Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Explorer.exe

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Explorer.exe

#1 Příspěvek od Tommy Puerto »

Zdravím,
mám problém se spouštěním počítače. Vždy se přihlásím a vyjede černé CMD kde musím zadat explorer.exe abych mě to pustilo do plochy, pokaždé když se přihlásím.

Proto prosím o podívání se na viry či radu.

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-05.2019
Ran by warto (25-05-2019 15:17:41)
Running from C:\Users\warto\Downloads
Windows 10 Pro Version 1809 17763.529 (X64) (2019-02-15 17:37:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3012513600-1294068158-3791818399-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3012513600-1294068158-3791818399-503 - Limited - Disabled)
Guest (S-1-5-21-3012513600-1294068158-3791818399-501 - Limited - Disabled)
Host (S-1-5-21-3012513600-1294068158-3791818399-1002 - Limited - Enabled) => C:\Users\Host
warto (S-1-5-21-3012513600-1294068158-3791818399-1001 - Administrator - Enabled) => C:\Users\warto
WDAGUtilityAccount (S-1-5-21-3012513600-1294068158-3791818399-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (HKLM\...\{5F4E8D94-3947-4019-9239-D2541C9A35F2}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\...\{7A5E4942-A527-42E6-A5FC-95109B756CA8}) (Version: 3.5.1.7 - Intel) Hidden
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.192 - Adobe)
Aktualizace NVIDIA 35.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 35.0.0.0 - NVIDIA Corporation) Hidden
ArcaniA - Gothic 4 (HKLM-x32\...\{07872B03-E301-4AE2-AA87-261C8E617769}) (Version: 1.00.0000 - JoWooD Entertainment AG)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 74.0.1376.132 - AVAST Software)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.154.333 - AVAST Software) Hidden
Bandicam (HKLM-x32\...\Bandicam) (Version: 4.4.0.1535 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\BitTorrent) (Version: 7.10.5.44995 - BitTorrent Inc.)
Caffeine (HKLM\...\{1247C26D-45E6-4D2E-973C-659FC86C6123}) (Version: 1.4.1.274 - Caffeine Inc) Hidden
Caffeine (HKLM-x32\...\{17147312-7df5-447d-afe8-c77fd4ad80b8}) (Version: 1.4.1.274 - Caffeine Inc)
CCleaner (HKLM\...\CCleaner) (Version: - Piriform Ltd.)
Connectify Hotspot 2019 (HKLM\...\Connectify) (Version: 2019.0.0.40040 - Connectify)
Crossout Launcher 1.0.3.36 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\CrossOutLauncher_is1) (Version: - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DiRT2 (HKLM-x32\...\{52D1D62C-FEAB-4580-849E-1DB624BADBBD}) (Version: 1.00.0000 - Codemasters)
Discord (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
Dragon Age Inquisition v.1.11.u10 (HKLM-x32\...\Dragon Age Inquisition_is1) (Version: - )
Epic Games Launcher (HKLM-x32\...\{93BFE5DF-776E-436F-8693-DF1F72C0E3C1}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
FlashBoot 2.3d (HKLM\...\FlashBoot_is1) (Version: - Mikhail Kupchik)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Fraps (HKLM-x32\...\Fraps) (Version: - )
Free Screen Recorder v2.9 (HKLM-x32\...\Free Screen Recorder_is1) (Version: 2.9 - Nbxsoft Software Development)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 74.0.3729.169 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
Intel(R) Computing Improvement Program (HKLM\...\{58FBAE3A-E602-47E6-9F32-AE25D48B378A}) (Version: 2.4.04140 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{ef2ad7ab-dd41-48ed-ae53-f7fe3cd903d8}) (Version: 3.5.1.7 - Intel)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Malwarebytes verze 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\OneDriveSetup.exe) (Version: 19.070.0410.0005 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 60.6.1 ESR (x86 en-US) (HKLM-x32\...\Mozilla Firefox 60.6.1 ESR (x86 en-US)) (Version: 60.6.1 - Mozilla)
Mozilla Firefox 67.0 (x64 cs) (HKLM\...\Mozilla Firefox 67.0 (x64 cs)) (Version: 67.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.2 - Mozilla)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.13 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.17.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.17.0.126 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{9530AE42-DAE1-4619-9594-B23487285D17}) (Version: 9.11.1107 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenShot Video Editor verze 2.4.3 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.4.3 - OpenShot Studios, LLC)
Origin (HKLM-x32\...\Origin) (Version: 10.5.34.21025 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 399.24 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 399.24 - NVIDIA Corporation) Hidden
paint.net (HKLM\...\{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}) (Version: 4.1.5 - dotPDN LLC)
PhotoFiltre 7 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\PhotoFiltre 7) (Version: - )
Rapture3D 2.3.22 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
RecoveRx version 3.8.0 (HKLM-x32\...\{3DE055DA-690F-43B8-9B7B-54E7D70806F9}_is1) (Version: 3.8.0 - Transcend Information, Inc.)
Roblox Player for warto (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\roblox-player) (Version: - Roblox Corporation)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
Shadow Of The Tomb Raider (HKLM-x32\...\{96F650BA-50B7-4E7B-B026-8C847F45ED92}_is1) (Version: - SQUARENIX)
Shadow of the Tomb Raider Cpy Čeština (HKLM-x32\...\{F233C280-925A-422A-91DD-F99B398A76E6}) (Version: 1.0.0 - cpy)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1495134320_is1) (Version: 2.0.0.51 - GOG.com)
Total War Arena (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\TWA.EU.PRODUCTION) (Version: - Wargaming.net)
Unity Web Player (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 80.0 - Ubisoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.0.0_x64__tf1gferkr813w [2019-05-07] (Autodesk Inc.)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.521.0_x64__rz1tebttyb220 [2019-03-12] (Dolby Laboratories)
Email.cz -> C:\Program Files\WindowsApps\949FFEAB.Email.cz_2.4.1.0_x64__refxrrjvvv3cw [2019-05-10] (Seznam.cz a.s.)
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.20.0_x64__kejf07qmg0jnm [2019-05-02] (Keeper Security Inc)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-09-07] (Plex)
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2018-10-12] (Microsoft Corporation)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-02-15] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Twitter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=edcifkpoamnkimdpjiabhfjahoinbpbp

==================== Loaded Modules (Whitelisted) ==============

2018-07-02 22:36 - 2018-07-02 22:36 - 098275328 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000092672 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 003922432 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2018-02-13 00:08 - 2017-11-29 10:11 - 001609216 _____ (Igor Pavlov) [File not signed] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\7z.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000547840 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001548288 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 000395776 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001177600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000038912 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qdds.dll
2018-02-13 00:08 - 2017-08-29 21:30 - 000024576 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qgif.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000031232 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qicns.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000025088 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000242176 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qjpeg.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000019968 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000018944 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qtga.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000318976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qtiff.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000017920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qwbmp.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000328704 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qwebp.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000993792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
2018-02-13 00:08 - 2017-10-27 11:24 - 004794368 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
2018-02-13 00:08 - 2017-08-29 21:27 - 005093888 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
2018-02-13 00:08 - 2017-08-29 21:25 - 002010624 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
2018-02-13 00:08 - 2017-08-29 21:34 - 002514944 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
2018-02-13 00:08 - 2017-08-29 21:37 - 002567168 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000247808 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
2018-02-13 00:08 - 2017-08-29 21:29 - 004480512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
2018-02-13 00:08 - 2017-08-29 21:40 - 000206336 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000697344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000172544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
2018-02-13 00:08 - 2017-08-29 21:44 - 000069632 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000096768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2018-02-28 14:45 - 000000753 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Windows Live\Shared
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\warto\Desktop\pičoviny\stretched-1920-1080-842957.jpg
DNS Servers: 10.1.0.33
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "DSATray"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "EA Core"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Discord"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{9A444B97-3320-4CAF-AFD7-CCF825EAD04F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [TCP Query User{302AB830-3147-469C-8CB6-358F70B7210E}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [{2943BAD5-0B17-44F6-AFD8-F886A05A70E1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8F1ECB3F-BB1B-4464-ADC3-4D836427E1F8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8F6B2F37-B472-42B0-B8FE-01B6CD3B2477}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{77DEC8DE-91AF-4666-AE51-6AC4398A75EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C065BEA0-AA37-44F8-B721-A32BDF8C3C9A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{B0725937-A22A-4390-9AAE-3F2EA27FE65F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{32955051-F35D-47E1-B0CB-FCE57E603D98}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{7CB67C81-3838-4269-8D25-2D2DDBED43C8}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{FE24C43C-9D27-44E6-843F-504502F5F203}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A01BD763-F1C8-42B4-8C48-A5558DFA67B2}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A0C8C48D-620B-4919-8FE7-510EACE9BE74}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{C8A83804-6167-453F-B838-9DB6489D9BE8}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A4E8F381-B403-40A9-B8BB-7FA087965B61}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [{74B1B2AE-1033-4F7C-A665-738C684DEB1F}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [UDP Query User{1E6AAAAC-6B5E-44C6-A9A6-471D3C19AB2E}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [TCP Query User{B87C723B-3BDF-45AA-BA72-E5D539DF48A7}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [UDP Query User{1248693B-A1BE-47BE-A697-6AE83EF38C84}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [TCP Query User{693305F7-92F7-4E0F-8AF4-81D5029A7646}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [{0B363149-DD6E-4F7F-B483-3DED1BC8E7E5}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{877274C3-04FF-453E-AD6D-9745E0CA973C}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{71BCA3F8-1108-4BB9-9F1C-CF95C3F34DD7}] => (Allow) LPort=1688
FirewallRules: [TCP Query User{4F06821A-7212-459A-B965-2DCD8D02A1A1}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5397481F-A840-4DA7-BBE9-7A5659313106}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{21B53C08-9147-4502-B390-7E01A03DAD87}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5D38FC9B-3BA3-4C5F-8102-2B08AA67C949}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CEA43369-C54E-4E28-B5A5-2DD330242125}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{15167DB2-9A30-455E-B8CA-9F2E73C170C7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{982F743C-5A18-4F12-9118-49EC9FBD5285}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{E9900D7C-0CF7-4D34-A6B2-9FDA0E490B75}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{BF24202F-0DD7-471C-BD4A-C5DD556056F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{126204BB-BA32-44A2-AC34-963279CAB2D5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{0024598A-FEAC-418B-A2EE-B36FD8D53AB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A24BB525-1C2E-4172-94E2-51A1203EC0B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{05A89F23-1566-4BBA-BBA9-EEB72F00D2EB}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{44B8882D-281B-4F9B-B2E5-C2A62C455515}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{34F512B3-225C-44CB-A151-2544D6025CFA}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1B5A931E-8D0A-4F16-872B-AABEE15A23C5}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{0A6D0211-8350-4960-8716-22072153BDBE}C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{7C73D6A0-5D60-4F1C-B35F-97D7E299B002}C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{C4D3F493-882E-42D5-B956-43C2FB9C587B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C23CD4BE-7964-4B42-82DF-B8C34596CF45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{1EA93D44-4704-4F5D-B89B-DC1CDB459723}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{35951E08-48E7-476E-AE12-4F004DE2C79A}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{F59F6728-93DA-4694-81F3-F31BFDC5A66B}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{24AB2205-4C5C-46DB-9443-40B08AA7D470}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{0CE020BF-D566-4CF4-BD3E-802E53E4CA7F}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{474CAD7A-6CEF-432F-B2BF-1B688E577696}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{78A3F1A0-58CC-46D5-93DE-FA8D8F80BA36}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FD033137-C54C-4677-85A1-7BF3DE5872F6}] => (Allow) LPort=2869
FirewallRules: [{E88DC7EB-1C82-4ABB-9808-C3CCE23BA419}] => (Allow) LPort=1900
FirewallRules: [{2921B86D-3849-43C4-ACC7-85060A95C650}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{65616C1B-9028-4B51-B643-9DD0CE2B84D0}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (AVAST Software s.r.o. -> AVAST Software)

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/25/2019 02:46:17 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: NT AUTHORITY)
Description: Systém Windows nemůže načíst knihovnu DLL rozšiřitelných čítačů C:\WINDOWS\system32\sysmain.dll (kód chyby Win32 126).

Error: (05/24/2019 07:17:53 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {4528DE87-43FB-4D5F-99AB-829BC759CCBA}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:53 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {4528DE87-43FB-4D5F-99AB-829BC759CCBA}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:43 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {60C1366B-3452-41F4-80C6-54D9F9534B8A}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:43 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {60C1366B-3452-41F4-80C6-54D9F9534B8A}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:33 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {C8C6C3B9-1B57-4381-A3D1-0488A819B848}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:33 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {C8C6C3B9-1B57-4381-A3D1-0488A819B848}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:23 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {5B605E4B-5069-44CA-A18F-48A9D109A13C}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.


System errors:
=============
Error: (05/25/2019 02:46:14 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.SecurityAppBroker
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:33:11 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:31:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Update Orchestrator Service byla ukončena s následující chybou:
Daná operace se vrátila, protože vypršel časový limit.

Error: (05/25/2019 02:24:10 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (05/25/2019 01:24:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2019-05-15 19:24:54.024
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {2C146212-B44C-4337-87B5-CE59AEFB5D8E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-05-15 18:52:08.510
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {BD1A9B29-EFEF-4B57-83DB-CB46BBDB28C4}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-04-24 16:23:44.867
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070643
Popis chyby :Při instalaci došlo k závažné chybě.

Date: 2019-04-24 16:23:41.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.293.68.0
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antispywarový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15900.4
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

Date: 2019-04-24 16:23:41.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.293.68.0
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antivirový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15900.4
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0501 10/03/2016
Motherboard: ASUSTeK COMPUTER INC. B150M PRO GAMING
Processor: Intel(R) Pentium(R) CPU G4600 @ 3.60GHz
Percentage of memory in use: 54%
Total physical RAM: 8128.61 MB
Available physical RAM: 3669.71 MB
Total Virtual: 14528.61 MB
Available Virtual: 7036.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.24 GB) (Free:5.01 GB) NTFS
Drive d: (USB DISK) (Removable) (Total:60.94 GB) (Free:44.79 GB) FAT32

\\?\Volume{5a6ae5dd-a1c3-46c1-a0fb-4e99138bf673}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{acd79ad2-c4af-4496-92ef-e9a2db0b22a9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (Protective MBR) (Size: 61 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-05.2019
Ran by warto (25-05-2019 15:17:41)
Running from C:\Users\warto\Downloads
Windows 10 Pro Version 1809 17763.529 (X64) (2019-02-15 17:37:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3012513600-1294068158-3791818399-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3012513600-1294068158-3791818399-503 - Limited - Disabled)
Guest (S-1-5-21-3012513600-1294068158-3791818399-501 - Limited - Disabled)
Host (S-1-5-21-3012513600-1294068158-3791818399-1002 - Limited - Enabled) => C:\Users\Host
warto (S-1-5-21-3012513600-1294068158-3791818399-1001 - Administrator - Enabled) => C:\Users\warto
WDAGUtilityAccount (S-1-5-21-3012513600-1294068158-3791818399-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (HKLM\...\{5F4E8D94-3947-4019-9239-D2541C9A35F2}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\...\{7A5E4942-A527-42E6-A5FC-95109B756CA8}) (Version: 3.5.1.7 - Intel) Hidden
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.192 - Adobe)
Aktualizace NVIDIA 35.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 35.0.0.0 - NVIDIA Corporation) Hidden
ArcaniA - Gothic 4 (HKLM-x32\...\{07872B03-E301-4AE2-AA87-261C8E617769}) (Version: 1.00.0000 - JoWooD Entertainment AG)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 74.0.1376.132 - AVAST Software)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.154.333 - AVAST Software) Hidden
Bandicam (HKLM-x32\...\Bandicam) (Version: 4.4.0.1535 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\BitTorrent) (Version: 7.10.5.44995 - BitTorrent Inc.)
Caffeine (HKLM\...\{1247C26D-45E6-4D2E-973C-659FC86C6123}) (Version: 1.4.1.274 - Caffeine Inc) Hidden
Caffeine (HKLM-x32\...\{17147312-7df5-447d-afe8-c77fd4ad80b8}) (Version: 1.4.1.274 - Caffeine Inc)
CCleaner (HKLM\...\CCleaner) (Version: - Piriform Ltd.)
Connectify Hotspot 2019 (HKLM\...\Connectify) (Version: 2019.0.0.40040 - Connectify)
Crossout Launcher 1.0.3.36 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\CrossOutLauncher_is1) (Version: - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DiRT2 (HKLM-x32\...\{52D1D62C-FEAB-4580-849E-1DB624BADBBD}) (Version: 1.00.0000 - Codemasters)
Discord (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
Dragon Age Inquisition v.1.11.u10 (HKLM-x32\...\Dragon Age Inquisition_is1) (Version: - )
Epic Games Launcher (HKLM-x32\...\{93BFE5DF-776E-436F-8693-DF1F72C0E3C1}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
FlashBoot 2.3d (HKLM\...\FlashBoot_is1) (Version: - Mikhail Kupchik)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Fraps (HKLM-x32\...\Fraps) (Version: - )
Free Screen Recorder v2.9 (HKLM-x32\...\Free Screen Recorder_is1) (Version: 2.9 - Nbxsoft Software Development)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 74.0.3729.169 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
Intel(R) Computing Improvement Program (HKLM\...\{58FBAE3A-E602-47E6-9F32-AE25D48B378A}) (Version: 2.4.04140 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{ef2ad7ab-dd41-48ed-ae53-f7fe3cd903d8}) (Version: 3.5.1.7 - Intel)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Malwarebytes verze 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\OneDriveSetup.exe) (Version: 19.070.0410.0005 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 60.6.1 ESR (x86 en-US) (HKLM-x32\...\Mozilla Firefox 60.6.1 ESR (x86 en-US)) (Version: 60.6.1 - Mozilla)
Mozilla Firefox 67.0 (x64 cs) (HKLM\...\Mozilla Firefox 67.0 (x64 cs)) (Version: 67.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.2 - Mozilla)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.13 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.17.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.17.0.126 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{9530AE42-DAE1-4619-9594-B23487285D17}) (Version: 9.11.1107 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenShot Video Editor verze 2.4.3 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.4.3 - OpenShot Studios, LLC)
Origin (HKLM-x32\...\Origin) (Version: 10.5.34.21025 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 399.24 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 399.24 - NVIDIA Corporation) Hidden
paint.net (HKLM\...\{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}) (Version: 4.1.5 - dotPDN LLC)
PhotoFiltre 7 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\PhotoFiltre 7) (Version: - )
Rapture3D 2.3.22 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
RecoveRx version 3.8.0 (HKLM-x32\...\{3DE055DA-690F-43B8-9B7B-54E7D70806F9}_is1) (Version: 3.8.0 - Transcend Information, Inc.)
Roblox Player for warto (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\roblox-player) (Version: - Roblox Corporation)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
Shadow Of The Tomb Raider (HKLM-x32\...\{96F650BA-50B7-4E7B-B026-8C847F45ED92}_is1) (Version: - SQUARENIX)
Shadow of the Tomb Raider Cpy Čeština (HKLM-x32\...\{F233C280-925A-422A-91DD-F99B398A76E6}) (Version: 1.0.0 - cpy)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1495134320_is1) (Version: 2.0.0.51 - GOG.com)
Total War Arena (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\TWA.EU.PRODUCTION) (Version: - Wargaming.net)
Unity Web Player (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 80.0 - Ubisoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.0.0_x64__tf1gferkr813w [2019-05-07] (Autodesk Inc.)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.521.0_x64__rz1tebttyb220 [2019-03-12] (Dolby Laboratories)
Email.cz -> C:\Program Files\WindowsApps\949FFEAB.Email.cz_2.4.1.0_x64__refxrrjvvv3cw [2019-05-10] (Seznam.cz a.s.)
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.20.0_x64__kejf07qmg0jnm [2019-05-02] (Keeper Security Inc)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-09-07] (Plex)
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2018-10-12] (Microsoft Corporation)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-02-15] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Twitter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=edcifkpoamnkimdpjiabhfjahoinbpbp

==================== Loaded Modules (Whitelisted) ==============

2018-07-02 22:36 - 2018-07-02 22:36 - 098275328 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000092672 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 003922432 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2018-02-13 00:08 - 2017-11-29 10:11 - 001609216 _____ (Igor Pavlov) [File not signed] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\7z.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000547840 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001548288 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 000395776 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001177600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000038912 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qdds.dll
2018-02-13 00:08 - 2017-08-29 21:30 - 000024576 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qgif.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000031232 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qicns.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000025088 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000242176 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qjpeg.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000019968 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000018944 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qtga.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000318976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qtiff.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000017920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qwbmp.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000328704 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qwebp.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000993792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
2018-02-13 00:08 - 2017-10-27 11:24 - 004794368 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
2018-02-13 00:08 - 2017-08-29 21:27 - 005093888 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
2018-02-13 00:08 - 2017-08-29 21:25 - 002010624 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
2018-02-13 00:08 - 2017-08-29 21:34 - 002514944 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
2018-02-13 00:08 - 2017-08-29 21:37 - 002567168 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000247808 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
2018-02-13 00:08 - 2017-08-29 21:29 - 004480512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
2018-02-13 00:08 - 2017-08-29 21:40 - 000206336 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000697344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000172544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
2018-02-13 00:08 - 2017-08-29 21:44 - 000069632 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000096768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2018-02-28 14:45 - 000000753 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Windows Live\Shared
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\warto\Desktop\pičoviny\stretched-1920-1080-842957.jpg
DNS Servers: 10.1.0.33
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "DSATray"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "EA Core"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Discord"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{9A444B97-3320-4CAF-AFD7-CCF825EAD04F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [TCP Query User{302AB830-3147-469C-8CB6-358F70B7210E}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [{2943BAD5-0B17-44F6-AFD8-F886A05A70E1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8F1ECB3F-BB1B-4464-ADC3-4D836427E1F8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8F6B2F37-B472-42B0-B8FE-01B6CD3B2477}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{77DEC8DE-91AF-4666-AE51-6AC4398A75EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C065BEA0-AA37-44F8-B721-A32BDF8C3C9A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{B0725937-A22A-4390-9AAE-3F2EA27FE65F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{32955051-F35D-47E1-B0CB-FCE57E603D98}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{7CB67C81-3838-4269-8D25-2D2DDBED43C8}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{FE24C43C-9D27-44E6-843F-504502F5F203}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A01BD763-F1C8-42B4-8C48-A5558DFA67B2}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A0C8C48D-620B-4919-8FE7-510EACE9BE74}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{C8A83804-6167-453F-B838-9DB6489D9BE8}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A4E8F381-B403-40A9-B8BB-7FA087965B61}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [{74B1B2AE-1033-4F7C-A665-738C684DEB1F}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [UDP Query User{1E6AAAAC-6B5E-44C6-A9A6-471D3C19AB2E}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [TCP Query User{B87C723B-3BDF-45AA-BA72-E5D539DF48A7}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [UDP Query User{1248693B-A1BE-47BE-A697-6AE83EF38C84}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [TCP Query User{693305F7-92F7-4E0F-8AF4-81D5029A7646}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [{0B363149-DD6E-4F7F-B483-3DED1BC8E7E5}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{877274C3-04FF-453E-AD6D-9745E0CA973C}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{71BCA3F8-1108-4BB9-9F1C-CF95C3F34DD7}] => (Allow) LPort=1688
FirewallRules: [TCP Query User{4F06821A-7212-459A-B965-2DCD8D02A1A1}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5397481F-A840-4DA7-BBE9-7A5659313106}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{21B53C08-9147-4502-B390-7E01A03DAD87}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5D38FC9B-3BA3-4C5F-8102-2B08AA67C949}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CEA43369-C54E-4E28-B5A5-2DD330242125}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{15167DB2-9A30-455E-B8CA-9F2E73C170C7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{982F743C-5A18-4F12-9118-49EC9FBD5285}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{E9900D7C-0CF7-4D34-A6B2-9FDA0E490B75}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{BF24202F-0DD7-471C-BD4A-C5DD556056F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{126204BB-BA32-44A2-AC34-963279CAB2D5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{0024598A-FEAC-418B-A2EE-B36FD8D53AB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A24BB525-1C2E-4172-94E2-51A1203EC0B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{05A89F23-1566-4BBA-BBA9-EEB72F00D2EB}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{44B8882D-281B-4F9B-B2E5-C2A62C455515}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{34F512B3-225C-44CB-A151-2544D6025CFA}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1B5A931E-8D0A-4F16-872B-AABEE15A23C5}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{0A6D0211-8350-4960-8716-22072153BDBE}C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{7C73D6A0-5D60-4F1C-B35F-97D7E299B002}C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{C4D3F493-882E-42D5-B956-43C2FB9C587B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C23CD4BE-7964-4B42-82DF-B8C34596CF45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{1EA93D44-4704-4F5D-B89B-DC1CDB459723}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{35951E08-48E7-476E-AE12-4F004DE2C79A}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{F59F6728-93DA-4694-81F3-F31BFDC5A66B}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{24AB2205-4C5C-46DB-9443-40B08AA7D470}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{0CE020BF-D566-4CF4-BD3E-802E53E4CA7F}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{474CAD7A-6CEF-432F-B2BF-1B688E577696}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{78A3F1A0-58CC-46D5-93DE-FA8D8F80BA36}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FD033137-C54C-4677-85A1-7BF3DE5872F6}] => (Allow) LPort=2869
FirewallRules: [{E88DC7EB-1C82-4ABB-9808-C3CCE23BA419}] => (Allow) LPort=1900
FirewallRules: [{2921B86D-3849-43C4-ACC7-85060A95C650}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{65616C1B-9028-4B51-B643-9DD0CE2B84D0}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (AVAST Software s.r.o. -> AVAST Software)

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/25/2019 02:46:17 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: NT AUTHORITY)
Description: Systém Windows nemůže načíst knihovnu DLL rozšiřitelných čítačů C:\WINDOWS\system32\sysmain.dll (kód chyby Win32 126).

Error: (05/24/2019 07:17:53 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {4528DE87-43FB-4D5F-99AB-829BC759CCBA}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:53 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {4528DE87-43FB-4D5F-99AB-829BC759CCBA}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:43 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {60C1366B-3452-41F4-80C6-54D9F9534B8A}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:43 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {60C1366B-3452-41F4-80C6-54D9F9534B8A}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:33 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {C8C6C3B9-1B57-4381-A3D1-0488A819B848}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:33 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {C8C6C3B9-1B57-4381-A3D1-0488A819B848}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:23 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {5B605E4B-5069-44CA-A18F-48A9D109A13C}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.


System errors:
=============
Error: (05/25/2019 02:46:14 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.SecurityAppBroker
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:33:11 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:31:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Update Orchestrator Service byla ukončena s následující chybou:
Daná operace se vrátila, protože vypršel časový limit.

Error: (05/25/2019 02:24:10 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (05/25/2019 01:24:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2019-05-15 19:24:54.024
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {2C146212-B44C-4337-87B5-CE59AEFB5D8E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-05-15 18:52:08.510
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {BD1A9B29-EFEF-4B57-83DB-CB46BBDB28C4}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-04-24 16:23:44.867
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070643
Popis chyby :Při instalaci došlo k závažné chybě.

Date: 2019-04-24 16:23:41.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.293.68.0
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antispywarový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15900.4
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

Date: 2019-04-24 16:23:41.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.293.68.0
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antivirový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15900.4
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0501 10/03/2016
Motherboard: ASUSTeK COMPUTER INC. B150M PRO GAMING
Processor: Intel(R) Pentium(R) CPU G4600 @ 3.60GHz
Percentage of memory in use: 54%
Total physical RAM: 8128.61 MB
Available physical RAM: 3669.71 MB
Total Virtual: 14528.61 MB
Available Virtual: 7036.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.24 GB) (Free:5.01 GB) NTFS
Drive d: (USB DISK) (Removable) (Total:60.94 GB) (Free:44.79 GB) FAT32

\\?\Volume{5a6ae5dd-a1c3-46c1-a0fb-4e99138bf673}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{acd79ad2-c4af-4496-92ef-e9a2db0b22a9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (Protective MBR) (Size: 61 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-05.2019
Ran by warto (25-05-2019 15:17:41)
Running from C:\Users\warto\Downloads
Windows 10 Pro Version 1809 17763.529 (X64) (2019-02-15 17:37:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3012513600-1294068158-3791818399-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3012513600-1294068158-3791818399-503 - Limited - Disabled)
Guest (S-1-5-21-3012513600-1294068158-3791818399-501 - Limited - Disabled)
Host (S-1-5-21-3012513600-1294068158-3791818399-1002 - Limited - Enabled) => C:\Users\Host
warto (S-1-5-21-3012513600-1294068158-3791818399-1001 - Administrator - Enabled) => C:\Users\warto
WDAGUtilityAccount (S-1-5-21-3012513600-1294068158-3791818399-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (HKLM\...\{5F4E8D94-3947-4019-9239-D2541C9A35F2}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\...\{7A5E4942-A527-42E6-A5FC-95109B756CA8}) (Version: 3.5.1.7 - Intel) Hidden
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.192 - Adobe)
Aktualizace NVIDIA 35.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 35.0.0.0 - NVIDIA Corporation) Hidden
ArcaniA - Gothic 4 (HKLM-x32\...\{07872B03-E301-4AE2-AA87-261C8E617769}) (Version: 1.00.0000 - JoWooD Entertainment AG)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 74.0.1376.132 - AVAST Software)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.154.333 - AVAST Software) Hidden
Bandicam (HKLM-x32\...\Bandicam) (Version: 4.4.0.1535 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\BitTorrent) (Version: 7.10.5.44995 - BitTorrent Inc.)
Caffeine (HKLM\...\{1247C26D-45E6-4D2E-973C-659FC86C6123}) (Version: 1.4.1.274 - Caffeine Inc) Hidden
Caffeine (HKLM-x32\...\{17147312-7df5-447d-afe8-c77fd4ad80b8}) (Version: 1.4.1.274 - Caffeine Inc)
CCleaner (HKLM\...\CCleaner) (Version: - Piriform Ltd.)
Connectify Hotspot 2019 (HKLM\...\Connectify) (Version: 2019.0.0.40040 - Connectify)
Crossout Launcher 1.0.3.36 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\CrossOutLauncher_is1) (Version: - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DiRT2 (HKLM-x32\...\{52D1D62C-FEAB-4580-849E-1DB624BADBBD}) (Version: 1.00.0000 - Codemasters)
Discord (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
Dragon Age Inquisition v.1.11.u10 (HKLM-x32\...\Dragon Age Inquisition_is1) (Version: - )
Epic Games Launcher (HKLM-x32\...\{93BFE5DF-776E-436F-8693-DF1F72C0E3C1}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
FlashBoot 2.3d (HKLM\...\FlashBoot_is1) (Version: - Mikhail Kupchik)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Fraps (HKLM-x32\...\Fraps) (Version: - )
Free Screen Recorder v2.9 (HKLM-x32\...\Free Screen Recorder_is1) (Version: 2.9 - Nbxsoft Software Development)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 74.0.3729.169 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
Intel(R) Computing Improvement Program (HKLM\...\{58FBAE3A-E602-47E6-9F32-AE25D48B378A}) (Version: 2.4.04140 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{ef2ad7ab-dd41-48ed-ae53-f7fe3cd903d8}) (Version: 3.5.1.7 - Intel)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Malwarebytes verze 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\OneDriveSetup.exe) (Version: 19.070.0410.0005 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 60.6.1 ESR (x86 en-US) (HKLM-x32\...\Mozilla Firefox 60.6.1 ESR (x86 en-US)) (Version: 60.6.1 - Mozilla)
Mozilla Firefox 67.0 (x64 cs) (HKLM\...\Mozilla Firefox 67.0 (x64 cs)) (Version: 67.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.2 - Mozilla)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.13 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.17.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.17.0.126 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{9530AE42-DAE1-4619-9594-B23487285D17}) (Version: 9.11.1107 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenShot Video Editor verze 2.4.3 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.4.3 - OpenShot Studios, LLC)
Origin (HKLM-x32\...\Origin) (Version: 10.5.34.21025 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 399.24 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 399.24 - NVIDIA Corporation) Hidden
paint.net (HKLM\...\{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}) (Version: 4.1.5 - dotPDN LLC)
PhotoFiltre 7 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\PhotoFiltre 7) (Version: - )
Rapture3D 2.3.22 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
RecoveRx version 3.8.0 (HKLM-x32\...\{3DE055DA-690F-43B8-9B7B-54E7D70806F9}_is1) (Version: 3.8.0 - Transcend Information, Inc.)
Roblox Player for warto (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\roblox-player) (Version: - Roblox Corporation)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
Shadow Of The Tomb Raider (HKLM-x32\...\{96F650BA-50B7-4E7B-B026-8C847F45ED92}_is1) (Version: - SQUARENIX)
Shadow of the Tomb Raider Cpy Čeština (HKLM-x32\...\{F233C280-925A-422A-91DD-F99B398A76E6}) (Version: 1.0.0 - cpy)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1495134320_is1) (Version: 2.0.0.51 - GOG.com)
Total War Arena (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\TWA.EU.PRODUCTION) (Version: - Wargaming.net)
Unity Web Player (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 80.0 - Ubisoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.0.0_x64__tf1gferkr813w [2019-05-07] (Autodesk Inc.)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.521.0_x64__rz1tebttyb220 [2019-03-12] (Dolby Laboratories)
Email.cz -> C:\Program Files\WindowsApps\949FFEAB.Email.cz_2.4.1.0_x64__refxrrjvvv3cw [2019-05-10] (Seznam.cz a.s.)
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.20.0_x64__kejf07qmg0jnm [2019-05-02] (Keeper Security Inc)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-09-07] (Plex)
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2018-10-12] (Microsoft Corporation)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-02-15] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Twitter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=edcifkpoamnkimdpjiabhfjahoinbpbp

==================== Loaded Modules (Whitelisted) ==============

2018-07-02 22:36 - 2018-07-02 22:36 - 098275328 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000092672 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 003922432 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2018-02-13 00:08 - 2017-11-29 10:11 - 001609216 _____ (Igor Pavlov) [File not signed] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\7z.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000547840 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001548288 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 000395776 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 001177600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2019-02-05 16:37 - 2019-02-05 16:37 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000038912 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qdds.dll
2018-02-13 00:08 - 2017-08-29 21:30 - 000024576 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qgif.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000031232 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qicns.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000025088 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000242176 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qjpeg.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000019968 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000018944 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qtga.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000318976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qtiff.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000017920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qwbmp.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000328704 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qwebp.dll
2018-02-13 00:08 - 2017-08-29 21:31 - 000993792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
2018-02-13 00:08 - 2017-10-27 11:24 - 004794368 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
2018-02-13 00:08 - 2017-08-29 21:27 - 005093888 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
2018-02-13 00:08 - 2017-08-29 21:25 - 002010624 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
2018-02-13 00:08 - 2017-08-29 21:34 - 002514944 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
2018-02-13 00:08 - 2017-08-29 21:37 - 002567168 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
2018-02-13 00:08 - 2017-08-29 21:32 - 000247808 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
2018-02-13 00:08 - 2017-08-29 21:29 - 004480512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
2018-02-13 00:08 - 2017-08-29 21:40 - 000206336 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000697344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000172544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
2018-02-13 00:08 - 2017-08-29 21:44 - 000069632 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:45 - 000096768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
2018-02-13 00:08 - 2017-08-29 21:39 - 000013312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2018-02-28 14:45 - 000000753 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Windows Live\Shared
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\warto\Desktop\pičoviny\stretched-1920-1080-842957.jpg
DNS Servers: 10.1.0.33
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "DSATray"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "EA Core"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Discord"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{9A444B97-3320-4CAF-AFD7-CCF825EAD04F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [TCP Query User{302AB830-3147-469C-8CB6-358F70B7210E}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [{2943BAD5-0B17-44F6-AFD8-F886A05A70E1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8F1ECB3F-BB1B-4464-ADC3-4D836427E1F8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8F6B2F37-B472-42B0-B8FE-01B6CD3B2477}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{77DEC8DE-91AF-4666-AE51-6AC4398A75EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C065BEA0-AA37-44F8-B721-A32BDF8C3C9A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{B0725937-A22A-4390-9AAE-3F2EA27FE65F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{32955051-F35D-47E1-B0CB-FCE57E603D98}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{7CB67C81-3838-4269-8D25-2D2DDBED43C8}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{FE24C43C-9D27-44E6-843F-504502F5F203}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A01BD763-F1C8-42B4-8C48-A5558DFA67B2}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A0C8C48D-620B-4919-8FE7-510EACE9BE74}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{C8A83804-6167-453F-B838-9DB6489D9BE8}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A4E8F381-B403-40A9-B8BB-7FA087965B61}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [{74B1B2AE-1033-4F7C-A665-738C684DEB1F}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [UDP Query User{1E6AAAAC-6B5E-44C6-A9A6-471D3C19AB2E}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [TCP Query User{B87C723B-3BDF-45AA-BA72-E5D539DF48A7}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [UDP Query User{1248693B-A1BE-47BE-A697-6AE83EF38C84}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [TCP Query User{693305F7-92F7-4E0F-8AF4-81D5029A7646}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [{0B363149-DD6E-4F7F-B483-3DED1BC8E7E5}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{877274C3-04FF-453E-AD6D-9745E0CA973C}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{71BCA3F8-1108-4BB9-9F1C-CF95C3F34DD7}] => (Allow) LPort=1688
FirewallRules: [TCP Query User{4F06821A-7212-459A-B965-2DCD8D02A1A1}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5397481F-A840-4DA7-BBE9-7A5659313106}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{21B53C08-9147-4502-B390-7E01A03DAD87}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5D38FC9B-3BA3-4C5F-8102-2B08AA67C949}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CEA43369-C54E-4E28-B5A5-2DD330242125}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{15167DB2-9A30-455E-B8CA-9F2E73C170C7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{982F743C-5A18-4F12-9118-49EC9FBD5285}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{E9900D7C-0CF7-4D34-A6B2-9FDA0E490B75}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{BF24202F-0DD7-471C-BD4A-C5DD556056F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{126204BB-BA32-44A2-AC34-963279CAB2D5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{0024598A-FEAC-418B-A2EE-B36FD8D53AB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A24BB525-1C2E-4172-94E2-51A1203EC0B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{05A89F23-1566-4BBA-BBA9-EEB72F00D2EB}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{44B8882D-281B-4F9B-B2E5-C2A62C455515}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{34F512B3-225C-44CB-A151-2544D6025CFA}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1B5A931E-8D0A-4F16-872B-AABEE15A23C5}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{0A6D0211-8350-4960-8716-22072153BDBE}C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{7C73D6A0-5D60-4F1C-B35F-97D7E299B002}C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{C4D3F493-882E-42D5-B956-43C2FB9C587B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C23CD4BE-7964-4B42-82DF-B8C34596CF45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{1EA93D44-4704-4F5D-B89B-DC1CDB459723}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{35951E08-48E7-476E-AE12-4F004DE2C79A}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{F59F6728-93DA-4694-81F3-F31BFDC5A66B}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{24AB2205-4C5C-46DB-9443-40B08AA7D470}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{0CE020BF-D566-4CF4-BD3E-802E53E4CA7F}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{474CAD7A-6CEF-432F-B2BF-1B688E577696}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{78A3F1A0-58CC-46D5-93DE-FA8D8F80BA36}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FD033137-C54C-4677-85A1-7BF3DE5872F6}] => (Allow) LPort=2869
FirewallRules: [{E88DC7EB-1C82-4ABB-9808-C3CCE23BA419}] => (Allow) LPort=1900
FirewallRules: [{2921B86D-3849-43C4-ACC7-85060A95C650}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{65616C1B-9028-4B51-B643-9DD0CE2B84D0}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (AVAST Software s.r.o. -> AVAST Software)

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/25/2019 02:46:17 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: NT AUTHORITY)
Description: Systém Windows nemůže načíst knihovnu DLL rozšiřitelných čítačů C:\WINDOWS\system32\sysmain.dll (kód chyby Win32 126).

Error: (05/24/2019 07:17:53 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {4528DE87-43FB-4D5F-99AB-829BC759CCBA}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:53 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {4528DE87-43FB-4D5F-99AB-829BC759CCBA}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:43 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {60C1366B-3452-41F4-80C6-54D9F9534B8A}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:43 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {60C1366B-3452-41F4-80C6-54D9F9534B8A}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:33 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {C8C6C3B9-1B57-4381-A3D1-0488A819B848}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.

Error: (05/24/2019 07:17:33 PM) (Source: ESENT) (EventID: 489) (User: )
Description: SettingSyncHost (7484,P,98) {C8C6C3B9-1B57-4381-A3D1-0488A819B848}: Pokus o otevření souboru C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb jen pro čtení selhal. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (05/24/2019 07:17:23 PM) (Source: ESENT) (EventID: 553) (User: )
Description: SettingSyncHost (7484,P,98) {5B605E4B-5069-44CA-A18F-48A9D109A13C}: Failed looking up restore-map entry for database C:\Users\warto\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb with unexpected error -1032.


System errors:
=============
Error: (05/25/2019 02:46:14 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.SecurityAppBroker
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:34:25 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:33:11 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/25/2019 02:31:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Update Orchestrator Service byla ukončena s následující chybou:
Daná operace se vrátila, protože vypršel časový limit.

Error: (05/25/2019 02:24:10 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (05/25/2019 01:24:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2019-05-15 19:24:54.024
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {2C146212-B44C-4337-87B5-CE59AEFB5D8E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-05-15 18:52:08.510
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {BD1A9B29-EFEF-4B57-83DB-CB46BBDB28C4}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-04-24 16:23:44.867
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070643
Popis chyby :Při instalaci došlo k závažné chybě.

Date: 2019-04-24 16:23:41.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.293.68.0
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antispywarový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15900.4
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

Date: 2019-04-24 16:23:41.832
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.293.68.0
Předchozí verze podpisu: 1.291.2489.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antivirový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15900.4
Předchozí verze modulu: 1.1.15900.4
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0501 10/03/2016
Motherboard: ASUSTeK COMPUTER INC. B150M PRO GAMING
Processor: Intel(R) Pentium(R) CPU G4600 @ 3.60GHz
Percentage of memory in use: 54%
Total physical RAM: 8128.61 MB
Available physical RAM: 3669.71 MB
Total Virtual: 14528.61 MB
Available Virtual: 7036.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.24 GB) (Free:5.01 GB) NTFS
Drive d: (USB DISK) (Removable) (Total:60.94 GB) (Free:44.79 GB) FAT32

\\?\Volume{5a6ae5dd-a1c3-46c1-a0fb-4e99138bf673}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{acd79ad2-c4af-4496-92ef-e9a2db0b22a9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (Protective MBR) (Size: 61 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#2 Příspěvek od Conder »

Ahoj :)

Nevlozil si hlavny log FRST.txt
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Re: Explorer.exe

#3 Příspěvek od Tommy Puerto »

Je tam ne? Tohle:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05.2019
Ran by warto (administrator) on DESKTOP-QD17RQH (25-05-2019 15:16:34)
Running from C:\Users\warto\Downloads
Loaded Profiles: warto (Available Profiles: warto & Host)
Platform: Windows 10 Pro Version 1809 17763.529 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19041.481.0_x64__8wekyb3d8bbwe\YourPhone.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler64.exe
(Connectify (Connectify, Inc.) -> Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(Connectify (Connectify, Inc.) -> Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel(R) Driver & Support Assistant -> Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1904.1-0\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1904.1-0\NisSrv.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11904.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [126712 2018-09-26] (Intel(R) Driver & Support Assistant -> Intel)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35211664 2019-05-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3152160 2019-04-30] (Valve -> Valve Corporation)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [Discord] => C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Winlogon: [Shell] %comspec% <==== ATTENTION
HKLM\...\Drivers32: [VIDC.FPS1] => C:\WINDOWS\system32\frapsv64.dll [105984 2018-09-26] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [vidc.mjpg] => C:\WINDOWS\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\WINDOWS\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\WINDOWS\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2018-09-26] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\74.0.3729.169\Installer\chrmstp.exe [2019-05-22] (Google LLC -> Google Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\74.0.1376.132\Installer\chrmstp.exe [2019-05-25] (AVAST Software s.r.o. -> AVAST Software)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0AEF4AF7-FB10-448D-8AE8-A537D42AFAF8} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2380088 2019-04-04] (AVAST Software s.r.o. -> AVAST Software)
Task: {11544983-8386-422A-A161-CB0FBCF7C2F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-09-07] (Google Inc -> Google Inc.)
Task: {18FA9E8B-20FF-4A3C-9B3A-D2C55A0EB46C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3724680 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2D3617D5-B11E-4979-8483-9552F540D618} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {33B923A1-025D-4513-86A7-F4EAB1299B72} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [841096 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {44BA7677-C66E-4051-9E7D-00599AE8C3F2} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-05-25] (AVAST Software s.r.o. -> AVAST Software)
Task: {5E28D911-2F3A-4106-B10E-680D5A9DE923} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1904.1-0\MpCmdRun.exe [480352 2019-04-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {60177393-1D43-47AF-87E2-1DE22BA5A775} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {727A4CE7-E8EE-4A6C-9670-9A5E1C479D09} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1951280 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
Task: {7431F5B5-E83E-4890-9FC3-CFCD1CE99C59} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1904.1-0\MpCmdRun.exe [480352 2019-04-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {7644EFBD-B800-4976-8E07-0EB3D0DDDDF3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [7685808 2017-09-20] (Piriform Ltd -> Piriform Ltd)
Task: {78D26CE1-C19F-41E1-8E79-2E4A3FB3D6F2} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7FC4A27E-62A3-4A6F-AF2C-81EDC63E6E6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1904.1-0\MpCmdRun.exe [480352 2019-04-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {821E0A23-EC14-4002-9D57-F66761564AE7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_192_pepper.exe [1452600 2019-05-14] (Adobe Inc. -> Adobe)
Task: {88ABC11F-2E70-4716-B7CB-56D9E5E903B4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8DA105C0-30B0-40DA-A2B2-6DC64DA160FE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [572808 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {921F0830-71BE-42F6-9ADF-ECED142541D8} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [841096 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {93C2404D-2F6E-4B81-9580-33E2B45AFBDC} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {987B836E-3162-486A-B4E3-07155FD21DE9} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-05-25] (AVAST Software s.r.o. -> AVAST Software)
Task: {99C090C2-C4C8-4894-8A52-6C9590E4A78D} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BA79BBCA-F190-49A6-84F5-52D080B6E7B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-09-07] (Google Inc -> Google Inc.)
Task: {C1967968-F056-4A52-85DC-70EBDA33BC60} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-05-14] (Adobe Inc. -> Adobe)
Task: {D04EC235-CB92-436D-83D5-A6D3AAF9FDD0} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D75AFEAE-FC90-40E1-B650-A2BF19241225} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {DA85AE09-51D0-4CDE-A62C-53D865923007} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {DF56422B-F76A-40FE-AE90-7456A2E2CBE1} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [702856 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EBB53AE1-720B-42D7-BFD4-2E6C6664A8E3} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1951280 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
Task: {EF23EBC5-4F15-4AE5-A800-0E21BD7997E0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1904.1-0\MpCmdRun.exe [480352 2019-04-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {FE3DF3C8-3F45-4484-AB8F-5B1086612FFC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.1.0.33
Tcpip\..\Interfaces\{9ff3c8b5-030d-4585-9c63-22cbaf552549}: [DhcpNameServer] 10.1.0.33

Internet Explorer:
==================

FireFox:
========
FF DefaultProfile: e1xefp5x.default-1554583981454
FF ProfilePath: C:\Users\warto\AppData\Roaming\Mozilla\Firefox\Profiles\e1xefp5x.default-1554583981454 [2019-05-25]
FF Extension: (Firefox ESR configurer for OLDJAWS screen reader ) - C:\Program Files (x86)\Mozilla Firefox\browser\features\jaws-esr@mozilla.org.xpi [2019-04-06] [Legacy] [not signed]
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-09] (VideoLAN -> VideoLAN)
FF Plugin HKU\S-1-5-21-3012513600-1294068158-3791818399-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\warto\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies SF -> Unity Technologies ApS)

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR DefaultSearchKeyword: Default -> google.cz_
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default [2019-05-25]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2019-02-19]
CHR Extension: (Twitter) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\edcifkpoamnkimdpjiabhfjahoinbpbp [2019-02-15]
CHR Extension: (uBlock) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\epcnnfbjfcgphgdmggkamkmgojdagdnn [2019-04-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Ochrana hesla) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\noondiphcddnnabmjcihcjfbhfklnnep [2018-06-04]
CHR Extension: (Chrome Media Router) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-05-23]
CHR Profile: C:\Users\warto\AppData\Local\Google\Chrome\User Data\System Profile [2018-02-24]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

HKLM\SYSTEM\CurrentControlSet\Services\aswSP <==== ATTENTION (Rootkit!)
HKLM\SYSTEM\CurrentControlSet\Services\aswMonFlt <==== ATTENTION (Rootkit!)
HKLM\SYSTEM\CurrentControlSet\Services\aswSnx <==== ATTENTION (Rootkit!)

S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-05-25] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-05-25] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\74.0.1376.132\elevation_service.exe [1079424 2019-05-14] (AVAST Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-03-27] (BattlEye Innovations e.K. -> )
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [275968 2019-01-18] (Connectify (Connectify, Inc.) -> Connectify)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23800 2018-09-26] (Intel(R) Driver & Support Assistant -> Intel)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-12-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [937192 2018-09-19] (Intel(R) Software Development Products -> )
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2298688 2019-02-05] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3171144 2019-02-05] (Electronic Arts, Inc. -> Electronic Arts)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5382448 2019-04-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe [194792 2018-09-19] (Intel(R) Software Development Products -> )
S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [937192 2018-09-19] (Intel(R) Software Development Products -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1904.1-0\NisSrv.exe [3851264 2019-04-24] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1904.1-0\MsMpEng.exe [118144 2019-04-24] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 cfywlan2; C:\WINDOWS\system32\DRIVERS\cfywlan2.sys [46088 2019-03-24] (Connectify (Connectify, Inc.) -> Connectify)
R1 cnnctfy4; C:\WINDOWS\system32\DRIVERS\cnnctfy4.sys [53216 2019-03-24] (Connectify (Connectify, Inc.) -> Connectify)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-08-31] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-08-31] (Disc Soft Ltd -> Disc Soft Ltd)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2019-05-25] (Malwarebytes Corporation -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_8e4f37220e99138f\nvlddmkm.sys [17213824 2018-09-25] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-01-16] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [70024 2018-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [66792 2018-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [43008 2018-09-19] (Intel Corporation -> )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-04-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [344544 2019-04-24] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60896 2019-04-24] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-05-25 15:15 - 2019-05-25 15:15 - 002435072 _____ (Farbar) C:\Users\warto\Downloads\FRST64.exe
2019-05-25 14:46 - 2019-05-25 14:46 - 000003856 _____ C:\WINDOWS\System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2019-05-25 14:46 - 2019-05-25 14:46 - 000003272 _____ C:\WINDOWS\System32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2019-05-25 14:46 - 2019-05-25 14:46 - 000002574 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2019-05-25 14:45 - 2019-05-25 14:45 - 000003512 _____ C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineUA
2019-05-25 14:45 - 2019-05-25 14:45 - 000003388 _____ C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineCore
2019-05-25 14:45 - 2019-05-25 14:45 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2019-05-25 14:43 - 2019-05-25 14:45 - 000000000 ____D C:\Users\warto\AppData\Local\AVAST Software
2019-05-25 14:43 - 2019-05-25 14:43 - 000000000 ____D C:\Users\warto\AppData\Roaming\AVAST Software
2019-05-25 14:42 - 2019-05-25 14:42 - 001030784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw1793f7063d5f99ea.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000477584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw94141e2912dd434f.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000385640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw32243212df55576a.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000363400 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2019-05-25 14:42 - 2019-05-25 14:42 - 000279120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw0431e0f6aa7dddf7.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000262496 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswf8d6f3ac0ac503a8.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000225096 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw0512987b7a012b13.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000207448 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asweaf2883269438e6e.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000205848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw6ac464f4543a8941.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000167872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswc58c0565b1df2dc9.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000112312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw8ed22c1f91b24963.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000087944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw045eb47f446e2400.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000061472 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw31cdc78d3ab4ff59.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000042288 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswfc66a74ea44c1d76.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000037104 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw697c61861522e31c.tmp
2019-05-25 14:42 - 2019-05-25 14:42 - 000015488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswd766b391a0030ff8.tmp
2019-05-25 14:41 - 2019-05-25 14:41 - 000000000 ____D C:\Program Files\AVAST Software
2019-05-25 14:40 - 2019-05-25 14:40 - 000231544 _____ (AVAST Software) C:\Users\warto\Downloads\avast_free_antivirus_setup_online.exe
2019-05-25 14:26 - 2019-05-25 14:26 - 026809856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 023439360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 018999808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 012869120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 012162048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 007724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 005112792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 002276192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 002096128 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-05-25 14:26 - 2019-05-25 14:26 - 002017280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-05-25 14:26 - 2019-05-25 14:26 - 001750016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 001387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 001260048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-05-25 14:26 - 2019-05-25 14:26 - 000927744 _____ (Microsoft Corporation) C:\WINDOWS\system32\assignedaccessmanagersvc.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessManager.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
2019-05-25 14:26 - 2019-05-25 14:26 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000351744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000345600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe
2019-05-25 14:26 - 2019-05-25 14:26 - 000311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-05-25 14:26 - 2019-05-25 14:26 - 000287912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2019-05-25 14:26 - 2019-05-25 14:26 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2019-05-25 14:26 - 2019-05-25 14:26 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 017484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 015221248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 009682744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 007884288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 007687576 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 007645608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 006926336 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 006545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 006441472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 006309040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 005764608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 005297152 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 004627456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 004588536 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 003983872 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 003637248 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 003426816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 003384832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 003344896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 002999808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 002928640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 002777736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 002707968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 002690048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 002638336 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 002627600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 002421760 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 002189312 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001860608 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001860096 ____R (The ICU Project) C:\WINDOWS\system32\icuin.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001761280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001700312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-05-25 14:25 - 2019-05-25 14:25 - 001644544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001618944 ____R (The ICU Project) C:\WINDOWS\SysWOW64\icuin.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001605120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001483872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001342904 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-05-25 14:25 - 2019-05-25 14:25 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001298952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001256448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001254912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001253688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 001229312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 001180184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 001072640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001054712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 001048592 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000924160 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000887808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000853504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000850760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000773632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000769536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000758688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000699392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000651064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000615440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000586040 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000555232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000515152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000451104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000430904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000427688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000375544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 000351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000292664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000282424 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000262160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000247608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000196920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spacebridge.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSrv.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 000152400 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000125528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000114648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000091424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000090632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000080400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-05-25 14:25 - 2019-05-25 14:25 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-05-25 14:25 - 2019-05-25 14:25 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-05-25 14:25 - 2019-05-25 14:25 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-05-25 13:23 - 2019-05-25 13:23 - 000076456 _____ C:\Users\warto\OneDrive\Dokumenty\cc_20190525_132353.reg
2019-05-23 21:18 - 2019-05-23 21:18 - 000236535 _____ C:\Users\warto\fffsa.osp
2019-05-23 21:15 - 2019-05-23 21:15 - 010556965 _____ C:\Users\warto\Nepojmenovaný projekt.mp4
2019-05-23 21:12 - 2019-05-23 21:12 - 002628564 ____C C:\Users\warto\Desktop\_Velké.mp4
2019-05-23 21:08 - 2019-05-24 17:06 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-05-23 20:59 - 2019-05-23 20:59 - 000215393 _____ C:\Users\warto\Desktop\giphy (3).mp4
2019-05-23 20:55 - 2019-05-23 20:55 - 001572263 _____ C:\Users\warto\Desktop\giphy (2).mp4
2019-05-23 20:52 - 2019-05-23 20:52 - 000307575 _____ C:\Users\warto\Desktop\giphy (1).mp4
2019-05-23 20:40 - 2019-05-23 20:40 - 000585120 _____ C:\Users\warto\Desktop\giphy.mp4
2019-05-20 16:44 - 2019-05-25 14:32 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 007879680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 006072320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 004883968 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 004660736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 003905536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 003743744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 003602944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 003557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 003363856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 001701888 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001641616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001484800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 001026792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000895792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000807464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000660992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000508432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000449376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000444944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000376320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000317240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000254952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000223544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-05-16 19:09 - 2019-05-16 19:09 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000212792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000203272 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000202768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000198456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-05-16 19:09 - 2019-05-16 19:09 - 000179728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000177976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-05-16 19:09 - 2019-05-16 19:09 - 000163240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000147736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-kernel-processor-power-events.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000121656 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2019-05-16 19:09 - 2019-05-16 19:09 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2019-05-16 19:09 - 2019-05-16 19:09 - 000066688 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptdll.dll
2019-05-16 19:09 - 2019-05-16 19:09 - 000055792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptdll.dll
2019-05-16 17:41 - 2019-05-16 17:46 - 049340059 _____ C:\Users\warto\Downloads\BestofYou.7z
2019-05-16 17:40 - 2019-05-16 17:42 - 021374974 _____ C:\Users\warto\Downloads\Mason.rar
2019-05-16 17:32 - 2019-05-16 17:33 - 021441239 _____ C:\Users\warto\Downloads\LargusTech.7z
2019-05-16 17:30 - 2019-05-16 17:31 - 022837626 _____ C:\Users\warto\Downloads\e171.7z
2019-05-16 17:23 - 2019-05-16 17:26 - 026351531 _____ C:\Users\warto\Downloads\ORUSM.zip
2019-05-15 21:12 - 2019-05-19 13:33 - 000000555 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
2019-05-15 21:12 - 2019-05-15 21:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2019-05-07 23:12 - 2019-05-14 21:39 - 000000000 ___DC C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2019-05-07 23:12 - 2019-05-07 23:30 - 000000256 ____C C:\Users\warto\AppData\LocalLow\rbxcsettings.rbx
2019-05-07 23:12 - 2019-05-07 23:17 - 000000000 ____D C:\Users\warto\AppData\Local\Roblox
2019-05-07 23:12 - 2019-05-07 23:12 - 001242200 _____ (Roblox Corporation) C:\Users\warto\Downloads\RobloxPlayerLauncher.exe
2019-05-04 22:20 - 2019-05-04 22:20 - 003071972 ____C C:\Users\warto\Desktop\150914113529-outdoor-cinemas--vietnam-super-169aa.pfi
2019-05-04 22:02 - 2019-05-04 22:02 - 005436904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 003551112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 003406848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 002393088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 002205184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2019-05-04 22:02 - 2019-05-04 22:02 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2019-05-04 22:02 - 2019-05-04 22:02 - 000370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe
2019-05-04 22:02 - 2019-05-04 22:02 - 000349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe
2019-05-04 22:02 - 2019-05-04 22:02 - 000263576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 000109568 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 000101376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncCsp.dll
2019-05-04 22:02 - 2019-05-04 22:02 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\EASPolicyManagerBrokerHost.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 005210904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 004997096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 002701512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 002073960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001994976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001768960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001674696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001671352 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001467552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 001219640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000806600 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-05-04 22:01 - 2019-05-04 22:01 - 000806600 _____ C:\WINDOWS\system32\locale.nls
2019-05-04 22:01 - 2019-05-04 22:01 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000780632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcrt.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000725696 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000676256 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000651576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 000649064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000638376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcrt.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000610304 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000553656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000540720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000454160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-05-04 22:01 - 2019-05-04 22:01 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SDDS.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000421392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-05-04 22:01 - 2019-05-04 22:01 - 000366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000320512 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 000244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 000197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000157200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000122680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2019-05-04 22:01 - 2019-05-04 22:01 - 000086960 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe
2019-05-04 22:01 - 2019-05-04 22:01 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnosticsTool.exe
2019-05-02 00:59 - 2019-05-02 00:59 - 000017502 _____ C:\Users\warto\Downloads\panel-39884664-image-9f94c758-c085-403e-977b-fa5bd52f79cc
2019-05-02 00:58 - 2019-05-02 00:58 - 000017502 _____ C:\Users\warto\Desktop\panel-39884664-image-9f94c758-c085-403e-977b-fa5bd52f79cc (1)
2019-05-02 00:58 - 2019-05-02 00:58 - 000017502 _____ C:\Users\warto\Desktop\panel-39884664-image-9f94c758-c085-403e-977b-fa5bd52f79cc
2019-04-25 20:28 - 2019-04-25 20:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Caffeine
2019-04-25 20:28 - 2019-04-25 20:28 - 000000000 ____D C:\Program Files\Caffeine

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-05-25 15:17 - 2018-12-13 22:35 - 000026392 _____ C:\Users\warto\Downloads\FRST.txt
2019-05-25 15:16 - 2018-02-24 13:08 - 000000000 ____D C:\FRST
2019-05-25 15:14 - 2018-09-15 09:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-05-25 14:56 - 2017-09-07 20:12 - 000000000 ____D C:\ProgramData\NVIDIA
2019-05-25 14:55 - 2019-04-10 13:02 - 000000000 ____D C:\Fortnite
2019-05-25 14:45 - 2018-09-15 09:31 - 000000000 ____D C:\WINDOWS\INF
2019-05-25 14:42 - 2019-01-06 02:58 - 000000000 ____D C:\ProgramData\AVAST Software
2019-05-25 14:42 - 2018-09-15 09:33 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-05-25 14:38 - 2019-02-15 19:39 - 001693700 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-05-25 14:38 - 2018-09-15 19:39 - 000716776 _____ C:\WINDOWS\system32\perfh005.dat
2019-05-25 14:38 - 2018-09-15 19:39 - 000144856 _____ C:\WINDOWS\system32\perfc005.dat
2019-05-25 14:32 - 2019-02-15 19:37 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-05-25 14:32 - 2019-02-15 19:32 - 000276392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-05-25 14:31 - 2018-09-15 09:33 - 000000000 ___RD C:\Program Files\Windows Defender
2019-05-25 14:31 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-05-25 14:31 - 2018-09-15 08:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-05-25 14:26 - 2018-09-15 09:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-05-25 13:45 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-05-25 13:29 - 2018-06-24 01:12 - 000000000 ___DC C:\Users\warto\AppData\Local\Battle.net
2019-05-25 13:02 - 2019-02-15 19:37 - 000004212 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E88C2868-49A2-458F-AB33-2959AC309739}
2019-05-25 12:14 - 2019-02-15 19:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-05-25 12:14 - 2018-02-16 18:11 - 000000000 ___DC C:\Users\warto\AppData\LocalLow\Mozilla
2019-05-24 17:13 - 2018-09-15 09:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-05-24 17:13 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-05-24 17:06 - 2019-02-16 12:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-05-23 23:30 - 2019-02-16 12:27 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-05-23 23:30 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-05-23 21:25 - 2018-02-10 14:52 - 000000000 ___DC C:\Users\warto\AppData\Roaming\vlc
2019-05-23 21:24 - 2019-01-08 18:13 - 000000000 ___DC C:\Users\warto\AppData\Local\CrashDumps
2019-05-23 21:18 - 2019-04-20 18:40 - 000000000 ____D C:\Users\warto\thumbnail
2019-05-23 21:18 - 2019-03-07 18:00 - 000000000 ____D C:\Users\warto\.openshot_qt
2019-05-23 21:18 - 2019-02-15 19:33 - 000000000 ____D C:\Users\warto
2019-05-23 16:39 - 2019-02-15 19:37 - 000003380 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3012513600-1294068158-3791818399-1001
2019-05-23 16:39 - 2019-02-15 19:33 - 000002365 ____C C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-05-23 16:39 - 2017-09-07 18:28 - 000000000 ___RD C:\Users\warto\OneDrive
2019-05-22 22:33 - 2017-09-07 19:09 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-05-21 00:37 - 2018-11-02 04:24 - 000000000 ___DC C:\Users\warto\AppData\Roaming\discord
2019-05-19 23:01 - 2018-10-07 22:44 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
2019-05-19 13:23 - 2017-11-14 18:17 - 000000000 ___DC C:\Users\warto\AppData\Local\Ubisoft Game Launcher
2019-05-19 12:58 - 2018-12-27 01:39 - 000000000 ____D C:\Program Files (x86)\Steam
2019-05-17 22:57 - 2018-05-20 20:35 - 000000000 ___DC C:\Users\warto\AppData\Local\D3DSCache
2019-05-17 01:07 - 2018-09-15 09:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-05-15 21:11 - 2019-04-19 09:22 - 000000000 ____D C:\Users\warto\OneDrive\Dokumenty\Assassin's Creed Unity
2019-05-15 21:01 - 2018-10-03 20:25 - 000000000 ____D C:\Program Files (x86)\Battle.net
2019-05-15 18:38 - 2017-11-09 18:14 - 000000000 __RDC C:\Users\warto\Desktop\nevermind
2019-05-15 17:49 - 2017-09-23 00:54 - 000000000 ___DC C:\Users\warto\AppData\Roaming\BitTorrent
2019-05-15 16:51 - 2018-09-15 09:36 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-05-15 16:51 - 2018-09-15 09:36 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-05-15 16:50 - 2017-09-07 20:14 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-05-15 16:42 - 2017-09-07 20:14 - 132445408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-05-15 16:27 - 2019-02-15 19:37 - 000003472 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-05-15 16:27 - 2019-02-15 19:37 - 000003348 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-05-14 21:50 - 2019-02-15 19:37 - 000004666 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-05-14 21:50 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-05-14 21:49 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-05-10 18:37 - 2017-10-24 19:13 - 000000000 ___DC C:\Users\warto\AppData\Local\PlaceholderTileLogoFolder
2019-05-10 18:37 - 2017-10-23 06:11 - 000000000 ___DC C:\Users\warto\AppData\Local\Packages
2019-05-05 12:02 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\TextInput
2019-05-05 12:02 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-05-05 12:02 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-05-04 20:06 - 2019-01-07 02:22 - 000000000 ___DC C:\Users\warto\Desktop\pičoviny
2019-05-04 19:01 - 2018-06-24 01:09 - 000000000 ___DC C:\Users\warto\AppData\Local\Blizzard
2019-05-04 19:01 - 2017-09-07 19:54 - 000000000 ___DC C:\Users\warto\AppData\Local\Blizzard Entertainment
2019-04-28 23:26 - 2017-09-07 18:36 - 000000000 ___DC C:\Users\warto\AppData\Local\ElevatedDiagnostics
2019-04-26 16:43 - 2018-12-08 21:17 - 000002156 ____C C:\Users\warto\Desktop\Scep.txt
2019-04-25 20:28 - 2019-04-24 20:38 - 000002485 _____ C:\Users\Public\Desktop\Caffeine.lnk
2019-04-25 20:28 - 2017-10-28 19:51 - 000000000 ____D C:\ProgramData\Package Cache

==================== Files in the root of some directories =======

2018-11-06 23:28 - 2018-11-06 23:28 - 000000001 ____C () C:\Users\warto\AppData\Local\llftool.4.40.agreement
2019-03-17 20:20 - 2019-03-17 20:20 - 000002117 _____ () C:\Users\warto\AppData\Local\recently-used.xbel

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#4 Příspěvek od Conder »

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
  • Nechaj zaskrtnute vsetky nalezy
  • Klikni na Cisteni a opravy (Clean and Repair) a potvrd restart PC teraz
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah sem skopiruj
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Re: Explorer.exe

#5 Příspěvek od Tommy Puerto »

Zatím žádná změna.


# -------------------------------
# Malwarebytes AdwCleaner 7.4.1.0
# -------------------------------
# Build: 09-04-2019
# Database: 2019-09-27.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-29-2019
# Duration: 00:00:14
# OS: Windows 10 Pro
# Scanned: 35645
# Detected: 2


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Seznam.cz Seznam doplněk - Email
PUP.Optional.Seznam.cz Seznam doplněk - Esko

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.


AdwCleaner[S00].txt - [2071 octets] - [14/12/2018 14:07:16]
AdwCleaner[C00].txt - [2035 octets] - [14/12/2018 14:07:40]
AdwCleaner_Debug.log - [5843 octets] - [29/09/2019 15:35:05]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########



# -------------------------------
# Malwarebytes AdwCleaner 7.4.1.0
# -------------------------------
# Build: 09-04-2019
# Database: 2019-09-27.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-29-2019
# Duration: 00:00:14
# OS: Windows 10 Pro
# Scanned: 35645
# Detected: 2


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Seznam.cz Seznam doplněk - Email
PUP.Optional.Seznam.cz Seznam doplněk - Esko

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.


AdwCleaner[S00].txt - [2071 octets] - [14/12/2018 14:07:16]
AdwCleaner[C00].txt - [2035 octets] - [14/12/2018 14:07:40]
AdwCleaner_Debug.log - [5843 octets] - [29/09/2019 15:35:05]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#6 Příspěvek od Conder »

:arrow: Poprosim o obidva nove logy z FRST.
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Re: Explorer.exe

#7 Příspěvek od Tommy Puerto »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-09-2019
Ran by warto (29-09-2019 19:37:14)
Running from C:\Users\warto\Downloads
Windows 10 Pro Version 1809 17763.737 (X64) (2019-02-15 17:37:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3012513600-1294068158-3791818399-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3012513600-1294068158-3791818399-503 - Limited - Disabled)
Guest (S-1-5-21-3012513600-1294068158-3791818399-501 - Limited - Disabled)
Host (S-1-5-21-3012513600-1294068158-3791818399-1002 - Limited - Enabled) => C:\Users\Host
warto (S-1-5-21-3012513600-1294068158-3791818399-1001 - Administrator - Enabled) => C:\Users\warto
WDAGUtilityAccount (S-1-5-21-3012513600-1294068158-3791818399-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (HKLM\...\{5F4E8D94-3947-4019-9239-D2541C9A35F2}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\...\{7A5E4942-A527-42E6-A5FC-95109B756CA8}) (Version: 3.5.1.7 - Intel) Hidden
A Plague Tale Innocence (HKLM-x32\...\A Plague Tale Innocence_is1) (Version: - )
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.255 - Adobe)
Aktualizace NVIDIA 35.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 35.0.0.0 - NVIDIA Corporation) Hidden
ArcaniA - Gothic 4 (HKLM-x32\...\{07872B03-E301-4AE2-AA87-261C8E617769}) (Version: 1.00.0000 - JoWooD Entertainment AG)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\BitTorrent) (Version: 7.10.5.45312 - BitTorrent Inc.)
Caffeine (HKLM\...\{1247C26D-45E6-4D2E-973C-659FC86C6123}) (Version: 1.4.1.274 - Caffeine Inc) Hidden
Caffeine (HKLM-x32\...\{17147312-7df5-447d-afe8-c77fd4ad80b8}) (Version: 1.4.1.274 - Caffeine Inc)
CCleaner (HKLM\...\CCleaner) (Version: - Piriform Ltd.)
Connectify Hotspot 2019 (HKLM\...\Connectify) (Version: 2019.0.0.40040 - Connectify)
Crossout Launcher 1.0.3.36 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\CrossOutLauncher_is1) (Version: - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DiRT2 (HKLM-x32\...\{52D1D62C-FEAB-4580-849E-1DB624BADBBD}) (Version: 1.00.0000 - Codemasters)
Discord (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
Epic Games Launcher (HKLM-x32\...\{93BFE5DF-776E-436F-8693-DF1F72C0E3C1}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version: - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
FlashBoot 2.3d (HKLM\...\FlashBoot_is1) (Version: - Mikhail Kupchik)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Free Screen Recorder v2.9 (HKLM-x32\...\Free Screen Recorder_is1) (Version: 2.9 - Nbxsoft Software Development)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.90 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
Intel(R) Computing Improvement Program (HKLM\...\{58FBAE3A-E602-47E6-9F32-AE25D48B378A}) (Version: 2.4.04140 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{ef2ad7ab-dd41-48ed-ae53-f7fe3cd903d8}) (Version: 3.5.1.7 - Intel)
JDiskReport 1.4.1 (HKLM-x32\...\JDiskReport 1.4.1) (Version: 1.4.1 (2014-02-26 11:50:44) - JGoodies Karsten Lentzsch)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Malwarebytes verze 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\OneDriveSetup.exe) (Version: 19.152.0801.0009 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 60.6.1 ESR (x86 en-US) (HKLM-x32\...\Mozilla Firefox 60.6.1 ESR (x86 en-US)) (Version: 60.6.1 - Mozilla)
Mozilla Firefox 69.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 69.0.1 (x64 cs)) (Version: 69.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 66.0.2 - Mozilla)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.13 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.17.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.17.0.126 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenShot Video Editor verze 2.4.3 (HKLM\...\{4BB0DCDC-BC24-49EC-8937-72956C33A470}_is1) (Version: 2.4.3 - OpenShot Studios, LLC)
Ovládací panel NVIDIA 399.24 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 399.24 - NVIDIA Corporation) Hidden
paint.net (HKLM\...\{E637E0EF-6EB3-44C4-97B8-6F9EA444D649}) (Version: 4.1.5 - dotPDN LLC)
PhotoFiltre 7 (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\PhotoFiltre 7) (Version: - )
Rapture3D 2.3.22 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
RecoveRx version 3.8.0 (HKLM-x32\...\{3DE055DA-690F-43B8-9B7B-54E7D70806F9}_is1) (Version: 3.8.0 - Transcend Information, Inc.)
Roblox Player for warto (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\roblox-player) (Version: - Roblox Corporation)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
Shadow Of The Tomb Raider (HKLM-x32\...\{96F650BA-50B7-4E7B-B026-8C847F45ED92}_is1) (Version: - SQUARENIX)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1495134320_is1) (Version: 2.0.0.51 - GOG.com)
Total War Arena (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\TWA.EU.PRODUCTION) (Version: - Wargaming.net)
Twitch (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.)
Unity Web Player (HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}) (Version: 2.54.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 80.0 - Ubisoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.2.0_x64__tf1gferkr813w [2019-05-28] (Autodesk Inc.)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.0.2058.0_x64__rz1tebttyb220 [2019-09-06] (Dolby Laboratories)
Email.cz -> C:\Program Files\WindowsApps\949FFEAB.Email.cz_2.4.1.0_x64__refxrrjvvv3cw [2019-05-10] (Seznam.cz a.s.)
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.33.0_x64__kejf07qmg0jnm [2019-07-29] (Keeper Security Inc)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.8204.0_x64__8wekyb3d8bbwe [2019-08-27] (Microsoft Studios) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) [MS Ad]
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-09-07] (Plex)
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-25] (Microsoft Corporation) [MS Ad]
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [2019-09-25] (Microsoft Corporation)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-02-15] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (win.rar GmbH -> Alexander Roshal)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\JGoodies Home Page.lnk -> hxxp://www.jgoodies.com

ShortcutWithArgument: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Twitter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=edcifkpoamnkimdpjiabhfjahoinbpbp

==================== Loaded Modules (Whitelisted) ==============

2018-07-02 22:36 - 2018-07-02 22:36 - 098275328 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000092672 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 003922432 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2018-07-02 22:36 - 2018-07-02 22:36 - 000547840 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2018-02-28 14:45 - 000000753 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Windows Live\Shared
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\warto\Desktop\pičoviny\stretched-1920-1080-842957.jpg
DNS Servers: 10.1.0.33
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "DSATray"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "EA Core"
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\StartupApproved\Run: => "Discord"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{8F6B2F37-B472-42B0-B8FE-01B6CD3B2477}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{77DEC8DE-91AF-4666-AE51-6AC4398A75EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C065BEA0-AA37-44F8-B721-A32BDF8C3C9A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe No File
FirewallRules: [{B0725937-A22A-4390-9AAE-3F2EA27FE65F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe No File
FirewallRules: [UDP Query User{32955051-F35D-47E1-B0CB-FCE57E603D98}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{7CB67C81-3838-4269-8D25-2D2DDBED43C8}C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe] => (Allow) C:\users\warto\appdata\roaming\bittorrent\updates\7.10.4_44633.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{FE24C43C-9D27-44E6-843F-504502F5F203}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A01BD763-F1C8-42B4-8C48-A5558DFA67B2}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A0C8C48D-620B-4919-8FE7-510EACE9BE74}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{C8A83804-6167-453F-B838-9DB6489D9BE8}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A4E8F381-B403-40A9-B8BB-7FA087965B61}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [{74B1B2AE-1033-4F7C-A665-738C684DEB1F}] => (Allow) D:\dirt2_game.exe No File
FirewallRules: [UDP Query User{1E6AAAAC-6B5E-44C6-A9A6-471D3C19AB2E}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [TCP Query User{B87C723B-3BDF-45AA-BA72-E5D539DF48A7}D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe] => (Allow) D:\mass effect 3 complete edition\binaries\win32\masseffect3.exe No File
FirewallRules: [UDP Query User{1248693B-A1BE-47BE-A697-6AE83EF38C84}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [TCP Query User{693305F7-92F7-4E0F-8AF4-81D5029A7646}D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe No File
FirewallRules: [{0B363149-DD6E-4F7F-B483-3DED1BC8E7E5}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{877274C3-04FF-453E-AD6D-9745E0CA973C}] => (Allow) C:\Users\warto\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{71BCA3F8-1108-4BB9-9F1C-CF95C3F34DD7}] => (Allow) LPort=1688
FirewallRules: [TCP Query User{4F06821A-7212-459A-B965-2DCD8D02A1A1}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5397481F-A840-4DA7-BBE9-7A5659313106}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{21B53C08-9147-4502-B390-7E01A03DAD87}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{5D38FC9B-3BA3-4C5F-8102-2B08AA67C949}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CEA43369-C54E-4E28-B5A5-2DD330242125}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{15167DB2-9A30-455E-B8CA-9F2E73C170C7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{982F743C-5A18-4F12-9118-49EC9FBD5285}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{E9900D7C-0CF7-4D34-A6B2-9FDA0E490B75}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{BF24202F-0DD7-471C-BD4A-C5DD556056F2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{126204BB-BA32-44A2-AC34-963279CAB2D5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{0024598A-FEAC-418B-A2EE-B36FD8D53AB6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{A24BB525-1C2E-4172-94E2-51A1203EC0B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{05A89F23-1566-4BBA-BBA9-EEB72F00D2EB}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{44B8882D-281B-4F9B-B2E5-C2A62C455515}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{34F512B3-225C-44CB-A151-2544D6025CFA}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1B5A931E-8D0A-4F16-872B-AABEE15A23C5}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{C4D3F493-882E-42D5-B956-43C2FB9C587B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C23CD4BE-7964-4B42-82DF-B8C34596CF45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{1EA93D44-4704-4F5D-B89B-DC1CDB459723}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [UDP Query User{35951E08-48E7-476E-AE12-4F004DE2C79A}C:\program files\caffeine\caffeine\caffeine.exe] => (Allow) C:\program files\caffeine\caffeine\caffeine.exe (Caffeine Inc -> Caffeine)
FirewallRules: [TCP Query User{F59F6728-93DA-4694-81F3-F31BFDC5A66B}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [UDP Query User{24AB2205-4C5C-46DB-9443-40B08AA7D470}C:\program files\openshot video editor\launch.exe] => (Allow) C:\program files\openshot video editor\launch.exe () [File not signed]
FirewallRules: [{0CE020BF-D566-4CF4-BD3E-802E53E4CA7F}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{474CAD7A-6CEF-432F-B2BF-1B688E577696}] => (Allow) D:\Assassin's Creed Unity\ACU.exe No File
FirewallRules: [{78A3F1A0-58CC-46D5-93DE-FA8D8F80BA36}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FD033137-C54C-4677-85A1-7BF3DE5872F6}] => (Allow) LPort=2869
FirewallRules: [{E88DC7EB-1C82-4ABB-9808-C3CCE23BA419}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{878A9E63-1B0C-404D-9A25-26630B03FC47}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{FEDEC65D-8114-4B5D-9E3C-1E6477F220E7}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{9143A86B-90B0-42FC-A0B6-83C9D9A5D960}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{F88C1DF4-D314-4AFE-B0EC-47EFC9A477C4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{3ACDBB07-D21D-4E9E-8F88-DE87C2E8E09A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{E0411E62-BB81-42B4-9BC0-0CE0C1335AB7}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{D7CD2CFA-6819-4D61-A899-9DFB41BB4930}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)

==================== Codecs (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.FPS1] => C:\WINDOWS\system32\frapsv64.dll [105984 2018-09-26] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [vidc.mjpg] => C:\WINDOWS\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\WINDOWS\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\WINDOWS\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2018-09-26] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )

==================== Restore Points =========================

24-09-2019 00:20:33 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/29/2019 03:10:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UnrealCEFSubProcess.exe, verze: 4.21.0.0, časové razítko: 0x5d8153dc
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17763.737, časové razítko: 0x7416f3ae
Kód výjimky: 0xe0000008
Posun chyby: 0x0000000000039129
ID chybujícího procesu: 0x2ae4
Čas spuštění chybující aplikace: 0x01d576a590624770
Cesta k chybující aplikaci: C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 187875ab-c957-4ca4-a9e5-444de8d76193
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/29/2019 07:01:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UnrealCEFSubProcess.exe, verze: 4.21.0.0, časové razítko: 0x5d8153dc
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17763.737, časové razítko: 0x7416f3ae
Kód výjimky: 0xe0000008
Posun chyby: 0x0000000000039129
ID chybujícího procesu: 0x2b84
Čas spuštění chybující aplikace: 0x01d57640f8245e16
Cesta k chybující aplikaci: C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: ba1bd6aa-9e67-4104-bcfa-aa4006a6cda2
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/24/2019 05:44:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program MicrosoftEdgeCP.exe verze 11.0.17763.1 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 17b8

Čas spuštění: 01d572eeb3e8c4cb

Čas ukončení: 8

Cesta k aplikaci: C:\Windows\System32\MicrosoftEdgeCP.exe

ID hlášení: e8fd9dbc-f590-4c29-b9e8-0d8691ad45ad

Úplný název balíčku s chybou: Microsoft.MicrosoftEdge_44.17763.1.0_neutral__8wekyb3d8bbwe

ID aplikace relativní podle balíčku s chybou: MicrosoftEdge

Typ zablokování: Unknown

Error: (09/24/2019 05:43:28 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program MicrosoftEdgeCP.exe verze 11.0.17763.1 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 107c

Čas spuštění: 01d572eeba6f3981

Čas ukončení: 36

Cesta k aplikaci: C:\Windows\System32\MicrosoftEdgeCP.exe

ID hlášení: 61962e0b-10f6-4c40-920d-460415937bc4

Úplný název balíčku s chybou: Microsoft.MicrosoftEdge_44.17763.1.0_neutral__8wekyb3d8bbwe

ID aplikace relativní podle balíčku s chybou: MicrosoftEdge

Typ zablokování: Cross-process

Error: (09/21/2019 03:49:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UnrealCEFSubProcess.exe, verze: 4.21.0.0, časové razítko: 0x5d8153dc
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17763.737, časové razítko: 0x7416f3ae
Kód výjimky: 0xe0000008
Posun chyby: 0x0000000000039129
ID chybujícího procesu: 0x158c
Čas spuštění chybující aplikace: 0x01d570627f96b458
Cesta k chybující aplikaci: C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: fe2a5c2a-3aa7-4601-a34c-d6d71a869724
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/17/2019 07:04:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UnrealCEFSubProcess.exe, verze: 4.21.0.0, časové razítko: 0x5d7a5982
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17763.737, časové razítko: 0x7416f3ae
Kód výjimky: 0xe0000008
Posun chyby: 0x0000000000039129
ID chybujícího procesu: 0x680
Čas spuštění chybující aplikace: 0x01d56ccad004b266
Cesta k chybující aplikaci: C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 86be98a6-542c-4351-995f-36baa5191f73
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/11/2019 05:13:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 3.0.0.0, časové razítko: 0x00dee6e6
Název chybujícího modulu: vlc.exe, verze: 3.0.0.0, časové razítko: 0x00dee6e6
Kód výjimky: 0xc0000005
Posun chyby: 0x00023393
ID chybujícího procesu: 0x2a48
Čas spuštění chybující aplikace: 0x01d568b379852e54
Cesta k chybující aplikaci: C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
ID zprávy: 3d6ba991-c922-4897-a247-8fd8d0eefedd
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/11/2019 05:12:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 3.0.0.0, časové razítko: 0x00dee6e6
Název chybujícího modulu: vlc.exe, verze: 3.0.0.0, časové razítko: 0x00dee6e6
Kód výjimky: 0xc0000005
Posun chyby: 0x00023393
ID chybujícího procesu: 0x2dfc
Čas spuštění chybující aplikace: 0x01d568b348a40ddc
Cesta k chybující aplikaci: C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
ID zprávy: c407860c-5903-4d42-8c9e-9cf8555ee4e6
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (09/29/2019 03:40:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/29/2019 03:40:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/29/2019 03:40:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.SecurityAppBroker
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/29/2019 03:40:02 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/28/2019 01:04:38 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/28/2019 01:03:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/27/2019 05:30:56 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-QD17RQH)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-QD17RQH\warto (SID: S-1-5-21-3012513600-1294068158-3791818399-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/27/2019 05:30:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2019-09-22 23:52:54.847
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {9E14FA8B-A601-4D7D-87C3-ED3869015487}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-09-20 00:13:23.787
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {CAD3C45F-1BB0-4FC9-806E-9F39C0BADC27}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-09-09 17:22:42.477
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {DC9A29ED-CA58-472E-8779-40C6A3148F0D}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-08-31 14:17:16.608
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {19A5C1B4-36A1-485A-BB4F-6B34740A9CA9}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

==================== Memory info ===========================

BIOS: American Megatrends Inc. 0501 10/03/2016
Motherboard: ASUSTeK COMPUTER INC. B150M PRO GAMING
Processor: Intel(R) Pentium(R) CPU G4600 @ 3.60GHz
Percentage of memory in use: 59%
Total physical RAM: 8128.61 MB
Available physical RAM: 3276.22 MB
Total Virtual: 16832.61 MB
Available Virtual: 9464.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.24 GB) (Free:54.84 GB) NTFS
Drive d: (USB DISK) (Removable) (Total:60.94 GB) (Free:60.14 GB) FAT32

\\?\Volume{5a6ae5dd-a1c3-46c1-a0fb-4e99138bf673}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{acd79ad2-c4af-4496-92ef-e9a2db0b22a9}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (Protective MBR) (Size: 61 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================



Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-09-2019
Ran by warto (administrator) on DESKTOP-QD17RQH (29-09-2019 19:35:39)
Running from C:\Users\warto\Downloads
Loaded Profiles: warto (Available Profiles: warto & Host)
Platform: Windows 10 Pro Version 1809 17763.737 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Connectify (Connectify, Inc.) -> Connectify) C:\Program Files (x86)\Connectify\Connectifyd.exe
(Connectify (Connectify, Inc.) -> Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel(R) Driver & Support Assistant -> Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(Intel(R) Software Development Products -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19082.1010.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19072.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\NisSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [126712 2018-09-26] (Intel(R) Driver & Support Assistant -> Intel)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35941264 2019-09-18] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [Steam] => "C:\Program Files (x86)\Steam\steam.exe" -silent
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Run: [Discord] => C:\Users\warto\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1694704 2019-09-18] (Google LLC -> Google LLC)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Winlogon: [Shell] %comspec% <==== ATTENTION
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.90\Installer\chrmstp.exe [2019-09-18] (Google LLC -> Google LLC)
Startup: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2019-07-10]
ShortcutTarget: Twitch.lnk -> C:\Users\warto\AppData\Roaming\Twitch\Bin\Twitch.exe (No File)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0AEF4AF7-FB10-448D-8AE8-A537D42AFAF8} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {11544983-8386-422A-A161-CB0FBCF7C2F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-09-07] (Google Inc -> Google Inc.)
Task: {18FA9E8B-20FF-4A3C-9B3A-D2C55A0EB46C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3724680 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {19A7270D-1FA7-417A-A116-93E50DD09C68} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2D3617D5-B11E-4979-8483-9552F540D618} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {33B923A1-025D-4513-86A7-F4EAB1299B72} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [841096 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3BA6BF50-477B-4DEF-8358-64F7B5710CE4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4DBEDE25-A78A-43C6-B501-F762F89CD94B} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {60177393-1D43-47AF-87E2-1DE22BA5A775} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7644EFBD-B800-4976-8E07-0EB3D0DDDDF3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [7685808 2017-09-20] (Piriform Ltd -> Piriform Ltd)
Task: {78D26CE1-C19F-41E1-8E79-2E4A3FB3D6F2} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {821E0A23-EC14-4002-9D57-F66761564AE7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_255_pepper.exe [1453112 2019-09-11] (Adobe Inc. -> Adobe)
Task: {88ABC11F-2E70-4716-B7CB-56D9E5E903B4} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8DA105C0-30B0-40DA-A2B2-6DC64DA160FE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [572808 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {921F0830-71BE-42F6-9ADF-ECED142541D8} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [841096 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {933F4B1C-BD1A-4CBE-8A7B-F1FB4808D3D6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {93C2404D-2F6E-4B81-9580-33E2B45AFBDC} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {99C090C2-C4C8-4894-8A52-6C9590E4A78D} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [877448 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AE1680A4-6007-4102-8D3D-1C2AA9AA25ED} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [467880 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BA79BBCA-F190-49A6-84F5-52D080B6E7B5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-09-07] (Google Inc -> Google Inc.)
Task: {C1967968-F056-4A52-85DC-70EBDA33BC60} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-09-11] (Adobe Inc. -> Adobe)
Task: {D04EC235-CB92-436D-83D5-A6D3AAF9FDD0} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D75AFEAE-FC90-40E1-B650-A2BF19241225} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {DA85AE09-51D0-4CDE-A62C-53D865923007} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {DF56422B-F76A-40FE-AE90-7456A2E2CBE1} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [702856 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FE3DF3C8-3F45-4484-AB8F-5B1086612FFC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.1.0.33
Tcpip\..\Interfaces\{5b1e732c-1e38-44ef-8821-e20f8ac531c4}: [DhcpNameServer] 10.1.0.33

Internet Explorer:
==================

FireFox:
========
FF DefaultProfile: e1xefp5x.default-1554583981454
FF ProfilePath: C:\Users\warto\AppData\Roaming\Mozilla\Firefox\Profiles\e1xefp5x.default-1554583981454 [2019-09-23]
FF Extension: (Firefox ESR configurer for OLDJAWS screen reader ) - C:\Program Files (x86)\Mozilla Firefox\browser\features\jaws-esr@mozilla.org.xpi [2019-04-06] [Legacy] [not signed]
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-09] (VideoLAN -> VideoLAN)
FF Plugin HKU\S-1-5-21-3012513600-1294068158-3791818399-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\warto\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies SF -> Unity Technologies ApS)

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR DefaultSearchKeyword: Default -> google.cz_
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default [2019-09-29]
CHR Extension: (Seznam doplněk - Email) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2019-08-31]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2019-06-03]
CHR Extension: (Seznam doplněk - Esko-) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2019-08-31]
CHR Extension: (Twitter) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\edcifkpoamnkimdpjiabhfjahoinbpbp [2019-02-15]
CHR Extension: (uBlock) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\epcnnfbjfcgphgdmggkamkmgojdagdnn [2019-09-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Ochrana hesla) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\noondiphcddnnabmjcihcjfbhfklnnep [2018-06-04]
CHR Extension: (Seznam doplněk - Esko) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2019-08-31]
CHR Extension: (Chrome Media Router) - C:\Users\warto\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-11]
CHR Profile: C:\Users\warto\AppData\Local\Google\Chrome\User Data\System Profile [2018-02-24]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-03-27] (BattlEye Innovations e.K. -> )
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [275968 2019-01-18] (Connectify (Connectify, Inc.) -> Connectify)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23800 2018-09-26] (Intel(R) Driver & Support Assistant -> Intel)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-12-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [937192 2018-09-19] (Intel(R) Software Development Products -> )
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes Corporation -> Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [790920 2019-01-30] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5357360 2019-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe [194792 2018-09-19] (Intel(R) Software Development Products -> )
S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [937192 2018-09-19] (Intel(R) Software Development Products -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\NisSrv.exe [3630832 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MsMpEng.exe [103168 2019-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 cfywlan2; C:\WINDOWS\system32\DRIVERS\cfywlan2.sys [46088 2019-03-24] (Connectify (Connectify, Inc.) -> Connectify)
R1 cnnctfy4; C:\WINDOWS\system32\DRIVERS\cnnctfy4.sys [53216 2019-03-24] (Connectify (Connectify, Inc.) -> Connectify)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-08-31] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-08-31] (Disc Soft Ltd -> Disc Soft Ltd)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_8e4f37220e99138f\nvlddmkm.sys [17213824 2018-09-25] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-01-16] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [70024 2018-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [66792 2018-10-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [43008 2018-09-19] (Intel Corporation -> )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-09-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [346336 2019-09-17] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-09-17] (Microsoft Windows -> Microsoft Corporation)
S3 BlueStacksDrv; \??\C:\Program Files\BlueStacks\BstkDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-09-29 19:35 - 2019-09-29 19:36 - 000023689 _____ C:\Users\warto\Downloads\FRST.txt
2019-09-29 19:35 - 2019-09-29 19:36 - 000000000 ____D C:\FRST
2019-09-29 19:34 - 2019-09-29 19:34 - 001615360 _____ (Farbar) C:\Users\warto\Downloads\FRST64.exe
2019-09-29 15:40 - 2019-09-29 15:40 - 007622344 _____ (Malwarebytes) C:\Users\warto\Downloads\adwcleaner_7.4.1 (1).exe
2019-09-29 15:37 - 2019-09-29 15:37 - 000003172 ____C C:\Users\warto\Desktop\Nový textový dokument.txt
2019-09-29 15:27 - 2019-09-29 15:28 - 007622344 _____ (Malwarebytes) C:\Users\warto\Downloads\adwcleaner_7.4.1.exe
2019-09-28 22:49 - 2019-09-28 22:49 - 000000000 ____D C:\Users\warto\Downloads\WinDirStatPortable
2019-09-28 22:48 - 2019-09-28 22:48 - 000970568 _____ (PortableApps.com) C:\Users\warto\Downloads\WinDirStatPortable_1.1.2.80_Rev_3.paf.exe
2019-09-28 22:47 - 2019-09-28 22:48 - 000001398 ____C C:\Users\warto\Desktop\JDiskReport.lnk
2019-09-28 22:47 - 2019-09-28 22:47 - 000000000 ___DC C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1
2019-09-28 22:47 - 2019-09-28 22:47 - 000000000 ____D C:\Program Files (x86)\JGoodies
2019-09-28 22:46 - 2019-09-28 22:47 - 000697246 _____ C:\Users\warto\Downloads\jdiskreport-1_4_1-win.exe
2019-09-28 22:35 - 2019-09-28 22:35 - 000081006 _____ C:\Users\warto\OneDrive\Dokumenty\cc_20190928_223542.reg
2019-09-25 19:14 - 2019-09-25 19:15 - 000000000 ___DC C:\Users\warto\Desktop\Nová složka
2019-09-21 16:38 - 2019-09-22 09:08 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-09-20 19:32 - 2019-09-20 19:33 - 024474886 ____C C:\Users\warto\Desktop\aaaa.mp4
2019-09-20 19:28 - 2019-09-20 19:28 - 003435627 _____ C:\Users\warto\Downloads\12 Rounds 3 Lockdown Movie CLIP - Flash the Badge (2015) - Dean Ambrose Thriller HD.mp4
2019-09-16 17:39 - 2019-09-16 17:39 - 001210754 _____ C:\Users\warto\Downloads\D5819.7z (4).crdownload
2019-09-13 17:59 - 2019-09-13 17:59 - 000974668 _____ C:\Users\warto\Desktop\youveju.mp4
2019-09-13 17:49 - 2019-09-13 17:49 - 002052457 _____ C:\Users\warto\Downloads\Husky Dog Talking - I love you .mp4
2019-09-12 22:30 - 2019-09-21 16:01 - 000000000 ____D C:\Users\warto\OneDrive\Dokumenty\GreedFall
2019-09-12 13:35 - 2019-09-12 13:35 - 000000000 ____D C:\WINDOWS\Panther
2019-09-11 17:02 - 2019-09-11 17:02 - 000392585 _____ C:\Users\warto\Downloads\Windows_Desktop_Background_Version_5.7z.crdownload
2019-09-11 16:40 - 2019-09-11 16:40 - 026808320 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 020817408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 019011584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 012939776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 012244992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 008903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 007921664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 006065664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 005436696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 004488192 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2019-09-11 16:40 - 2019-09-11 16:40 - 003702784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 003550384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 003442176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-09-11 16:40 - 2019-09-11 16:40 - 002469432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 002127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 002099752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001782272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001604760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001521664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001297120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001132032 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001075832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2019-09-11 16:40 - 2019-09-11 16:40 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000798736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2019-09-11 16:40 - 2019-09-11 16:40 - 000793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000773632 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-09-11 16:40 - 2019-09-11 16:40 - 000480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000409256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000386048 _____ (curl, hxxps://curl.haxx.se/) C:\WINDOWS\SysWOW64\curl.exe
2019-09-11 16:40 - 2019-09-11 16:40 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000349144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000195224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityCenterBroker.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll
2019-09-11 16:40 - 2019-09-11 16:40 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComputerDefaults.exe
2019-09-11 16:40 - 2019-09-11 16:40 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LSCSHostPolicy.dll
2019-09-11 16:39 - 2019-09-11 16:40 - 023453696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 022124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 017484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 015221248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 009679672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 007886848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 007871488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 007690648 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 007645392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 006542464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 006444544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 006310064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 005597808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 005573232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 005569024 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 004874752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 004588752 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 004353016 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 004056576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 003821728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 003634688 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 003490816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 003385856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 003333984 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 003096576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 003082752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002924344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 002879488 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 002779488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 002700784 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002693120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002645504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002593032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002421248 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 002415416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002279296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002233688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002199864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002192384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002148864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002085168 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 002073240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001966096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 001929728 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001904128 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001899152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001893376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001864192 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001764352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001743168 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001721360 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001720120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001702096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-09-11 16:39 - 2019-09-11 16:39 - 001687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001668752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001655976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001641400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001573240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001563880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001522704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001484592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001465472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001397048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001387512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001344960 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-09-11 16:39 - 2019-09-11 16:39 - 001331536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001294280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001272560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001256960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001253688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001221528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001191512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001187840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AgentService.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001183744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001180248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001098136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001081656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Services.TargetedContent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001054952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001048888 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001022824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 001010688 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000968192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000900096 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000888120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000865576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000851272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Signals.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000811024 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000807760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000806568 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-09-11 16:39 - 2019-09-11 16:39 - 000806568 _____ C:\WINDOWS\system32\locale.nls
2019-09-11 16:39 - 2019-09-11 16:39 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000793824 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000791352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000782968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000774968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Services.TargetedContent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000774192 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000773632 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000764416 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000762880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000751928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000741392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000740904 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000736056 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000689664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000675096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000660544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000652832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000652600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000652304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000626176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000622392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000607744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000606088 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000604344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000603784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000591160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000585184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000554000 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000540240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000535056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000532192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000520208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000519168 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000515960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000515152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000506200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000505128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000464912 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000450872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000449376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000439808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000435712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000425472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000421376 _____ (curl, hxxps://curl.haxx.se/) C:\WINDOWS\system32\curl.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000405304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000402368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000398336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000398208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000351432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000347576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000330672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000330592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000294728 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ConfigWrapper.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000279416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000272648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ManagePhone.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32tm.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ptpprov.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\w32tm.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecureTimeAggregator.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000177176 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcaSvc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000168248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000164504 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000144080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000140600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000140088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tsusbhub.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000130872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Display.BrightnessOverride.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000120344 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvsetup.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000106048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsiCx.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000098080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Display.BrightnessOverride.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvsetup.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000090632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000087056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComputerDefaults.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000071696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-09-11 16:39 - 2019-09-11 16:39 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-09-11 16:39 - 2019-09-11 16:39 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsiAcpiClient.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ws2ifsl.sys
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-09-11 16:39 - 2019-09-11 16:39 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-09-11 16:35 - 2019-09-11 16:35 - 000327011 _____ C:\Users\warto\Downloads\banf.rar (3).crdownload
2019-09-07 16:28 - 2019-09-07 16:28 - 000044117 _____ C:\Users\warto\Downloads\likes.html
2019-09-06 19:03 - 2019-09-06 19:03 - 001573568 _____ C:\Users\warto\Downloads\SteamSetup.exe
2019-09-05 18:04 - 2019-09-05 18:04 - 000001274 _____ C:\Users\warto\Downloads\text.txt
2019-09-05 17:22 - 2019-09-05 17:36 - 000001274 ____C C:\Users\warto\Desktop\Scep2.txt
2019-08-31 19:11 - 2019-08-31 19:11 - 004100438 _____ C:\Users\warto\aaassa.mp4
2019-08-31 18:46 - 2019-08-31 18:46 - 000656928 _____ C:\Users\warto\Desktop\giphy.mp4

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-09-29 19:32 - 2018-09-15 09:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-09-29 16:29 - 2018-02-16 18:11 - 000000000 ___DC C:\Users\warto\AppData\LocalLow\Mozilla
2019-09-29 15:48 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-09-29 15:44 - 2019-02-15 19:39 - 001693700 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-09-29 15:44 - 2018-09-15 19:39 - 000716776 _____ C:\WINDOWS\system32\perfh005.dat
2019-09-29 15:44 - 2018-09-15 19:39 - 000144856 _____ C:\WINDOWS\system32\perfc005.dat
2019-09-29 15:44 - 2018-09-15 09:31 - 000000000 ____D C:\WINDOWS\INF
2019-09-29 15:40 - 2017-09-07 20:12 - 000000000 ____D C:\ProgramData\NVIDIA
2019-09-29 15:38 - 2019-02-15 19:37 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-09-29 15:38 - 2018-09-15 08:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-09-29 15:36 - 2019-08-09 14:10 - 000000000 ____D C:\Users\warto\AppData\Local\Battle.net
2019-09-29 15:27 - 2019-02-15 19:37 - 000004212 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{E88C2868-49A2-458F-AB33-2959AC309739}
2019-09-29 15:10 - 2019-01-08 18:13 - 000000000 ___DC C:\Users\warto\AppData\Local\CrashDumps
2019-09-29 11:06 - 2019-08-09 14:06 - 000000000 ____D C:\Program Files (x86)\Battle.net
2019-09-28 23:09 - 2018-05-20 20:35 - 000000000 ___DC C:\Users\warto\AppData\Local\D3DSCache
2019-09-28 23:01 - 2019-03-24 16:50 - 000000000 ____D C:\Program Files (x86)\Connectify
2019-09-28 23:01 - 2019-01-24 00:23 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2019-09-28 23:00 - 2019-01-19 13:41 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2019-09-28 23:00 - 2018-07-19 23:25 - 000000000 ____D C:\Program Files (x86)\Image-Line
2019-09-28 22:58 - 2018-07-19 23:29 - 000000000 ____D C:\Users\warto\OneDrive\Dokumenty\Image-Line
2019-09-28 22:43 - 2019-02-05 16:26 - 000000000 ____D C:\ProgramData\Origin
2019-09-28 22:33 - 2018-01-10 18:16 - 000000000 ____D C:\Games
2019-09-27 18:45 - 2018-02-10 14:52 - 000000000 ___DC C:\Users\warto\AppData\Roaming\vlc
2019-09-27 17:32 - 2018-09-15 09:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-09-27 17:31 - 2019-02-15 19:37 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3012513600-1294068158-3791818399-1001
2019-09-27 17:31 - 2019-02-15 19:33 - 000002365 ____C C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-09-27 17:31 - 2017-09-07 18:28 - 000000000 ___RD C:\Users\warto\OneDrive
2019-09-27 17:28 - 2018-10-07 22:44 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
2019-09-27 05:31 - 2019-02-15 19:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-09-26 22:44 - 2018-11-02 04:24 - 000000000 ___DC C:\Users\warto\AppData\Roaming\discord
2019-09-25 19:03 - 2019-01-07 02:22 - 000000000 ___DC C:\Users\warto\Desktop\pičoviny
2019-09-22 09:08 - 2019-02-16 12:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-09-21 19:57 - 2019-02-16 12:27 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-09-20 19:34 - 2019-03-07 18:00 - 000000000 ____D C:\Users\warto\.openshot_qt
2019-09-19 20:31 - 2018-11-21 01:43 - 000000000 ____D C:\Program Files (x86)\World of Warcraft
2019-09-18 21:32 - 2017-09-07 19:09 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-09-17 14:51 - 2018-02-28 14:46 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-09-13 17:59 - 2019-02-15 19:33 - 000000000 ____D C:\Users\warto
2019-09-13 16:45 - 2017-09-23 00:54 - 000000000 ___DC C:\Users\warto\AppData\Roaming\BitTorrent
2019-09-12 22:03 - 2019-03-12 15:29 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2019-09-12 22:03 - 2017-10-04 21:47 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2019-09-12 13:38 - 2017-10-23 16:13 - 000000000 ___RD C:\Users\warto\3D Objects
2019-09-12 13:38 - 2017-09-07 18:26 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-09-12 13:35 - 2019-02-15 19:32 - 000276392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-09-12 05:27 - 2018-09-15 19:40 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-09-12 05:27 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-09-12 05:27 - 2018-09-15 08:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-09-11 18:08 - 2018-09-15 09:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-09-11 16:42 - 2018-09-15 09:36 - 000835480 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-09-11 16:42 - 2018-09-15 09:36 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-09-11 01:55 - 2019-02-15 19:37 - 000004666 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2019-09-11 01:55 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-09-11 01:55 - 2018-09-15 09:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-09-06 19:03 - 2018-12-27 01:39 - 000001036 _____ C:\Users\Public\Desktop\Steam.lnk
2019-08-31 19:06 - 2019-05-23 21:15 - 004096440 _____ C:\Users\warto\Nepojmenovaný projekt.mp4

==================== Files in the root of some directories ================

2018-11-06 23:28 - 2018-11-06 23:28 - 000000001 ____C () C:\Users\warto\AppData\Local\llftool.4.40.agreement
2019-03-17 20:20 - 2019-03-17 20:20 - 000002117 _____ () C:\Users\warto\AppData\Local\recently-used.xbel

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#8 Příspěvek od Conder »

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
    
    HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1694704 2019-09-18] (Google LLC -> Google LLC)
    HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Winlogon: [Shell] %comspec% <==== ATTENTION
    Startup: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2019-07-10]
    S3 BlueStacksDrv; \??\C:\Program Files\BlueStacks\BstkDrv.sys [X]
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Re: Explorer.exe

#9 Příspěvek od Tommy Puerto »

Už je to pryč, tak děkuji moc. Nebo ještě něco dodělat?


Fix result of Farbar Recovery Scan Tool (x64) Version: 29-09-2019
Ran by warto (30-09-2019 16:24:24) Run:1
Running from C:\Users\warto\Desktop
Loaded Profiles: warto (Available Profiles: warto & Host)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum

HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1694704 2019-09-18] (Google LLC -> Google LLC)
HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\...\Winlogon: [Shell] %comspec% <==== ATTENTION
Startup: C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2019-07-10]
S3 BlueStacksDrv; \??\C:\Program Files\BlueStacks\BstkDrv.sys [X]
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.

========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========



Count : 1582
Average :
Sum : 6592843853
Maximum :
Minimum :
Property : Length




========= End of Powershell: =========

"HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #1" => removed successfully
"HKU\S-1-5-21-3012513600-1294068158-3791818399-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => removed successfully
C:\Users\warto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk => moved successfully
HKLM\System\CurrentControlSet\Services\BlueStacksDrv => removed successfully
BlueStacksDrv => service removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 419248512 B
Java, Flash, Steam htmlcache => 1110 B
Windows/system/drivers => 367397 B
Edge => 17792266 B
Chrome => 446198224 B
Firefox => 599652471 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 7444 B
NetworkService => 0 B
warto => 51184299 B
Host => 141373630 B

RecycleBin => 33405354 B
EmptyTemp: => 1.6 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 16:25:45 ====

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#10 Příspěvek od Conder »

:arrow: Plocha ma cca 6 GB. Presun vsetky subory a zlozky z plochy do dokumentov a na ploche nechaj iba odkazy/zastupcov. Prilis velka velkost plochy moze sposobit spomalenie systemu.

:arrow: Dalej este odporucam nasledovne:

:arrow: Spusti kontrolu integrity systemovych suborov:
  • Otvor Start, napis "cmd" (bez uvodzoviek), klikni pravym tlacitkom mysi na Prikazovy riadok a klikni na Spustit ako spravca
  • Skopiruj a spusti prikaz:

    Kód: Vybrat vše

    DISM.exe /Online /Cleanup-image /Restorehealth
  • Po dokonceni skopiruj a spusti druhy prikaz:

    Kód: Vybrat vše

    sfc /scannow
  • Po dokonceni obidvoch prikazov skopiruj a spusti tento prikaz:

    Kód: Vybrat vše

    findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >> "%userprofile%\desktop\sfcdetails.txt" && copy %windir%\logs\dism\dism.log %userprofile%\desktop\dism.txt
  • Na ploche sa vytvoria subory sfcdetails.txt a dism.txt, tieto subory zabal ho do archivu RAR alebo ZIP a posli ako prilohu k dalsiemu prispevku
  • Restartuj PC a napis ako sa chova PC
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Re: Explorer.exe

#11 Příspěvek od Tommy Puerto »

Vše udělané, žádná vetší změna.
Přílohy
Dism.rar
(12.33 KiB) Staženo 46 x

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#12 Příspěvek od Conder »

:arrow: OK, ak uz teda nie su ziadne problemy, tak este upraceme po pouzitych nastrojoch:
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Tommy Puerto
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 04 zář 2014 01:52

Re: Explorer.exe

#13 Příspěvek od Tommy Puerto »

Hotové,

Díky

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Explorer.exe

#14 Příspěvek od Conder »

Nie je zaco, rad som pomohol :)
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Odpovědět