Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Opakované spouštění obnovení systému - zotavení z chyb

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#16 Příspěvek od 102mn »

Po provedení opravy systému a jeho restartu již obnovení systému a zotavení z chyb nenaskočilo, ani po úplném vypnutí PC.
PC se zatím chová normálně, trošičku pomalejší.

K těm 4 krokům jsem Vám zkopírovala z nápovědy programu krátký popis. Nevím, zda ještě mám provést tyto další kroky.


Step 1: Do A Proper Power Reset First
Doing proper power reset is easy. It isn't the same as simply shutting down your machine.
A proper power reset means draining all the electricity out of the system.
This will properly reset the hardware and also clear volatile memory, it also helps since Windows will be restarted after, clearing out any memory leaks, not enough system resources or other problems that might get in the way of the repairs.
Have you ever heard someone say their computer wasn't working right, so they unhooked it, took it to a computer repair shop and when they got there the system was working fine? This is because the power had drained out of the system!
(Step 1) Shut down and power off the computer.
(Step 2) Once the computer is powered off, unplug the power cord. If it is a laptop also remove the battery. It is important that any way for the system to keep getting power is unplugged or unhooked.
(Step 3) With the power cord unplugged and the battery removed (if you have one), hit the power button a few times as if you are trying to turn on the computer. When you do this and the computer tries to turn on, all the electricity is drained out of the system.
(Step 4) Plug the power cord back in and reinsert the battery (if you have one) and turn the computer on.

Step 2: Pre-Scan: (Optional)
This tool will do a quick scan of 3 sections of the system that might interfere with the repairs as well as identify other potential problems.
1. Windows Packages Files. This scan checks for any missing or corrupt packaging files. These do not interfere with the repairs, but they do keep any Windows Updates from installing that might depend on them and from the SFC (System File Checker) from being able to successfully run.
2. System Reparse Points. This scan checks for any missing default or corrupted symbolic or junction links. There is a lot to explain on why these are important, if you are interested you can search online more information.
3. Environment Variables. This scan is important for both the repairs and most software on your system including Windows itself. Many things depend on the environment variables to know where to find certain files and tools on the system.
This program has built in tools to repair #2 & #3.


Step 3: Check File System
Before working with files on the system it is a very good idea to have windows check the file system for errors. If there are any file system errors windows will repair them. If there are errors in the file system when you try to repair windows then the repairs could fail.
The "Check" button.
See if check disk is needed (no restart required), this will run chkdsk in read only mode. This can cause false positives if a file it is checking is being written too.
If it reports any errors there is no way to tell if they are false positives, so just make sure to run the check disk at next boot option, if it comes back clean you do not need to check the drive again.
The "Open Check Disk At Next Boot" button.
Check Disk will scan the drive for file system errors. This is a good idea before doing repairs to make sure a bad file system doesn't cause more problems. This action requires a system restart.
This tool will allow you to easily schedule a chkdsk at the next boot of Windows.

Step 4: System File Check
Before working with files on the system it is a very good idea to have windows check the file system files for corruptions or mis matched versions. Having the system files checked by the System File Checker can even repair some known problems. Problems that are caused by wrong versions of the system files.
System File Checker will scan your system for corrupt or wrong Windows system files. This is a good idea to do to make sure proper files are intact before starting the repairs. For Windows XP && 2003 you will need your Windows CD. Vista or newer do not require the Windows CD. Please restart Windows after.
The System File Checker is a tool built into Windows and not a part of this program. If you have trouble with the SFC you may need to skip it.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Opakované spouštění obnovení systému - zotavení z chyb

#17 Příspěvek od Rudy »

Pokud se stav změl k lepšímu, nebude třeba další kroky aplikovat. Vzhledem ke zpomalení ještě PC vyčistíme. Dejte log FRST: https://forum.viry.cz/viewtopic.php?f=13&t=152707 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#18 Příspěvek od 102mn »

LOG 1

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Lenka (administrator) on LENKANB (30-01-2018 20:18:10)
Running from C:\Users\Lenka\Downloads
Loaded Profiles: Lenka (Available Profiles: Lenka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(McAfee, Inc.) C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe
(PLUMBYTES) C:\Program Files\PCCare Software\PCCare Anti-Malware\AmwService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
() C:\windows\System32\spool\drivers\x64\3\WrtMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\windows\System32\igfxtray.exe
(Intel Corporation) C:\windows\System32\hkcmd.exe
(Intel Corporation) C:\windows\System32\igfxpers.exe
() C:\windows\System32\spool\drivers\x64\3\WrtProc.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\windows\System32\dllhost.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
() C:\Program Files (x86)\Winamp\winampa.exe
(ScanSoft, Inc.) C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
(Microsoft Corporation) C:\windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-11-22] (Realtek Semiconductor)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9769888 2011-09-14] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-09-14] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-09-14] (Lenovo)
HKLM\...\Run: [WrtMon.exe] => C:\windows\system32\spool\drivers\x64\3\WrtMon.exe [20480 2006-09-20] ()
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-11-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-11-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [548864 2014-11-22] (Vimicro)
HKLM-x32\...\Run: [PLTSR] => C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe [364400 2010-10-22] (Egis Technology Inc. )
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2010-12-24] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [224352 2010-12-24] (CyberLink Corp.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePRCShortCut] => "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [3744552 2011-11-28] (AVAST Software)
HKLM-x32\...\Run: [NeroFilterCheck] => C:\windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\Winampa.exe [12288 2002-04-26] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [OpwareSE4] => C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44016 2018-01-08] (Glarysoft Ltd)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Lsa: [Notification Packages] scecli EgisPLPwdFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2011-09-14]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2016-02-21]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
BootExecute: autocheck autochk *

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.29.254
Tcpip\..\Interfaces\{AAB07F94-1087-4DD3-9E9E-E0F1454C75CB}: [DhcpNameServer] 192.168.29.254

Internet Explorer:
==================
HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=12454
HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {11C2D730-E25D-4AA7-9CE9-67CBA7C5CBCC} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {28071E18-7870-4CF9-AB84-74340EB83C41} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {6539E413-939D-4416-9BBE-CD0AECF96FC6} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7LENN
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {6D8243F2-E9E5-4DEE-B194-63EB16A0B52C} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {89643858-2BED-4421-940B-6B6E663E3070} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {8BEF890E-265B-4A21-8BDA-B984254EB833} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {B54D56E8-BAFD-4827-8B93-D0E6E950040D} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {B8CA1E71-4F07-46A4-96F8-6F4F7A56D70D} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {DA7A6777-3DD5-4F37-8998-E88E249D66C4} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
BHO: avast! WebRep -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28] (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28] (AVAST Software)
Toolbar: HKLM-x32 - No Name - {84F23192-A475-4038-B5C0-8584777F2DF4} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

FireFox:
========
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [No File]

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR NewTab: Default -> Not-active:"chrome-extension://gfoabcdjalmeenbjjngidappmppchblc/homePageRedirect.html"
CHR Profile: C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default [2018-01-30]
CHR Extension: (YouTube) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Vyhledávání Google) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Norton Home Page for Chrome) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfoabcdjalmeenbjjngidappmppchblc [2017-04-26]
CHR Extension: (Norton Safe) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbmobhkkblcgdifigjglcjneplefbkmh [2017-04-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-25]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [icmlaeflemplmjndnaapfdbbnpncnbda] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2011-12-20]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44768 2011-11-28] (AVAST Software)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [956192 2011-02-15] (Broadcom Corporation.)
R2 EgisTec Service Help; C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [327024 2010-10-22] (Egis Technology Inc. )
R2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [189840 2017-03-02] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 pccareamw_service; C:\Program Files\PCCare Software\PCCare Anti-Malware\AmwService.exe [125968 2016-07-19] (PLUMBYTES)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [24408 2011-11-28] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [66904 2011-11-28] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [42328 2011-11-28] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [591192 2011-11-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [304472 2011-11-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [58712 2011-11-28] (AVAST Software)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [20160 2017-04-17] (Glarysoft Ltd)
R3 MEIx64; C:\windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-11-22] (Intel Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
S3 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [3300568 2014-11-22] (Realtek Semiconductor Corporation )
R3 SmbDrvI; C:\windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2014-11-22] (Synaptics Incorporated)
U3 BcmSqlStartupSvc; no ImagePath
U2 CLKMSVC10_3A60B698; no ImagePath
U2 CLKMSVC10_C3B3B687; no ImagePath
U2 DriverService; no ImagePath
S2 eamonm; system32\DRIVERS\eamonm.sys [X]
U2 IAStorDataMgrSvc; no ImagePath
U2 iATAgentService; no ImagePath
U2 idealife Update Service; no ImagePath
U3 IGRS; no ImagePath
U2 IviRegMgr; no ImagePath
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20170419.020\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20170419.020\EX64.SYS [X]
U2 nvUpdatusService; no ImagePath
U2 Oasis2Service; no ImagePath
U2 PCCarerService; no ImagePath
U2 ReadyComm.DirectRouter; no ImagePath
U2 RichVideo; no ImagePath
U2 RtLedService; no ImagePath
U2 SeaPort; no ImagePath
U2 SoftwareService; no ImagePath
U3 SQLWriter; no ImagePath
U2 Stereo Service; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-30 20:18 - 2018-01-30 20:20 - 000019919 _____ C:\Users\Lenka\Downloads\FRST.txt
2018-01-30 20:17 - 2018-01-30 20:18 - 000000000 ____D C:\FRST
2018-01-30 20:14 - 2018-01-30 20:14 - 002393088 _____ (Farbar) C:\Users\Lenka\Downloads\FRST64.exe
2018-01-30 19:25 - 2018-01-30 19:08 - 000481104 _____ (DriverPack) C:\Users\Lenka\Desktop\DriverPack-Online.exe
2018-01-30 19:09 - 2018-01-30 19:17 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\DRPSu
2018-01-30 19:08 - 2018-01-30 19:08 - 000481104 _____ (DriverPack) C:\Users\Lenka\Downloads\DriverPack-Online.exe
2018-01-30 17:53 - 2018-01-30 17:53 - 000003160 _____ C:\windows\System32\Tasks\SidebarExecute
2018-01-30 17:19 - 2018-01-30 17:19 - 000000207 _____ C:\windows\tweaking.com-regbackup-LENKANB-Windows-7-Home-Premium-(64-bit).dat
2018-01-30 17:19 - 2018-01-30 17:19 - 000000000 ____D C:\RegBackup
2018-01-30 17:00 - 2018-01-30 17:00 - 000003652 _____ C:\windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2018-01-30 17:00 - 2018-01-30 17:00 - 000002159 _____ C:\Users\Lenka\Desktop\Tweaking.com - Windows Repair.lnk
2018-01-30 17:00 - 2018-01-30 17:00 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2018-01-30 16:59 - 2018-01-30 16:59 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2018-01-30 16:57 - 2018-01-30 17:00 - 000194556 _____ C:\windows\Tweaking.com - Windows Repair Setup Log.txt
2018-01-30 16:56 - 2018-01-30 16:57 - 037693392 _____ (Tweaking.com) C:\Users\Lenka\Downloads\tweaking.com_windows_repair_aio_setup.exe
2018-01-30 16:46 - 2018-01-30 16:46 - 203768152 _____ C:\windows\MEMORY.DMP
2018-01-30 16:46 - 2018-01-30 16:46 - 000266576 _____ C:\windows\Minidump\013018-15210-01.dmp
2018-01-29 22:07 - 2018-01-29 22:07 - 000000000 ____D C:\Users\Lenka\Downloads\nettun.inf_amd64_neutral_bd24fb174fabec97
2018-01-29 22:05 - 2018-01-29 22:05 - 000007298 _____ C:\Users\Lenka\Downloads\nettun.inf_amd64_neutral_bd24fb174fabec97.zip
2018-01-29 18:13 - 2018-01-29 18:13 - 000001200 _____ C:\Users\Lenka\Desktop\CrystalDiskInfo.lnk
2018-01-29 18:13 - 2018-01-29 18:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2018-01-29 18:13 - 2018-01-29 18:13 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2018-01-29 18:12 - 2018-01-29 18:12 - 003947992 _____ (Crystal Dew World ) C:\Users\Lenka\Downloads\CrystalDiskInfo7_5_1.exe
2018-01-28 15:36 - 2018-01-28 16:23 - 000000000 ____D C:\Users\Lenka\AppData\Local\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}
2018-01-28 15:14 - 2018-01-28 15:14 - 008206624 _____ (Malwarebytes) C:\Users\Lenka\Downloads\adwcleaner_7.0.7.0.exe
2018-01-28 15:00 - 2018-01-29 17:12 - 000000000 ____D C:\Program Files\trend micro
2018-01-28 15:00 - 2018-01-28 15:00 - 000000000 ____D C:\rsit
2018-01-28 14:59 - 2018-01-28 14:59 - 001329152 _____ C:\Users\Lenka\Downloads\RSITx64.exe
2018-01-28 13:35 - 2018-01-28 13:35 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PCCare Anti-Malware
2018-01-28 13:35 - 2018-01-28 13:35 - 000000000 ____D C:\Program Files\PCCare Software
2018-01-28 13:31 - 2018-01-28 13:31 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ErrorFix Kit
2018-01-28 13:31 - 2018-01-28 13:31 - 000000000 ____D C:\Program Files (x86)\ErrorFixKIT
2018-01-28 13:28 - 2018-01-28 13:28 - 000961552 _____ (PCCare) C:\Users\Lenka\Downloads\antimalware-setup.exe
2018-01-28 13:27 - 2018-01-28 13:27 - 000888304 _____ C:\Users\Lenka\Downloads\errorfixkit-setup.exe
2018-01-28 13:20 - 2018-01-28 13:20 - 000001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2018-01-28 12:28 - 2018-01-28 12:28 - 000000000 ____D C:\Users\Lenka\AppData\Local\{003ACA6A-C058-424D-B955-A82DE5375C64}
2018-01-28 12:06 - 2018-01-28 12:06 - 000790528 _____ C:\windows\system32\config\default.gu
2018-01-28 12:06 - 2018-01-28 12:06 - 000024576 _____ C:\windows\system32\config\security.gu
2018-01-28 12:06 - 2018-01-28 12:06 - 000024576 _____ C:\windows\system32\config\sam.gu
2018-01-28 11:48 - 2018-01-30 19:53 - 000000000 ____D C:\Program Files (x86)\Glary Utilities 5
2018-01-28 11:48 - 2018-01-28 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2018-01-28 09:55 - 2018-01-30 19:50 - 000000368 _____ C:\windows\Tasks\WinThruster64-Lenka-Startup.job
2018-01-28 09:55 - 2018-01-28 09:55 - 000002746 _____ C:\windows\System32\Tasks\WinThruster64-Lenka-Startup
2018-01-28 09:54 - 2018-01-30 19:50 - 000000376 _____ C:\windows\Tasks\WinThruster64-Lenka-Notification.job
2018-01-28 09:54 - 2018-01-28 09:54 - 000003438 _____ C:\windows\System32\Tasks\WinThruster64-Lenka-Notification
2018-01-27 20:30 - 2018-01-27 23:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-01-27 20:01 - 2018-01-28 15:18 - 000000000 ____D C:\AdwCleaner
2018-01-16 18:45 - 2018-01-16 18:45 - 000357011 _____ C:\Users\Lenka\Desktop\Šichtovník 2018 ver1.xlsx
2018-01-16 17:22 - 2018-01-01 03:21 - 005581544 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-01-16 17:22 - 2018-01-01 03:21 - 001680616 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2018-01-16 17:22 - 2018-01-01 03:21 - 000948968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2018-01-16 17:22 - 2018-01-01 03:21 - 000708328 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-01-16 17:22 - 2018-01-01 03:21 - 000288488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fltMgr.sys
2018-01-16 17:22 - 2018-01-01 03:19 - 001665384 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 014183936 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 002066432 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 002004480 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001942016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001867776 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001741312 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001110528 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 000749568 _____ (Microsoft Corporation) C:\windows\system32\FirewallAPI.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 000512000 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll
2018-01-16 17:22 - 2018-01-01 03:13 - 000631680 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-01-16 17:22 - 2018-01-01 03:02 - 001314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-01-16 17:22 - 2018-01-01 03:00 - 012880384 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2018-01-16 17:22 - 2018-01-01 03:00 - 001417728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2018-01-16 17:22 - 2018-01-01 03:00 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2018-01-16 17:22 - 2018-01-01 02:59 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2018-01-16 17:22 - 2018-01-01 02:54 - 004013800 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2018-01-16 17:22 - 2018-01-01 02:54 - 003959016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2018-01-16 17:22 - 2018-01-01 02:50 - 000455680 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2018-01-16 17:22 - 2018-01-01 02:42 - 000460288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2018-01-16 17:22 - 2018-01-01 02:42 - 000406016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2018-01-16 17:22 - 2018-01-01 02:41 - 000754176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2018-01-16 17:22 - 2017-12-30 08:29 - 000395968 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-01-16 17:22 - 2017-12-29 19:39 - 020274688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-01-16 17:22 - 2017-12-29 19:13 - 000499712 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-01-16 17:22 - 2017-12-29 19:12 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2018-01-16 17:22 - 2017-12-29 19:09 - 002294272 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-01-16 17:22 - 2017-12-29 19:04 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2018-01-16 17:22 - 2017-12-29 19:03 - 000662528 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-01-16 17:22 - 2017-12-29 18:45 - 004508160 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-01-16 17:22 - 2017-12-29 18:38 - 013680128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-01-16 17:22 - 2017-12-29 18:36 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2018-01-16 17:22 - 2017-12-29 18:19 - 002767872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-01-16 17:22 - 2017-12-29 18:15 - 001313792 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-01-16 17:22 - 2017-12-29 10:15 - 025737728 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-01-16 17:22 - 2017-12-29 09:52 - 002900480 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-01-16 17:22 - 2017-12-29 09:51 - 005796352 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-01-16 17:22 - 2017-12-29 09:50 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-01-16 17:22 - 2017-12-29 09:40 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-01-16 17:22 - 2017-12-29 09:39 - 000817152 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-01-16 17:22 - 2017-12-29 09:39 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-01-16 17:22 - 2017-12-29 09:32 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-01-16 17:22 - 2017-12-29 09:04 - 015284224 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-01-16 17:22 - 2017-12-29 09:03 - 000807936 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-01-16 17:22 - 2017-12-29 09:01 - 002134528 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-01-16 17:22 - 2017-12-29 09:01 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-01-16 17:22 - 2017-12-29 08:50 - 003241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-01-16 17:22 - 2017-12-29 08:39 - 001545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-01-16 17:22 - 2017-12-29 08:27 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-01-16 17:22 - 2017-12-21 07:27 - 000634312 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2018-01-16 17:22 - 2017-12-13 17:31 - 000383720 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2018-01-16 17:22 - 2017-12-13 17:15 - 000309480 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2018-01-16 17:21 - 2018-01-01 03:21 - 000262376 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-01-16 17:21 - 2018-01-01 03:21 - 000213736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdyboost.sys
2018-01-16 17:21 - 2018-01-01 03:21 - 000154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-01-16 17:21 - 2018-01-01 03:21 - 000114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2018-01-16 17:21 - 2018-01-01 03:21 - 000095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-01-16 17:21 - 2018-01-01 03:18 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000977408 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000961024 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000863232 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2018-01-16 17:21 - 2018-01-01 03:18 - 000842752 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000828928 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000705024 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL
2018-01-16 17:21 - 2018-01-01 03:18 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000473600 _____ (Microsoft Corporation) C:\windows\system32\taskcomp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000444928 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000439296 _____ (Microsoft Corporation) C:\windows\system32\p2psvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000366592 _____ (Microsoft Corporation) C:\windows\system32\wcncsvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000327168 _____ (Microsoft Corporation) C:\windows\system32\pnrpsvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2018-01-16 17:21 - 2018-01-01 03:18 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000303104 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000264704 _____ (Microsoft Corporation) C:\windows\system32\P2P.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000223232 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000120320 _____ (Microsoft Corporation) C:\windows\system32\WcnApi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000108544 _____ (Microsoft Corporation) C:\windows\system32\icfupgd.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000101376 _____ (Microsoft Corporation) C:\windows\system32\fdWCN.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000095744 _____ (Microsoft Corporation) C:\windows\system32\rascfg.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000076288 _____ (Microsoft Corporation) C:\windows\system32\rasdiag.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000070656 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\ndptsp.tsp
2018-01-16 17:21 - 2018-01-01 03:18 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000047104 _____ (Microsoft Corporation) C:\windows\system32\kmddsp.tsp
2018-01-16 17:21 - 2018-01-01 03:18 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\rasmxs.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000039424 _____ (Microsoft Corporation) C:\windows\system32\traffic.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\rasser.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000026112 _____ (Microsoft Corporation) C:\windows\system32\oleres.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000024576 _____ (Microsoft Corporation) C:\windows\system32\WcnEapPeerProxy.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000024064 _____ (Microsoft Corporation) C:\windows\system32\WcnEapAuthProxy.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000022528 _____ (Microsoft Corporation) C:\windows\system32\wfapigp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000016896 _____ (Microsoft Corporation) C:\windows\system32\wshqos.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wshnetbs.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000008704 _____ (Microsoft Corporation) C:\windows\system32\comcat.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2018-01-16 17:21 - 2018-01-01 03:04 - 000559616 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2018-01-16 17:21 - 2018-01-01 03:00 - 001499648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 001390080 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000463360 _____ (Microsoft Corporation) C:\windows\SysWOW64\FirewallAPI.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000351744 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000304640 _____ (Microsoft Corporation) C:\windows\SysWOW64\taskcomp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000276992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wcncsvc.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000217600 _____ (Microsoft Corporation) C:\windows\SysWOW64\P2P.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2018-01-16 17:21 - 2018-01-01 03:00 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000162304 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdWCN.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\rascfg.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasdiag.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\ndptsp.tsp
2018-01-16 17:21 - 2018-01-01 03:00 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\traffic.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000026112 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleres.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 001806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000309760 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:55 - 000131584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pacer.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000088576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wanarp.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000058368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndproxy.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000045056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbios.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndistapi.sys
2018-01-16 17:21 - 2018-01-01 02:54 - 000077312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mpsdrv.sys
2018-01-16 17:21 - 2018-01-01 02:49 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-01-16 17:21 - 2018-01-01 02:49 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-01-16 17:21 - 2018-01-01 02:49 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-01-16 17:21 - 2018-01-01 02:49 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-01-16 17:21 - 2018-01-01 02:46 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2018-01-16 17:21 - 2018-01-01 02:45 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-01-16 17:21 - 2018-01-01 02:43 - 000086528 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcnApi.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000038912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kmddsp.tsp
2018-01-16 17:21 - 2018-01-01 02:43 - 000033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasmxs.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasser.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcnEapPeerProxy.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000019968 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcnEapAuthProxy.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfapigp.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000013824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshqos.dll
2018-01-16 17:21 - 2018-01-01 02:42 - 000168448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2018-01-16 17:21 - 2018-01-01 02:42 - 000159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-01-16 17:21 - 2018-01-01 02:41 - 000106496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dfsc.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-01-16 17:21 - 2018-01-01 02:41 - 000007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\comcat.dll
2018-01-16 17:21 - 2018-01-01 02:39 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2018-01-16 17:21 - 2018-01-01 02:36 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2018-01-16 17:21 - 2018-01-01 02:36 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2018-01-16 17:21 - 2018-01-01 02:36 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2018-01-16 17:21 - 2018-01-01 02:36 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2018-01-16 17:21 - 2018-01-01 02:35 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-16 17:21 - 2017-12-30 07:42 - 000347328 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-01-16 17:21 - 2017-12-29 19:24 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2018-01-16 17:21 - 2017-12-29 19:13 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2018-01-16 17:21 - 2017-12-29 19:12 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2018-01-16 17:21 - 2017-12-29 19:11 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2018-01-16 17:21 - 2017-12-29 19:06 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2018-01-16 17:21 - 2017-12-29 19:06 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2018-01-16 17:21 - 2017-12-29 19:03 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-01-16 17:21 - 2017-12-29 19:03 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2018-01-16 17:21 - 2017-12-29 18:55 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2018-01-16 17:21 - 2017-12-29 18:51 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-01-16 17:21 - 2017-12-29 18:50 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2018-01-16 17:21 - 2017-12-29 18:50 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2018-01-16 17:21 - 2017-12-29 18:47 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2018-01-16 17:21 - 2017-12-29 18:47 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2018-01-16 17:21 - 2017-12-29 18:46 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2018-01-16 17:21 - 2017-12-29 18:44 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2018-01-16 17:21 - 2017-12-29 18:39 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2018-01-16 17:21 - 2017-12-29 18:38 - 000694272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-01-16 17:21 - 2017-12-29 18:37 - 002058752 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-01-16 17:21 - 2017-12-29 18:13 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-01-16 17:21 - 2017-12-29 10:04 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-01-16 17:21 - 2017-12-29 10:04 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-01-16 17:21 - 2017-12-29 09:51 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-01-16 17:21 - 2017-12-29 09:50 - 000577024 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-01-16 17:21 - 2017-12-29 09:50 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-01-16 17:21 - 2017-12-29 09:50 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-01-16 17:21 - 2017-12-29 09:44 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-01-16 17:21 - 2017-12-29 09:43 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-01-16 17:21 - 2017-12-29 09:39 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-01-16 17:21 - 2017-12-29 09:39 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-01-16 17:21 - 2017-12-29 09:28 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-01-16 17:21 - 2017-12-29 09:22 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-01-16 17:21 - 2017-12-29 09:22 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-01-16 17:21 - 2017-12-29 09:21 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-01-16 17:21 - 2017-12-29 09:18 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-01-16 17:21 - 2017-12-29 09:18 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-01-16 17:21 - 2017-12-29 09:16 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-01-16 17:21 - 2017-12-29 09:14 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-01-16 17:21 - 2017-12-29 09:05 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-01-16 17:21 - 2017-12-29 09:03 - 000726528 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-01-16 17:21 - 2017-12-13 17:27 - 000100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2018-01-16 17:21 - 2017-12-13 17:27 - 000046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2018-01-16 17:21 - 2017-12-13 17:27 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2018-01-16 17:21 - 2017-12-13 17:27 - 000014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2018-01-16 17:21 - 2017-12-13 17:11 - 000071168 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2018-01-16 17:21 - 2017-12-13 17:11 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2018-01-16 17:21 - 2017-12-13 17:11 - 000010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2018-01-16 17:21 - 2017-12-13 16:50 - 000034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2018-01-16 17:21 - 2017-12-05 18:36 - 000625664 _____ (Microsoft Corporation) C:\windows\system32\mscms.dll
2018-01-16 17:21 - 2017-12-05 18:36 - 000250880 _____ (Microsoft Corporation) C:\windows\system32\icm32.dll
2018-01-16 17:21 - 2017-12-05 18:36 - 000040960 _____ (Microsoft Corporation) C:\windows\system32\WcsPlugInService.dll
2018-01-16 17:21 - 2017-12-05 18:08 - 000481792 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscms.dll
2018-01-16 17:21 - 2017-12-05 18:08 - 000215040 _____ (Microsoft Corporation) C:\windows\SysWOW64\icm32.dll
2018-01-16 17:21 - 2017-12-05 16:59 - 003222528 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2018-01-16 17:21 - 2017-12-05 16:49 - 000032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcsPlugInService.dll
2018-01-14 14:58 - 2018-01-14 15:38 - 000355834 _____ C:\Users\Lenka\Desktop\Šichtovník 2018.xlsx
2018-01-14 14:34 - 2018-01-14 15:07 - 000004096 ____H C:\Users\Lenka\AppData\Local\keyfile3.drm
2018-01-14 12:45 - 2018-01-14 12:47 - 017234512 _____ C:\Users\Lenka\Downloads\Glary_Utilities_v5.91.0.112.exe
2018-01-14 09:59 - 2018-01-30 16:46 - 000000000 ____D C:\windows\Minidump
2018-01-13 17:58 - 2018-01-13 17:58 - 000027138 _____ C:\Users\Lenka\Downloads\planovaci-kalendar-2017-na-sirku-web.xlsx
2018-01-07 20:55 - 2018-01-07 20:55 - 000026581 _____ C:\Users\Lenka\Downloads\posun-offset-prakticky-radky-sloupce-excel-2010-prakticky (1).xlsx
2018-01-07 20:55 - 2018-01-07 20:55 - 000014732 _____ C:\Users\Lenka\Downloads\posun-offset-excel-2010.xlsx
2018-01-07 20:53 - 2018-01-07 20:53 - 000026581 _____ C:\Users\Lenka\Downloads\posun-offset-prakticky-radky-sloupce-excel-2010-prakticky.xlsx
2018-01-07 20:35 - 2018-01-07 20:35 - 000014538 _____ C:\Users\Lenka\Downloads\kdyz-funkce-logicka-excel.xlsx
2018-01-04 19:31 - 2018-01-04 19:31 - 000040448 _____ C:\Users\Lenka\Downloads\HODNOTA-NA-TEXT-TEXT.xls
2018-01-04 18:33 - 2018-01-04 18:33 - 000034712 _____ C:\Users\Lenka\Downloads\podminene-formatovani-datum-excel.xlsx
2018-01-04 18:28 - 2018-01-04 18:28 - 000023270 _____ C:\Users\Lenka\Downloads\podminene-formatovani-datum-cas.xlsx
2018-01-04 18:25 - 2018-01-04 18:25 - 000035328 _____ C:\Users\Lenka\Downloads\oznaceni-radku-podminene-formatovani.xls
2018-01-04 18:06 - 2018-01-04 18:06 - 000013997 _____ C:\Users\Lenka\Downloads\priklad-podminene-formatovani-den.xlsx
2018-01-04 17:49 - 2018-01-04 17:49 - 000041472 _____ C:\Users\Lenka\Downloads\podminene-formatovani-datum.xls
2018-01-03 20:55 - 2018-01-03 20:55 - 000011851 _____ C:\Users\Lenka\Downloads\Příklad.xlsx
2018-01-03 16:58 - 2018-01-03 16:58 - 000029234 _____ C:\Users\Lenka\Downloads\rocni-kalendar-2018-excel-barvy-jazyk.xlsx
2018-01-02 21:37 - 2018-01-02 21:37 - 000012155 _____ C:\Users\Lenka\Downloads\BINGO.xlsx
2018-01-02 20:03 - 2018-01-02 20:03 - 000031281 _____ C:\Users\Lenka\Downloads\2018-calendar-landscape-linear-days-aligned.xlsx
2018-01-02 19:59 - 2018-01-02 19:59 - 000037036 _____ C:\Users\Lenka\Downloads\calendar-2018-landscape-linear.xlsx
2018-01-02 18:04 - 2018-01-02 18:04 - 000029057 _____ C:\Users\Lenka\Downloads\rocni-kalendar-2017-excel-barvy-jazyk.xlsx
2018-01-02 17:41 - 2018-01-02 17:41 - 000204288 _____ C:\Users\Lenka\Downloads\ŠICHTOVNICE DISPEČINK_aktual.xls

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-30 20:08 - 2009-07-14 05:45 - 000028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-30 20:08 - 2009-07-14 05:45 - 000028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-30 19:56 - 2011-09-15 04:40 - 000623032 _____ C:\windows\system32\perfh005.dat
2018-01-30 19:56 - 2011-09-15 04:40 - 000124746 _____ C:\windows\system32\perfc005.dat
2018-01-30 19:56 - 2009-07-14 06:13 - 001488216 _____ C:\windows\system32\PerfStringBackup.INI
2018-01-30 19:56 - 2009-07-14 04:20 - 000000000 ____D C:\windows\inf
2018-01-30 19:51 - 2011-09-14 22:13 - 000103871 _____ C:\windows\system32\fastboot.set
2018-01-30 19:50 - 2009-07-14 06:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-01-30 17:58 - 2011-12-20 13:00 - 000111624 _____ C:\Users\Lenka\AppData\Local\GDIPFONTCACHEV1.DAT
2018-01-30 17:57 - 2009-07-14 05:45 - 000410520 _____ C:\windows\system32\FNTCACHE.DAT
2018-01-30 17:49 - 2009-07-14 03:34 - 000000538 _____ C:\windows\win.ini
2018-01-28 22:12 - 2011-12-20 12:58 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2018-01-28 22:12 - 2011-09-14 21:59 - 000000000 ____D C:\ProgramData\Port Locker
2018-01-28 22:12 - 2009-07-14 04:20 - 000000000 ____D C:\windows\registration
2018-01-28 13:34 - 2009-07-14 06:32 - 000000000 ____D C:\windows\Downloaded Program Files
2018-01-28 13:20 - 2017-04-17 16:23 - 000003306 _____ C:\windows\System32\Tasks\GlaryInitialize 5
2018-01-28 13:20 - 2017-04-17 16:23 - 000002970 _____ C:\windows\System32\Tasks\GU5SkipUAC
2018-01-28 13:14 - 2011-12-20 12:58 - 000000000 ____D C:\Users\Lenka
2018-01-28 12:06 - 2009-07-14 03:34 - 114819072 _____ C:\windows\system32\config\software.gu.bak
2018-01-28 12:06 - 2009-07-14 03:34 - 025427968 _____ C:\windows\system32\config\system.gu.bak
2018-01-28 11:48 - 2017-04-17 16:23 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\GlarySoft
2018-01-28 11:20 - 2016-01-16 20:17 - 000000000 ____D C:\Users\Lenka\AppData\Local\ElevatedDiagnostics
2018-01-27 23:38 - 2017-05-06 07:57 - 000000000 ____D C:\Users\Lenka\AppData\Local\CrashDumps
2018-01-27 23:37 - 2011-12-27 10:20 - 000000000 ____D C:\Program Files\CCleaner
2018-01-27 23:33 - 2015-01-04 16:08 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Seznam.cz
2018-01-27 23:33 - 2015-01-04 16:08 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
2018-01-27 23:27 - 2009-07-14 04:20 - 000000000 ____D C:\windows\schemas
2018-01-27 20:16 - 2017-04-17 17:50 - 000000000 ____D C:\ProgramData\GlarySoft
2018-01-27 10:49 - 2013-08-17 09:57 - 000000000 ____D C:\windows\system32\MRT
2018-01-27 10:46 - 2017-10-15 10:00 - 129365736 ____C (Microsoft Corporation) C:\windows\system32\MRT-KB890830.exe
2018-01-27 10:45 - 2011-12-20 13:58 - 129365736 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-01-27 10:35 - 2011-12-20 13:45 - 001560276 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2018-01-23 19:58 - 2010-11-21 04:27 - 000548000 _____ (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2018-01-14 21:36 - 2017-04-18 17:20 - 000000000 ____D C:\ProgramData\Norton
2018-01-14 21:36 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-01-14 12:20 - 2017-04-20 16:13 - 000000000 ____D C:\Users\Lenka\AppData\Local\NPE
2018-01-14 12:13 - 2017-04-20 16:17 - 000000000 ____D C:\NPE
2018-01-04 22:09 - 2011-09-14 22:08 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-03 20:45 - 2012-01-03 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2018-01-01 16:50 - 2015-01-04 14:40 - 000066263 _____ C:\Users\Lenka\Desktop\model.xlsx

==================== Files in the root of some directories =======

2018-01-14 14:34 - 2018-01-14 15:07 - 000004096 ____H () C:\Users\Lenka\AppData\Local\keyfile3.drm
2017-04-20 17:20 - 2017-04-20 17:20 - 000007637 _____ () C:\Users\Lenka\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-01-03 13:47

==================== End of FRST.txt ============================

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#19 Příspěvek od 102mn »

LOG 2

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Lenka (30-01-2018 20:21:11)
Running from C:\Users\Lenka\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2011-12-20 11:58:54)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-118739109-790167221-2496289451-500 - Administrator - Disabled)
Guest (S-1-5-21-118739109-790167221-2496289451-501 - Limited - Disabled)
Lenka (S-1-5-21-118739109-790167221-2496289451-1000 - Administrator - Enabled) => C:\Users\Lenka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 25.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.270 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
avast! Free Antivirus (HKLM-x32\...\avast) (Version: 6.0.1367.0 - AVAST Software)
Canon MF4010 Series (HKLM\...\{900A29A0-52BA-4a78-8E6C-5F4F821397CE}) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 3.13 - Piriform)
Codec Pack - All In 1 6.0.3.0 (HKLM-x32\...\Cool's_Codec_pack_4.12) (Version: - )
CrystalDiskInfo 7.5.1 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.5.1 - Crystal Dew World)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3623 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Management (HKLM-x32\...\{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo)
ErrorFix Kit 2018 (HKLM\...\ErrorFix Kit 2018) (Version: - )
FastStone Image Viewer 6.2 (HKLM-x32\...\FastStone Image Viewer) (Version: 6.2 - FastStone Soft)
Glary Utilities 5.91 (HKLM-x32\...\Glary Utilities 5) (Version: 5.91.0.112 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8000 - Broadcom Corporation)
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.12.204.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo OneKey Recovery (HKLM\...\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo Security Suite (HKLM-x32\...\{0034859F-8E01-4C1D-BE77-F891C4786FBC}) (Version: 2.0.11.0 - Lenovo) Hidden
Lenovo Security Suite (HKLM-x32\...\InstallShield_{0034859F-8E01-4C1D-BE77-F891C4786FBC}) (Version: 2.0.11.0 - Lenovo)
Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PCCare Anti-Malware 2016 (HKLM\...\PCCare Anti-Malware 2016) (Version: - PCCare Software)
PDF Architect 5 (HKLM-x32\...\PDF Architect 5) (Version: 5.0.21.32007 - pdfforge GmbH)
PDF Architect 5 View Module (HKLM\...\{AD72FB9B-80C6-461D-B099-9DD76A62115E}) (Version: 5.0.22.32126 - pdfforge GmbH) Hidden
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.1 - Frank Heindörfer, Philip Chinery)
Port Locker (HKLM\...\{1F494B8A-D6E6-4540-9A74-F773B63164A6}) (Version: 1.0.5.24 - Egis Technology Inc.) Hidden
Port Locker (HKLM-x32\...\{A6FEE06D-C7E1-48CB-A9DF-1E317CF83CA4}) (Version: 1.0.5.24 - Egis Technology Inc.) Hidden
Port Locker (HKLM-x32\...\InstallShield_{A6FEE06D-C7E1-48CB-A9DF-1E317CF83CA4}) (Version: 1.0.5.24 - Egis Technology Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.21.531.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10008 - Realtek Semiconductor Corp.)
ScanSoft OmniPage SE 4.0 (HKLM-x32\...\{C1E693A4-B1D5-4DCD-B68D-2087835B7184}) (Version: 15.00.0020 - Nuance Communications, Inc.)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.7.0 - Synaptics Incorporated)
TP-LINK TL-WN721N_TL-WN722N Driver (HKLM-x32\...\{38A1E3ED-D913-41D2-9953-A93D5ACE3ADF}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.0.11 - Tweaking.com)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Winamp (remove only) (HKLM-x32\...\Winamp) (Version: - )
Windows Driver Package - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => -> No File
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2017-11-17] (Glarysoft Ltd)
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers1: [PDFArchitect5_ManagerExt] -> {00B7B69F-6774-4906-9C7F-7D117A3644A9} => -> No File
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)
ContextMenuHandlers1: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2017-11-17] (Glarysoft Ltd)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers4: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2014-11-22] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2017-11-17] (Glarysoft Ltd)
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {033210DE-4EB8-40B7-8B03-1A9CA0CE8432} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {039A173C-3423-4308-9EF1-C851C8FD79A8} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {064E7D24-30B5-417B-B124-017AB8CB1FF2} - System32\Tasks\GoogleUpdateTaskMachineCore1d164318cc5ddaf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {2BB6C322-B773-4DCF-BAD3-21708A2CCF7A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {302089F9-C875-42D9-A743-6670CF0A80E6} - System32\Tasks\GoogleUpdateTaskMachineUA1d164318d1adb8b => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {3A05CDFA-4664-41CF-9CAF-3E0800C59337} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-18] (Adobe Systems Incorporated)
Task: {3D17A568-54CE-4568-B988-C44999F15F38} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2018-01-08] (Glarysoft Ltd)
Task: {486E1EC9-C9A2-4F36-9E17-CA03C1BE1505} - System32\Tasks\Uninstaller_SkipUac_Lenka => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {4AE12823-DA52-4F1E-BCE9-75889C2D0475} - System32\Tasks\WinThruster64-Lenka-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: {5C696F6E-908E-4CBA-A8B1-F376F9BF0990} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2017-05-02] (Tweaking.com)
Task: {661D0234-2492-47B7-BC21-9EDBE1A366F0} - System32\Tasks\WinThruster64-Lenka-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION
Task: {67D9BCE8-D59B-4EC7-BE06-0C6A335605FD} - System32\Tasks\{030E4F12-6DD0-4494-871E-2B70C6CFD488} => C:\windows\system32\pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {899F9674-9D8D-4E33-B88A-2C0BE6A39B84} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {8B4E62D3-4B85-48C6-9B84-5175CFC227A6} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\windows\system32\srtasks.exe
Task: {A044028A-5EDB-42E4-94F3-A9662BE8981A} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\windows\System32\LocationNotificationWindows.exe
Task: {A9EA48F6-2D66-43D4-B1D9-B1F025E536F3} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2010-12-24] (CyberLink)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B0B8DDEC-EFF0-4C73-AEED-17BB6A91A91F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2011-11-28] (Piriform Ltd)
Task: {C4DD4F48-138A-472C-80A6-D4D4EC7474C4} - System32\Tasks\{1C65C05D-E69F-4164-9D8C-35C303FF6721} => C:\windows\system32\pcalua.exe -a "F:\Power DVD v6.0 Deluxe Cracked\pdvd6_setup.exe" -d "F:\Power DVD v6.0 Deluxe Cracked"
Task: {CAE611F0-1084-433B-BCBB-371FB6CDD318} - System32\Tasks\Driver Booster SkipUAC (Lenka) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {CBFC7168-BD9E-4B24-A019-AB72BBA8B16D} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2018-01-08] (Glarysoft Ltd)
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {D0251434-9883-4CB9-B76B-E0B5992BF87E} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {DAD18027-6700-4B1F-AA71-A5461AEEF0CB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {E4622B9C-84CC-4280-85B3-4276AFE3F196} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_148_pepper.exe
Task: {E95DB84E-8D32-4A0F-B731-9EE63FC7AB22} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-03-01] (McAfee, Inc.)
Task: {F9D82E58-8FD1-46E6-BC97-B9EC8DB2FBEE} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\WinThruster64-Lenka-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: C:\windows\Tasks\WinThruster64-Lenka-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2010-10-22 15:38 - 2010-10-22 15:38 - 001407344 _____ () C:\Program Files (x86)\EgisTec Port Locker\x64\LIBEAY32.dll
2011-02-15 13:26 - 2011-02-15 13:26 - 000205088 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll
2008-12-20 04:20 - 2011-09-14 22:11 - 000054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 04:20 - 2011-09-14 22:11 - 000054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2012-04-08 09:51 - 2006-09-20 07:35 - 000020480 _____ () C:\windows\System32\spool\drivers\x64\3\WrtMon.exe
2011-04-15 06:28 - 2011-03-25 10:28 - 000094208 _____ () C:\windows\System32\IccLibDll_x64.dll
2012-04-08 09:51 - 2006-09-19 15:05 - 000024576 _____ () C:\windows\System32\spool\drivers\x64\3\WrtProc.exe
2016-02-21 15:52 - 2014-05-23 16:36 - 000847872 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
2002-04-26 18:53 - 2002-04-26 18:53 - 000012288 _____ () C:\Program Files (x86)\Winamp\winampa.exe
2018-01-04 22:09 - 2018-01-03 10:20 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\libglesv2.dll
2018-01-04 22:09 - 2018-01-03 10:20 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\libegl.dll
2016-02-21 15:52 - 2014-05-23 16:36 - 001411072 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll
2016-02-21 15:52 - 2014-05-23 16:36 - 000193024 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll
2018-01-08 03:15 - 2018-01-08 03:15 - 000087024 _____ () C:\Program Files (x86)\Glary Utilities 5\zlib1.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\100sexlinks.com -> 100sexlinks.com

There are 4788 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2018-01-30 17:49 - 000000855 _____ C:\windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-118739109-790167221-2496289451-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Lenka\AppData\Roaming\FastStone\FSIV\FSViewerWallPaper.jpg
DNS Servers: 192.168.29.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7B0D5B12-42B4-4C0D-8E65-0AE2B856C7AB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A411A133-11AC-49C7-9393-8F035D032FF5}] => (Allow) LPort=2869
FirewallRules: [{319B78C4-F8B0-4982-A27C-E444008F7F06}] => (Allow) LPort=1900
FirewallRules: [{5D967DD1-D3DD-4151-A93A-BD17E2DCE79C}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{45D1F6D6-4626-4DA2-87AB-C8EE89E7B454}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{EFD7CEBF-D806-47B4-B152-8C12A05A4A10}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{5151E4DE-0D49-4931-97E5-5F27B34846AC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

30-01-2018 16:58:44 Windows Update

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/30/2018 07:51:22 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Nelze načíst informace registru o čítači výkonu pro WSearchIdxPi pro instanci z důvodu následující chyby: Operace byla dokončena úspěšně. 0x0.

Error: (01/30/2018 07:51:18 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Sledování výkonu objektu indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Kontext: aplikace , katalog SystemIndex

Error: (01/30/2018 07:51:17 PM) (Source: Windows Search Service) (EventID: 3006) (User: )
Description: Sledování výkonu služby indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Error: (01/30/2018 06:37:05 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Nelze načíst informace registru o čítači výkonu pro WSearchIdxPi pro instanci z důvodu následující chyby: Operace byla dokončena úspěšně. 0x0.

Error: (01/30/2018 06:37:03 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Sledování výkonu objektu indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Kontext: aplikace , katalog SystemIndex

Error: (01/30/2018 06:37:03 PM) (Source: Windows Search Service) (EventID: 3006) (User: )
Description: Sledování výkonu služby indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Error: (01/30/2018 05:54:47 PM) (Source: .NET Runtime Optimization Service) (EventID: 1103) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (01/30/2018 05:54:47 PM) (Source: .NET Runtime Optimization Service) (EventID: 1103) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (01/30/2018 05:59:22 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Nelze načíst informace registru o čítači výkonu pro WSearchIdxPi pro instanci z důvodu následující chyby: Operace byla dokončena úspěšně. 0x0.

Error: (01/30/2018 05:59:18 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Sledování výkonu objektu indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Kontext: aplikace , katalog SystemIndex


System errors:
=============
Error: (01/30/2018 07:50:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 07:41:37 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {51FA2736-5DEE-11D4-98E8-006008BF430C} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 06:36:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 06:31:33 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {51FA2736-5DEE-11D4-98E8-006008BF430C} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 05:59:49 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Windows Update přestala během spouštění reagovat.

Error: (01/30/2018 05:57:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 05:56:37 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {51FA2736-5DEE-11D4-98E8-006008BF430C} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 05:54:31 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {995C996E-D918-4A8C-A302-45719A6F4EA7} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 04:46:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 04:46:26 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: Počítač byl restartován z procesu kontroly chyb. Kontrola chyb: 0x00000050 (0xfffff80003e00000, 0x0000000000000000, 0xfffff88003e828ae, 0x0000000000000002). Výpis byl uložen do: C:\windows\MEMORY.DMP. ID hlášení: 013018-15210-01


CodeIntegrity:
===================================
Date: 2017-04-17 17:06:18.157
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-04-17 17:06:17.923
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-04-17 17:06:17.704
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-04-17 17:06:17.470
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Celeron(R) CPU B800 @ 1.50GHz
Percentage of memory in use: 27%
Total physical RAM: 6058.14 MB
Available physical RAM: 4407.41 MB
Total Virtual: 12114.45 MB
Available Virtual: 10447.22 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:136.96 GB) (Free:77.35 GB) NTFS
Drive d: (Data) (Fixed) (Total:141.6 GB) (Free:68.87 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 0AF4037F)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=137 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=146.2 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Opakované spouštění obnovení systému - zotavení z chyb

#20 Příspěvek od Rudy »

Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#21 Příspěvek od 102mn »

# AdwCleaner 7.0.7.0 - Logfile created on Tue Jan 30 20:08:12 2018
# Updated on 2018/18/01 by Malwarebytes
# Database: 01-30-2018.1
# Running on Windows 7 Home Premium (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.ThreatSupport, C:\Users\Lenka\AppData\Local\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}
PUP.Optional.DriverPack, C:\Users\Lenka\AppData\Roaming\DRPSu


***** [ Files ] *****

PUP.Optional.AdvancedSystemCare, C:\Windows\SysNative\REGISTRYDEFRAGBOOTTIME.EXE


***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IObit\RealTimeProtector
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
PUP.Optional.Legacy, [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Appscion
PUP.Optional.Legacy, [Key] - HKCU\Software\Appscion
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\reimagerepair
PUP.Optional.Legacy, [Key] - HKCU\Software\reimagerepair
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\YahooPartnerToolbar
PUP.Optional.Legacy, [Key] - HKCU\Software\YahooPartnerToolbar
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
PUP.Optional.Spigot, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90E4CD0C-426F-4207-805B-7885AB32D43F}
PUP.Optional.DriverPack, [Key] - HKLM\SOFTWARE\drpsu
PUP.Optional.DriverPack, [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\drpsu
PUP.Optional.DriverPack, [Key] - HKCU\Software\drpsu


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [3082 B] - [2018/1/27 19:8:39]
C:/AdwCleaner/AdwCleaner[C1].txt - [1664 B] - [2018/1/27 19:25:47]
C:/AdwCleaner/AdwCleaner[S0].txt - [3238 B] - [2018/1/27 19:4:29]
C:/AdwCleaner/AdwCleaner[S1].txt - [1528 B] - [2018/1/27 19:25:7]
C:/AdwCleaner/AdwCleaner[S2].txt - [4554 B] - [2018/1/28 9:47:7]
C:/AdwCleaner/AdwCleaner[S3].txt - [3964 B] - [2018/1/28 10:33:41]
C:/AdwCleaner/AdwCleaner[S4].txt - [3760 B] - [2018/1/28 11:25:56]
C:/AdwCleaner/AdwCleaner[S5].txt - [3420 B] - [2018/1/28 14:18:14]


########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt ##########

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#22 Příspěvek od 102mn »

Po čištění a následném restartu opět problém s obnovením systému, do PC jsem se dostala po dvou restartech.



Log po čištění
# AdwCleaner 7.0.7.0 - Logfile created on Tue Jan 30 20:11:49 2018
# Updated on 2018/18/01 by Malwarebytes
# Running on Windows 7 Home Premium (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\Users\Lenka\AppData\Local\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}
Deleted: C:\Users\Lenka\AppData\Roaming\DRPSu


***** [ Files ] *****

Deleted: C:\Windows\SysNative\REGISTRYDEFRAGBOOTTIME.EXE


***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\IObit\RealTimeProtector
Deleted: [Key] - HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain
Deleted: [Value] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain
Deleted: [Value] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain
Deleted: [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Appscion
Deleted: [Key] - HKCU\Software\Appscion
Deleted: [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\reimagerepair
Deleted: [Key] - HKCU\Software\reimagerepair
Deleted: [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\YahooPartnerToolbar
Deleted: [Key] - HKCU\Software\YahooPartnerToolbar
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90E4CD0C-426F-4207-805B-7885AB32D43F}
Deleted: [Key] - HKLM\SOFTWARE\drpsu
Deleted: [Key] - HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\drpsu
Deleted: [Key] - HKCU\Software\drpsu


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [3082 B] - [2018/1/27 19:8:39]
C:/AdwCleaner/AdwCleaner[C1].txt - [1664 B] - [2018/1/27 19:25:47]
C:/AdwCleaner/AdwCleaner[S0].txt - [3238 B] - [2018/1/27 19:4:29]
C:/AdwCleaner/AdwCleaner[S1].txt - [1528 B] - [2018/1/27 19:25:7]
C:/AdwCleaner/AdwCleaner[S2].txt - [4554 B] - [2018/1/28 9:47:7]
C:/AdwCleaner/AdwCleaner[S3].txt - [3964 B] - [2018/1/28 10:33:41]
C:/AdwCleaner/AdwCleaner[S4].txt - [3760 B] - [2018/1/28 11:25:56]
C:/AdwCleaner/AdwCleaner[S5].txt - [3420 B] - [2018/1/28 14:18:14]
C:/AdwCleaner/AdwCleaner[S6].txt - [3520 B] - [2018/1/30 20:8:12]


########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Opakované spouštění obnovení systému - zotavení z chyb

#23 Příspěvek od Rudy »

Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#24 Příspěvek od 102mn »

LOG 1

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Lenka (administrator) on LENKANB (30-01-2018 22:42:37)
Running from C:\Users\Lenka\Downloads
Loaded Profiles: Lenka (Available Profiles: Lenka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(McAfee, Inc.) C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe
() C:\windows\System32\spool\drivers\x64\3\WrtMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\windows\System32\igfxtray.exe
(Intel Corporation) C:\windows\System32\hkcmd.exe
(Intel Corporation) C:\windows\System32\igfxpers.exe
() C:\windows\System32\spool\drivers\x64\3\WrtProc.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\Program Files (x86)\Winamp\winampa.exe
(ScanSoft, Inc.) C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\windows\System32\dllhost.exe
(PLUMBYTES) C:\Program Files\PCCare Software\PCCare Anti-Malware\AmwService.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(Microsoft Corporation) C:\windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\SoftwareUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-11-22] (Realtek Semiconductor)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9769888 2011-09-14] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-09-14] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-09-14] (Lenovo)
HKLM\...\Run: [WrtMon.exe] => C:\windows\system32\spool\drivers\x64\3\WrtMon.exe [20480 2006-09-20] ()
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-11-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-11-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [548864 2014-11-22] (Vimicro)
HKLM-x32\...\Run: [PLTSR] => C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe [364400 2010-10-22] (Egis Technology Inc. )
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2010-12-24] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [224352 2010-12-24] (CyberLink Corp.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-10] (Egis Technology Inc.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePRCShortCut] => "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [3744552 2011-11-28] (AVAST Software)
HKLM-x32\...\Run: [NeroFilterCheck] => C:\windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\Winampa.exe [12288 2002-04-26] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [OpwareSE4] => C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44016 2018-01-08] (Glarysoft Ltd)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Lsa: [Notification Packages] scecli EgisPLPwdFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2011-09-14]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2016-02-21]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
BootExecute: autocheck autochk *

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.29.254
Tcpip\..\Interfaces\{AAB07F94-1087-4DD3-9E9E-E0F1454C75CB}: [DhcpNameServer] 192.168.29.254

Internet Explorer:
==================
HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=12454
HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {11C2D730-E25D-4AA7-9CE9-67CBA7C5CBCC} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {28071E18-7870-4CF9-AB84-74340EB83C41} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {6539E413-939D-4416-9BBE-CD0AECF96FC6} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7LENN
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {6D8243F2-E9E5-4DEE-B194-63EB16A0B52C} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {89643858-2BED-4421-940B-6B6E663E3070} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {8BEF890E-265B-4A21-8BDA-B984254EB833} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {B54D56E8-BAFD-4827-8B93-D0E6E950040D} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {B8CA1E71-4F07-46A4-96F8-6F4F7A56D70D} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> {DA7A6777-3DD5-4F37-8998-E88E249D66C4} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_12454
BHO: avast! WebRep -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28] (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28] (AVAST Software)
Toolbar: HKLM-x32 - No Name - {84F23192-A475-4038-B5C0-8584777F2DF4} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

FireFox:
========
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [No File]

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR NewTab: Default -> Not-active:"chrome-extension://gfoabcdjalmeenbjjngidappmppchblc/homePageRedirect.html"
CHR Profile: C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default [2018-01-30]
CHR Extension: (YouTube) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Vyhledávání Google) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Norton Home Page for Chrome) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfoabcdjalmeenbjjngidappmppchblc [2017-04-26]
CHR Extension: (Norton Safe) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbmobhkkblcgdifigjglcjneplefbkmh [2017-04-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Lenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-25]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [icmlaeflemplmjndnaapfdbbnpncnbda] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2011-12-20]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44768 2011-11-28] (AVAST Software)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [956192 2011-02-15] (Broadcom Corporation.)
R2 EgisTec Service Help; C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [327024 2010-10-22] (Egis Technology Inc. )
R2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [189840 2017-03-02] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 pccareamw_service; C:\Program Files\PCCare Software\PCCare Anti-Malware\AmwService.exe [125968 2016-07-19] (PLUMBYTES)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [24408 2011-11-28] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [66904 2011-11-28] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [42328 2011-11-28] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [591192 2011-11-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [304472 2011-11-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [58712 2011-11-28] (AVAST Software)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [20160 2017-04-17] (Glarysoft Ltd)
R3 MEIx64; C:\windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-11-22] (Intel Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
S3 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [3300568 2014-11-22] (Realtek Semiconductor Corporation )
R3 SmbDrvI; C:\windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2014-11-22] (Synaptics Incorporated)
U3 BcmSqlStartupSvc; no ImagePath
U2 CLKMSVC10_3A60B698; no ImagePath
U2 CLKMSVC10_C3B3B687; no ImagePath
U2 DriverService; no ImagePath
S2 eamonm; system32\DRIVERS\eamonm.sys [X]
U2 IAStorDataMgrSvc; no ImagePath
U2 iATAgentService; no ImagePath
U2 idealife Update Service; no ImagePath
U3 IGRS; no ImagePath
U2 IviRegMgr; no ImagePath
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20170419.020\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.7.0.76\Definitions\SDSDefs\20170419.020\EX64.SYS [X]
U2 nvUpdatusService; no ImagePath
U2 Oasis2Service; no ImagePath
U2 PCCarerService; no ImagePath
U2 ReadyComm.DirectRouter; no ImagePath
U2 RichVideo; no ImagePath
U2 RtLedService; no ImagePath
U2 SeaPort; no ImagePath
U2 SoftwareService; no ImagePath
U3 SQLWriter; no ImagePath
U2 Stereo Service; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-30 22:25 - 2018-01-30 22:25 - 000266576 _____ C:\windows\Minidump\013018-33072-01.dmp
2018-01-30 21:41 - 2018-01-30 21:41 - 000266576 _____ C:\windows\Minidump\013018-19780-01.dmp
2018-01-30 21:24 - 2018-01-30 21:25 - 000266576 _____ C:\windows\Minidump\013018-16801-01.dmp
2018-01-30 21:13 - 2018-01-30 21:13 - 000266576 _____ C:\windows\Minidump\013018-16582-01.dmp
2018-01-30 20:21 - 2018-01-30 20:21 - 000036036 _____ C:\Users\Lenka\Downloads\Addition.txt
2018-01-30 20:18 - 2018-01-30 22:43 - 000019321 _____ C:\Users\Lenka\Downloads\FRST.txt
2018-01-30 20:17 - 2018-01-30 22:42 - 000000000 ____D C:\FRST
2018-01-30 20:14 - 2018-01-30 20:14 - 002393088 _____ (Farbar) C:\Users\Lenka\Downloads\FRST64.exe
2018-01-30 19:25 - 2018-01-30 19:08 - 000481104 _____ (DriverPack) C:\Users\Lenka\Desktop\DriverPack-Online.exe
2018-01-30 19:08 - 2018-01-30 19:08 - 000481104 _____ (DriverPack) C:\Users\Lenka\Downloads\DriverPack-Online.exe
2018-01-30 17:53 - 2018-01-30 22:19 - 000003160 _____ C:\windows\System32\Tasks\SidebarExecute
2018-01-30 17:19 - 2018-01-30 17:19 - 000000207 _____ C:\windows\tweaking.com-regbackup-LENKANB-Windows-7-Home-Premium-(64-bit).dat
2018-01-30 17:19 - 2018-01-30 17:19 - 000000000 ____D C:\RegBackup
2018-01-30 17:00 - 2018-01-30 17:00 - 000003652 _____ C:\windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2018-01-30 17:00 - 2018-01-30 17:00 - 000002159 _____ C:\Users\Lenka\Desktop\Tweaking.com - Windows Repair.lnk
2018-01-30 17:00 - 2018-01-30 17:00 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2018-01-30 16:59 - 2018-01-30 16:59 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2018-01-30 16:57 - 2018-01-30 17:00 - 000194556 _____ C:\windows\Tweaking.com - Windows Repair Setup Log.txt
2018-01-30 16:56 - 2018-01-30 16:57 - 037693392 _____ (Tweaking.com) C:\Users\Lenka\Downloads\tweaking.com_windows_repair_aio_setup.exe
2018-01-30 16:46 - 2018-01-30 22:25 - 205500760 _____ C:\windows\MEMORY.DMP
2018-01-30 16:46 - 2018-01-30 16:46 - 000266576 _____ C:\windows\Minidump\013018-15210-01.dmp
2018-01-29 22:07 - 2018-01-29 22:07 - 000000000 ____D C:\Users\Lenka\Downloads\nettun.inf_amd64_neutral_bd24fb174fabec97
2018-01-29 22:05 - 2018-01-29 22:05 - 000007298 _____ C:\Users\Lenka\Downloads\nettun.inf_amd64_neutral_bd24fb174fabec97.zip
2018-01-29 18:13 - 2018-01-29 18:13 - 000001200 _____ C:\Users\Lenka\Desktop\CrystalDiskInfo.lnk
2018-01-29 18:13 - 2018-01-29 18:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2018-01-29 18:13 - 2018-01-29 18:13 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2018-01-29 18:12 - 2018-01-29 18:12 - 003947992 _____ (Crystal Dew World ) C:\Users\Lenka\Downloads\CrystalDiskInfo7_5_1.exe
2018-01-28 15:14 - 2018-01-28 15:14 - 008206624 _____ (Malwarebytes) C:\Users\Lenka\Downloads\adwcleaner_7.0.7.0.exe
2018-01-28 15:00 - 2018-01-29 17:12 - 000000000 ____D C:\Program Files\trend micro
2018-01-28 15:00 - 2018-01-28 15:00 - 000000000 ____D C:\rsit
2018-01-28 14:59 - 2018-01-28 14:59 - 001329152 _____ C:\Users\Lenka\Downloads\RSITx64.exe
2018-01-28 13:35 - 2018-01-28 13:35 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PCCare Anti-Malware
2018-01-28 13:35 - 2018-01-28 13:35 - 000000000 ____D C:\Program Files\PCCare Software
2018-01-28 13:31 - 2018-01-28 13:31 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ErrorFix Kit
2018-01-28 13:31 - 2018-01-28 13:31 - 000000000 ____D C:\Program Files (x86)\ErrorFixKIT
2018-01-28 13:28 - 2018-01-28 13:28 - 000961552 _____ (PCCare) C:\Users\Lenka\Downloads\antimalware-setup.exe
2018-01-28 13:27 - 2018-01-28 13:27 - 000888304 _____ C:\Users\Lenka\Downloads\errorfixkit-setup.exe
2018-01-28 13:20 - 2018-01-28 13:20 - 000001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2018-01-28 12:28 - 2018-01-28 12:28 - 000000000 ____D C:\Users\Lenka\AppData\Local\{003ACA6A-C058-424D-B955-A82DE5375C64}
2018-01-28 12:06 - 2018-01-28 12:06 - 000790528 _____ C:\windows\system32\config\default.gu
2018-01-28 12:06 - 2018-01-28 12:06 - 000024576 _____ C:\windows\system32\config\security.gu
2018-01-28 12:06 - 2018-01-28 12:06 - 000024576 _____ C:\windows\system32\config\sam.gu
2018-01-28 11:48 - 2018-01-30 22:41 - 000000000 ____D C:\Program Files (x86)\Glary Utilities 5
2018-01-28 11:48 - 2018-01-28 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2018-01-28 09:55 - 2018-01-30 22:37 - 000000368 _____ C:\windows\Tasks\WinThruster64-Lenka-Startup.job
2018-01-28 09:55 - 2018-01-28 09:55 - 000002746 _____ C:\windows\System32\Tasks\WinThruster64-Lenka-Startup
2018-01-28 09:54 - 2018-01-30 22:37 - 000000376 _____ C:\windows\Tasks\WinThruster64-Lenka-Notification.job
2018-01-28 09:54 - 2018-01-28 09:54 - 000003438 _____ C:\windows\System32\Tasks\WinThruster64-Lenka-Notification
2018-01-27 20:30 - 2018-01-27 23:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-01-27 20:01 - 2018-01-30 21:11 - 000000000 ____D C:\AdwCleaner
2018-01-16 18:45 - 2018-01-16 18:45 - 000357011 _____ C:\Users\Lenka\Desktop\Šichtovník 2018 ver1.xlsx
2018-01-16 17:22 - 2018-01-01 03:21 - 005581544 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-01-16 17:22 - 2018-01-01 03:21 - 001680616 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2018-01-16 17:22 - 2018-01-01 03:21 - 000948968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2018-01-16 17:22 - 2018-01-01 03:21 - 000708328 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-01-16 17:22 - 2018-01-01 03:21 - 000288488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fltMgr.sys
2018-01-16 17:22 - 2018-01-01 03:19 - 001665384 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 014183936 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 002066432 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 002004480 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001942016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001867776 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001741312 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 001110528 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 000749568 _____ (Microsoft Corporation) C:\windows\system32\FirewallAPI.dll
2018-01-16 17:22 - 2018-01-01 03:18 - 000512000 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll
2018-01-16 17:22 - 2018-01-01 03:13 - 000631680 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-01-16 17:22 - 2018-01-01 03:02 - 001314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-01-16 17:22 - 2018-01-01 03:00 - 012880384 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2018-01-16 17:22 - 2018-01-01 03:00 - 001417728 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2018-01-16 17:22 - 2018-01-01 03:00 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2018-01-16 17:22 - 2018-01-01 02:59 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2018-01-16 17:22 - 2018-01-01 02:54 - 004013800 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2018-01-16 17:22 - 2018-01-01 02:54 - 003959016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2018-01-16 17:22 - 2018-01-01 02:50 - 000455680 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2018-01-16 17:22 - 2018-01-01 02:42 - 000460288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2018-01-16 17:22 - 2018-01-01 02:42 - 000406016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2018-01-16 17:22 - 2018-01-01 02:41 - 000754176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2018-01-16 17:22 - 2017-12-30 08:29 - 000395968 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-01-16 17:22 - 2017-12-29 19:39 - 020274688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-01-16 17:22 - 2017-12-29 19:13 - 000499712 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-01-16 17:22 - 2017-12-29 19:12 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2018-01-16 17:22 - 2017-12-29 19:09 - 002294272 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-01-16 17:22 - 2017-12-29 19:04 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2018-01-16 17:22 - 2017-12-29 19:03 - 000662528 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-01-16 17:22 - 2017-12-29 18:45 - 004508160 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-01-16 17:22 - 2017-12-29 18:38 - 013680128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-01-16 17:22 - 2017-12-29 18:36 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2018-01-16 17:22 - 2017-12-29 18:19 - 002767872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-01-16 17:22 - 2017-12-29 18:15 - 001313792 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-01-16 17:22 - 2017-12-29 10:15 - 025737728 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-01-16 17:22 - 2017-12-29 09:52 - 002900480 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-01-16 17:22 - 2017-12-29 09:51 - 005796352 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-01-16 17:22 - 2017-12-29 09:50 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-01-16 17:22 - 2017-12-29 09:40 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-01-16 17:22 - 2017-12-29 09:39 - 000817152 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-01-16 17:22 - 2017-12-29 09:39 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-01-16 17:22 - 2017-12-29 09:32 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-01-16 17:22 - 2017-12-29 09:04 - 015284224 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-01-16 17:22 - 2017-12-29 09:03 - 000807936 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-01-16 17:22 - 2017-12-29 09:01 - 002134528 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-01-16 17:22 - 2017-12-29 09:01 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-01-16 17:22 - 2017-12-29 08:50 - 003241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-01-16 17:22 - 2017-12-29 08:39 - 001545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-01-16 17:22 - 2017-12-29 08:27 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-01-16 17:22 - 2017-12-21 07:27 - 000634312 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2018-01-16 17:22 - 2017-12-13 17:31 - 000383720 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2018-01-16 17:22 - 2017-12-13 17:15 - 000309480 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2018-01-16 17:21 - 2018-01-01 03:21 - 000262376 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-01-16 17:21 - 2018-01-01 03:21 - 000213736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdyboost.sys
2018-01-16 17:21 - 2018-01-01 03:21 - 000154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-01-16 17:21 - 2018-01-01 03:21 - 000114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2018-01-16 17:21 - 2018-01-01 03:21 - 000095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-01-16 17:21 - 2018-01-01 03:18 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000977408 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000961024 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000863232 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2018-01-16 17:21 - 2018-01-01 03:18 - 000842752 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000828928 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000705024 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL
2018-01-16 17:21 - 2018-01-01 03:18 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000473600 _____ (Microsoft Corporation) C:\windows\system32\taskcomp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000444928 _____ (Microsoft Corporation) C:\windows\system32\winhttp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000439296 _____ (Microsoft Corporation) C:\windows\system32\p2psvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000366592 _____ (Microsoft Corporation) C:\windows\system32\wcncsvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000327168 _____ (Microsoft Corporation) C:\windows\system32\pnrpsvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000324096 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2018-01-16 17:21 - 2018-01-01 03:18 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000303104 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000264704 _____ (Microsoft Corporation) C:\windows\system32\P2P.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000223232 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000120320 _____ (Microsoft Corporation) C:\windows\system32\WcnApi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000108544 _____ (Microsoft Corporation) C:\windows\system32\icfupgd.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000101376 _____ (Microsoft Corporation) C:\windows\system32\fdWCN.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000095744 _____ (Microsoft Corporation) C:\windows\system32\rascfg.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000076288 _____ (Microsoft Corporation) C:\windows\system32\rasdiag.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000070656 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\ndptsp.tsp
2018-01-16 17:21 - 2018-01-01 03:18 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000047104 _____ (Microsoft Corporation) C:\windows\system32\kmddsp.tsp
2018-01-16 17:21 - 2018-01-01 03:18 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\rasmxs.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000039424 _____ (Microsoft Corporation) C:\windows\system32\traffic.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\rasser.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000026112 _____ (Microsoft Corporation) C:\windows\system32\oleres.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000024576 _____ (Microsoft Corporation) C:\windows\system32\WcnEapPeerProxy.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000024064 _____ (Microsoft Corporation) C:\windows\system32\WcnEapAuthProxy.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000022528 _____ (Microsoft Corporation) C:\windows\system32\wfapigp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000016896 _____ (Microsoft Corporation) C:\windows\system32\wshqos.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wshnetbs.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000008704 _____ (Microsoft Corporation) C:\windows\system32\comcat.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 03:18 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2018-01-16 17:21 - 2018-01-01 03:04 - 000559616 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2018-01-16 17:21 - 2018-01-01 03:00 - 001499648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 001390080 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000463360 _____ (Microsoft Corporation) C:\windows\SysWOW64\FirewallAPI.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000351744 _____ (Microsoft Corporation) C:\windows\SysWOW64\winhttp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000304640 _____ (Microsoft Corporation) C:\windows\SysWOW64\taskcomp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000276992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wcncsvc.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000217600 _____ (Microsoft Corporation) C:\windows\SysWOW64\P2P.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000216576 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2018-01-16 17:21 - 2018-01-01 03:00 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000162304 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncsi.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdWCN.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\rascfg.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasdiag.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000052224 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\ndptsp.tsp
2018-01-16 17:21 - 2018-01-01 03:00 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\traffic.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000026112 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleres.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2018-01-16 17:21 - 2018-01-01 03:00 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 001806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000309760 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:59 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:55 - 000131584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pacer.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000088576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wanarp.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000058368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndproxy.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000045056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netbios.sys
2018-01-16 17:21 - 2018-01-01 02:55 - 000024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndistapi.sys
2018-01-16 17:21 - 2018-01-01 02:54 - 000077312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mpsdrv.sys
2018-01-16 17:21 - 2018-01-01 02:49 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-01-16 17:21 - 2018-01-01 02:49 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-01-16 17:21 - 2018-01-01 02:49 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-01-16 17:21 - 2018-01-01 02:49 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-01-16 17:21 - 2018-01-01 02:46 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2018-01-16 17:21 - 2018-01-01 02:45 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-01-16 17:21 - 2018-01-01 02:43 - 000086528 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcnApi.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000038912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kmddsp.tsp
2018-01-16 17:21 - 2018-01-01 02:43 - 000033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasmxs.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000022528 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasser.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcnEapPeerProxy.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000019968 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcnEapAuthProxy.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfapigp.dll
2018-01-16 17:21 - 2018-01-01 02:43 - 000013824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshqos.dll
2018-01-16 17:21 - 2018-01-01 02:42 - 000168448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2018-01-16 17:21 - 2018-01-01 02:42 - 000159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-01-16 17:21 - 2018-01-01 02:41 - 000106496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dfsc.sys
2018-01-16 17:21 - 2018-01-01 02:41 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-01-16 17:21 - 2018-01-01 02:41 - 000007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\comcat.dll
2018-01-16 17:21 - 2018-01-01 02:39 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2018-01-16 17:21 - 2018-01-01 02:36 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2018-01-16 17:21 - 2018-01-01 02:36 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2018-01-16 17:21 - 2018-01-01 02:36 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2018-01-16 17:21 - 2018-01-01 02:36 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2018-01-16 17:21 - 2018-01-01 02:35 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-16 17:21 - 2018-01-01 02:35 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-16 17:21 - 2017-12-30 07:42 - 000347328 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-01-16 17:21 - 2017-12-29 19:24 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2018-01-16 17:21 - 2017-12-29 19:13 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2018-01-16 17:21 - 2017-12-29 19:12 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2018-01-16 17:21 - 2017-12-29 19:11 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2018-01-16 17:21 - 2017-12-29 19:06 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2018-01-16 17:21 - 2017-12-29 19:06 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2018-01-16 17:21 - 2017-12-29 19:03 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-01-16 17:21 - 2017-12-29 19:03 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2018-01-16 17:21 - 2017-12-29 18:55 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2018-01-16 17:21 - 2017-12-29 18:51 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-01-16 17:21 - 2017-12-29 18:50 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2018-01-16 17:21 - 2017-12-29 18:50 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2018-01-16 17:21 - 2017-12-29 18:47 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2018-01-16 17:21 - 2017-12-29 18:47 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2018-01-16 17:21 - 2017-12-29 18:46 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2018-01-16 17:21 - 2017-12-29 18:44 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2018-01-16 17:21 - 2017-12-29 18:39 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2018-01-16 17:21 - 2017-12-29 18:38 - 000694272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-01-16 17:21 - 2017-12-29 18:37 - 002058752 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-01-16 17:21 - 2017-12-29 18:13 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-01-16 17:21 - 2017-12-29 10:04 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-01-16 17:21 - 2017-12-29 10:04 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-01-16 17:21 - 2017-12-29 09:51 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-01-16 17:21 - 2017-12-29 09:50 - 000577024 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-01-16 17:21 - 2017-12-29 09:50 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-01-16 17:21 - 2017-12-29 09:50 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-01-16 17:21 - 2017-12-29 09:44 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-01-16 17:21 - 2017-12-29 09:43 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-01-16 17:21 - 2017-12-29 09:39 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-01-16 17:21 - 2017-12-29 09:39 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-01-16 17:21 - 2017-12-29 09:28 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-01-16 17:21 - 2017-12-29 09:22 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-01-16 17:21 - 2017-12-29 09:22 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-01-16 17:21 - 2017-12-29 09:21 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-01-16 17:21 - 2017-12-29 09:18 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-01-16 17:21 - 2017-12-29 09:18 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-01-16 17:21 - 2017-12-29 09:16 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-01-16 17:21 - 2017-12-29 09:14 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-01-16 17:21 - 2017-12-29 09:05 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-01-16 17:21 - 2017-12-29 09:03 - 000726528 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-01-16 17:21 - 2017-12-13 17:27 - 000100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2018-01-16 17:21 - 2017-12-13 17:27 - 000046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2018-01-16 17:21 - 2017-12-13 17:27 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2018-01-16 17:21 - 2017-12-13 17:27 - 000014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2018-01-16 17:21 - 2017-12-13 17:11 - 000071168 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2018-01-16 17:21 - 2017-12-13 17:11 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2018-01-16 17:21 - 2017-12-13 17:11 - 000010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2018-01-16 17:21 - 2017-12-13 16:50 - 000034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2018-01-16 17:21 - 2017-12-05 18:36 - 000625664 _____ (Microsoft Corporation) C:\windows\system32\mscms.dll
2018-01-16 17:21 - 2017-12-05 18:36 - 000250880 _____ (Microsoft Corporation) C:\windows\system32\icm32.dll
2018-01-16 17:21 - 2017-12-05 18:36 - 000040960 _____ (Microsoft Corporation) C:\windows\system32\WcsPlugInService.dll
2018-01-16 17:21 - 2017-12-05 18:08 - 000481792 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscms.dll
2018-01-16 17:21 - 2017-12-05 18:08 - 000215040 _____ (Microsoft Corporation) C:\windows\SysWOW64\icm32.dll
2018-01-16 17:21 - 2017-12-05 16:59 - 003222528 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2018-01-16 17:21 - 2017-12-05 16:49 - 000032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WcsPlugInService.dll
2018-01-14 14:58 - 2018-01-14 15:38 - 000355834 _____ C:\Users\Lenka\Desktop\Šichtovník 2018.xlsx
2018-01-14 14:34 - 2018-01-14 15:07 - 000004096 ____H C:\Users\Lenka\AppData\Local\keyfile3.drm
2018-01-14 12:45 - 2018-01-14 12:47 - 017234512 _____ C:\Users\Lenka\Downloads\Glary_Utilities_v5.91.0.112.exe
2018-01-14 09:59 - 2018-01-30 22:25 - 000000000 ____D C:\windows\Minidump
2018-01-13 17:58 - 2018-01-13 17:58 - 000027138 _____ C:\Users\Lenka\Downloads\planovaci-kalendar-2017-na-sirku-web.xlsx
2018-01-07 20:55 - 2018-01-07 20:55 - 000026581 _____ C:\Users\Lenka\Downloads\posun-offset-prakticky-radky-sloupce-excel-2010-prakticky (1).xlsx
2018-01-07 20:55 - 2018-01-07 20:55 - 000014732 _____ C:\Users\Lenka\Downloads\posun-offset-excel-2010.xlsx
2018-01-07 20:53 - 2018-01-07 20:53 - 000026581 _____ C:\Users\Lenka\Downloads\posun-offset-prakticky-radky-sloupce-excel-2010-prakticky.xlsx
2018-01-07 20:35 - 2018-01-07 20:35 - 000014538 _____ C:\Users\Lenka\Downloads\kdyz-funkce-logicka-excel.xlsx
2018-01-04 19:31 - 2018-01-04 19:31 - 000040448 _____ C:\Users\Lenka\Downloads\HODNOTA-NA-TEXT-TEXT.xls
2018-01-04 18:33 - 2018-01-04 18:33 - 000034712 _____ C:\Users\Lenka\Downloads\podminene-formatovani-datum-excel.xlsx
2018-01-04 18:28 - 2018-01-04 18:28 - 000023270 _____ C:\Users\Lenka\Downloads\podminene-formatovani-datum-cas.xlsx
2018-01-04 18:25 - 2018-01-04 18:25 - 000035328 _____ C:\Users\Lenka\Downloads\oznaceni-radku-podminene-formatovani.xls
2018-01-04 18:06 - 2018-01-04 18:06 - 000013997 _____ C:\Users\Lenka\Downloads\priklad-podminene-formatovani-den.xlsx
2018-01-04 17:49 - 2018-01-04 17:49 - 000041472 _____ C:\Users\Lenka\Downloads\podminene-formatovani-datum.xls
2018-01-03 20:55 - 2018-01-03 20:55 - 000011851 _____ C:\Users\Lenka\Downloads\Příklad.xlsx
2018-01-03 16:58 - 2018-01-03 16:58 - 000029234 _____ C:\Users\Lenka\Downloads\rocni-kalendar-2018-excel-barvy-jazyk.xlsx
2018-01-02 21:37 - 2018-01-02 21:37 - 000012155 _____ C:\Users\Lenka\Downloads\BINGO.xlsx
2018-01-02 20:03 - 2018-01-02 20:03 - 000031281 _____ C:\Users\Lenka\Downloads\2018-calendar-landscape-linear-days-aligned.xlsx
2018-01-02 19:59 - 2018-01-02 19:59 - 000037036 _____ C:\Users\Lenka\Downloads\calendar-2018-landscape-linear.xlsx
2018-01-02 18:04 - 2018-01-02 18:04 - 000029057 _____ C:\Users\Lenka\Downloads\rocni-kalendar-2017-excel-barvy-jazyk.xlsx
2018-01-02 17:41 - 2018-01-02 17:41 - 000204288 _____ C:\Users\Lenka\Downloads\ŠICHTOVNICE DISPEČINK_aktual.xls

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-30 22:43 - 2011-09-15 04:40 - 000623874 _____ C:\windows\system32\perfh005.dat
2018-01-30 22:43 - 2011-09-15 04:40 - 000125274 _____ C:\windows\system32\perfc005.dat
2018-01-30 22:43 - 2009-07-14 06:13 - 001490782 _____ C:\windows\system32\PerfStringBackup.INI
2018-01-30 22:43 - 2009-07-14 04:20 - 000000000 ____D C:\windows\inf
2018-01-30 22:38 - 2011-09-14 22:13 - 000112263 _____ C:\windows\system32\fastboot.set
2018-01-30 22:37 - 2009-07-14 06:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-01-30 22:34 - 2009-07-14 05:45 - 000028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-30 22:34 - 2009-07-14 05:45 - 000028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-30 22:27 - 2011-12-20 13:00 - 000111624 _____ C:\Users\Lenka\AppData\Local\GDIPFONTCACHEV1.DAT
2018-01-30 22:25 - 2009-07-14 05:45 - 000410520 _____ C:\windows\system32\FNTCACHE.DAT
2018-01-30 22:16 - 2009-07-14 03:34 - 000000538 _____ C:\windows\win.ini
2018-01-30 17:49 - 2009-07-14 03:34 - 000000855 _____ C:\windows\system32\Drivers\etc\hosts_bak_981
2018-01-28 22:12 - 2011-12-20 12:58 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2018-01-28 22:12 - 2011-09-14 21:59 - 000000000 ____D C:\ProgramData\Port Locker
2018-01-28 22:12 - 2009-07-14 04:20 - 000000000 ____D C:\windows\registration
2018-01-28 13:34 - 2009-07-14 06:32 - 000000000 ____D C:\windows\Downloaded Program Files
2018-01-28 13:20 - 2017-04-17 16:23 - 000003306 _____ C:\windows\System32\Tasks\GlaryInitialize 5
2018-01-28 13:20 - 2017-04-17 16:23 - 000002970 _____ C:\windows\System32\Tasks\GU5SkipUAC
2018-01-28 13:14 - 2011-12-20 12:58 - 000000000 ____D C:\Users\Lenka
2018-01-28 12:06 - 2009-07-14 03:34 - 114819072 _____ C:\windows\system32\config\software.gu.bak
2018-01-28 12:06 - 2009-07-14 03:34 - 025427968 _____ C:\windows\system32\config\system.gu.bak
2018-01-28 11:48 - 2017-04-17 16:23 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\GlarySoft
2018-01-28 11:20 - 2016-01-16 20:17 - 000000000 ____D C:\Users\Lenka\AppData\Local\ElevatedDiagnostics
2018-01-27 23:38 - 2017-05-06 07:57 - 000000000 ____D C:\Users\Lenka\AppData\Local\CrashDumps
2018-01-27 23:37 - 2011-12-27 10:20 - 000000000 ____D C:\Program Files\CCleaner
2018-01-27 23:33 - 2015-01-04 16:08 - 000000000 ____D C:\Users\Lenka\AppData\Roaming\Seznam.cz
2018-01-27 23:33 - 2015-01-04 16:08 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
2018-01-27 23:27 - 2009-07-14 04:20 - 000000000 ____D C:\windows\schemas
2018-01-27 20:16 - 2017-04-17 17:50 - 000000000 ____D C:\ProgramData\GlarySoft
2018-01-27 10:49 - 2013-08-17 09:57 - 000000000 ____D C:\windows\system32\MRT
2018-01-27 10:46 - 2017-10-15 10:00 - 129365736 ____C (Microsoft Corporation) C:\windows\system32\MRT-KB890830.exe
2018-01-27 10:45 - 2011-12-20 13:58 - 129365736 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-01-27 10:35 - 2011-12-20 13:45 - 001560276 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2018-01-23 19:58 - 2010-11-21 04:27 - 000548000 _____ (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2018-01-14 21:36 - 2017-04-18 17:20 - 000000000 ____D C:\ProgramData\Norton
2018-01-14 21:36 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-01-14 12:20 - 2017-04-20 16:13 - 000000000 ____D C:\Users\Lenka\AppData\Local\NPE
2018-01-14 12:13 - 2017-04-20 16:17 - 000000000 ____D C:\NPE
2018-01-04 22:09 - 2011-09-14 22:08 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-03 20:45 - 2012-01-03 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2018-01-01 16:50 - 2015-01-04 14:40 - 000066263 _____ C:\Users\Lenka\Desktop\model.xlsx

==================== Files in the root of some directories =======

2018-01-14 14:34 - 2018-01-14 15:07 - 000004096 ____H () C:\Users\Lenka\AppData\Local\keyfile3.drm
2017-04-20 17:20 - 2017-04-20 17:20 - 000007637 _____ () C:\Users\Lenka\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-01-03 13:47

==================== End of FRST.txt ============================

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#25 Příspěvek od 102mn »

LOG 2

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Lenka (30-01-2018 22:44:58)
Running from C:\Users\Lenka\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2011-12-20 11:58:54)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-118739109-790167221-2496289451-500 - Administrator - Disabled)
Guest (S-1-5-21-118739109-790167221-2496289451-501 - Limited - Disabled)
Lenka (S-1-5-21-118739109-790167221-2496289451-1000 - Administrator - Enabled) => C:\Users\Lenka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 25.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.270 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Atheros Client Installation Program (HKLM-x32\...\{D3694B69-6F8C-42D3-8A0A-EB2AB528C02C}) (Version: 7.0 - Atheros)
avast! Free Antivirus (HKLM-x32\...\avast) (Version: 6.0.1367.0 - AVAST Software)
Canon MF4010 Series (HKLM\...\{900A29A0-52BA-4a78-8E6C-5F4F821397CE}) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 3.13 - Piriform)
Codec Pack - All In 1 6.0.3.0 (HKLM-x32\...\Cool's_Codec_pack_4.12) (Version: - )
CrystalDiskInfo 7.5.1 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.5.1 - Crystal Dew World)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3623 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Management (HKLM-x32\...\{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo)
ErrorFix Kit 2018 (HKLM\...\ErrorFix Kit 2018) (Version: - )
FastStone Image Viewer 6.2 (HKLM-x32\...\FastStone Image Viewer) (Version: 6.2 - FastStone Soft)
Glary Utilities 5.91 (HKLM-x32\...\Glary Utilities 5) (Version: 5.91.0.112 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3517 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8000 - Broadcom Corporation)
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.12.204.1 - Lenovo EasyCamera)
Lenovo EE Boot Optimizer (HKLM\...\Lenovo EE Boot Optimizer) (Version: 0.0.1.6 - Lenovo)
Lenovo OneKey Recovery (HKLM\...\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo Security Suite (HKLM-x32\...\{0034859F-8E01-4C1D-BE77-F891C4786FBC}) (Version: 2.0.11.0 - Lenovo) Hidden
Lenovo Security Suite (HKLM-x32\...\InstallShield_{0034859F-8E01-4C1D-BE77-F891C4786FBC}) (Version: 2.0.11.0 - Lenovo)
Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PCCare Anti-Malware 2016 (HKLM\...\PCCare Anti-Malware 2016) (Version: - PCCare Software)
PDF Architect 5 (HKLM-x32\...\PDF Architect 5) (Version: 5.0.21.32007 - pdfforge GmbH)
PDF Architect 5 View Module (HKLM\...\{AD72FB9B-80C6-461D-B099-9DD76A62115E}) (Version: 5.0.22.32126 - pdfforge GmbH) Hidden
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.1 - Frank Heindörfer, Philip Chinery)
Port Locker (HKLM\...\{1F494B8A-D6E6-4540-9A74-F773B63164A6}) (Version: 1.0.5.24 - Egis Technology Inc.) Hidden
Port Locker (HKLM-x32\...\{A6FEE06D-C7E1-48CB-A9DF-1E317CF83CA4}) (Version: 1.0.5.24 - Egis Technology Inc.) Hidden
Port Locker (HKLM-x32\...\InstallShield_{A6FEE06D-C7E1-48CB-A9DF-1E317CF83CA4}) (Version: 1.0.5.24 - Egis Technology Inc.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.7303 - CyberLink Corp.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.21.531.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10008 - Realtek Semiconductor Corp.)
ScanSoft OmniPage SE 4.0 (HKLM-x32\...\{C1E693A4-B1D5-4DCD-B68D-2087835B7184}) (Version: 15.00.0020 - Nuance Communications, Inc.)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.7.0 - Synaptics Incorporated)
TP-LINK TL-WN721N_TL-WN722N Driver (HKLM-x32\...\{38A1E3ED-D913-41D2-9953-A93D5ACE3ADF}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.0.11 - Tweaking.com)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Winamp (remove only) (HKLM-x32\...\Winamp) (Version: - )
Windows Driver Package - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2017-11-17] (Glarysoft Ltd)
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers1: [PDFArchitect5_ManagerExt] -> {00B7B69F-6774-4906-9C7F-7D117A3644A9} => -> No File
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)
ContextMenuHandlers1: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2017-11-17] (Glarysoft Ltd)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers4: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2014-11-22] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2011-11-28] (AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2017-11-17] (Glarysoft Ltd)
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {033210DE-4EB8-40B7-8B03-1A9CA0CE8432} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {039A173C-3423-4308-9EF1-C851C8FD79A8} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {064E7D24-30B5-417B-B124-017AB8CB1FF2} - System32\Tasks\GoogleUpdateTaskMachineCore1d164318cc5ddaf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {2BB6C322-B773-4DCF-BAD3-21708A2CCF7A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {302089F9-C875-42D9-A743-6670CF0A80E6} - System32\Tasks\GoogleUpdateTaskMachineUA1d164318d1adb8b => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {3A05CDFA-4664-41CF-9CAF-3E0800C59337} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-18] (Adobe Systems Incorporated)
Task: {3D17A568-54CE-4568-B988-C44999F15F38} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2018-01-08] (Glarysoft Ltd)
Task: {486E1EC9-C9A2-4F36-9E17-CA03C1BE1505} - System32\Tasks\Uninstaller_SkipUac_Lenka => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {4AE12823-DA52-4F1E-BCE9-75889C2D0475} - System32\Tasks\WinThruster64-Lenka-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: {5C696F6E-908E-4CBA-A8B1-F376F9BF0990} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2017-05-02] (Tweaking.com)
Task: {661D0234-2492-47B7-BC21-9EDBE1A366F0} - System32\Tasks\WinThruster64-Lenka-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION
Task: {67D9BCE8-D59B-4EC7-BE06-0C6A335605FD} - System32\Tasks\{030E4F12-6DD0-4494-871E-2B70C6CFD488} => C:\windows\system32\pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {7A84CB09-6D70-4863-A9EA-629993EC75C8} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {8088D225-3443-46D1-AD3E-9E967F3DF4B5} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation)
Task: {899F9674-9D8D-4E33-B88A-2C0BE6A39B84} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\windows\system32\srtasks.exe
Task: {9C5AD7AA-F081-4009-91E4-C5743D05BF8D} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {A044028A-5EDB-42E4-94F3-A9662BE8981A} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\windows\System32\LocationNotificationWindows.exe
Task: {A9EA48F6-2D66-43D4-B1D9-B1F025E536F3} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2010-12-24] (CyberLink)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B0B8DDEC-EFF0-4C73-AEED-17BB6A91A91F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2011-11-28] (Piriform Ltd)
Task: {C4DD4F48-138A-472C-80A6-D4D4EC7474C4} - System32\Tasks\{1C65C05D-E69F-4164-9D8C-35C303FF6721} => C:\windows\system32\pcalua.exe -a "F:\Power DVD v6.0 Deluxe Cracked\pdvd6_setup.exe" -d "F:\Power DVD v6.0 Deluxe Cracked"
Task: {CAE611F0-1084-433B-BCBB-371FB6CDD318} - System32\Tasks\Driver Booster SkipUAC (Lenka) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {CBFC7168-BD9E-4B24-A019-AB72BBA8B16D} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2018-01-08] (Glarysoft Ltd)
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {DAD18027-6700-4B1F-AA71-A5461AEEF0CB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {E4622B9C-84CC-4280-85B3-4276AFE3F196} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_148_pepper.exe
Task: {E95DB84E-8D32-4A0F-B731-9EE63FC7AB22} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-03-01] (McAfee, Inc.)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\WinThruster64-Lenka-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: C:\windows\Tasks\WinThruster64-Lenka-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2010-10-22 15:38 - 2010-10-22 15:38 - 001407344 _____ () C:\Program Files (x86)\EgisTec Port Locker\x64\LIBEAY32.dll
2008-12-20 04:20 - 2011-09-14 22:11 - 000054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2008-12-20 04:20 - 2011-09-14 22:11 - 000054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2012-04-08 09:51 - 2006-09-20 07:35 - 000020480 _____ () C:\windows\System32\spool\drivers\x64\3\WrtMon.exe
2011-04-15 06:28 - 2011-03-25 10:28 - 000094208 _____ () C:\windows\System32\IccLibDll_x64.dll
2012-04-08 09:51 - 2006-09-19 15:05 - 000024576 _____ () C:\windows\System32\spool\drivers\x64\3\WrtProc.exe
2011-02-15 13:26 - 2011-02-15 13:26 - 000205088 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll
2016-02-21 15:52 - 2014-05-23 16:36 - 000847872 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
2002-04-26 18:53 - 2002-04-26 18:53 - 000012288 _____ () C:\Program Files (x86)\Winamp\winampa.exe
2016-02-21 15:52 - 2014-05-23 16:36 - 001411072 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll
2016-02-21 15:52 - 2014-05-23 16:36 - 000193024 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll
2018-01-08 03:15 - 2018-01-08 03:15 - 000087024 _____ () C:\Program Files (x86)\Glary Utilities 5\zlib1.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-118739109-790167221-2496289451-1000\...\100sexlinks.com -> 100sexlinks.com

There are 4788 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2018-01-30 22:16 - 000000855 _____ C:\windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-118739109-790167221-2496289451-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Lenka\AppData\Roaming\FastStone\FSIV\FSViewerWallPaper.jpg
DNS Servers: 192.168.29.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7B0D5B12-42B4-4C0D-8E65-0AE2B856C7AB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A411A133-11AC-49C7-9393-8F035D032FF5}] => (Allow) LPort=2869
FirewallRules: [{319B78C4-F8B0-4982-A27C-E444008F7F06}] => (Allow) LPort=1900
FirewallRules: [{5D967DD1-D3DD-4151-A93A-BD17E2DCE79C}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{45D1F6D6-4626-4DA2-87AB-C8EE89E7B454}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{EFD7CEBF-D806-47B4-B152-8C12A05A4A10}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{5151E4DE-0D49-4931-97E5-5F27B34846AC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

30-01-2018 16:58:44 Windows Update

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/30/2018 10:38:40 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Nelze načíst informace registru o čítači výkonu pro WSearchIdxPi pro instanci z důvodu následující chyby: Operace byla dokončena úspěšně. 0x0.

Error: (01/30/2018 10:38:40 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Sledování výkonu objektu indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Kontext: aplikace , katalog SystemIndex

Error: (01/30/2018 10:38:37 PM) (Source: Windows Search Service) (EventID: 3006) (User: )
Description: Sledování výkonu služby indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Error: (01/30/2018 10:26:29 PM) (Source: .NET Runtime Optimization Service) (EventID: 1103) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (01/30/2018 10:26:28 PM) (Source: .NET Runtime Optimization Service) (EventID: 1103) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown

Error: (01/30/2018 10:26:26 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Nelze načíst informace registru o čítači výkonu pro WSearchIdxPi pro instanci z důvodu následující chyby: Operace byla dokončena úspěšně. 0x0.

Error: (01/30/2018 10:26:26 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Sledování výkonu objektu indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Kontext: aplikace , katalog SystemIndex

Error: (01/30/2018 10:26:25 PM) (Source: Windows Search Service) (EventID: 3006) (User: )
Description: Sledování výkonu služby indexování nebylo inicializováno, protože nejsou načteny čítače nebo nebyl otevřen sdílený objekt paměti. Tato skutečnost má vliv pouze na dostupnost čítačů výkonu. Restartujte počítač.

Error: (01/30/2018 10:12:28 PM) (Source: WinMgmt) (EventID: 4) (User: )
Description: Error 0x8004401e encountered when trying to load MOF C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPWMI.MOF while recovering .MOF file marked with autorecover.

Error: (01/30/2018 09:42:01 PM) (Source: Windows Search Service) (EventID: 10021) (User: )
Description: Nelze načíst informace registru o čítači výkonu pro WSearchIdxPi pro instanci z důvodu následující chyby: Operace byla dokončena úspěšně. 0x0.


System errors:
=============
Error: (01/30/2018 10:37:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 10:34:11 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {F9717507-6651-4EDB-BFF7-AE615179BCCF} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 10:34:10 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {51FA2736-5DEE-11D4-98E8-006008BF430C} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 10:33:05 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Windows Update přestala během spouštění reagovat.

Error: (01/30/2018 10:25:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 10:25:56 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: Počítač byl restartován z procesu kontroly chyb. Kontrola chyb: 0x00000050 (0xfffff80003e00000, 0x0000000000000000, 0xfffff88003d2c8ae, 0x0000000000000002). Výpis byl uložen do: C:\windows\MEMORY.DMP. ID hlášení: 013018-33072-01

Error: (01/30/2018 10:21:28 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {995C996E-D918-4A8C-A302-45719A6F4EA7} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/30/2018 10:18:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (01/30/2018 09:41:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eamonm neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (01/30/2018 09:41:37 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: Počítač byl restartován z procesu kontroly chyb. Kontrola chyb: 0x00000050 (0xfffff80003e00000, 0x0000000000000000, 0xfffff88001b1c8ae, 0x0000000000000002). Výpis byl uložen do: C:\windows\MEMORY.DMP. ID hlášení: 013018-19780-01


CodeIntegrity:
===================================
Date: 2017-04-17 17:06:18.157
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-04-17 17:06:17.923
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-04-17 17:06:17.704
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-04-17 17:06:17.470
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Celeron(R) CPU B800 @ 1.50GHz
Percentage of memory in use: 26%
Total physical RAM: 6058.14 MB
Available physical RAM: 4440.16 MB
Total Virtual: 12114.45 MB
Available Virtual: 10360.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:136.96 GB) (Free:78 GB) NTFS
Drive d: (Data) (Fixed) (Total:141.6 GB) (Free:68.87 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 0AF4037F)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=137 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=146.2 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Opakované spouštění obnovení systému - zotavení z chyb

#26 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers1: [PDFArchitect5_ManagerExt] -> {00B7B69F-6774-4906-9C7F-7D117A3644A9} => -> No File
ContextMenuHandlers1: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers4: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
Task: {033210DE-4EB8-40B7-8B03-1A9CA0CE8432} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {039A173C-3423-4308-9EF1-C851C8FD79A8} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {4AE12823-DA52-4F1E-BCE9-75889C2D0475} - System32\Tasks\WinThruster64-Lenka-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: {67D9BCE8-D59B-4EC7-BE06-0C6A335605FD} - System32\Tasks\{030E4F12-6DD0-4494-871E-2B70C6CFD488} => C:\windows\system32\pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {899F9674-9D8D-4E33-B88A-2C0BE6A39B84} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\WinThruster64-Lenka-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: C:\windows\Tasks\WinThruster64-Lenka-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION
HKLM-x32\...\Run: [NeroFilterCheck] => C:\windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
Toolbar: HKLM-x32 - No Name - {84F23192-A475-4038-B5C0-8584777F2DF4} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [No File]
U3 BcmSqlStartupSvc; no ImagePath
U2 CLKMSVC10_3A60B698; no ImagePath
U2 CLKMSVC10_C3B3B687; no ImagePath
U2 DriverService; no ImagePath
U2 IAStorDataMgrSvc; no ImagePath
U2 iATAgentService; no ImagePath
U2 idealife Update Service; no ImagePath
U3 IGRS; no ImagePath
U2 IviRegMgr; no ImagePath
U2 nvUpdatusService; no ImagePath
U2 Oasis2Service; no ImagePath
U2 PCCarerService; no ImagePath
U2 ReadyComm.DirectRouter; no ImagePath
U2 RichVideo; no ImagePath
U2 RtLedService; no ImagePath
U2 SeaPort; no ImagePath
U2 SoftwareService; no ImagePath
U3 SQLWriter; no ImagePath
U2 Stereo Service; no ImagePath

EmptyTemp:
ResetHosts:
End
Uložte do C:\Users\Lenka\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#27 Příspěvek od 102mn »

Fix result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Lenka (31-01-2018 16:28:02) Run:1
Running from C:\Users\Lenka\Downloads
Loaded Profiles: Lenka (Available Profiles: Lenka)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers1: [PDFArchitect5_ManagerExt] -> {00B7B69F-6774-4906-9C7F-7D117A3644A9} => -> No File
ContextMenuHandlers1: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers4: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [UnLockerMenu] -> {A6FF0E3A-8437-482C-8E04-4F9E15C57538} => -> No File
Task: {033210DE-4EB8-40B7-8B03-1A9CA0CE8432} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {039A173C-3423-4308-9EF1-C851C8FD79A8} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {4AE12823-DA52-4F1E-BCE9-75889C2D0475} - System32\Tasks\WinThruster64-Lenka-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: {67D9BCE8-D59B-4EC7-BE06-0C6A335605FD} - System32\Tasks\{030E4F12-6DD0-4494-871E-2B70C6CFD488} => C:\windows\system32\pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {899F9674-9D8D-4E33-B88A-2C0BE6A39B84} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\WinThruster64-Lenka-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION
Task: C:\windows\Tasks\WinThruster64-Lenka-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION
HKLM-x32\...\Run: [NeroFilterCheck] => C:\windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
Toolbar: HKLM-x32 - No Name - {84F23192-A475-4038-B5C0-8584777F2DF4} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-118739109-790167221-2496289451-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [No File]
U3 BcmSqlStartupSvc; no ImagePath
U2 CLKMSVC10_3A60B698; no ImagePath
U2 CLKMSVC10_C3B3B687; no ImagePath
U2 DriverService; no ImagePath
U2 IAStorDataMgrSvc; no ImagePath
U2 iATAgentService; no ImagePath
U2 idealife Update Service; no ImagePath
U3 IGRS; no ImagePath
U2 IviRegMgr; no ImagePath
U2 nvUpdatusService; no ImagePath
U2 Oasis2Service; no ImagePath
U2 PCCarerService; no ImagePath
U2 ReadyComm.DirectRouter; no ImagePath
U2 RichVideo; no ImagePath
U2 RtLedService; no ImagePath
U2 SeaPort; no ImagePath
U2 SoftwareService; no ImagePath
U3 SQLWriter; no ImagePath
U2 Stereo Service; no ImagePath

EmptyTemp:
ResetHosts:
End
*****************

"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\IObitUnstaler" => removed successfully
HKLM\Software\Classes\CLSID\{B19ED566-D419-470b-B111-3C89040BC027} => key not found
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\PDFArchitect5_ManagerExt" => removed successfully
HKLM\Software\Classes\CLSID\{00B7B69F-6774-4906-9C7F-7D117A3644A9} => key not found
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UnLockerMenu" => removed successfully
HKLM\Software\Classes\CLSID\{A6FF0E3A-8437-482C-8E04-4F9E15C57538} => key not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\IObitUnstaler" => removed successfully
HKLM\Software\Classes\CLSID\{B19ED566-D419-470b-B111-3C89040BC027} => key not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE" => removed successfully
HKLM\Software\Classes\CLSID\{0365FE2C-F183-4091-AC82-BFC39FB75C49} => key not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files" => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\UnLockerMenu" => removed successfully
HKLM\Software\Classes\CLSID\{A6FF0E3A-8437-482C-8E04-4F9E15C57538} => key not found
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\IObitUnstaler" => removed successfully
HKLM\Software\Classes\CLSID\{B19ED566-D419-470b-B111-3C89040BC027} => key not found
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files" => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UnLockerMenu" => removed successfully
HKLM\Software\Classes\CLSID\{A6FF0E3A-8437-482C-8E04-4F9E15C57538} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{033210DE-4EB8-40B7-8B03-1A9CA0CE8432} => could not remove key. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{033210DE-4EB8-40B7-8B03-1A9CA0CE8432}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{039A173C-3423-4308-9EF1-C851C8FD79A8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{039A173C-3423-4308-9EF1-C851C8FD79A8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4AE12823-DA52-4F1E-BCE9-75889C2D0475}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AE12823-DA52-4F1E-BCE9-75889C2D0475}" => removed successfully
C:\windows\System32\Tasks\WinThruster64-Lenka-Notification => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinThruster64-Lenka-Notification" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{67D9BCE8-D59B-4EC7-BE06-0C6A335605FD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{67D9BCE8-D59B-4EC7-BE06-0C6A335605FD}" => removed successfully
C:\windows\System32\Tasks\{030E4F12-6DD0-4494-871E-2B70C6CFD488} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{030E4F12-6DD0-4494-871E-2B70C6CFD488}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{899F9674-9D8D-4E33-B88A-2C0BE6A39B84}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{899F9674-9D8D-4E33-B88A-2C0BE6A39B84}" => removed successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector" => removed successfully
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\windows\Tasks\WinThruster64-Lenka-Notification.job => moved successfully
C:\windows\Tasks\WinThruster64-Lenka-Startup.job => moved successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck" => removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{84F23192-A475-4038-B5C0-8584777F2DF4}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{84F23192-A475-4038-B5C0-8584777F2DF4} => key not found
"HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => removed successfully
HKLM\Software\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found
"HKU\S-1-5-21-118739109-790167221-2496289451-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => removed successfully
"HKLM\Software\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => removed successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\PDF Architect 5" => removed successfully
"HKLM\System\CurrentControlSet\Services\BcmSqlStartupSvc" => removed successfully
BcmSqlStartupSvc => service removed successfully
"HKLM\System\CurrentControlSet\Services\CLKMSVC10_3A60B698" => removed successfully
CLKMSVC10_3A60B698 => service removed successfully
"HKLM\System\CurrentControlSet\Services\CLKMSVC10_C3B3B687" => removed successfully
CLKMSVC10_C3B3B687 => service removed successfully
"HKLM\System\CurrentControlSet\Services\DriverService" => removed successfully
DriverService => service removed successfully
"HKLM\System\CurrentControlSet\Services\IAStorDataMgrSvc" => removed successfully
IAStorDataMgrSvc => service removed successfully
"HKLM\System\CurrentControlSet\Services\iATAgentService" => removed successfully
iATAgentService => service removed successfully
"HKLM\System\CurrentControlSet\Services\idealife Update Service" => removed successfully
idealife Update Service => service removed successfully
"HKLM\System\CurrentControlSet\Services\IGRS" => removed successfully
IGRS => service removed successfully
"HKLM\System\CurrentControlSet\Services\IviRegMgr" => removed successfully
IviRegMgr => service removed successfully
"HKLM\System\CurrentControlSet\Services\nvUpdatusService" => removed successfully
nvUpdatusService => service removed successfully
"HKLM\System\CurrentControlSet\Services\Oasis2Service" => removed successfully
Oasis2Service => service removed successfully
"HKLM\System\CurrentControlSet\Services\PCCarerService" => removed successfully
PCCarerService => service removed successfully
"HKLM\System\CurrentControlSet\Services\ReadyComm.DirectRouter" => removed successfully
ReadyComm.DirectRouter => service removed successfully
"HKLM\System\CurrentControlSet\Services\RichVideo" => removed successfully
RichVideo => service removed successfully
"HKLM\System\CurrentControlSet\Services\RtLedService" => removed successfully
RtLedService => service removed successfully
"HKLM\System\CurrentControlSet\Services\SeaPort" => removed successfully
SeaPort => service removed successfully
"HKLM\System\CurrentControlSet\Services\SoftwareService" => removed successfully
SoftwareService => service removed successfully
"HKLM\System\CurrentControlSet\Services\SQLWriter" => removed successfully
SQLWriter => service removed successfully
"HKLM\System\CurrentControlSet\Services\Stereo Service" => removed successfully
Stereo Service => service removed successfully
ResetHosts: => Error: No automatic fix found for this entry.

=========== EmptyTemp: ==========

BITS transfer queue => 16777216 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 7848127 B
Java, Flash, Steam htmlcache => 531 B
Windows/system/drivers => 1733 B
Edge => 0 B
Chrome => 118940565 B
Firefox => 0 B
Opera => 540672 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128742 B
systemprofile32 => 92089 B
LocalService => 0 B
NetworkService => 194944640 B
Lenka => 6270044 B

RecycleBin => 509823 B
EmptyTemp: => 330 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 16:29:40 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Opakované spouštění obnovení systému - zotavení z chyb

#28 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

102mn
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 10 lis 2009 21:11

Re: Opakované spouštění obnovení systému - zotavení z chyb

#29 Příspěvek od 102mn »

Po restartu a vypnutí PC zatím vše OK. Co způsobilo tento problém?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Opakované spouštění obnovení systému - zotavení z chyb

#30 Příspěvek od Rudy »

Převážně zbytečnosti, nic co by stálo za řeč.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno