SysWOW64\polstore.dll
2016-07-01 00:31 - 2016-05-12 17:37 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\FwRemoteSvr.dll
2016-07-01 00:31 - 2016-05-09 23:35 - 07075328 _____ (Microsoft Corporation) C:\windows\system32\glcndFilter.dll
2016-07-01 00:31 - 2016-05-09 22:56 - 05270016 _____ (Microsoft Corporation) C:\windows\SysWOW64\glcndFilter.dll
2016-07-01 00:31 - 2016-05-09 22:45 - 07793152 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2016-07-01 00:31 - 2016-05-09 22:23 - 05265920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2016-07-01 00:31 - 2016-05-06 17:45 - 00748544 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
2016-07-01 00:31 - 2016-05-06 17:23 - 00503808 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
2016-07-01 00:31 - 2016-04-14 17:25 - 02778624 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2016-07-01 00:31 - 2016-04-14 17:11 - 02464768 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2016-07-01 00:31 - 2016-04-12 17:46 - 14467584 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2016-07-01 00:31 - 2016-04-12 17:30 - 12879872 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2016-07-01 00:31 - 2016-01-31 21:17 - 00118624 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2016-07-01 00:31 - 2016-01-31 20:07 - 00110080 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2016-07-01 00:31 - 2016-01-31 19:42 - 03320832 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2016-07-01 00:31 - 2016-01-31 19:14 - 03607040 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2016-07-01 00:19 - 2016-07-01 00:19 - 00002790 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2016-07-01 00:19 - 2016-07-01 00:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-07-01 00:19 - 2016-07-01 00:19 - 00000000 ____D C:\Program Files\CCleaner
2016-06-30 23:22 - 2016-06-30 23:22 - 00390984 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-06-30 23:22 - 2016-06-30 23:22 - 00053208 _____ (AVAST Software) C:\windows\avastSS.scr
2016-06-29 22:47 - 2016-06-29 23:26 - 365948928 _____ C:\Users\User\Downloads\Vikings.S04E08.cz-tit.avi
2016-06-29 19:45 - 2016-06-29 21:06 - 364900352 _____ C:\Users\User\Downloads\Vikings.S04E07.cz-tit.avi
2016-06-28 23:04 - 2016-06-28 23:24 - 365948928 _____ C:\Users\User\Downloads\Vikings.S04E06.cz-tit.avi
2016-06-26 16:56 - 2016-06-16 12:49 - 00044040 _____ C:\Users\Public\[CzT]Total_War_Rome_II_Emperor_Edition_2014_CZ_.torrent
2016-06-26 15:47 - 2016-06-26 15:52 - 00000000 ____D C:\Users\Public\Total.War.ROME.II.Emperor.Edition.MULTi9-PROPHET
2016-06-26 14:17 - 2016-06-27 07:20 - 00000000 ____D C:\ProgramData\Steam
2016-06-24 17:47 - 2016-06-24 17:47 - 00495694 _____ C:\Users\User\Downloads\DENNÍ DISPOZICE, 26.6..pdf
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\Users\User\AppData\Roaming\.mono
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\Users\User\AppData\Local\Blizzard
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2016-06-21 19:40 - 2016-06-21 19:40 - 00000000 ____D C:\ProgramData\.mono
2016-06-21 17:49 - 2016-06-21 17:49 - 00515936 _____ C:\Users\User\Downloads\TECHNICKÝ SCÉNÁŘ - SOUKROMÉ LEKCE.pdf
2016-06-21 12:09 - 2016-06-21 12:09 - 00216790 _____ C:\Users\User\Downloads\SOUKROMÉ LEKCE - natáčecí plán.pdf
2016-06-18 18:46 - 2016-06-19 22:22 - 00000000 ____D C:\Users\User\Documents\Overwatch
2016-06-18 18:45 - 2016-06-18 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch
2016-06-18 13:35 - 2016-06-18 13:40 - 00000000 ____D C:\Users\User\Documents\DayZ
2016-06-18 13:35 - 2016-06-18 13:40 - 00000000 ____D C:\Users\User\AppData\Local\DayZ
2016-06-16 13:31 - 2016-06-16 13:31 - 00032256 _____ C:\Users\User\Downloads\ZTP_2017 (1).xls
2016-06-15 22:47 - 2016-06-15 22:47 - 00031232 _____ C:\Users\User\Downloads\ZTP_2017.xls
2016-06-15 00:40 - 2016-06-15 05:44 - 201340585 _____ C:\Users\User\Downloads\Elysium-2013-(R)-akční,-scifi-cz-dabing_xvid.avi.crdownload
2016-06-14 23:20 - 2016-06-14 23:20 - 00000000 ____D C:\Users\User\Documents\League of Legends
2016-06-14 23:05 - 2016-06-14 23:05 - 00000000 ____D C:\Users\User\AppData\Roaming\LolClient
2016-06-14 00:02 - 2016-07-09 15:41 - 00000000 ____D C:\Users\User\AppData\Roaming\vlc
2016-06-14 00:02 - 2016-06-14 00:02 - 00071755 _____ C:\Users\User\Downloads\Elysium(0000227835).srt
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2016-06-13 11:47 - 2016-06-13 11:47 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-06-13 11:46 - 2016-06-13 11:46 - 00000000 ____D C:\windows\PCHEALTH
2016-06-13 11:46 - 2016-06-13 11:46 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
2016-06-13 11:46 - 2016-06-13 11:46 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2016-06-13 11:45 - 2016-06-13 11:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2016-06-13 11:44 - 2016-06-13 11:46 - 00000000 ____D C:\Program Files\Microsoft Office
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 __RHD C:\MSOCache
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2016-06-13 11:44 - 2016-06-13 11:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2016-06-13 10:41 - 2016-06-14 08:35 - 00000000 ____D C:\Users\User\Downloads\Elysium (2013) [1080p]
2016-06-12 17:22 - 2016-06-12 18:39 - 710028459 _____ C:\Users\User\Downloads\Microsoft-Office-2010-Profesional-64-bit-CZ-+-key.rar
2016-06-12 17:21 - 2016-06-12 17:21 - 00168448 _____ C:\Users\User\Downloads\iivos.xls
2016-06-12 11:59 - 2016-06-12 11:59 - 00000000 ____D C:\Users\User\AppData\Roaming\WinRAR
2016-06-12 11:59 - 2016-04-18 15:40 - 00000000 ____D C:\Users\User\Desktop\Literatura a film - houska
2016-06-12 11:57 - 2016-06-12 11:57 - 02120008 _____ C:\Users\User\Downloads\Literatura a film - houska.rar
2016-06-11 22:11 - 2016-07-11 14:35 - 00310784 ___SH C:\Users\User\Downloads\Thumbs.db
2016-06-11 22:11 - 2016-06-11 22:11 - 00000000 ____D C:\Users\User\AppData\Roaming\FastStone
2016-06-11 20:54 - 2016-07-10 12:57 - 00084480 ___SH C:\Users\User\Desktop\Thumbs.db
2016-06-11 12:58 - 2016-06-11 12:58 - 00000000 ____D C:\ProgramData\Riot Games
2016-06-11 12:56 - 2016-06-11 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-06-11 12:56 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_39.dll
2016-06-11 12:56 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_39.dll
2016-06-11 12:56 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx10_39.dll
2016-06-11 12:52 - 2016-06-11 12:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Riot Games
2016-06-11 11:39 - 2016-06-11 11:39 - 00000000 ____D C:\Users\User\Documents\Diablo III
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-11 13:11 - 2016-06-10 11:41 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2016-07-11 10:46 - 2016-06-02 11:24 - 00003970 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{D4D1F84D-9AA4-4E87-842B-3909A9629ABA}
2016-07-11 08:04 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppReadiness
2016-07-11 06:49 - 2016-06-02 16:00 - 00003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2130949904-3043617627-3509382821-1001
2016-07-11 05:24 - 2016-06-10 12:27 - 00000000 ____D C:\Users\User\AppData\Local\Battle.net
2016-07-11 04:24 - 2016-06-10 11:12 - 00000000 ___RD C:\Users\User\OneDrive
2016-07-10 01:22 - 2013-08-22 15:36 - 00000000 ____D C:\windows\Inf
2016-07-10 00:07 - 2016-06-10 16:33 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2016-07-09 20:31 - 2015-06-09 17:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-07-09 20:31 - 2015-06-09 17:01 - 00000000 ____D C:\ProgramData\NVIDIA
2016-07-09 18:10 - 2016-06-10 12:32 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-07-09 15:46 - 2015-06-09 16:34 - 00739924 _____ C:\windows\system32\perfh005.dat
2016-07-09 15:46 - 2015-06-09 16:34 - 00151610 _____ C:\windows\system32\perfc005.dat
2016-07-09 15:46 - 2014-11-21 06:44 - 01745984 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-06 18:20 - 2016-06-02 16:59 - 00001283 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-07-06 18:20 - 2016-06-02 16:59 - 00000000 ____D C:\ProgramData\LU
2016-07-06 18:09 - 2013-08-22 16:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-07-06 18:08 - 2015-06-09 17:27 - 00002560 _____ C:\windows\system32\VfService.trf
2016-07-06 18:08 - 2013-08-22 15:25 - 00262144 ___SH C:\windows\system32\config\BBI
2016-07-05 18:34 - 2016-06-10 11:41 - 00000000 ____D C:\ProgramData\Skype
2016-07-05 18:33 - 2016-06-10 11:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-07-05 05:00 - 2015-06-09 17:36 - 00000000 ____D C:\ProgramData\Energy Manager
2016-07-02 13:39 - 2013-08-22 17:36 - 00000000 ____D C:\windows\rescache
2016-07-01 10:50 - 2016-06-10 11:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-01 10:50 - 2016-06-10 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-01 02:09 - 2015-06-09 16:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-07-01 02:08 - 2015-06-09 17:31 - 00000000 ____D C:\Program Files\Lenovo PhoneCompanion
2016-07-01 00:53 - 2016-06-10 11:30 - 00003892 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1465551034
2016-07-01 00:53 - 2016-06-10 11:30 - 00001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-07-01 00:52 - 2013-08-22 16:44 - 00491760 _____ C:\windows\system32\FNTCACHE.DAT
2016-07-01 00:49 - 2016-06-10 15:40 - 00000000 ____D C:\windows\system32\appraiser
2016-07-01 00:49 - 2013-08-22 17:36 - 00000000 ___RD C:\windows\ToastData
2016-07-01 00:40 - 2013-08-22 17:20 - 00000000 ____D C:\windows\CbsTemp
2016-07-01 00:36 - 2016-06-10 13:58 - 00000000 ____D C:\windows\system32\MRT
2016-07-01 00:32 - 2016-06-10 13:58 - 142482544 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-07-01 00:23 - 2016-06-02 15:55 - 00000000 ____D C:\Users\User\AppData\Local\Packages
2016-07-01 00:23 - 2015-06-09 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo Photo Master
2016-07-01 00:23 - 2015-06-09 17:08 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-07-01 00:23 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-07-01 00:22 - 2015-06-09 17:35 - 00000000 ____D C:\ProgramData\CyberLink
2016-07-01 00:20 - 2014-12-10 03:49 - 00000000 ____D C:\windows\Panther
2016-06-30 23:23 - 2016-06-10 11:28 - 00473592 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00473592 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys.146732178325002
2016-06-30 23:22 - 2016-06-10 11:28 - 00290088 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00162904 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00108304 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-06-30 23:22 - 2016-06-10 11:28 - 00003922 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-06-30 23:21 - 2016-06-10 11:30 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-06-30 23:21 - 2016-06-10 11:28 - 01070904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-06-30 00:44 - 2015-06-09 17:00 - 03828968 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2016-06-30 00:44 - 2015-06-09 17:00 - 03387080 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2016-06-30 00:44 - 2015-06-09 17:00 - 00039124 _____ C:\windows\system32\nvinfo.pb
2016-06-29 20:36 - 2015-06-09 17:01 - 06364728 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 02455608 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 01762752 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 01352760 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2016-06-29 20:36 - 2015-06-09 17:01 - 00532416 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00124984 _____ (NVIDIA Corporation) C:\windows\SysWOW64\oemdspif.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00083512 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2016-06-29 20:36 - 2015-06-09 17:01 - 00069568 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2016-06-26 16:38 - 2016-06-10 16:04 - 00000000 ____D C:\Users\User\AppData\Roaming\The Creative Assembly
2016-06-26 16:34 - 2016-06-10 11:11 - 00000000 __SHD C:\Users\User\AppData\LocalLow\EmieUserList
2016-06-26 16:34 - 2016-06-10 11:11 - 00000000 __SHD C:\Users\User\AppData\LocalLow\EmieSiteList
2016-06-26 16:34 - 2016-06-10 11:11 - 00000000 __SHD C:\Users\User\AppData\LocalLow\EmieBrowserModeList
2016-06-23 10:04 - 2015-06-09 17:01 - 07208075 _____ C:\windows\system32\nvcoproc.bin
2016-06-18 02:34 - 2016-06-10 11:20 - 00002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-14 22:01 - 2016-06-10 12:02 - 00112216 _____ C:\windows\system32\NvRtmpStreamer64.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01767944 _____ (NVIDIA Corporation) C:\windows\system32\nvspcap64.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01756424 _____ (NVIDIA Corporation) C:\windows\system32\nvspbridge64.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01377800 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspcap.dll
2016-06-14 22:01 - 2015-06-09 17:01 - 01316184 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspbridge.dll
2016-06-14 19:13 - 2016-06-10 15:49 - 00828408 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-06-14 19:13 - 2016-06-10 15:49 - 00176632 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-06-14 16:58 - 2016-06-10 12:04 - 00000000 ____D C:\ProgramData\Origin
2016-06-13 11:47 - 2014-11-21 06:20 - 00000000 ____D C:\windows\ShellNew
2016-06-13 11:47 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-06-13 11:46 - 2014-12-10 03:57 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-06-13 11:44 - 2015-06-09 17:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-06-13 11:44 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\System
2016-06-13 11:44 - 2013-08-22 15:25 - 00000167 _____ C:\windows\win.ini
2016-06-12 12:50 - 2016-06-10 11:54 - 00000000 ____D C:\Users\User\AppData\Roaming\Winamp
2016-06-11 10:12 - 2015-06-09 17:26 - 00000000 ____D C:\windows\System32\Tasks\Lenovo
2016-06-11 00:28 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppCompat
==================== Files in the root of some directories =======
2016-06-02 12:51 - 2016-06-02 12:51 - 0000041 _____ () C:\Program Files\smaple.txt
2016-07-01 02:12 - 2016-07-01 02:12 - 0007597 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
2015-06-09 17:08 - 2015-06-09 17:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\User\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-06 17:30
==================== End of FRST.txt ============================
Re: Výkyvy ve výkonu notebooku
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-07-2016 01
Ran by User (2016-07-11 14:37:16)
Running from C:\Users\User\Desktop
Windows 8.1 (Update) (X64) (2016-06-02 13:54:09)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2130949904-3043617627-3509382821-500 - Administrator - Disabled)
Guest (S-1-5-21-2130949904-3043617627-3509382821-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2130949904-3043617627-3509382821-1003 - Limited - Enabled)
User (S-1-5-21-2130949904-3043617627-3509382821-1001 - Administrator - Enabled) => C:\Users\User
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Aktualizace NVIDIA 2.11.4.0 (Version: 2.11.4.0 - NVIDIA Corporation) Hidden
ARK: Survival Evolved (HKLM\...\Steam App 346110) (Version: - Studio Wildcard)
Armello (HKLM\...\Steam App 290340) (Version: - League of Geeks)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.1.2272 - AVAST Software)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
CCleaner (HKLM\...\CCleaner) (Version: 5.19 - Piriform)
CCSDK (HKLM-x32\...\{AE75190B-11B4-4F90-8254-DAB275CF2557}_is1) (Version: 1.0.3.4 - Lenovo)
CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CrystalDiskInfo 7.0.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.0 - Crystal Dew World)
CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0192 - Disc Soft Ltd)
DayZ (HKLM\...\Steam App 221100) (Version: - Bohemia Interactive)
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.32.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.38.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (x32 Version: 1.6.38.00 - Lenovo Group Limited) Hidden
Dependency Package Update (x32 Version: 1.6.38.01 - Lenovo Group Limited) Hidden
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Divinity - Original Sin (HKLM-x32\...\1207664923_is1) (Version: 2.11.0.21 - GOG.com)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.23 - Lenovo)
Energy Manager (x32 Version: 1.5.0.23 - Lenovo) Hidden
FastStone Image Viewer 5.7 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.7 - FastStone Soft)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4029 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.2.1000 - Intel Corporation)
League of Legends (HKLM-x32\...\League of Legends 4.1.1) (Version: 4.1.1 - Riot Games)
League of Legends (x32 Version: 4.1.1 - Riot Games) Hidden
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.1.200 - Broadcom Corporation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.38.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10279 - Realtek Semiconductor Corp.)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.1.12.0 - Lenovo)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo Motion Control (HKLM-x32\...\InstallShield_{A60E1DE0-2AD1-4BD3-BBCC-4FBB22FB6F85}) (Version: 2.5.1.0225 - PointGrab)
Lenovo Motion Control (x32 Version: 2.5.1.0225 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.39.1 - ELAN Microelectronic Corp.)
Lenovo Settings (HKLM-x32\...\InstallShield_{42F8AFC3-7944-46CC-9689-94FF9869D0A7}) (Version: 1.0.0.52 - Lenovo)
Lenovo Settings (x32 Version: 1.0.0.52 - Lenovo) Hidden
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.1.14.6181 - Lenovo)
Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.35.223.5 - Lenovo)
Malwarebytes Anti-Malware verze 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4641.3004 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
NVIDIA GeForce Experience 2.11.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.4.0 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 368.69 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.69 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 368.69 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.69 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Onekey Theater (HKLM-x32\...\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo)
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Ovládací panel NVIDIA 368.69 (Version: 368.69 - NVIDIA Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.21243 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7195 - Realtek Semiconductor Corp.)
SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden
SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.1.8.0 - Lenovo Group Limited)
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.4.0 - NVIDIA Corporation) Hidden
Skype™ 7.25 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.25.106 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total War™: WARHAMMER® (HKLM\...\Steam App 364360) (Version: - Creative Assembly)
UESDK (HKLM-x32\...\{EB3F6640-58AE-4886-B8BA-466B6939A933}_is1) (Version: 1.0.3.6 - Lenovo)
Uplay (HKLM-x32\...\Uplay) (Version: 20.0 - Ubisoft)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.31 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {001A157F-31B2-4D9D-A677-1946945B504B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {02D95D45-C3D6-47A4-9CD5-2355386EACD9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {07E428D6-E002-4B03-B7DD-409CE5A11FBC} - System32\Tasks\SafeZone scheduled Autoupdate 1465551034 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)
Task: {0ED61202-1E92-452F-A262-E7A164B8ACC5} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-11-21] (Lenovo)
Task: {11C092E2-6763-476C-8CF8-9A1704DE0376} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: {212B4681-F4C7-4CA7-AAC4-ABDE2FD6780E} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2016-06-11] (Lenovo)
Task: {25DEF58B-B4D9-4682-8463-64E8BFEE5BC3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-06-10] (Piriform Ltd)
Task: {2D231141-8164-460B-B594-B989BE9909C4} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {559D3545-282B-44DC-86C8-12A1AE251FE2} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-06-30] (AVAST Software)
Task: {68CA9D1F-4277-49F6-A34A-6275FEE3921B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-10] (Lenovo)
Task: {9F8A80DC-6F52-4E4A-9DBE-3D61DB43018D} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {A0A69B08-FBDC-49FB-AE97-9A7DA48C3B7A} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-12-14] ()
Task: {DB60EACF-E17B-40A1-8FE3-AA4D00191943} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe
Task: {DDDED6AF-8D34-4083-81BE-BDD2E89B882F} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-30] (AVAST Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-12-05 04:21 - 2014-12-05 04:21 - 00049408 _____ () C:\Program Files\Lenovo\Bluetooth Software\btwleapi.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 00367552 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 00288192 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 03611584 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2015-06-09 17:31 - 2012-04-24 12:43 - 00390632 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-06-09 17:27 - 2015-06-09 17:27 - 00068880 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2015-06-09 17:27 - 2015-06-09 17:27 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 01840576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 00207296 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 02665920 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 01988544 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2015-06-09 17:26 - 2014-07-10 02:19 - 00592880 _____ () C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
2015-06-09 17:01 - 2016-06-29 20:37 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-01-30 02:40 - 2010-01-30 02:40 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-06-09 00:19 - 2014-11-21 10:54 - 00456808 _____ () C:\windows\system32\igfxTray.exe
2015-06-09 17:07 - 2013-10-01 11:09 - 00078880 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2014-03-26 21:50 - 2015-06-09 17:36 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2016-06-10 12:01 - 2016-06-14 22:03 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2016-06-10 12:01 - 2016-06-14 22:03 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2013-05-10 02:58 - 2013-05-10 02:58 - 00119808 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
2016-06-18 02:34 - 2016-06-15 10:26 - 02334360 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libglesv2.dll
2016-06-18 02:34 - 2016-06-15 10:26 - 00105112 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libegl.dll
2015-06-09 00:19 - 2014-11-21 10:54 - 17170624 _____ () C:\windows\SYSTEM32\igd11dxva64.dll
2016-06-18 02:34 - 2016-06-15 10:26 - 31519384 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\PepperFlash\pepflashplayer.dll
2016-06-30 23:22 - 2016-06-30 23:22 - 00146232 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-06-30 23:22 - 2016-06-30 23:22 - 00479288 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-07-11 12:22 - 2016-07-11 12:22 - 02996736 _____ () C:\Program Files\AVAST Software\Avast\defs\16071100\algo.dll
2014-02-26 01:42 - 2014-02-26 01:42 - 00013576 _____ () C:\Program Files (x86)\Lenovo\Motion Control\PointGrabDeviceAPI.dll
2015-06-09 16:55 - 2013-09-16 21:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-06-10 12:01 - 2016-06-14 22:03 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-06-30 23:22 - 2016-06-30 23:22 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
2013-03-07 21:53 - 2013-03-07 21:53 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
2010-01-13 01:55 - 2010-01-13 01:55 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
2010-01-13 01:55 - 2010-01-13 01:55 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
2010-12-16 21:16 - 2010-12-16 21:16 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
2010-01-18 08:34 - 2010-01-18 08:34 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
2013-03-07 21:55 - 2013-03-07 21:55 - 00472576 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
2013-03-07 21:58 - 2013-03-07 21:58 - 00499488 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
2013-03-07 21:54 - 2013-03-07 21:54 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2016-07-06 17:56 - 00000753 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\fsviewerwallpaper.bmp
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "OnekeyStudio"
HKLM\...\StartupApproved\Run: => "BCSSync"
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\StartupApproved\Run: => "Skype"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{9487B656-FA62-4D1D-9CFA-DD9365C49380}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BB1C516E-D097-4432-913F-FAFBD6CB588E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{2679EC09-A13B-4CC7-8A80-B94212763F1F}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{C6DBAF3A-E872-4406-B780-71EDCFDB4F8D}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{93023D62-D5F7-4E90-BACA-82D92F33830E}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{6BE3CB8B-368E-4E51-B42B-8D26C3C97806}] => (Allow) LPort=55100
FirewallRules: [{192EF4B7-B171-44CD-8126-D4EF76814D3F}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{60FE0E9A-8AA5-4E2C-899F-1EAFD0784A65}] => (Allow) D:\Programy\Winamp\winamp.exe
FirewallRules: [{EA63F9C0-3A66-426F-A31B-90B4F1ED16CB}] => (Allow) D:\Programy\Winamp\winamp.exe
FirewallRules: [{2CCC9156-27A8-4872-BE61-02B5CBB9BC4A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{103005EB-1F89-4DE9-994C-E0797AF797BB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{53C24971-C6DC-42F5-981E-5EB36D0F245E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{7CC271F2-FB27-4AA2-8E59-C4E9CBE772A4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{40100EC2-93B1-4D85-A027-8A1A8FE5F705}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{EBEDAC76-BA68-4931-8BC6-CE510CA2911F}] => (Allow) C:\Data\Hry\Steam\Steam.exe
FirewallRules: [{067A4B92-7F22-4921-8764-510212D880B9}] => (Allow) C:\Data\Hry\Steam\Steam.exe
FirewallRules: [{E046AF4B-2F39-481A-ABAB-DAC13FAB0BC0}] => (Allow) C:\Data\Hry\Steam\bin\steamwebhelper.exe
FirewallRules: [{75ADCFD1-0CF8-4706-9560-28D337B8758F}] => (Allow) C:\Data\Hry\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{4C648A13-3926-45F1-A840-EE6CFE01F7A0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{55C20CAA-6F90-440C-AC07-3924227C866E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{3FCE8F96-9AD1-4F7E-8912-107B2A460224}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [UDP Query User{C137616E-8BE4-4ECF-82C0-609B9B1930DD}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [TCP Query User{23043871-4696-46F5-9C21-AAA3C15AE539}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{056D05B4-3199-498B-AC1F-6FC45856D6E3}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [{8FFD2EDA-8043-4EBC-BED8-57BA0CC47C7A}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Armello\armello.exe
FirewallRules: [{2BF6243E-1B76-4D74-97B8-E927A2E87344}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Armello\armello.exe
FirewallRules: [TCP Query User{7CAEE44A-3AE6-4383-8C8C-B153E4BE27F9}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{4B6FA89F-190B-4A09-9391-96C6DBF4D8B5}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{A8827CBA-5541-4A20-8972-18F319BDBA9B}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [UDP Query User{4AEF1A38-9392-48C0-B34A-20D22E2628AC}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [TCP Query User{1117CA93-14EB-4AA2-8133-D128734BD193}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{F6DFA071-63A5-4F35-8076-BC64453C48EB}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [{5394A299-BEA5-4BAC-A4D2-1540AA24CEB2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E8F0885D-0B3D-412B-B5FE-5B64391288D1}] => (Allow) C:\Data\Hry\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{FEEBDD5F-290C-483D-9E4B-ED76B0D0CD73}] => (Allow) C:\Data\Hry\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [TCP Query User{4248397A-988D-41AF-B13A-44669CC5A010}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [UDP Query User{814D8C5F-E2A0-4C72-92D8-80D3D984A836}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [TCP Query User{4FDF422C-2163-42A9-BB3D-FC2DCCF73486}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [UDP Query User{EC8CACDC-88AB-4AEC-9A33-58E8833BC276}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [TCP Query User{3EB7FDF3-49A5-43FB-AD09-1941C06CB173}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [UDP Query User{9B3AA125-0DA1-496C-B1B8-6815E53C15B5}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [TCP Query User{FDDD2F9B-5C30-4F32-B363-96215267C2EE}C:\data\hry\hearthstone\hearthstone.exe] => (Allow) C:\data\hry\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{1E9C5515-4207-4239-B208-034D0713FF58}C:\data\hry\hearthstone\hearthstone.exe] => (Allow) C:\data\hry\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{561FCDE4-2293-4C41-A72E-684945DA54C1}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [UDP Query User{2FC26ABF-E96E-4E5C-B339-E18BCFF3ED75}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [{70431E78-E848-47C2-A8F3-95336D600315}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Total War WARHAMMER\launcher\launcher.exe
FirewallRules: [{C4E7FB09-B955-4B51-BBC8-DA6A4BA0B021}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Total War WARHAMMER\launcher\launcher.exe
FirewallRules: [TCP Query User{EE3C7745-F59D-4D14-99D4-988205FDF904}D:\programy\torrent\utorrent.exe] => (Allow) D:\programy\torrent\utorrent.exe
FirewallRules: [UDP Query User{AE360EA7-2D07-448F-94B2-8BEA1A8C8B5D}D:\programy\torrent\utorrent.exe] => (Allow) D:\programy\torrent\utorrent.exe
FirewallRules: [{6C78100A-12BD-4E6F-B8EC-8EC3B8389451}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{0F8B5836-6C21-46EC-9FE1-0BD34D1227F6}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{1732B051-9D30-4A97-B168-AF857E3726B3}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{7CD0B434-167C-4EFD-8F5A-D47B1DEDC061}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [TCP Query User{4E3BB76D-C308-416D-8880-637D5020585D}C:\data\hry\divinity - original sin\shipping\eocapp.exe] => (Allow) C:\data\hry\divinity - original sin\shipping\eocapp.exe
FirewallRules: [UDP Query User{A733CA85-35FC-427E-B020-11220B30A757}C:\data\hry\divinity - original sin\shipping\eocapp.exe] => (Allow) C:\data\hry\divinity - original sin\shipping\eocapp.exe
==================== Restore Points =========================
04-07-2016 20:33:06 JRT Pre-Junkware Removal
06-07-2016 17:54:45 zoek.exe restore point
10-07-2016 00:06:56 Avast Cleanup
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/10/2016 01:13:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Aplikaci microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 se nepovedlo aktivovat, protože došlo k chybě: -2144927141. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.
Error: (07/10/2016 03:36:16 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Svazek WINRE_DRV nebyl optimalizován, protože byla zjištěna chyba: Parametr není správný. (0x80070057).
Error: (07/10/2016 12:18:21 AM) (Source: ESENT) (EventID: 104) (User: )
Description: SearchIndexer (4100) Windows: Databázový stroj zastavil instanci (0) s chybou (-510).
Sekvence interního načasování: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.062, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.016, [10] 0.062, [11] 0.000, [12] 0.000, [13] 0.000, [14] 0.000, [15] 0.000.
Error: (07/10/2016 12:18:20 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.
Podrobnosti:
Katalog indexu obsahu je poškozený. 0xc0041801 (0xc0041801)
Error: (07/10/2016 12:18:20 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4810 - enduser\mssearch2\search\ytrip\common\util\jetutil.cpp (540)} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.
Podrobnosti:
0x8e5e01fe (0x8e5e01fe)
Error: (07/10/2016 12:18:17 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (07/10/2016 12:18:17 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4811 - enduser\mssearch2\search\search\propstore\propsess.cxx (239)} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.
Podrobnosti:
Databáze indexu obsahu je poškozená. (HRESULT : 0xc0041800) (0xc0041800)
Error: (07/10/2016 12:17:48 AM) (Source: ESENT) (EventID: 492) (User: )
Description: SearchIndexer (4100) Windows: Posloupnost souborů protokolu v C:\ProgramData\Microsoft\Search\Data\Applications\Windows\ byla zastavena. Došlo k závažné chybě. Databáze, které používají tuto posloupnost souborů protokolu, již nelze aktualizovat. Odstraňte potíže a restartujte nebo obnovte databázi ze záložní kopie.
Error: (07/10/2016 12:17:48 AM) (Source: ESENT) (EventID: 418) (User: )
Description: SearchIndexer (4100) Windows: Při otevírání nově vytvořeného souboru protokolu C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.log došlo k chybě -1811 (0xfffff8ed).
Error: (07/09/2016 05:07:03 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
System errors:
=============
Error: (07/11/2016 04:22:14 AM) (Source: iaStorA) (EventID: 4102) (User: )
Description: Error log: Smart event occured on disk :WD-WXD1A154TLV0
Error: (07/10/2016 01:58:07 PM) (Source: iaStorA) (EventID: 4102) (User: )
Description: Error log: Smart event occured on disk :WD-WXD1A154TLV0
Error: (07/10/2016 01:13:06 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (07/10/2016 12:11:37 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/10/2016 12:11:37 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/10/2016 12:04:28 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/10/2016 12:04:27 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/09/2016 06:58:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/09/2016 06:58:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/09/2016 05:06:59 PM) (Source: iaStorA) (EventID: 4102) (User: )
Description: Error log: Smart event occured on disk :WD-WXD1A154TLV0
CodeIntegrity:
===================================
Date: 2016-06-27 03:04:03.827
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.687
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.577
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.468
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.369
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.275
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.153
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.057
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:02.962
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:02.853
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4720HQ CPU @ 2.60GHz
Percentage of memory in use: 32%
Total physical RAM: 8104.27 MB
Available physical RAM: 5488.25 MB
Total Virtual: 11176.27 MB
Available Virtual: 8137.95 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:890.3 GB) (Free:588.18 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.47 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 4D6302D9)
Partition: GPT.
==================== End of Addition.txt ============================
Ran by User (2016-07-11 14:37:16)
Running from C:\Users\User\Desktop
Windows 8.1 (Update) (X64) (2016-06-02 13:54:09)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2130949904-3043617627-3509382821-500 - Administrator - Disabled)
Guest (S-1-5-21-2130949904-3043617627-3509382821-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2130949904-3043617627-3509382821-1003 - Limited - Enabled)
User (S-1-5-21-2130949904-3043617627-3509382821-1001 - Administrator - Enabled) => C:\Users\User
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Aktualizace NVIDIA 2.11.4.0 (Version: 2.11.4.0 - NVIDIA Corporation) Hidden
ARK: Survival Evolved (HKLM\...\Steam App 346110) (Version: - Studio Wildcard)
Armello (HKLM\...\Steam App 290340) (Version: - League of Geeks)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.1.2272 - AVAST Software)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
CCleaner (HKLM\...\CCleaner) (Version: 5.19 - Piriform)
CCSDK (HKLM-x32\...\{AE75190B-11B4-4F90-8254-DAB275CF2557}_is1) (Version: 1.0.3.4 - Lenovo)
CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CrystalDiskInfo 7.0.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.0 - Crystal Dew World)
CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0192 - Disc Soft Ltd)
DayZ (HKLM\...\Steam App 221100) (Version: - Bohemia Interactive)
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.32.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.38.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dependency Package Update (x32 Version: 1.6.38.00 - Lenovo Group Limited) Hidden
Dependency Package Update (x32 Version: 1.6.38.01 - Lenovo Group Limited) Hidden
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Divinity - Original Sin (HKLM-x32\...\1207664923_is1) (Version: 2.11.0.21 - GOG.com)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.23 - Lenovo)
Energy Manager (x32 Version: 1.5.0.23 - Lenovo) Hidden
FastStone Image Viewer 5.7 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.7 - FastStone Soft)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4029 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.2.1000 - Intel Corporation)
League of Legends (HKLM-x32\...\League of Legends 4.1.1) (Version: 4.1.1 - Riot Games)
League of Legends (x32 Version: 4.1.1 - Riot Games) Hidden
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.1.200 - Broadcom Corporation)
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.38.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10279 - Realtek Semiconductor Corp.)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.1.12.0 - Lenovo)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo Motion Control (HKLM-x32\...\InstallShield_{A60E1DE0-2AD1-4BD3-BBCC-4FBB22FB6F85}) (Version: 2.5.1.0225 - PointGrab)
Lenovo Motion Control (x32 Version: 2.5.1.0225 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.39.1 - ELAN Microelectronic Corp.)
Lenovo Settings (HKLM-x32\...\InstallShield_{42F8AFC3-7944-46CC-9689-94FF9869D0A7}) (Version: 1.0.0.52 - Lenovo)
Lenovo Settings (x32 Version: 1.0.0.52 - Lenovo) Hidden
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.3.0.6 - Lenovo)
Lenovo Updates (x32 Version: 1.3.0.6 - Lenovo) Hidden
Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.1.14.6181 - Lenovo)
Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.35.223.5 - Lenovo)
Malwarebytes Anti-Malware verze 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4641.3004 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
NVIDIA GeForce Experience 2.11.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.4.0 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 368.69 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.69 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 368.69 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.69 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Onekey Theater (HKLM-x32\...\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo)
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Ovládací panel NVIDIA 368.69 (Version: 368.69 - NVIDIA Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.21243 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7195 - Realtek Semiconductor Corp.)
SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden
SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.1.8.0 - Lenovo Group Limited)
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.4.0 - NVIDIA Corporation) Hidden
Skype™ 7.25 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.25.106 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total War™: WARHAMMER® (HKLM\...\Steam App 364360) (Version: - Creative Assembly)
UESDK (HKLM-x32\...\{EB3F6640-58AE-4886-B8BA-466B6939A933}_is1) (Version: 1.0.3.6 - Lenovo)
Uplay (HKLM-x32\...\Uplay) (Version: 20.0 - Ubisoft)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.31 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {001A157F-31B2-4D9D-A677-1946945B504B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {02D95D45-C3D6-47A4-9CD5-2355386EACD9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {07E428D6-E002-4B03-B7DD-409CE5A11FBC} - System32\Tasks\SafeZone scheduled Autoupdate 1465551034 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)
Task: {0ED61202-1E92-452F-A262-E7A164B8ACC5} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-11-21] (Lenovo)
Task: {11C092E2-6763-476C-8CF8-9A1704DE0376} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: {212B4681-F4C7-4CA7-AAC4-ABDE2FD6780E} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2016-06-11] (Lenovo)
Task: {25DEF58B-B4D9-4682-8463-64E8BFEE5BC3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-06-10] (Piriform Ltd)
Task: {2D231141-8164-460B-B594-B989BE9909C4} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {559D3545-282B-44DC-86C8-12A1AE251FE2} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-06-30] (AVAST Software)
Task: {68CA9D1F-4277-49F6-A34A-6275FEE3921B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-10] (Lenovo)
Task: {9F8A80DC-6F52-4E4A-9DBE-3D61DB43018D} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {A0A69B08-FBDC-49FB-AE97-9A7DA48C3B7A} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-12-14] ()
Task: {DB60EACF-E17B-40A1-8FE3-AA4D00191943} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe
Task: {DDDED6AF-8D34-4083-81BE-BDD2E89B882F} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-30] (AVAST Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-12-05 04:21 - 2014-12-05 04:21 - 00049408 _____ () C:\Program Files\Lenovo\Bluetooth Software\btwleapi.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 00367552 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 00288192 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 03611584 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2015-06-09 17:31 - 2012-04-24 12:43 - 00390632 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-06-09 17:27 - 2015-06-09 17:27 - 00068880 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2015-06-09 17:27 - 2015-06-09 17:27 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 01840576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 00207296 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 02665920 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2016-06-10 12:02 - 2016-06-14 22:03 - 01988544 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2015-06-09 17:26 - 2014-07-10 02:19 - 00592880 _____ () C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
2015-06-09 17:01 - 2016-06-29 20:37 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-01-30 02:40 - 2010-01-30 02:40 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-06-09 00:19 - 2014-11-21 10:54 - 00456808 _____ () C:\windows\system32\igfxTray.exe
2015-06-09 17:07 - 2013-10-01 11:09 - 00078880 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2014-03-26 21:50 - 2015-06-09 17:36 - 00058864 _____ () C:\Program Files (x86)\Lenovo\Energy Manager\kbdhook.dll
2016-06-10 12:01 - 2016-06-14 22:03 - 00034240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2016-06-10 12:01 - 2016-06-14 22:03 - 00920000 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2013-05-10 02:58 - 2013-05-10 02:58 - 00119808 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
2016-06-18 02:34 - 2016-06-15 10:26 - 02334360 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libglesv2.dll
2016-06-18 02:34 - 2016-06-15 10:26 - 00105112 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libegl.dll
2015-06-09 00:19 - 2014-11-21 10:54 - 17170624 _____ () C:\windows\SYSTEM32\igd11dxva64.dll
2016-06-18 02:34 - 2016-06-15 10:26 - 31519384 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\PepperFlash\pepflashplayer.dll
2016-06-30 23:22 - 2016-06-30 23:22 - 00146232 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-06-30 23:22 - 2016-06-30 23:22 - 00479288 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-07-11 12:22 - 2016-07-11 12:22 - 02996736 _____ () C:\Program Files\AVAST Software\Avast\defs\16071100\algo.dll
2014-02-26 01:42 - 2014-02-26 01:42 - 00013576 _____ () C:\Program Files (x86)\Lenovo\Motion Control\PointGrabDeviceAPI.dll
2015-06-09 16:55 - 2013-09-16 21:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-06-10 12:01 - 2016-06-14 22:03 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-06-30 23:22 - 2016-06-30 23:22 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
2013-03-07 21:53 - 2013-03-07 21:53 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
2010-01-13 01:55 - 2010-01-13 01:55 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
2010-01-13 01:55 - 2010-01-13 01:55 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
2010-12-16 21:16 - 2010-12-16 21:16 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
2010-01-18 08:34 - 2010-01-18 08:34 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
2013-03-07 21:55 - 2013-03-07 21:55 - 00472576 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
2013-03-07 21:58 - 2013-03-07 21:58 - 00499488 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
2013-03-07 21:54 - 2013-03-07 21:54 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll
2010-12-17 21:56 - 2010-12-17 21:56 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2016-07-06 17:56 - 00000753 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\fsviewerwallpaper.bmp
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "OnekeyStudio"
HKLM\...\StartupApproved\Run: => "BCSSync"
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\...\StartupApproved\Run: => "Skype"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{9487B656-FA62-4D1D-9CFA-DD9365C49380}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BB1C516E-D097-4432-913F-FAFBD6CB588E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{2679EC09-A13B-4CC7-8A80-B94212763F1F}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{C6DBAF3A-E872-4406-B780-71EDCFDB4F8D}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{93023D62-D5F7-4E90-BACA-82D92F33830E}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{6BE3CB8B-368E-4E51-B42B-8D26C3C97806}] => (Allow) LPort=55100
FirewallRules: [{192EF4B7-B171-44CD-8126-D4EF76814D3F}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{60FE0E9A-8AA5-4E2C-899F-1EAFD0784A65}] => (Allow) D:\Programy\Winamp\winamp.exe
FirewallRules: [{EA63F9C0-3A66-426F-A31B-90B4F1ED16CB}] => (Allow) D:\Programy\Winamp\winamp.exe
FirewallRules: [{2CCC9156-27A8-4872-BE61-02B5CBB9BC4A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{103005EB-1F89-4DE9-994C-E0797AF797BB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{53C24971-C6DC-42F5-981E-5EB36D0F245E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{7CC271F2-FB27-4AA2-8E59-C4E9CBE772A4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{40100EC2-93B1-4D85-A027-8A1A8FE5F705}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{EBEDAC76-BA68-4931-8BC6-CE510CA2911F}] => (Allow) C:\Data\Hry\Steam\Steam.exe
FirewallRules: [{067A4B92-7F22-4921-8764-510212D880B9}] => (Allow) C:\Data\Hry\Steam\Steam.exe
FirewallRules: [{E046AF4B-2F39-481A-ABAB-DAC13FAB0BC0}] => (Allow) C:\Data\Hry\Steam\bin\steamwebhelper.exe
FirewallRules: [{75ADCFD1-0CF8-4706-9560-28D337B8758F}] => (Allow) C:\Data\Hry\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{4C648A13-3926-45F1-A840-EE6CFE01F7A0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{55C20CAA-6F90-440C-AC07-3924227C866E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{3FCE8F96-9AD1-4F7E-8912-107B2A460224}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [UDP Query User{C137616E-8BE4-4ECF-82C0-609B9B1930DD}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [TCP Query User{23043871-4696-46F5-9C21-AAA3C15AE539}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{056D05B4-3199-498B-AC1F-6FC45856D6E3}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [{8FFD2EDA-8043-4EBC-BED8-57BA0CC47C7A}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Armello\armello.exe
FirewallRules: [{2BF6243E-1B76-4D74-97B8-E927A2E87344}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Armello\armello.exe
FirewallRules: [TCP Query User{7CAEE44A-3AE6-4383-8C8C-B153E4BE27F9}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{4B6FA89F-190B-4A09-9391-96C6DBF4D8B5}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{A8827CBA-5541-4A20-8972-18F319BDBA9B}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [UDP Query User{4AEF1A38-9392-48C0-B34A-20D22E2628AC}C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\data\hry\steam\steamapps\common\total war warhammer\warhammer.exe
FirewallRules: [TCP Query User{1117CA93-14EB-4AA2-8133-D128734BD193}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{F6DFA071-63A5-4F35-8076-BC64453C48EB}C:\data\hry\diablo iii\diablo iii.exe] => (Allow) C:\data\hry\diablo iii\diablo iii.exe
FirewallRules: [{5394A299-BEA5-4BAC-A4D2-1540AA24CEB2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E8F0885D-0B3D-412B-B5FE-5B64391288D1}] => (Allow) C:\Data\Hry\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{FEEBDD5F-290C-483D-9E4B-ED76B0D0CD73}] => (Allow) C:\Data\Hry\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [TCP Query User{4248397A-988D-41AF-B13A-44669CC5A010}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [UDP Query User{814D8C5F-E2A0-4C72-92D8-80D3D984A836}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [TCP Query User{4FDF422C-2163-42A9-BB3D-FC2DCCF73486}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [UDP Query User{EC8CACDC-88AB-4AEC-9A33-58E8833BC276}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [TCP Query User{3EB7FDF3-49A5-43FB-AD09-1941C06CB173}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [UDP Query User{9B3AA125-0DA1-496C-B1B8-6815E53C15B5}C:\data\hry\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\data\hry\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [TCP Query User{FDDD2F9B-5C30-4F32-B363-96215267C2EE}C:\data\hry\hearthstone\hearthstone.exe] => (Allow) C:\data\hry\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{1E9C5515-4207-4239-B208-034D0713FF58}C:\data\hry\hearthstone\hearthstone.exe] => (Allow) C:\data\hry\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{561FCDE4-2293-4C41-A72E-684945DA54C1}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [UDP Query User{2FC26ABF-E96E-4E5C-B339-E18BCFF3ED75}C:\data\hry\overwatch\overwatch.exe] => (Allow) C:\data\hry\overwatch\overwatch.exe
FirewallRules: [{70431E78-E848-47C2-A8F3-95336D600315}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Total War WARHAMMER\launcher\launcher.exe
FirewallRules: [{C4E7FB09-B955-4B51-BBC8-DA6A4BA0B021}] => (Allow) C:\Data\Hry\Steam\steamapps\common\Total War WARHAMMER\launcher\launcher.exe
FirewallRules: [TCP Query User{EE3C7745-F59D-4D14-99D4-988205FDF904}D:\programy\torrent\utorrent.exe] => (Allow) D:\programy\torrent\utorrent.exe
FirewallRules: [UDP Query User{AE360EA7-2D07-448F-94B2-8BEA1A8C8B5D}D:\programy\torrent\utorrent.exe] => (Allow) D:\programy\torrent\utorrent.exe
FirewallRules: [{6C78100A-12BD-4E6F-B8EC-8EC3B8389451}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{0F8B5836-6C21-46EC-9FE1-0BD34D1227F6}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe
FirewallRules: [{1732B051-9D30-4A97-B168-AF857E3726B3}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{7CD0B434-167C-4EFD-8F5A-D47B1DEDC061}] => (Allow) C:\Data\Hry\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [TCP Query User{4E3BB76D-C308-416D-8880-637D5020585D}C:\data\hry\divinity - original sin\shipping\eocapp.exe] => (Allow) C:\data\hry\divinity - original sin\shipping\eocapp.exe
FirewallRules: [UDP Query User{A733CA85-35FC-427E-B020-11220B30A757}C:\data\hry\divinity - original sin\shipping\eocapp.exe] => (Allow) C:\data\hry\divinity - original sin\shipping\eocapp.exe
==================== Restore Points =========================
04-07-2016 20:33:06 JRT Pre-Junkware Removal
06-07-2016 17:54:45 zoek.exe restore point
10-07-2016 00:06:56 Avast Cleanup
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/10/2016 01:13:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Aplikaci microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 se nepovedlo aktivovat, protože došlo k chybě: -2144927141. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.
Error: (07/10/2016 03:36:16 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Svazek WINRE_DRV nebyl optimalizován, protože byla zjištěna chyba: Parametr není správný. (0x80070057).
Error: (07/10/2016 12:18:21 AM) (Source: ESENT) (EventID: 104) (User: )
Description: SearchIndexer (4100) Windows: Databázový stroj zastavil instanci (0) s chybou (-510).
Sekvence interního načasování: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.062, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.016, [10] 0.062, [11] 0.000, [12] 0.000, [13] 0.000, [14] 0.000, [15] 0.000.
Error: (07/10/2016 12:18:20 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.
Podrobnosti:
Katalog indexu obsahu je poškozený. 0xc0041801 (0xc0041801)
Error: (07/10/2016 12:18:20 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4810 - enduser\mssearch2\search\ytrip\common\util\jetutil.cpp (540)} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.
Podrobnosti:
0x8e5e01fe (0x8e5e01fe)
Error: (07/10/2016 12:18:17 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (07/10/2016 12:18:17 AM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4811 - enduser\mssearch2\search\search\propstore\propsess.cxx (239)} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.
Podrobnosti:
Databáze indexu obsahu je poškozená. (HRESULT : 0xc0041800) (0xc0041800)
Error: (07/10/2016 12:17:48 AM) (Source: ESENT) (EventID: 492) (User: )
Description: SearchIndexer (4100) Windows: Posloupnost souborů protokolu v C:\ProgramData\Microsoft\Search\Data\Applications\Windows\ byla zastavena. Došlo k závažné chybě. Databáze, které používají tuto posloupnost souborů protokolu, již nelze aktualizovat. Odstraňte potíže a restartujte nebo obnovte databázi ze záložní kopie.
Error: (07/10/2016 12:17:48 AM) (Source: ESENT) (EventID: 418) (User: )
Description: SearchIndexer (4100) Windows: Při otevírání nově vytvořeného souboru protokolu C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.log došlo k chybě -1811 (0xfffff8ed).
Error: (07/09/2016 05:07:03 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
System errors:
=============
Error: (07/11/2016 04:22:14 AM) (Source: iaStorA) (EventID: 4102) (User: )
Description: Error log: Smart event occured on disk :WD-WXD1A154TLV0
Error: (07/10/2016 01:58:07 PM) (Source: iaStorA) (EventID: 4102) (User: )
Description: Error log: Smart event occured on disk :WD-WXD1A154TLV0
Error: (07/10/2016 01:13:06 PM) (Source: DCOM) (EventID: 10010) (User: LENOVO-PC)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (07/10/2016 12:11:37 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/10/2016 12:11:37 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/10/2016 12:04:28 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/10/2016 12:04:27 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/09/2016 06:58:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/09/2016 06:58:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 10. Stav chyby Windows SChannel: 10
Error: (07/09/2016 05:06:59 PM) (Source: iaStorA) (EventID: 4102) (User: )
Description: Error log: Smart event occured on disk :WD-WXD1A154TLV0
CodeIntegrity:
===================================
Date: 2016-06-27 03:04:03.827
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.687
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.577
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.468
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.369
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.275
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.153
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:03.057
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:02.962
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-06-27 03:04:02.853
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4720HQ CPU @ 2.60GHz
Percentage of memory in use: 32%
Total physical RAM: 8104.27 MB
Available physical RAM: 5488.25 MB
Total Virtual: 11176.27 MB
Available Virtual: 8137.95 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:890.3 GB) (Free:588.18 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.47 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 4D6302D9)
Partition: GPT.
==================== End of Addition.txt ============================
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Výkyvy ve výkonu notebooku
Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).
Ulož jej na na plochu jako fixlist.txt
Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
00000000055F Čas na roztočení ploten
Znovu CDI.
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.
Kód: Vybrat vše
Start
CloseProcesses:
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
S3 mfeaack01; \Device\mfeaack01.sys [X]
C:\ProgramData\DP45977C.lfl
C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\User\AppData\Local\Temp\nvStInst.exe
Task: {001A157F-31B2-4D9D-A677-1946945B504B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {02D95D45-C3D6-47A4-9CD5-2355386EACD9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {11C092E2-6763-476C-8CF8-9A1704DE0376} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
EmptyTemp:
End
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).
Ulož jej na na plochu jako fixlist.txt
Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
00000000055F Čas na roztočení ploten
Znovu CDI.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Výkyvy ve výkonu notebooku
Fix result of Farbar Recovery Scan Tool (x64) Version: 10-07-2016 01
Ran by User (2016-07-12 06:39:37) Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
S3 mfeaack01; \Device\mfeaack01.sys [X]
C:\ProgramData\DP45977C.lfl
C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\User\AppData\Local\Temp\nvStInst.exe
Task: {001A157F-31B2-4D9D-A677-1946945B504B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {02D95D45-C3D6-47A4-9CD5-2355386EACD9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {11C092E2-6763-476C-8CF8-9A1704DE0376} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
mfeaack01 => service removed successfully
C:\ProgramData\DP45977C.lfl => moved successfully
"C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll" => not found.
C:\Users\User\AppData\Local\Temp\nvStInst.exe => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{001A157F-31B2-4D9D-A677-1946945B504B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{001A157F-31B2-4D9D-A677-1946945B504B}" => key removed successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02D95D45-C3D6-47A4-9CD5-2355386EACD9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02D95D45-C3D6-47A4-9CD5-2355386EACD9}" => key removed successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11C092E2-6763-476C-8CF8-9A1704DE0376}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11C092E2-6763-476C-8CF8-9A1704DE0376}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OFFICE2013ACT => key not found.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19988112 B
Java, Flash, Steam htmlcache => 380028281 B
Windows/system/drivers => 44478 B
Edge => 0 B
Chrome => 469802993 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 4092 B
NetworkService => 0 B
User => 219361152 B
RecycleBin => 24217839 B
EmptyTemp: => 1 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 06:39:46 ====
v CDI je na času roztočení 00000000056F
Ran by User (2016-07-12 06:39:37) Run:1
Running from C:\Users\User\Desktop
Loaded Profiles: User (Available Profiles: User)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2130949904-3043617627-3509382821-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
S3 mfeaack01; \Device\mfeaack01.sys [X]
C:\ProgramData\DP45977C.lfl
C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\User\AppData\Local\Temp\nvStInst.exe
Task: {001A157F-31B2-4D9D-A677-1946945B504B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {02D95D45-C3D6-47A4-9CD5-2355386EACD9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-10] (Google Inc.)
Task: {11C092E2-6763-476C-8CF8-9A1704DE0376} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-2130949904-3043617627-3509382821-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
mfeaack01 => service removed successfully
C:\ProgramData\DP45977C.lfl => moved successfully
"C:\Users\User\AppData\Local\Temp\nvSCPAPI64.dll" => not found.
C:\Users\User\AppData\Local\Temp\nvStInst.exe => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{001A157F-31B2-4D9D-A677-1946945B504B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{001A157F-31B2-4D9D-A677-1946945B504B}" => key removed successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02D95D45-C3D6-47A4-9CD5-2355386EACD9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02D95D45-C3D6-47A4-9CD5-2355386EACD9}" => key removed successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11C092E2-6763-476C-8CF8-9A1704DE0376}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11C092E2-6763-476C-8CF8-9A1704DE0376}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OFFICE2013ACT => key not found.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19988112 B
Java, Flash, Steam htmlcache => 380028281 B
Windows/system/drivers => 44478 B
Edge => 0 B
Chrome => 469802993 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 4092 B
NetworkService => 0 B
User => 219361152 B
RecycleBin => 24217839 B
EmptyTemp: => 1 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 06:39:46 ====
v CDI je na času roztočení 00000000056F
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Výkyvy ve výkonu notebooku
Spin Up Time
Čas potřebný k roztočení ploten. S časem se zhoršuje, avšak poměrně pomalu. Náhlá změna značí poškození motorku otáčejícího plotny.
údaj se zvyšuje , ale není kritický..
Co problémy? Máš na systémovém disku nejméně 15-20% volného místa?
Čas potřebný k roztočení ploten. S časem se zhoršuje, avšak poměrně pomalu. Náhlá změna značí poškození motorku otáčejícího plotny.
údaj se zvyšuje , ale není kritický..
Co problémy? Máš na systémovém disku nejméně 15-20% volného místa?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Výkyvy ve výkonu notebooku
mám tam 60% volného místa.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Výkyvy ve výkonu notebooku
Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Výkyvy ve výkonu notebooku
Zatím nic, zkoušel jsem dneska i chvilku náročnější aplikace. zatím v pohodě.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Výkyvy ve výkonu notebooku
Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/
ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci
Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
https://toolslib.net/downloads/viewdownload/2-delfix/
ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci
Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Kdo je online
Uživatelé prohlížející si toto fórum: Google [Bot] a 101 hostů