﻿Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-08-2015
Ran by Marketa (administrator) on MARKETA-PC (02-09-2015 17:50:12)
Running from D:\Users\Marketa\Desktop
Loaded Profiles: Marketa (Available Profiles: Marketa & ADMIN & Guest)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Lenovo) C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe
(Intel Corporation) C:\Program Files\Intel\Bluetooth\devmonsrv.exe
() C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489\hnsp540A.tmp
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489\jnsp2E40.tmp
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(DTools LIMITED) C:\ProgramData\9WdsManPro9\WdsManPro.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo) C:\Program Files\Lenovo\Access Connections\AcSvc.exe
(Intel Corporation) C:\Program Files\Intel\Bluetooth\obexsrv.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(http://lucky-tab.com/) C:\Program Files\LuckyTab\LuckyTab.exe
() C:\Users\Marketa\AppData\Local\DailyPcClean Support\updpcc_en_009010077.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Intel Corporation) C:\Program Files\Intel\Bluetooth\BleServicesCtrl.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Vimicro) C:\Program Files\USB Camera\VM331STI.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(GoPro) C:\Program Files\GoPro\Tools\Importer\GoPro Importer.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Corporation) C:\Users\Marketa\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\baidu\pps.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Intel Corporation) C:\Program Files\Intel\Bluetooth\mediasrv.exe
(Lenovo Group Limited) C:\Program Files\ThinkPad\Utilities\SCHTASK.EXE
(Intel Corporation) C:\Program Files\Intel\Bluetooth\btplayerctrl.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Lenovo) C:\Program Files\Lenovo\Access Connections\SvcGuiHlpr.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(TODO: <公司名>) C:\Program Files\SFK\SSFK.exe
() C:\Program Files\SFK\SFKEX.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489\knsu2B8D.tmp
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [ResetACGauge] => C:\Program Files\Lenovo\Access Connections\smbhlpr.exe [147456 2014-03-14] (Lenovo)
HKLM\...\Run: [AcWin7Hlpr] => C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe [63832 2014-03-14] (Lenovo)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [180224 2012-06-21] (Lenovo.)
HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-26] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2358584 2012-06-19] (Synaptics Incorporated)
HKLM\...\Run: [PWMTRV] => rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-29] (Microsoft Corporation)
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [60920 2013-02-26] (Lenovo Group Limited)
HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files\Intel\Bluetooth\BleServicesCtrl.exe [152336 2012-02-17] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [331BigDog] => C:\Program Files\USB Camera\VM331STI.EXE [548864 2011-11-24] (Vimicro)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-05-09] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1013616 2014-05-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1013616 2014-05-13] (Realtek Semiconductor)
HKLM\...\Run: [mbot_es_362] => [X]
HKLM\...\Run: [gpuminer] => C:\Users\Marketa\AppData\Roaming\cpuminer\sgminer\sgminer.cmd [96 2015-05-02] ()
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [GoPro Studio Importer] => C:\Program Files\GoPro\Tools\Importer\GoPro Importer.exe [3217672 2015-07-02] (GoPro)
HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe"
HKLM\...\Run: [gmsd_br_005010077] => [X]
HKLM\...\Run: [prtstart] => C:\Program Files\shopperz300820151717\dr_inst.exe url=aHR0cDovL2Nkcy5zNm01bTlkNy5od2Nkbi5uZXQvYWRkb25fNC9wci8zMDA4MjAxNS8vcHJjMzIuZXhl lpath=QzpcUHJvZ3JhbSBGaWxlc1xzaG9wcGVyejMwMDgyMDE1MTcxN1xwcmMuZXh (the data entry has 24 more characters).
HKLM\...\Run: [gmsd_br_005010078] => [X]
HKLM\...\RunOnce: [updpcc_en_009010077.exe] => C:\Users\Marketa\AppData\Local\DailyPcClean Support\updpcc_en_009010077.exe [3312784 2015-09-01] ()
HKLM\...\RunOnce: [Update] => C:\Users\Marketa\AppData\Roaming\VOPackage\VOPackage.exe /runonce
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [WindApp] => "C:\Users\Marketa\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [Selection Tools] => "C:\Users\Marketa\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe" /winstartup
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [OneDrive] => C:\Users\Marketa\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-20] (Microsoft Corporation)
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2015-03-18] (Microsoft Corporation)
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [apphide] => C:\Program Files\baidu\pps.exe [77824 2015-08-11] ()
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [53737488 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\...\RunOnce: [Application Restart #4] => C:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-08-18] (Google Inc.)
Lsa: [Notification Packages] scecli ACGina
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2015-03-13]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\Marketa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2013-01-10]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog9 01 C:\Windows\system32\Siybbud.dll [283504 2015-09-01] ()
Winsock: Catalog9 02 C:\Windows\system32\Siybbud.dll [283504 2015-09-01] ()
Winsock: Catalog9 03 C:\Windows\system32\Siybbud.dll [283504 2015-09-01] ()
Winsock: Catalog9 04 C:\Windows\system32\Siybbud.dll [283504 2015-09-01] ()
Winsock: Catalog9 42 C:\Windows\system32\Siybbud.dll [283504 2015-09-01] ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 201.17.0.80 201.17.0.120
Tcpip\..\Interfaces\{419CC682-0491-4D70-AFB6-81A4453EB92F}: [DhcpNameServer] 201.17.0.80 201.17.0.120

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1439583935&z=33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1439583935&z=33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX&q={searchTerms}
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1439583935&z=33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX&q={searchTerms}
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=cs-CZ&Src=MSE&Tid=0003446E&OHP=http%3A%2F%2Fwww.mystartsearch.com%2F%3Ftype%3Dhp%26ts%3D1439583935%26z%3D33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee%26from%3Dcmi%26uid%3DHITACHIXHTS545050A7E380%5FTA95113VGJ3VBSGJ3VBSX&OSP=http%3A%2F%2Fwww.mystartsearch.com%2Fweb%2F%3Ftype%3Dds%26ts%3D1439583935%26z%3D33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee%26from%3Dcmi%26uid%3DHITACHIXHTS545050A7E380%5FTA95113VGJ3VBSGJ3VBSX%26q%3D%7BsearchTerms%7D
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-21-3439579005-2339205203-1695108522-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1439583935&z=33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX
URLSearchHook: HKLM -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
SearchScopes: HKU\S-1-5-21-3439579005-2339205203-1695108522-1000 -> {407BEB8C-F784-4ED7-8E9C-4CB02EA8BFEC} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
BHO: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} ->  No File
BHO: No Name -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} ->  No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
DPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cab
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1423315013&from=exp&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX

FireFox:
========
FF ProfilePath: C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923
FF NewTab: hxxp://www.delta-homes.com/newtab/?type=nt&ts=1432150310&z=8daacc54afab738128c3544gdzec1o4g5wce2c6g1g&from=wpm05203&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX
FF SelectedSearchEngine: webssearches
FF Homepage: hxxp://www.delta-homes.com/?type=hp&ts=1432150310&z=8daacc54afab738128c3544gdzec1o4g5wce2c6g1g&from=wpm05203&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-30] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-30] (Google Inc.)
FF user.js: detected! => C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\user.js [2015-09-01]
FF SearchPlugin: C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\searchplugins\delta-homes.xml [2015-05-20]
FF Extension: FF Toolbar - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\fftoolbar2014@etech.com [2015-03-13]
FF Extension: QuickSearch - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\quick_searchff@gmail.com [2015-05-20]
FF Extension: Search Enginer - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\sweetsearch@gmail.com [2015-05-20]
FF Extension: Mozilla Firefox Hotfixer - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\veggy@veggyAddon.com [2015-05-20]
FF Extension: Zoom It - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\{5e8e14f1-ca7f-892e-f4c8-db890edf44f6} [2015-05-20]
FF Extension: Web Protector - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\{a1ec290a-8ad8-c41a-855e-38572413c1aa} [2015-05-09]
FF Extension: Adblock Plus - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-18]
FF Extension: MP3Tube Toolbar - C:\Program Files\Mozilla Firefox\extensions\mp3tubetoolbar@mp3tubetoolbar.com [2015-03-05]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]
FF HKLM\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\extensions\fftoolbar2014@etech.com
FF HKLM\...\Firefox\Extensions: [{5081D2D4-1637-404c-B74F-50526718257D}] - C:\Program Files\shopperz\Firefox
FF HKLM\...\Firefox\Extensions: [quick_searchff@gmail.com] - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\extensions\quick_searchff@gmail.com
FF HKLM\...\Firefox\Extensions: [sweetsearch@gmail.com] - C:\Users\Marketa\AppData\Roaming\Mozilla\Firefox\Profiles\pa14tznl.default-1418815034923\extensions\sweetsearch@gmail.com
FF HKLM\...\Firefox\Extensions: [{0420BEC0-F2C1-4578-8F19-471B9E5C63A5}] - C:\Program Files\shopperz240820151333\Firefox
FF HKLM\...\Firefox\Extensions: [{8152CFEC-06C1-4BA3-95C2-AD1A8E15AD1D}] - C:\Program Files\shopperz300820151717\Firefox

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.mystartsearch.com/?type=hp&ts=1439221466&z=e771d28074912908ccf7e0fgfz4c6t3ofo8gfc8bem&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX","hxxp://www.mystartsearch.com/?type=hp&ts=1439449859&z=d3da56953daa049dd8a8941gazec1t0z7zct8mcmcq&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX","hxxp://www.mystartsearch.com/?type=hp&ts=1439583935&z=33be6d1fa1e70e7baa70d4fgdzbcftaw6bbcab6wee&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX","hxxp://www.mystartsearch.com/?type=hp&ts=1440104547&z=e57a0700b81acb84da8a9bdg3z7zfefgee0z7zbzaq&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX","hxxp://www.mystartsearch.com/?type=hp&ts=1440618917&z=e90816b7a97845e829c4754gczbzaeaq8g9b1b2e0e&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX","hxxp://www.mystartsearch.com/?type=hp&ts=1440970102&z=439d2fb73014696bd7d568eg1zbz7e8t5q2tet7m5c&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX","hxxp://www.mystartsearch.com/?type=hp&ts=1441142878&z=47e90b2f86e1567deb59f23g2z6z6gfg4z5o7m0zbb&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-22]
CHR Extension: (Google Docs) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-22]
CHR Extension: (Google Drive) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-22]
CHR Extension: (YouTube) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-22]
CHR Extension: (Adblock Plus) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-03-22]
CHR Extension: (Google Search) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-22]
CHR Extension: (Google Sheets) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-22]
CHR Extension: (AdBlock) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-08-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-22]
CHR Extension: (Gmail) - C:\Users\Marketa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-22]
StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe http://www.mystartsearch.com/?type=sc&ts=1441219888&z=bfe7edad465f23923ad7a58g6z4z6geodg8t6m5w9w&from=cmi&uid=HITACHIXHTS545050A7E380_TA95113VGJ3VBSGJ3VBSX

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AcPrfMgrSvc; C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe [133464 2014-03-14] (Lenovo)
R2 AcSvc; C:\Program Files\Lenovo\Access Connections\AcSvc.exe [272728 2014-03-14] (Lenovo)
R2 Bluetooth Device Monitor; C:\Program Files\Intel\Bluetooth\devmonsrv.exe [1014096 2012-02-21] (Intel Corporation)
R3 Bluetooth Media Service; C:\Program Files\Intel\Bluetooth\mediasrv.exe [1304912 2012-02-21] (Intel Corporation)
R2 Bluetooth OBEX Service; C:\Program Files\Intel\Bluetooth\obexsrv.exe [1104208 2012-02-21] (Intel Corporation)
R2 comyninu; C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489\hnsp540A.tmp [161792 2015-08-10] () [File not signed]
S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [276248 2012-03-08] (Intel Corporation)
R2 hyverumu; C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489\jnsp2E40.tmp [209920 2015-08-10] () [File not signed]
R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1799272 2011-12-07] (Realsil Microelectronics Inc.)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [458464 2012-02-02] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-06] ()
R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation)
R2 LENOVO.CAMMUTE; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [44024 2013-02-26] (Lenovo Group Limited)
R2 LENOVO.TPKNRSVC; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [62456 2013-02-26] (Lenovo Group Limited)
R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [179568 2012-06-01] (Lenovo Group Limited)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [127336 2011-07-12] (Lenovo Group Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272440 2015-03-09] (Lenovo)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-29] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [241936 2012-02-26] ()
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-29] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [52736 2006-05-11] (Hewlett-Packard) [File not signed]
S3 PwmEWSvc; C:\Program Files\ThinkPad\Utilities\PWMEWSVC.EXE [1665120 2012-05-16] (Lenovo Group Limited)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 SSFK; C:\Program Files\SFK\SSFK.exe [411648 2015-09-02] (TODO: <公司名>) [File not signed]
R4 WdsManPro; C:\ProgramData\9WdsManPro9\WdsManPro.exe [709288 2015-09-01] (DTools LIMITED)
R2 wikuholy; C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489\knsu2B8D.tmp [1343488 2015-09-02] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2324752 2012-02-26] (Intel® Corporation)
S2 qudutepi; C:\Users\Marketa\AppData\Roaming\VOPackage\nsr3A70.tmpfs [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 bsdriver; C:\Windows\system32\drivers\bsdriver.sys [30112 2015-08-30] ()
R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [76800 2011-11-30] (Intel Corporation)
R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [558592 2011-11-30] (Intel Corporation)
R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [56480 2015-08-20] (Cherimoya Ltd)
R1 ElRawDisk; C:\Windows\system32\drivers\rsdrv.sys [22312 2009-02-12] (EldoS Corporation)
R3 ibtfltcoex; C:\Windows\System32\DRIVERS\iBtFltCoex.sys [48128 2012-02-14] (Intel Corporation)
R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [15640 2012-03-26] (Intel Corporation)
R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [349976 2012-03-26] (Intel Corporation)
R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [792856 2012-03-26] (Intel Corporation)
S3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH) [File not signed]
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-17] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R3 NETwNs32; C:\Windows\System32\DRIVERS\Netwsn00.sys [10339840 2012-02-20] (Intel Corporation)
R3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [254096 2012-05-16] (Realtek Semiconductor Corp.)
R3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [23608 2012-06-19] (Synaptics Incorporated)
R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [24872 2011-12-07] (ThinkVantage Communications Utility)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [924160 2012-02-29] (Vimicro Corporation)
S3 vmcam325av; C:\Windows\System32\Drivers\vmcam323av.sys [232448 2014-07-04] (Vimicro Corporation)
S3 vvftav323; C:\Windows\System32\drivers\vvftav323.sys [475136 2014-07-04] (Vimicro Corporation)
S1 wsafd_1_10_0_19; system32\drivers\wsafd_1_10_0_19.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-02 17:45 - 2015-09-02 17:47 - 00029696 _____ C:\Users\Marketa\AppData\Local\MSGBOX.EXE
2015-09-02 17:33 - 2015-09-02 17:50 - 00000000 ____D C:\FRST
2015-09-02 16:00 - 2015-09-02 16:00 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsg5018.tmp
2015-09-02 15:52 - 2015-09-02 15:52 - 00000000 ____D C:\ProgramData\OWdsManProO
2015-09-02 15:17 - 2015-09-02 15:17 - 00154504 _____ C:\Windows\Minidump\090215-19593-01.dmp
2015-09-01 19:55 - 2015-09-01 19:55 - 00000020 ___SH C:\Users\Marketa\ntuser.ini
2015-09-01 19:49 - 2015-09-01 19:50 - 00000000 ____D C:\ProgramData\9WdsManPro9
2015-09-01 19:22 - 2015-09-01 19:22 - 00000000 ____D C:\Program Files\predm
2015-09-01 19:12 - 2015-09-01 19:12 - 00131072 ____N C:\Windows\Minidump\090115-17300-01.dmp
2015-09-01 19:07 - 2015-09-01 19:17 - 00004744 _____ C:\Windows\system32\Siybbud.ini
2015-09-01 19:07 - 2015-09-01 19:17 - 00002464 _____ C:\Windows\system32\SiybbudOff.ini
2015-09-01 19:07 - 2015-08-30 11:19 - 00283504 _____ C:\Windows\system32\Siybbud.dll
2015-09-01 19:06 - 2015-09-01 19:18 - 00000000 ____D C:\Program Files\shopperz300820151717
2015-09-01 19:06 - 2015-08-20 11:46 - 00056480 _____ (Cherimoya Ltd) C:\Windows\system32\Drivers\cherimoya.sys
2015-09-01 19:05 - 2015-09-01 19:05 - 00005406 _____ C:\claraInstaller.txt
2015-09-01 18:59 - 2015-09-01 18:59 - 00000000 ___HD C:\OneDriveTemp
2015-09-01 18:42 - 2015-09-01 18:42 - 00000270 __RSH C:\ProgramData\ntuser.pol
2015-09-01 18:36 - 2015-09-01 18:36 - 00131072 ____N C:\Windows\Minidump\090115-19188-01.dmp
2015-09-01 18:30 - 2015-09-02 15:28 - 00000000 ____D C:\Users\Marketa\AppData\Local\DailyPcClean Support
2015-09-01 18:30 - 2015-09-02 09:42 - 00000000 ____D C:\Program Files\DailyPcClean Support
2015-09-01 18:30 - 2015-09-02 09:42 - 00000000 ____D C:\Program Files\DailyPCClean
2015-09-01 18:30 - 2015-09-01 18:42 - 00000000 ____D C:\Program Files\UPCleaner
2015-09-01 18:28 - 2015-09-02 15:52 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\mystartsearch
2015-09-01 18:28 - 2015-09-01 18:29 - 00000000 ____D C:\ProgramData\tWdsManProt
2015-08-31 02:20 - 2015-08-31 02:20 - 00000000 _____ C:\DC49.tmp
2015-08-30 18:37 - 2015-08-30 18:37 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsp1CB2.tmp
2015-08-30 18:34 - 2015-08-30 18:34 - 00030112 _____ () C:\Windows\system32\Drivers\bsdriver.sys
2015-08-30 18:31 - 2015-08-30 18:31 - 00000000 ____D C:\Windows\system32\abis
2015-08-30 18:30 - 2015-08-30 18:34 - 00000000 ____D C:\Program Files\shopperz240820151333
2015-08-30 18:30 - 2015-08-30 18:31 - 00000000 ____D C:\ProgramData\lWdsManProl
2015-08-30 18:29 - 2015-08-30 18:32 - 00000000 ____D C:\Users\Marketa\AppData\Local\SmartWeb
2015-08-26 16:57 - 2015-08-26 16:57 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsh1B07.tmp
2015-08-26 16:56 - 2015-09-02 15:53 - 00000000 ____D C:\Program Files\SFK
2015-08-26 16:56 - 2015-09-02 15:52 - 00000102 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-08-26 16:56 - 2015-08-28 22:50 - 00000000 ____D C:\ProgramData\iWinManProi
2015-08-26 13:04 - 2015-08-10 21:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-26 13:04 - 2015-08-10 21:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-21 14:36 - 2015-08-21 15:28 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\GoPro
2015-08-21 14:36 - 2015-08-21 14:36 - 00000000 ____D C:\Users\Marketa\AppData\Local\GoPro
2015-08-21 14:33 - 2015-08-21 14:45 - 00000000 ____D C:\Users\Public\CineForm
2015-08-21 14:32 - 2015-08-21 14:32 - 00000780 _____ C:\Users\Public\Desktop\GoPro Studio.lnk
2015-08-21 14:32 - 2015-08-21 14:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoPro
2015-08-21 14:32 - 2015-08-21 14:32 - 00000000 ____D C:\Program Files\GoPro
2015-08-21 14:32 - 2015-08-21 14:32 - 00000000 ____D C:\Program Files\CineForm
2015-08-20 18:15 - 2015-08-20 18:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-20 18:15 - 2015-08-20 18:15 - 00000000 ____D C:\Program Files\Common Files\Skype
2015-08-20 18:05 - 2015-08-20 18:05 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsr28CF.tmp
2015-08-14 17:27 - 2015-08-14 17:27 - 00000000 ____D C:\Program Files\baidu
2015-08-14 17:24 - 2015-08-14 17:24 - 00000217 _____ C:\task.vbs
2015-08-14 04:23 - 2015-08-14 04:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-08-13 17:48 - 2009-06-10 18:39 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.20150813-224833.backup
2015-08-13 17:27 - 2015-08-13 17:27 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsx3E62.tmp
2015-08-13 17:25 - 2015-08-20 04:21 - 00000000 ____D C:\ProgramData\2WinManPro2
2015-08-13 16:52 - 2015-08-13 16:52 - 00131072 ____N C:\Windows\Minidump\081315-20716-01.dmp
2015-08-13 10:39 - 2015-08-13 17:28 - 00057426 _____ C:\Windows\wininit.ini
2015-08-13 10:39 - 2015-08-13 10:39 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsvC0DA.tmp
2015-08-13 10:29 - 2015-08-20 04:21 - 00000000 ____D C:\ProgramData\9WinManPro9
2015-08-13 10:21 - 2015-08-13 10:21 - 00000000 ____D C:\Program Files\Common Files\AV
2015-08-13 10:21 - 2015-07-28 12:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2015-08-13 10:09 - 2015-08-24 12:12 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2015-08-13 10:09 - 2015-08-13 17:34 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-08-13 10:09 - 2015-08-13 10:09 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-08-13 10:09 - 2015-08-13 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-08-13 10:09 - 2013-09-20 05:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2015-08-13 07:12 - 2015-09-02 17:12 - 00003130 _____ C:\Windows\Tasks\891dcc30-c117-4420-adc0-97a8b763a1db-1-6.job
2015-08-13 07:12 - 2015-09-02 15:25 - 00003130 _____ C:\Windows\Tasks\891dcc30-c117-4420-adc0-97a8b763a1db-1-7.job
2015-08-13 07:12 - 2015-09-02 15:25 - 00002438 _____ C:\Windows\Tasks\891dcc30-c117-4420-adc0-97a8b763a1db-5_user.job
2015-08-13 07:12 - 2015-09-02 15:25 - 00002438 _____ C:\Windows\Tasks\891dcc30-c117-4420-adc0-97a8b763a1db-5.job
2015-08-13 04:11 - 2015-08-20 04:21 - 00000000 ____D C:\ProgramData\6WinManPro6
2015-08-13 03:22 - 2015-07-30 10:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-12 04:55 - 2015-08-12 04:55 - 00000000 ____D C:\Quarantine
2015-08-12 04:40 - 2015-08-12 05:31 - 00000000 ____D C:\Program Files\stinger
2015-08-12 04:38 - 2015-08-12 04:38 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsrA36F.tmp
2015-08-12 04:37 - 2015-09-02 15:37 - 00002404 _____ C:\Windows\Tasks\5bb39839-2498-4eaa-838f-b0a760f3181e-5_user.job
2015-08-12 04:37 - 2015-09-02 15:37 - 00002404 _____ C:\Windows\Tasks\5bb39839-2498-4eaa-838f-b0a760f3181e-5.job
2015-08-12 04:34 - 2015-08-13 10:36 - 00000000 ____D C:\Program Files\RCP
2015-08-12 04:28 - 2015-07-28 17:04 - 00015808 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-12 04:28 - 2015-07-28 17:00 - 00952832 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-12 04:28 - 2015-07-28 17:00 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-12 04:28 - 2015-07-28 17:00 - 00598528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-12 04:28 - 2015-07-28 17:00 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-12 04:28 - 2015-07-28 17:00 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-12 04:28 - 2015-07-28 17:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-12 04:28 - 2015-07-28 16:54 - 00934400 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 02943488 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 02061312 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-12 04:28 - 2015-07-20 14:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-12 04:28 - 2015-07-20 14:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-12 04:28 - 2015-07-20 14:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-12 04:28 - 2015-07-15 14:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-12 04:28 - 2015-07-14 23:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-12 04:28 - 2015-07-14 23:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-12 04:28 - 2015-07-14 23:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-12 04:28 - 2015-07-14 23:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-12 04:28 - 2015-07-09 14:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-12 04:28 - 2015-07-09 14:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-12 04:28 - 2015-07-01 17:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-12 04:28 - 2015-07-01 17:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-12 04:27 - 2015-07-15 14:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-08-12 04:27 - 2015-07-15 14:59 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-12 04:27 - 2015-07-15 14:59 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-12 04:27 - 2015-07-15 14:59 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-12 04:27 - 2015-07-15 14:56 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-12 04:27 - 2015-07-15 14:55 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-12 04:27 - 2015-07-15 14:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-12 04:27 - 2015-07-15 14:54 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-12 04:27 - 2015-07-15 14:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-12 04:27 - 2015-07-15 14:54 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-12 04:27 - 2015-07-15 14:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-12 04:27 - 2015-07-15 14:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-12 04:27 - 2015-07-15 14:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-12 04:27 - 2015-07-15 14:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-12 04:27 - 2015-07-15 14:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-12 04:27 - 2015-07-15 13:36 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-12 04:27 - 2015-07-15 13:36 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-12 04:27 - 2015-07-15 13:36 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-12 04:25 - 2015-07-30 14:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-12 04:25 - 2015-07-30 14:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-12 04:25 - 2015-07-30 14:57 - 00909824 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-12 04:25 - 2015-07-30 14:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-12 04:25 - 2015-07-30 14:57 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-12 04:25 - 2015-07-30 14:57 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-12 04:25 - 2015-07-30 14:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-12 04:25 - 2015-07-30 13:52 - 02384384 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-12 04:25 - 2015-07-30 13:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-12 04:25 - 2015-07-20 21:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-12 04:25 - 2015-07-16 16:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-12 04:25 - 2015-07-16 16:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-12 04:25 - 2015-07-16 16:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-12 04:25 - 2015-07-16 16:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-12 04:25 - 2015-07-16 16:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-12 04:25 - 2015-07-16 16:39 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-12 04:25 - 2015-07-16 16:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-12 04:25 - 2015-07-16 16:32 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-12 04:25 - 2015-07-16 16:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-12 04:25 - 2015-07-16 16:12 - 06131200 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-12 04:25 - 2015-07-16 16:12 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-08-12 04:25 - 2015-07-16 16:12 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-12 04:25 - 2015-07-16 16:06 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-12 04:25 - 2015-07-16 15:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-12 04:25 - 2015-07-16 12:14 - 00355840 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-08-12 04:24 - 2015-07-16 17:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-12 04:24 - 2015-07-16 16:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-12 04:24 - 2015-07-16 16:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-12 04:24 - 2015-07-16 16:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-12 04:24 - 2015-07-16 16:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-12 04:24 - 2015-07-16 16:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-12 04:24 - 2015-07-16 16:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-12 04:24 - 2015-07-16 16:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-12 04:24 - 2015-07-16 16:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-12 04:24 - 2015-07-16 16:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-12 04:24 - 2015-07-16 16:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-12 04:24 - 2015-07-16 16:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-12 04:24 - 2015-07-16 16:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-12 04:24 - 2015-07-16 16:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-12 04:24 - 2015-07-16 16:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-12 04:24 - 2015-07-16 16:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-12 04:24 - 2015-07-16 15:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-12 04:24 - 2015-07-16 15:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-12 04:24 - 2015-07-10 14:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-12 04:24 - 2015-05-09 15:09 - 00715200 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-12 04:23 - 2015-08-12 04:26 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\Opera Software
2015-08-12 04:23 - 2015-08-12 04:26 - 00000000 ____D C:\Users\Marketa\AppData\Local\Opera Software
2015-08-12 04:23 - 2015-07-14 23:55 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-10 13:46 - 2015-09-01 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-10 13:45 - 2015-09-02 16:56 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-10 13:45 - 2015-09-02 15:25 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-10 13:36 - 2015-09-02 16:06 - 00000366 _____ C:\Windows\Tasks\APSnotifierPP1.job
2015-08-10 13:36 - 2015-09-02 16:06 - 00000364 _____ C:\Windows\Tasks\APSnotifierPP3.job
2015-08-10 13:36 - 2015-09-02 16:06 - 00000364 _____ C:\Windows\Tasks\APSnotifierPP2.job
2015-08-10 13:35 - 2015-08-10 13:35 - 00613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsr27E9.tmp
2015-08-10 13:35 - 2015-08-10 13:35 - 00001998 _____ C:\Windows\Tasks\temp_ebfcfff9-7822-4bc7-b7b7-6c86ee886f55-10_user.job
2015-08-10 13:35 - 2015-08-10 13:35 - 00000000 __SHD C:\Users\Marketa\AppData\Roaming\AnyProtectEx
2015-08-10 13:31 - 2015-08-13 17:27 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\systweak
2015-08-10 13:05 - 2015-09-02 15:25 - 00002438 _____ C:\Windows\Tasks\ff57ecdf-89e4-4c3f-881a-33047fd86661-5_user.job
2015-08-10 13:05 - 2015-09-02 15:25 - 00002438 _____ C:\Windows\Tasks\ff57ecdf-89e4-4c3f-881a-33047fd86661-5.job
2015-08-10 13:03 - 2015-08-10 13:03 - 00000000 ____D C:\Users\Guest\AppData\Local\Crossbrowse
2015-08-10 12:58 - 2015-08-10 13:04 - 00000000 ____D C:\Program Files\Seznam.cz
2015-08-10 12:57 - 2015-08-10 13:04 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\Seznam.cz
2015-08-10 12:45 - 2015-08-20 04:21 - 00000000 ____D C:\ProgramData\UWinManProU
2015-08-10 12:45 - 2015-08-10 13:22 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\cpuminer
2015-08-10 12:45 - 2015-08-10 12:45 - 00000000 _____ C:\Windows\prleth.sys
2015-08-10 12:45 - 2015-08-10 12:45 - 00000000 _____ C:\Windows\hgfs.sys
2015-08-10 12:34 - 2015-08-10 12:55 - 00000000 ____D C:\Users\Marketa\AppData\Local\8A264F81-1439228080-11CB-9639-E89C0F4F1489
2015-08-10 12:33 - 2009-06-10 18:39 - 00000824 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-08-10 12:32 - 2015-09-02 17:18 - 00000000 ____D C:\Program Files\8A264F81-1439220725-11CB-9639-E89C0F4F1489
2015-08-10 09:21 - 2015-08-13 10:42 - 00000000 ____D C:\Program Files\globalUpdate
2015-08-10 09:21 - 2015-08-13 10:37 - 00000004 _____ C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-08-10 09:21 - 2015-08-10 09:21 - 00000000 ____D C:\Users\Marketa\AppData\Local\globalUpdate

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-02 17:44 - 2012-09-08 05:57 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\Skype
2015-09-02 17:39 - 2012-09-09 05:39 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-02 17:09 - 2012-09-03 17:16 - 01978937 _____ C:\Windows\WindowsUpdate.log
2015-09-02 16:03 - 2009-07-13 23:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-02 15:46 - 2009-07-14 01:34 - 00022656 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-02 15:46 - 2009-07-14 01:34 - 00022656 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-02 15:35 - 2009-07-14 01:39 - 00220974 _____ C:\Windows\setupact.log
2015-09-02 15:25 - 2012-09-04 05:49 - 00000000 ____D C:\Users\Marketa\SkyDrive
2015-09-02 15:25 - 2012-09-03 11:30 - 01593150 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-02 15:17 - 2012-12-02 11:35 - 272710210 _____ C:\Windows\MEMORY.DMP
2015-09-02 15:17 - 2012-12-02 11:35 - 00000000 ____D C:\Windows\Minidump
2015-09-02 15:17 - 2012-09-03 12:51 - 00379942 _____ C:\Windows\PFRO.log
2015-09-02 15:17 - 2009-07-14 01:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-02 09:43 - 2012-09-13 11:00 - 00000000 ____D C:\Users\Marketa\AppData\Local\CrashDumps
2015-09-01 19:55 - 2012-09-03 11:25 - 00000000 ____D C:\Users\Marketa
2015-09-01 18:58 - 2009-07-14 01:53 - 00032538 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-01 18:31 - 2009-07-13 23:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-08-31 10:01 - 2014-12-13 17:38 - 00000000 ____D C:\Users\ADMIN
2015-08-31 10:01 - 2012-11-03 12:47 - 00000000 ____D C:\Users\Guest
2015-08-30 18:31 - 2012-09-03 14:16 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-08-21 14:33 - 2015-06-18 16:00 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-21 14:33 - 2009-07-13 23:37 - 00000000 ___RD C:\Users\Public
2015-08-20 18:15 - 2014-10-18 06:51 - 00000000 ___RD C:\Program Files\Skype
2015-08-20 18:15 - 2012-09-08 05:57 - 00000000 ____D C:\ProgramData\Skype
2015-08-20 11:28 - 2014-02-20 06:49 - 00002200 _____ C:\Users\Marketa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-08-20 10:15 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\system32\NDF
2015-08-13 17:28 - 2012-09-16 07:14 - 00000000 ____D C:\Users\Marketa\AppData\Roaming\Foxit Software
2015-08-13 10:39 - 2012-09-06 05:21 - 00000000 ____D C:\Program Files\7-Zip
2015-08-13 05:02 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\rescache
2015-08-13 04:31 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-08-13 04:24 - 2009-07-14 01:33 - 00594904 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-13 04:21 - 2014-12-12 23:31 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-13 04:21 - 2014-05-07 04:03 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-13 04:03 - 2012-09-03 12:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 03:55 - 2013-08-15 05:59 - 00000000 ____D C:\Windows\system32\MRT
2015-08-13 03:40 - 2012-09-03 16:23 - 129304528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-13 03:24 - 2009-07-13 23:04 - 00000478 _____ C:\Windows\win.ini
2015-08-12 15:39 - 2012-09-09 05:39 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-12 15:39 - 2012-09-09 05:39 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-12 03:42 - 2012-09-03 13:42 - 00000000 ____D C:\Users\Marketa\AppData\Local\Google
2015-08-10 13:46 - 2012-09-06 05:41 - 00000000 ____D C:\Program Files\Google
2015-08-10 13:45 - 2012-09-03 13:42 - 00000000 ____D C:\Users\Marketa\AppData\Local\Deployment
2015-08-10 13:42 - 2014-11-29 13:23 - 00000000 __SHD C:\Users\Marketa\AppData\Local\EmieUserList
2015-08-10 13:42 - 2014-11-29 13:23 - 00000000 __SHD C:\Users\Marketa\AppData\Local\EmieSiteList
2015-08-10 13:42 - 2014-11-29 13:23 - 00000000 __SHD C:\Users\Marketa\AppData\Local\EmieBrowserModeList
2015-08-10 13:04 - 2013-12-22 07:25 - 00000000 ____D C:\Program Files\3M
2015-08-07 16:20 - 2012-09-03 12:21 - 00000000 ___HD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2015-08-07 16:20 - 2012-09-03 12:20 - 00000000 ____D C:\Program Files\Lenovo
2015-08-07 16:19 - 2012-09-03 13:17 - 00000000 ____D C:\ProgramData\Lenovo

==================== Files in the root of some directories =======

2014-10-18 00:02 - 2014-10-18 00:02 - 6000640 _____ () C:\Program Files\GUT9D6B.tmp
2015-02-08 15:14 - 2015-02-08 15:54 - 0001267 _____ () C:\Users\Marketa\AppData\Roaming\Bubble Dock.boostrap.log
2015-02-08 15:14 - 2015-02-08 15:25 - 0005211 _____ () C:\Users\Marketa\AppData\Roaming\Bubble Dock.installation.log
2015-02-08 15:40 - 2015-02-08 15:40 - 0000078 _____ () C:\Users\Marketa\AppData\Roaming\Selection Tools.installation.log
2015-02-08 15:31 - 2015-02-08 15:31 - 0000078 _____ () C:\Users\Marketa\AppData\Roaming\WindApp.installation.log
2015-02-08 15:14 - 2015-02-08 15:14 - 0000097 _____ () C:\Users\Marketa\AppData\Roaming\WOffer.boostrap.log
2013-06-14 09:13 - 2013-06-14 17:24 - 0006144 _____ () C:\Users\Marketa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-09-02 17:45 - 2015-09-02 17:47 - 0029696 _____ () C:\Users\Marketa\AppData\Local\MSGBOX.EXE
2015-09-02 16:00 - 2015-09-02 16:00 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsg5018.tmp
2015-08-26 16:57 - 2015-08-26 16:57 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsh1B07.tmp
2015-08-30 18:37 - 2015-08-30 18:37 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsp1CB2.tmp
2015-08-10 13:35 - 2015-08-10 13:35 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsr27E9.tmp
2015-08-20 18:05 - 2015-08-20 18:05 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsr28CF.tmp
2015-08-12 04:38 - 2015-08-12 04:38 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsrA36F.tmp
2015-08-13 10:39 - 2015-08-13 10:39 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsvC0DA.tmp
2015-08-13 17:27 - 2015-08-13 17:27 - 0613255 _____ (CMI Limited) C:\Users\Marketa\AppData\Local\nsx3E62.tmp
2015-07-30 16:05 - 2015-07-30 16:05 - 0002766 _____ () C:\Users\Marketa\AppData\Local\recently-used.xbel
2013-06-18 11:13 - 2014-01-20 18:26 - 0007597 _____ () C:\Users\Marketa\AppData\Local\Resmon.ResmonCfg
2012-09-04 04:26 - 2012-09-04 04:26 - 0002739 _____ () C:\Users\Marketa\AppData\Local\WiDiSetupLog.20120904.092604.txt
2012-09-04 04:51 - 2012-09-04 04:52 - 0002747 _____ () C:\Users\Marketa\AppData\Local\WiDiSetupLog.20120904.095159.txt
2014-01-20 18:30 - 2014-01-20 18:31 - 0002748 _____ () C:\Users\Marketa\AppData\Local\WiDiSetupLog.20140120.223056.txt
2014-06-29 15:15 - 2014-06-29 15:15 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-08-26 16:56 - 2015-09-02 15:52 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Some files in TEMP:
====================
C:\Users\Marketa\AppData\Local\Temp\fsd628A.exe
C:\Users\Marketa\AppData\Local\Temp\Uninstall.exe


Some zero byte size files/folders:
==========================
C:\Windows\System32\ARAudioCDGrabber2.dll
C:\Windows\System32\ARAudioPlayer2.dll
C:\Windows\System32\ARAudioTransform2.dll

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll
[2012-09-03 14:16] - [2015-08-30 18:31] - 0270336 ____A (Microsoft Corporation) CF5C2D3562991284A5E75F928692D058

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-12 12:47

==================== End of FRST.txt ============================