Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu - pomalejší noťas

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Prosím o kontrolu logu - pomalejší noťas

#1 Příspěvek od gomik »

Zdravím a zároveň prosím o preventivní kontrolu logu. Celkem nemám s ničím problém, jen mi přijde, že je počítač poslední dobou pomalejší. Hlavně zlobí průzkumník po startu, jinak vše celkem OK...

děkuji za kontrolu :-)

Logfile of random's system information tool 1.10 (written by random/random)
Run by Thymallus at 2017-04-15 23:23:02
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 116 GB (20%) free of 588 GB
Total RAM: 8126 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:23:05, on 15.4.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18639)
Boot mode: Normal

Running processes:
C:\Program Files\Mouse\Amoumain.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Standard Mouse Driver\Monitor.EXE
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files\trend micro\Thymallus.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [HPQuickWebProxy] "c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [Standard Mouse Driver] "C:\Program Files (x86)\Standard Mouse Driver\Monitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Svátky a výročí] C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
O4 - Startup: AutorunsDisabled
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V3 Service4(05) (EPSON_PM_RPCV4_05) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Sentinel HASP License Manager (hasplms) - Unknown owner - C:\windows\system32\hasplms.exe (file missing)
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe

--
End of file - 14897 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
atieclxx
"C:\Program Files\Tablet\Wacom\WTabletServicePro.exe"
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Mouse\Amoumain.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe"
"C:\Program Files (x86)\RocketDock\RocketDock.exe"
"C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
AvastUI.exe /nogui
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
C:\windows\system32\hasplms.exe -run
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Standard Mouse Driver\Monitor.EXE"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe"
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 4016
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\EscSvc64.exe
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k WindowsMobile
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" /hidden
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "https://get3.adobe.com/cz/flashplayer/update/plugin"
"C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe"
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --disable-3d-apis --disable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\THYMAL~1\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 6.1.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/537.36 CreativeCloud/3.9.0.327" --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --disable-gpu-compositing --channel="3176.0.1233081218\319981991" /prefetch:673131151
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" --onOSstartup=true --showwindow=false --waitForRegistration=true
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="6928.0.1148661129\796359693" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 6928 "\\.\pipe\gecko-crash-server-pipe.6928" tab
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe" -Embedding
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\main.js"
\??\C:\windows\system32\conhost.exe "15875565241465852829-19311629731718979129995432510-789139441-221512448710871831
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe"
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a8552768-a4b9-40a8-be62-2bac5f9add6b -SystemEventPortName:HostProcess-9ede8d2e-1c09-4d90-808e-699c71c5cd33 -IoCancelEventPortName:HostProcess-705a2423-43af-4221-87ea-8e74029d7a9a -NonStateChangingEventPortName:HostProcess-89c6bed2-7824-4e00-b71e-599fa5ea50f8 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:9d0c5c69-e478-457d-9da8-cee0bfc44eb1 -DeviceGroupId:
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\igfxext.exe -Embedding
C:\windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --disable-3d-apis --disable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\THYMAL~1\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 6.1.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/537.36 CreativeCloud/3.9.0.327" --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --disable-gpu-compositing --channel="3176.1.374882311\216270459" /prefetch:673131151
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\windows\system32\wbem\wmiprvse.exe
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe17_ Global\UsGthrCtrlFltPipeMssGthrPipe17 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

"C:\windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Thymallus\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\HPCeeScheduleForTHYMALLUS-HP$.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForTHYMALLUS-HP$ (null)
C:\windows\tasks\HPCeeScheduleForThymallus.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForThymallus (null)

=========Mozilla firefox=========

ProfilePath - C:\Users\Thymallus\AppData\Roaming\Mozilla\Firefox\Profiles\9gvor96q.default-1441736287780

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF48
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF48


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.148 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\wacom.com/WacomTabletPlugin]
"Description"=
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.148 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\wacom.com/WacomTabletPlugin]
"Description"=
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-01 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-07 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-01 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21 186944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile Device Center"=C:\windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-01-27 418328]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-01-07 379040]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-01-07 615584]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-01-27 391704]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
"WheelMouse"=C:\Program Files\Mouse\Amoumain.exe [2008-03-07 237568]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-04-01 213824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"RocketDock"=C:\Program Files (x86)\RocketDock\RocketDock.exe [2007-09-02 495616]
"Svátky a výročí"=C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [2003-03-28 881664]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2012-04-02 1058912]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"HPQuickWebProxy"=c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-02-11 76344]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"Standard Mouse Driver"=C:\Program Files (x86)\Standard Mouse Driver\Monitor.exe [2013-03-05 147456]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-28 336384]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-10-12 2383040]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]

C:\Users\Thymallus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
AutorunsDisabled
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-01-27 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - C:\windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2017-04-15 22:55:33 ----D---- C:\rsit
2017-04-15 21:33:26 ----D---- C:\ProgramData\SWCUTemp
2017-04-12 19:40:15 ----SHD---- C:\Config.Msi
2017-04-12 19:31:24 ----A---- C:\windows\system32\mshtml.dll
2017-04-12 19:31:21 ----A---- C:\windows\SYSWOW64\mshtml.dll
2017-04-12 19:31:18 ----A---- C:\windows\system32\ieframe.dll
2017-04-12 19:31:16 ----A---- C:\windows\SYSWOW64\ieframe.dll
2017-04-12 19:31:15 ----A---- C:\windows\SYSWOW64\wininet.dll
2017-04-12 19:31:15 ----A---- C:\windows\SYSWOW64\jscript9.dll
2017-04-12 19:31:15 ----A---- C:\windows\system32\wininet.dll
2017-04-12 19:31:14 ----A---- C:\windows\system32\wuaueng.dll
2017-04-12 19:31:14 ----A---- C:\windows\system32\iertutil.dll
2017-04-12 19:31:13 ----A---- C:\windows\SYSWOW64\iertutil.dll
2017-04-12 19:31:13 ----A---- C:\windows\system32\ole32.dll
2017-04-12 19:31:11 ----A---- C:\windows\system32\win32k.sys
2017-04-12 19:31:11 ----A---- C:\windows\system32\urlmon.dll
2017-04-12 19:31:10 ----A---- C:\windows\SYSWOW64\urlmon.dll
2017-04-12 19:31:10 ----A---- C:\windows\system32\wucltux.dll
2017-04-12 19:31:09 ----A---- C:\windows\SYSWOW64\win32spl.dll
2017-04-12 19:31:09 ----A---- C:\windows\system32\wuapi.dll
2017-04-12 19:31:09 ----A---- C:\windows\system32\win32spl.dll
2017-04-12 19:31:09 ----A---- C:\windows\system32\ucrtbase.dll
2017-04-12 19:31:09 ----A---- C:\windows\system32\samsrv.dll
2017-04-12 19:31:09 ----A---- C:\windows\system32\quartz.dll
2017-04-12 19:31:08 ----A---- C:\windows\system32\msfeeds.dll
2017-04-12 19:31:08 ----A---- C:\windows\system32\cdosys.dll
2017-04-12 19:31:08 ----A---- C:\windows\system32\atmfd.dll
2017-04-12 19:31:07 ----A---- C:\windows\SYSWOW64\quartz.dll
2017-04-12 19:31:07 ----A---- C:\windows\SYSWOW64\ole32.dll
2017-04-12 19:31:07 ----A---- C:\windows\SYSWOW64\atmfd.dll
2017-04-12 19:31:07 ----A---- C:\windows\system32\gdi32.dll
2017-04-12 19:31:06 ----A---- C:\windows\SYSWOW64\wuapi.dll
2017-04-12 19:31:06 ----A---- C:\windows\SYSWOW64\gdi32.dll
2017-04-12 19:31:06 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\jscript.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\iedkcs32.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 19:31:05 ----A---- C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 19:31:04 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2017-04-12 19:31:04 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2017-04-12 19:31:03 ----A---- C:\windows\system32\ntoskrnl.exe
2017-04-12 19:31:03 ----A---- C:\windows\system32\ntdll.dll
2017-04-12 19:31:02 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2017-04-12 19:31:02 ----A---- C:\windows\system32\drivers\ksecdd.sys
2017-04-12 19:31:02 ----A---- C:\windows\system32\asycfilt.dll
2017-04-12 19:31:01 ----A---- C:\windows\SYSWOW64\asycfilt.dll
2017-04-12 19:31:01 ----A---- C:\windows\system32\samlib.dll
2017-04-12 19:31:01 ----A---- C:\windows\system32\jscript9.dll
2017-04-12 19:31:00 ----A---- C:\windows\SYSWOW64\webcheck.dll
2017-04-12 19:31:00 ----A---- C:\windows\SYSWOW64\ntdll.dll
2017-04-12 19:31:00 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2017-04-12 19:31:00 ----A---- C:\windows\SYSWOW64\mfmjpegdec.dll
2017-04-12 19:31:00 ----A---- C:\windows\SYSWOW64\cdosys.dll
2017-04-12 19:31:00 ----A---- C:\windows\system32\webcheck.dll
2017-04-12 19:31:00 ----A---- C:\windows\system32\mfmjpegdec.dll
2017-04-12 19:30:59 ----A---- C:\windows\SYSWOW64\samlib.dll
2017-04-12 19:30:59 ----A---- C:\windows\system32\rdpudd.dll
2017-04-12 19:30:59 ----A---- C:\windows\system32\certcli.dll
2017-04-12 19:30:58 ----A---- C:\windows\SYSWOW64\certcli.dll
2017-04-12 19:30:58 ----A---- C:\windows\system32\ie4uinit.exe
2017-04-12 19:30:57 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2017-04-12 19:30:57 ----A---- C:\windows\SYSWOW64\wups.dll
2017-04-12 19:30:57 ----A---- C:\windows\SYSWOW64\wudriver.dll
2017-04-12 19:30:57 ----A---- C:\windows\SYSWOW64\vbscript.dll
2017-04-12 19:30:57 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2017-04-12 19:30:57 ----A---- C:\windows\SYSWOW64\jscript.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\wuwebv.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\wups2.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\wups.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\wudriver.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\wuauclt.exe
2017-04-12 19:30:57 ----A---- C:\windows\system32\vbscript.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\srcore.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\rpcrt4.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\mshtmlmedia.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\lsasrv.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\ieui.dll
2017-04-12 19:30:57 ----A---- C:\windows\system32\ieapfltr.dll
2017-04-12 19:30:56 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\srclient.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\smss.exe
2017-04-12 19:30:56 ----A---- C:\windows\system32\msrating.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\mshtmled.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\kerberos.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\dxtrans.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\dxtmsft.dll
2017-04-12 19:30:56 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2017-04-12 19:30:56 ----A---- C:\windows\system32\advapi32.dll
2017-04-12 19:30:55 ----A---- C:\windows\SYSWOW64\sspicli.dll
2017-04-12 19:30:55 ----A---- C:\windows\SYSWOW64\srclient.dll
2017-04-12 19:30:55 ----A---- C:\windows\SYSWOW64\kerberos.dll
2017-04-12 19:30:55 ----A---- C:\windows\SYSWOW64\ieui.dll
2017-04-12 19:30:55 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2017-04-12 19:30:55 ----A---- C:\windows\SYSWOW64\advapi32.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\wow64win.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\winsrv.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\WinSetupUI.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\schannel.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\rstrui.exe
2017-04-12 19:30:55 ----A---- C:\windows\system32\occache.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\ncrypt.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\msv1_0.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2017-04-12 19:30:55 ----A---- C:\windows\system32\MshtmlDac.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\KernelBase.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\kernel32.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\jsproxy.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\jscript9diag.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\inseng.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\ieUnatt.exe
2017-04-12 19:30:55 ----A---- C:\windows\system32\ieetwproxystub.dll
2017-04-12 19:30:55 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2017-04-12 19:30:55 ----A---- C:\windows\system32\conhost.exe
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\occache.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\msrating.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2017-04-12 19:30:54 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2017-04-12 19:30:54 ----A---- C:\windows\system32\wuapp.exe
2017-04-12 19:30:54 ----A---- C:\windows\system32\wow64.dll
2017-04-12 19:30:54 ----A---- C:\windows\system32\wdigest.dll
2017-04-12 19:30:54 ----A---- C:\windows\system32\TSpkg.dll
2017-04-12 19:30:54 ----A---- C:\windows\system32\sspicli.dll
2017-04-12 19:30:54 ----A---- C:\windows\system32\iesetup.dll
2017-04-12 19:30:54 ----A---- C:\windows\system32\bcrypt.dll
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\wuapp.exe
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\wdigest.dll
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\schannel.dll
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\inseng.dll
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2017-04-12 19:30:53 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2017-04-12 19:30:53 ----A---- C:\windows\system32\rpchttp.dll
2017-04-12 19:30:53 ----A---- C:\windows\system32\iernonce.dll
2017-04-12 19:30:53 ----A---- C:\windows\system32\ieetwcollector.exe
2017-04-12 19:30:53 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2017-04-12 19:30:53 ----A---- C:\windows\system32\csrsrv.dll
2017-04-12 19:30:53 ----A---- C:\windows\system32\cdd.dll
2017-04-12 19:30:52 ----A---- C:\windows\system32\cryptbase.dll
2017-04-12 19:30:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-12 19:30:51 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\wow32.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\secur32.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\lpk.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\kernel32.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\iernonce.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\fontsub.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\dciman32.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\credssp.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\bcrypt.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\auditpol.exe
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\atmlib.dll
2017-04-12 19:30:51 ----A---- C:\windows\SYSWOW64\appidapi.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\wow64cpu.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\sspisrv.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\setbcdlocale.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\secur32.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\rdpcorets.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\ntvdm64.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\lsass.exe
2017-04-12 19:30:51 ----A---- C:\windows\system32\lpk.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\fontsub.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\drivers\appid.sys
2017-04-12 19:30:51 ----A---- C:\windows\system32\dciman32.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\credssp.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\auditpol.exe
2017-04-12 19:30:51 ----A---- C:\windows\system32\atmlib.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\appidsvc.dll
2017-04-12 19:30:51 ----A---- C:\windows\system32\appidpolicyconverter.exe
2017-04-12 19:30:51 ----A---- C:\windows\system32\appidcertstorecheck.exe
2017-04-12 19:30:51 ----A---- C:\windows\system32\appidapi.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 19:30:50 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-12 19:30:50 ----A---- C:\windows\SYSWOW64\user.exe
2017-04-12 19:30:50 ----A---- C:\windows\SYSWOW64\tzres.dll
2017-04-12 19:30:50 ----A---- C:\windows\SYSWOW64\setup16.exe
2017-04-12 19:30:50 ----A---- C:\windows\SYSWOW64\instnm.exe
2017-04-12 19:30:50 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2017-04-12 19:30:50 ----A---- C:\windows\system32\tzres.dll
2017-04-12 19:30:50 ----A---- C:\windows\system32\apisetschema.dll
2017-04-12 19:30:50 ----A---- C:\windows\system32\adtschema.dll
2017-04-12 19:30:49 ----A---- C:\windows\SYSWOW64\msobjs.dll
2017-04-12 19:30:49 ----A---- C:\windows\SYSWOW64\msaudite.dll
2017-04-12 19:30:49 ----A---- C:\windows\SYSWOW64\adtschema.dll
2017-04-12 19:30:49 ----A---- C:\windows\system32\msobjs.dll
2017-04-12 19:30:49 ----A---- C:\windows\system32\msaudite.dll
2017-04-12 19:30:49 ----A---- C:\windows\system32\ieetwcollectorres.dll
2017-04-12 19:30:48 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2017-04-01 20:07:20 ----A---- C:\windows\system32\aswBoot.exe
2017-03-20 00:48:06 ----A---- C:\windows\SYSWOW64\msvcr110_clr0400.dll
2017-03-20 00:48:06 ----A---- C:\windows\SYSWOW64\msvcr100_clr0400.dll
2017-03-20 00:48:06 ----A---- C:\windows\SYSWOW64\msvcp110_clr0400.dll
2017-03-20 00:48:06 ----A---- C:\windows\SYSWOW64\aspnet_counters.dll
2017-03-20 00:41:38 ----A---- C:\windows\system32\msvcr110_clr0400.dll
2017-03-20 00:41:38 ----A---- C:\windows\system32\msvcr100_clr0400.dll
2017-03-20 00:41:38 ----A---- C:\windows\system32\msvcp110_clr0400.dll
2017-03-20 00:41:38 ----A---- C:\windows\system32\aspnet_counters.dll
2017-03-16 19:04:24 ----RD---- C:\Program Files (x86)\Skype

======List of files/folders modified in the last 1 month======

2017-04-15 23:23:04 ----D---- C:\Program Files\trend micro
2017-04-15 23:21:32 ----D---- C:\windows\Temp
2017-04-15 22:41:23 ----D---- C:\windows\System32
2017-04-15 22:41:23 ----D---- C:\windows\inf
2017-04-15 22:41:23 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-04-15 22:33:15 ----D---- C:\windows\system32\config
2017-04-15 21:48:28 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2017-04-15 21:48:13 ----D---- C:\windows\system32\Macromed
2017-04-15 21:47:49 ----D---- C:\windows\SYSWOW64\Macromed
2017-04-15 21:40:14 ----D---- C:\windows\system32\drivers
2017-04-15 21:34:20 ----A---- C:\windows\SYSWOW64\log.txt
2017-04-15 21:33:26 ----D---- C:\ProgramData
2017-04-15 21:29:33 ----D---- C:\ProgramData\PDFC
2017-04-13 19:55:21 ----RSD---- C:\windows\Fonts
2017-04-12 23:21:11 ----D---- C:\windows\winsxs
2017-04-12 23:16:50 ----D---- C:\Program Files\Microsoft Silverlight
2017-04-12 23:16:46 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 23:09:52 ----D---- C:\Program Files\Internet Explorer
2017-04-12 23:09:48 ----D---- C:\windows\SYSWOW64\cs-CZ
2017-04-12 23:09:45 ----D---- C:\windows\SYSWOW64\en-US
2017-04-12 23:09:44 ----D---- C:\windows\SysWOW64
2017-04-12 23:09:26 ----D---- C:\windows\system32\cs-CZ
2017-04-12 23:09:22 ----D---- C:\windows\system32\en-US
2017-04-12 23:09:00 ----D---- C:\windows\AppPatch
2017-04-12 23:08:59 ----D---- C:\Program Files (x86)\Internet Explorer
2017-04-12 23:08:51 ----D---- C:\windows\system32\Boot
2017-04-12 20:47:54 ----SHD---- C:\windows\Installer
2017-04-12 20:46:57 ----D---- C:\ProgramData\Microsoft Help
2017-04-12 20:38:08 ----D---- C:\windows\Microsoft.NET
2017-04-12 20:14:50 ----D---- C:\windows\system32\MRT
2017-04-12 20:01:07 ----D---- C:\windows\debug
2017-04-12 19:59:59 ----AC---- C:\windows\system32\MRT.exe
2017-04-12 19:45:02 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2017-04-12 19:35:03 ----SHD---- C:\System Volume Information
2017-04-12 18:52:44 ----D---- C:\windows\system32\catroot2
2017-04-12 18:41:30 ----D---- C:\windows\system32\Tasks
2017-04-01 21:21:45 ----SD---- C:\Users\Thymallus\AppData\Roaming\Microsoft
2017-04-01 19:15:20 ----D---- C:\Program Files (x86)\TomTom HOME 2
2017-03-28 20:51:55 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-28 20:51:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-03-28 20:51:55 ----AD---- C:\Windows
2017-03-26 08:41:45 ----D---- C:\Users\Thymallus\AppData\Roaming\Audacity
2017-03-23 18:24:19 ----D---- C:\Users\Thymallus\AppData\Roaming\Skype
2017-03-22 22:13:11 ----D---- C:\windows\SoftwareDistribution
2017-03-21 19:55:31 ----D---- C:\ProgramData\tmp
2017-03-21 19:15:03 ----D---- C:\windows\Tasks
2017-03-16 19:04:25 ----D---- C:\Program Files (x86)\Common Files
2017-03-16 19:04:24 ----RD---- C:\Program Files (x86)
2017-03-16 19:04:15 ----D---- C:\ProgramData\Skype
2017-03-16 19:02:31 ----D---- C:\ProgramData\Package Cache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [2017-04-01 189768]
R0 aswblog;aswblog; C:\windows\system32\drivers\aswbloga.sys [2017-04-01 334088]
R0 aswbuniv;aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [2017-04-01 48528]
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2017-04-01 75704]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2017-04-01 339696]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2011-10-08 871408]
R1 Amfilter;Compatible Mouse Filter Driver; C:\windows\system32\DRIVERS\Amfltx64.sys [2007-10-15 12288]
R1 aswbidsdriver;aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [2017-04-01 307736]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2017-04-01 32600]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2017-04-01 101152]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2017-04-01 1005048]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2017-04-01 556784]
R2 aksdf;aksdf; C:\windows\system32\DRIVERS\aksdf.sys [2015-05-21 100504]
R2 aksfridge;aksfridge; \??\C:\windows\system32\drivers\aksfridge.sys [2015-05-21 170864]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2017-04-01 127112]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2017-04-01 164064]
R2 hardlock;hardlock; \??\C:\windows\system32\drivers\hardlock.sys [2015-05-21 340336]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-28 9319424]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-28 303616]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2011-01-07 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2011-01-07 298144]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2011-01-07 28832]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-07 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-07 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-07 154272]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2011-01-07 279200]
R3 bthathfax;Bluetooth Fax Modem; C:\windows\system32\DRIVERS\bthathfax.sys [2011-01-07 75424]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2015-03-30 33856]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-12-03 25912]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-01-27 12273408]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 pcouffin;VSO Software pcouffin; C:\windows\System32\Drivers\pcouffin.sys [2011-10-10 82816]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8169;Realtek 8169 NT Driver; C:\windows\system32\DRIVERS\Rtlh64.sys [2014-12-10 797400]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-10-30 549104]
S2 multikey;Virtual USB MultiKey; C:\windows\system32\DRIVERS\multikey.sys [2011-10-11 68608]
S3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 akshasp;SafeNet Inc. HASP Key; C:\windows\system32\DRIVERS\akshasp.sys [2015-05-21 69208]
S3 aksusb;SafeNet Inc. USB Key; C:\windows\system32\DRIVERS\aksusb.sys [2015-05-21 312344]
S3 Amusbprt;USB HID-compliant Mouse Driver; C:\windows\system32\DRIVERS\Amusbx64.sys [2008-02-13 17920]
S3 aswHwid;aswHwid; C:\windows\system32\drivers\aswHwid.sys [2017-04-01 38296]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2012-11-04 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2012-11-04 27760]
S3 hidkmdf;KMDF Driver; C:\windows\system32\DRIVERS\hidkmdf.sys [2015-04-28 14104]
S3 libusb0;LibUsb-Win32 - Kernel Driver 09/17/2010, 1.2.1.0; C:\windows\system32\DRIVERS\libusb0.sys [2010-11-06 42944]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\windows\system32\DRIVERS\s1018bus.sys [2009-03-25 113704]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\windows\system32\DRIVERS\s1018mdfl.sys [2009-03-25 19496]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\windows\system32\DRIVERS\s1018mdm.sys [2009-03-25 153128]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\windows\system32\DRIVERS\s1018mgmt.sys [2009-03-25 133160]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\windows\system32\DRIVERS\s1018nd5.sys [2009-03-25 34856]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\windows\system32\DRIVERS\s1018obex.sys [2009-03-25 128552]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\windows\system32\DRIVERS\s1018unic.sys [2009-03-25 146472]
S3 s115bus;Sony Ericsson Device 115 driver (WDM); C:\windows\system32\DRIVERS\s115bus.sys [2007-04-23 108296]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter; C:\windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 19720]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver; C:\windows\system32\DRIVERS\s115mdm.sys [2007-04-23 144648]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM); C:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 126216]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface; C:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 123656]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 Ser2pl;Prolific Serial port WDF driver; C:\windows\system32\DRIVERS\ser2pl64.sys [2013-02-22 160256]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\windows\system32\DRIVERS\sscebus.sys [2011-10-27 127488]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\windows\system32\DRIVERS\sscemdfl.sys [2011-10-27 18944]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\windows\system32\DRIVERS\sscemdm.sys [2011-10-27 161280]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 TPM;Čip TPM; C:\windows\system32\drivers\tpm.sys [2016-02-05 147904]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;Ovladač modemu USB; C:\windows\system32\drivers\usbser.sys [2013-08-29 33280]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-02-02 82640]
R2 AdobeUpdateService;AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-12 744640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2017-02-27 2227312]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-28 203264]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 53920]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-04-01 261712]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-20 105096]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-03-20 125064]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE [2012-02-27 151648]
R2 EpsonScanSvc;Epson Scanner Service; C:\windows\system32\EscSvc64.exe [2011-12-12 135824]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2015-03-30 2490216]
R2 hasplms;Sentinel HASP License Manager; C:\windows\system32\hasplms.exe [2009-12-16 3750400]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-03-30 417552]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2009-07-14 27136]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2017-03-17 99704]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-22 3154224]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-04-01 7398336]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-15 271448]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-03-20 51320]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-10-09 1030600]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-09-30 246520]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2017-03-25 114688]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-03-28 172488]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2015-06-10 155520]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-20 135800]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-20 135800]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-20 135800]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu - pomalejší noťas

#2 Příspěvek od Márty84 »

Zdravim :-)

:arrow: Stahnete crystal disk info http://www.slunecnice.cz/sw/crystaldiskinfo/
Nainstalujte (pozor na pripadne doplnky, ty odmitnete zrusenim zatrzitka) a spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Cleaning
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner[C?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#3 Příspěvek od gomik »

Tady je výstup z CrystalDiskInfo 7.0.5:

----------------------------------------------------------------------------
CrystalDiskInfo 7.0.5 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x64)
Date : 2017/04/18 18:51:42

-- Controller Map ----------------------------------------------------------
+ Intel(R) Mobile Express Chipset SATA AHCI Controller [ATA]
- Hitachi HTS547564A9E384
- hp DVD A DS8A5LH
+ A9RKUTZ7 IDE Controller [SCSI]
- GTGRAZ 81UJ41Q7K SCSI CdRom Device

-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS547564A9E384 : 640,1 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(1) Hitachi HTS547564A9E384
----------------------------------------------------------------------------
Model : Hitachi HTS547564A9E384
Firmware : JEDOA50A
Serial Number : J21B0053C6MVVS
Disk Size : 640,1 GB (8,4/137,4/640,1/640,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1250263728
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : ---- | SATA/300
Power On Hours : 5470 hod.
Power On Count : 2563 krát
Temperature : 34 C (93 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : ----
Drive Letter : C: E: F:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 _99 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 176 100 _33 001100000001 Čas na roztočení ploten
04 _99 _99 __0 000000000A0B Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _88 _88 __0 00000000155E Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _99 _99 __0 000000000A03 Počet cyklů zapnutí zařízení
B7 100 100 __0 000000000000 Specifický pro výrobce
B8 100 100 _97 000000000000 Ukončovacích chyb
BB 100 100 __0 0177223F0000 Ohlášeno neopravitelných chyb
BC 100 100 __0 0000000E0001 Časový limit příkazu
BE _66 _50 _45 000014220022 Teplota toku vzduchu
BF __3 __3 __0 00000000610D Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 0000001C001C Počet vypnutí disku
C1 100 100 __0 0000000019E6 Počet cyklů načítání/vymazání
C4 100 100 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 100 100 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2020 4A32 3142 3030 3533 4336 4D56 5653
020: 0003 4000 0004 4A45 444F 4135 3041 4869 7461 6368
030: 6920 4854 5335 3437 3536 3441 3945 3338 3420 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 0D06 0000 004C 004C
080: 01FC 0028 706B 7C09 6123 7069 BC09 6123 203F 004B
090: 004C 4080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 82B0 4A85 0000 0000 0000 0000 6003 826C 5000 CCA6
110: 3EC3 04CD 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 000B
130: 0000 0000 2182 1CF1 3A10 0000 4000 0400 0108 0000
140: 0000 0904 0A03 0A04 0C03 0000 0000 0000 0000 0000
150: 0000 0000 4448 4435 0000 2904 0000 5DAD 2518 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 101F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0080 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 4AA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 64 63 00 00 00 00 00 00 00 02 25
010: 00 64 64 00 00 00 00 00 00 00 03 23 00 B0 64 01
020: 00 00 00 11 00 00 04 32 00 63 63 0B 0A 00 00 00
030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 2F
040: 00 64 64 00 00 00 00 00 00 00 08 25 00 64 64 00
050: 00 00 00 00 00 00 09 32 00 58 58 5E 15 00 00 00
060: 00 00 0A 33 00 64 64 00 00 00 00 00 00 00 0C 32
070: 00 63 63 03 0A 00 00 00 00 00 B7 32 00 64 64 00
080: 00 00 00 00 00 00 B8 33 00 64 64 00 00 00 00 00
090: 00 00 BB 32 00 64 64 00 00 3F 22 77 01 00 BC 32
0A0: 00 64 64 01 00 0E 00 00 00 00 BE 22 00 42 32 22
0B0: 00 22 14 00 00 00 BF 32 00 03 03 0D 61 00 00 00
0C0: 00 00 C0 32 00 64 64 1C 00 1C 00 00 00 00 C1 32
0D0: 00 64 64 E6 19 00 00 00 00 00 C4 32 00 64 64 00
0E0: 00 00 00 00 00 00 C5 32 00 64 64 00 00 00 00 00
0F0: 00 00 C6 30 00 64 64 00 00 00 00 00 00 00 C7 36
100: 00 64 64 00 00 00 00 00 00 00 DF 2A 00 64 64 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 2D 00 01 51
170: 03 00 01 00 02 98 00 00 00 00 00 00 00 00 00 00
180: 00 00 16 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 CE

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 3E 00 00 00 00 00 00 00 00 00 00 02 28
010: 00 00 00 00 00 00 00 00 00 00 03 21 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 05 00 00 00 00 00 00 00 00 00 00 07 43
040: 00 00 00 00 00 00 00 00 00 00 08 28 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 3C 00 00 00 00 00 00 00 00 00 00 0C 00
070: 00 00 00 00 00 00 00 00 00 00 B7 00 00 00 00 00
080: 00 00 00 00 00 00 B8 61 00 00 00 00 00 00 00 00
090: 00 00 BB 00 00 00 00 00 00 00 00 00 00 00 BC 00
0A0: 00 00 00 00 00 00 00 00 00 00 BE 2D 00 00 00 00
0B0: 00 00 00 00 00 00 BF 00 00 00 00 00 00 00 00 00
0C0: 00 00 C0 00 00 00 00 00 00 00 00 00 00 00 C1 00
0D0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00
0E0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00
0F0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00
100: 00 00 00 00 00 00 00 00 00 00 DF 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#4 Příspěvek od gomik »

A tady je log z AdwCleaneru:

# AdwCleaner v6.045 - Log vytvořen 18/04/2017 v 19:03:22
# Aktualizováno dne 28/03/2017 z Malwarebytes
# Databáze : 2017-04-18.1 [Server]
# Operační systém : Windows 7 Home Premium Service Pack 1 (X64)
# Uživatelské jméno : Thymallus - THYMALLUS-HP
# Spuštěno z : C:\Users\Thymallus\Desktop\adwcleaner_6.045.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKU\S-1-5-21-2229627116-1106471772-112158516-1002\Software\Conduit
[#] Klíč smazán po restartu: HKCU\Software\Conduit
[#] Klíč smazán po restartu: [x64] HKCU\Software\Conduit


***** [ Prohlížeče ] *****

[-] Firefox předvolby vyčištěny: "browser.search.hiddenOneOffs" - "DuckDuckGo,Slunečnice"


*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1122 Bajty] - [18/04/2017 19:03:22]
C:\AdwCleaner\AdwCleaner[R0].txt - [2183 Bajty] - [15/03/2015 22:18:59]
C:\AdwCleaner\AdwCleaner[R1].txt - [2242 Bajty] - [15/03/2015 22:26:26]
C:\AdwCleaner\AdwCleaner[S0].txt - [2152 Bajty] - [15/03/2015 22:30:29]
C:\AdwCleaner\AdwCleaner[S1].txt - [1851 Bajty] - [18/04/2017 19:00:45]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1487 Bajty] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu - pomalejší noťas

#5 Příspěvek od Márty84 »

:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#6 Příspěvek od gomik »

jen se ozývám, že jsem to nevzdal. Včera večer, jak jsem přišel z práce jsem spustil dle návodu kontrolu disků MBAM a dnes ráno to ještě po deseti hodinách furt běží... akorát poslední dvě hodiny to kontroluje furt jeden soubor v C/users/thymallus/appdata/local/mozilla/firefox/.../entries... (viz příloha), tak snad se to nezaseklo a pofrčí to dál.
případně (až přijdu z práce a kdyby to furt prohledával ostejný soubor) mám to přerušit a spustit znovu?
Přílohy
DSC_5036++.jpg
DSC_5036++.jpg (111.67 KiB) Zobrazeno 5056 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu - pomalejší noťas

#7 Příspěvek od Márty84 »

Jestli to porad pobezi, vypnete to a zkuste dat jen Sken hrozeb.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#8 Příspěvek od gomik »

ano, seklo se to na tom souboru, ale asi to bude má vina, protože jak jsem to včera spustil, tak mi nějak spadl firefox...
pouštím to znova, do rána to určo bude :-)
(ať to mám proskenované pořádně)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu - pomalejší noťas

#9 Příspěvek od Márty84 »

OK :-)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#10 Příspěvek od gomik »

v příloze je log z MBAM
vše už proběhlo až do konce, po restartu PC

tak přílohu txt to nebere:

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 20.04.17
Čas skenování: 17:12
Logovací soubor: MBAM.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentů: 1.0.103
Aktualizovat verzi balíku komponent: 1.0.1769
Licence: Zkušební

-Systémová informace-
OS: Windows 7 Service Pack 1
CPU: x64
Systém souborů: NTFS
Uživatel: Thymallus-HP\Thymallus

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 578543
Uplynulý čas: 12 hod, 44 min, 2 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 6
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\diagnostics, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\PROGRAMS, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\DRIVERS, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\events, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\Logs, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\USERS\THYMALLUS\APPDATA\ROAMING\DRPSU, Žádná uživatelská akce, [2110], [358060],1.0.1769

Soubor: 8
PUP.Optional.DriverPack, C:\USERS\THYMALLUS\APPDATA\ROAMING\DRPSU\DIAGNOSTICS\HARDWARE.JSON, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\diagnostics\drivers.json, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\diagnostics\localdiagnostics.json, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\diagnostics\newsoft.json, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\diagnostics\soft.json, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.DriverPack, C:\Users\Thymallus\AppData\Roaming\DRPSu\Logs\log___2016-04-04-19-19-20.html, Žádná uživatelská akce, [2110], [358060],1.0.1769
PUP.Optional.SofTonic, C:\USERS\THYMALLUS\DOCUMENTS\ZBYTEK\FOTOGRAFOV\u00c3\u00a1N\u00c3\u00ad\KURZ LIGHTROOM SULASULA.COM\01_ZACNETE ZDE\B_KMPLAYER\SOFTONICDOWNLOADER_FOR_KMPLAYER.EXE, Žádná uživatelská akce, [3611], [77251],1.0.1769
HackTool.Patcher, C:\USERS\THYMALLUS\DOCUMENTS\EPLAN CRACK PRO W7X64\EPLAN_P8_V1.8_1.9_ALL_CRACK - POU\u00c5\u00beITO\CRACK CABINET1.8.RAR, Žádná uživatelská akce, [1963], [353136],1.0.1769

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu - pomalejší noťas

#11 Příspěvek od Márty84 »

Vsechny nalezy nechte odstranit. Po odstraneni a restartu pc test s MBAM zopakujte (staci uz jen Sken hrozeb), at vime, jestli se to nevraci. Napiste vysledek testu a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#12 Příspěvek od gomik »

projeto znova komplet vše 2x - protože když se vypne MBAM, tak po zapnutí jsem už nikde nenašel volbu odstranit dané položky, tak jsem to musel nechat projet a přesunout do karantény, vyp/zap PC a nové projetí
tady je výsledek:

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 23.04.17
Čas skenování: 16:23
Logovací soubor: MBAM1.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentů: 1.0.103
Aktualizovat verzi balíku komponent: 1.0.1792
Licence: Zkušební

-Systémová informace-
OS: Windows 7 Service Pack 1
CPU: x64
Systém souborů: NTFS
Uživatel: Thymallus-HP\Thymallus

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 573612
Uplynulý čas: 13 hod, 19 min, 2 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu logu - pomalejší noťas

#13 Příspěvek od Márty84 »

:arrow: MBAM odinstalujte.

:arrow: Dejte logy podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach :)
(Kdyby nesel Launcher stahnout, dejte logy jen ze samotneho FRST, tedy bez pouziti Launcheru)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#14 Příspěvek od gomik »

FRST.txt:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-04-2017 01
Ran by Thymallus (administrator) on THYMALLUS-HP (25-04-2017 18:02:42)
Running from C:\Users\Thymallus\Desktop
Loaded Profiles: Thymallus (Available Profiles: Thymallus)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files\Mouse\Amoumain.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Igor Gottwald - OKsoftware) C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(ArcSoft, Inc.) C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
() C:\Program Files (x86)\Standard Mouse Driver\Monitor.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(forum.viry.cz) C:\Users\Thymallus\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Windows Mobile Device Center] => C:\windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379040 2011-01-07] (Atheros Commnucations)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [615584 2011-01-07] (Atheros Communications)
HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2919992 2011-01-27] (Hewlett-Packard Company)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [WheelMouse] => C:\Program Files\Mouse\Amoumain.exe [237568 2008-03-07] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-04-01] (AVAST Software)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] => C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] ()
HKLM-x32\...\Run: [HPQuickWebProxy] => c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [76344 2011-02-11] (Hewlett-Packard Company)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [299576 2011-01-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Standard Mouse Driver] => C:\Program Files (x86)\Standard Mouse Driver\Monitor.exe [147456 2013-03-05] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\...\Run: [Svátky a výročí] => C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [881664 2003-03-28] (Igor Gottwald - OKsoftware)
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\PhotoScreensaver.scr [477696 2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-01] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-01] (AVAST Software)
ShellIconOverlayIdentifiers: [Správa překryvné ikony digitálních podpisů AutoCADu ] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2009-02-09] (Autodesk, Inc.)
Startup: C:\Users\Thymallus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2014-12-27] ()
Startup: C:\Users\Thymallus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk [2017-04-01]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3E896FF8-07AD-4AF1-8D57-8E60DA17A476}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2229627116-1106471772-112158516-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-22] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-01] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-22] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-22] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-01-07] (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-01] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-22] (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-2229627116-1106471772-112158516-1002 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File

FireFox:
========
FF ProfilePath: C:\Users\Thymallus\AppData\Roaming\TomTom\HOME\Profiles\azxo5ozt.default [2017-04-01]
FF ProfilePath: C:\Users\Thymallus\AppData\Roaming\Mozilla\Firefox\Profiles\9gvor96q.default-1441736287780 [2017-04-25]
FF Homepage: Mozilla\Firefox\Profiles\9gvor96q.default-1441736287780 -> hxxps://www.seznam.cz/
FF Session Restore: Mozilla\Firefox\Profiles\9gvor96q.default-1441736287780 -> is enabled.
FF Extension: (uBlock Origin) - C:\Users\Thymallus\AppData\Roaming\Mozilla\Firefox\Profiles\9gvor96q.default-1441736287780\Extensions\uBlock0@raymondhill.net.xpi [2017-04-17]
FF Extension: (FxIF) - C:\Users\Thymallus\AppData\Roaming\Mozilla\Firefox\Profiles\9gvor96q.default-1441736287780\Extensions\{11483926-db67-4190-91b1-ef20fcec5f33}.xpi [2015-09-08]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-04-01]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-04-01]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-15] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-22] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-12] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-15] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-12] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-12] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-04-01] (AVAST Software s.r.o.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-07] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [53920 2011-01-07] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-04-01] (AVAST Software)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
S3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1030600 2011-10-09] (Macrovision Europe Ltd.) [File not signed]
R2 hasplms; C:\windows\system32\hasplms.exe [3750400 2009-12-16] (SafeNet Inc.)
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-29] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2011-06-20] (Hewlett-Packard Company) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-03-30] (LogMeIn, Inc.)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1127448 2011-02-01] (PDF Complete Inc)
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [655552 2015-07-14] (Wacom Technology, Corp.)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 akshasp; C:\windows\System32\DRIVERS\akshasp.sys [69208 2015-05-21] (SafeNet Inc.)
S3 aksusb; C:\windows\System32\DRIVERS\aksusb.sys [312344 2015-05-21] (SafeNet Inc.)
R1 Amfilter; C:\windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))
S3 Amusbprt; C:\windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)
U5 AppMgmt; C:\windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 ARCVCAM; C:\windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
R1 aswbidsdriver; C:\windows\system32\drivers\aswbidsdrivera.sys [307736 2017-04-01] (AVAST Software s.r.o.)
R0 aswbidsh; C:\windows\system32\drivers\aswbidsha.sys [189768 2017-04-01] (AVAST Software s.r.o.)
R0 aswblog; C:\windows\system32\drivers\aswbloga.sys [334088 2017-04-01] (AVAST Software s.r.o.)
R0 aswbuniv; C:\windows\system32\drivers\aswbuniva.sys [48528 2017-04-01] (AVAST Software s.r.o.)
S3 aswHwid; C:\windows\system32\drivers\aswHwid.sys [38296 2017-04-01] (AVAST Software)
R1 aswKbd; C:\windows\system32\drivers\aswKbd.sys [32600 2017-04-01] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [127112 2017-04-01] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [101152 2017-04-01] (AVAST Software)
R0 aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [75704 2017-04-01] (AVAST Software)
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1005048 2017-04-01] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [556784 2017-04-01] (AVAST Software)
S2 aswStm; C:\windows\system32\drivers\aswStm.sys [164064 2017-04-01] (AVAST Software)
R0 aswVmm; C:\windows\system32\drivers\aswVmm.sys [339696 2017-04-01] (AVAST Software)
R3 bthathfax; C:\windows\System32\DRIVERS\bthathfax.sys [75424 2011-01-07] (Microsoft Corporation)
R2 hardlock; C:\windows\system32\drivers\hardlock.sys [340336 2015-05-21] (SafeNet Inc.)
S3 libusb0; C:\windows\System32\DRIVERS\libusb0.sys [42944 2010-11-06] (hxxp://libusb-win32.sourceforge.net)
S2 multikey; C:\windows\System32\DRIVERS\multikey.sys [68608 2011-10-11] (Chingachguk & Denger2k (Elite & SP edition))
S3 s1018bus; C:\windows\System32\DRIVERS\s1018bus.sys [113704 2009-03-25] (MCCI Corporation)
S3 s1018mdfl; C:\windows\System32\DRIVERS\s1018mdfl.sys [19496 2009-03-25] (MCCI Corporation)
S3 s1018mdm; C:\windows\System32\DRIVERS\s1018mdm.sys [153128 2009-03-25] (MCCI Corporation)
S3 s1018mgmt; C:\windows\System32\DRIVERS\s1018mgmt.sys [133160 2009-03-25] (MCCI Corporation)
S3 s1018nd5; C:\windows\System32\DRIVERS\s1018nd5.sys [34856 2009-03-25] (MCCI Corporation)
S3 s1018obex; C:\windows\System32\DRIVERS\s1018obex.sys [128552 2009-03-25] (MCCI Corporation)
S3 s1018unic; C:\windows\System32\DRIVERS\s1018unic.sys [146472 2009-03-25] (MCCI Corporation)
S3 s115bus; C:\windows\System32\DRIVERS\s115bus.sys [108296 2007-04-23] (MCCI Corporation)
S3 s115mdfl; C:\windows\System32\DRIVERS\s115mdfl.sys [19720 2007-04-23] (MCCI Corporation)
S3 s115mdm; C:\windows\System32\DRIVERS\s115mdm.sys [144648 2007-04-23] (MCCI Corporation)
S3 s115mgmt; C:\windows\System32\DRIVERS\s115mgmt.sys [126216 2007-04-23] (MCCI Corporation)
S3 s115obex; C:\windows\System32\DRIVERS\s115obex.sys [123656 2007-04-23] (MCCI Corporation)
R0 sptd; C:\windows\System32\Drivers\sptd.sys [871408 2011-10-08] () [File not signed]
R3 SPUVCbv; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2611704 2011-01-12] (Sunplus Technology)
S3 XHASP; c:\windows\SysWOW64\drivers\XHASP.sys [259584 2011-10-10] () [File not signed]
U3 ajriq3ns; C:\Windows\System32\Drivers\ajriq3ns.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-25 18:02 - 2017-04-25 18:03 - 00025886 _____ C:\Users\Thymallus\Desktop\FRST.txt
2017-04-25 17:52 - 2017-04-25 17:52 - 00000000 ____D C:\FRST
2017-04-25 17:51 - 2017-04-25 17:51 - 00112640 _____ (forum.viry.cz) C:\Users\Thymallus\Desktop\FRSTLauncher.exe
2017-04-25 17:48 - 2017-04-25 17:48 - 02426368 _____ (Farbar) C:\Users\Thymallus\Desktop\FRST64.exe
2017-04-25 17:41 - 2017-04-25 17:41 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-04-25 17:18 - 2017-04-25 17:46 - 00000000 ___HD C:\Users\Public\Documents\AdobeGC
2017-04-24 18:38 - 2017-04-24 18:38 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignb5badca04a2eaff2
2017-04-24 18:10 - 2017-04-24 18:10 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign7fb602f04a86dec2
2017-04-24 05:42 - 2017-04-24 05:42 - 00001492 _____ C:\Users\Thymallus\Desktop\MBAM1.txt
2017-04-23 12:12 - 2017-04-21 01:21 - 00091304 _____ (AVAST Software) C:\windows\system32\Drivers\aswHdsKe.sys
2017-04-22 10:33 - 2017-04-22 10:30 - 00110144 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-64.dll
2017-04-22 10:21 - 2017-04-22 10:22 - 00000000 ____D C:\Users\Thymallus\Desktop\000 REKLAMKA
2017-04-21 06:01 - 2017-04-21 06:01 - 00003513 _____ C:\Users\Thymallus\Desktop\MBAM.txt
2017-04-19 19:24 - 2017-04-19 19:24 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign3090a863ae4a4c37
2017-04-19 19:16 - 2017-04-19 19:16 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign72e971587318e393
2017-04-19 19:13 - 2017-04-19 19:13 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign837de2ce4707a035
2017-04-19 19:10 - 2017-04-19 19:12 - 60107896 _____ (Malwarebytes ) C:\Users\Thymallus\Downloads\mb3-setup-consumer-3.0.6.1469-10103.exe
2017-04-18 20:19 - 2017-04-18 20:19 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsigncf4e1dac09b34167
2017-04-18 20:19 - 2017-04-18 20:19 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign14ee1677ecfd9696
2017-04-18 20:04 - 2017-04-18 20:04 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsigne4bdf76b59b2e709
2017-04-18 20:02 - 2017-04-18 20:02 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsigne63f75577a3e1657
2017-04-18 19:40 - 2017-04-18 19:40 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign463307f2ff4132b8
2017-04-18 19:37 - 2017-04-18 19:37 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign550aa256d55cfbc5
2017-04-18 18:53 - 2017-04-18 18:53 - 04089296 _____ C:\Users\Thymallus\Desktop\adwcleaner_6.045.exe
2017-04-18 18:47 - 2017-04-18 18:50 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2017-04-18 18:47 - 2017-04-18 18:47 - 00001200 _____ C:\Users\Thymallus\Desktop\CrystalDiskInfo.lnk
2017-04-18 18:47 - 2017-04-18 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-04-17 17:50 - 2017-04-17 17:50 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign7af3f58c290c2490
2017-04-17 17:29 - 2017-04-17 17:29 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign82189b9d90e37d18
2017-04-15 23:21 - 2017-04-15 23:22 - 00001381 _____ C:\Users\Thymallus\Desktop\fotky do fotolabu.lnk
2017-04-15 23:11 - 2017-04-15 23:22 - 00001340 _____ C:\Users\Thymallus\Desktop\CANON eos40d.lnk
2017-04-15 23:09 - 2017-04-15 23:22 - 00001363 _____ C:\Users\Thymallus\Desktop\Untitled Export.lnk
2017-04-15 23:04 - 2017-04-15 23:06 - 00001939 _____ C:\Users\Thymallus\Desktop\PLOCHA.lnk
2017-04-15 23:03 - 2017-04-15 23:06 - 00001911 _____ C:\Users\Thymallus\Desktop\NakrmZvíře.lnk
2017-04-15 23:03 - 2017-04-15 23:06 - 00001858 _____ C:\Users\Thymallus\Desktop\Reico.lnk
2017-04-15 23:03 - 2017-04-15 23:06 - 00001109 _____ C:\Users\Thymallus\Desktop\Kasa FIK.lnk
2017-04-15 23:01 - 2017-04-17 21:40 - 00000000 ____D C:\Users\Thymallus\Documents\000 PLOCHA
2017-04-15 22:55 - 2017-04-15 22:56 - 00000000 ____D C:\rsit
2017-04-15 22:55 - 2017-04-15 22:55 - 01222144 _____ C:\Users\Thymallus\Downloads\RSITx64.exe
2017-04-15 22:27 - 2017-04-15 22:27 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign33495c2ac2466765
2017-04-15 22:26 - 2017-04-15 22:26 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign64262906852470bf
2017-04-14 14:53 - 2017-04-14 14:53 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign953ecbc93497f962
2017-04-14 14:52 - 2017-04-14 14:52 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign78b90554d769cc96
2017-04-13 20:33 - 2017-04-13 20:33 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignc23ccde79905b90e
2017-04-13 19:42 - 2017-04-13 19:42 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign718975f52b053d41
2017-04-13 19:41 - 2017-04-13 19:41 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsigne7b32ba9e948f985
2017-04-12 20:55 - 2017-04-12 20:55 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign5bb4e243972068fe
2017-04-12 20:49 - 2017-04-12 20:49 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign9c69ad52369a474b
2017-04-12 19:34 - 2017-04-12 19:34 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignfc6e295daf51e32b
2017-04-12 19:31 - 2017-03-27 20:13 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2017-04-12 19:31 - 2017-03-27 19:28 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2017-04-12 19:31 - 2017-03-25 21:39 - 20284416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2017-04-12 19:31 - 2017-03-25 21:07 - 04604416 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2017-04-12 19:31 - 2017-03-25 21:06 - 13654016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2017-04-12 19:31 - 2017-03-25 20:55 - 02767360 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2017-04-12 19:31 - 2017-03-25 20:52 - 02289152 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2017-04-12 19:31 - 2017-03-25 20:51 - 01313280 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2017-04-12 19:31 - 2017-03-25 20:47 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2017-04-12 19:31 - 2017-03-25 20:46 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2017-04-12 19:31 - 2017-03-25 20:46 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2017-04-12 19:31 - 2017-03-25 20:10 - 02898432 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2017-04-12 19:31 - 2017-03-25 19:56 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2017-04-12 19:31 - 2017-03-25 19:52 - 25746944 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2017-04-12 19:31 - 2017-03-25 19:41 - 06045696 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2017-04-12 19:31 - 2017-03-25 19:04 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2017-04-12 19:31 - 2017-03-25 18:59 - 00806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2017-04-12 19:31 - 2017-03-25 18:57 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2017-04-12 19:31 - 2017-03-25 18:28 - 15259136 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2017-04-12 19:31 - 2017-03-25 18:27 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2017-04-12 19:31 - 2017-03-25 18:24 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2017-04-12 19:31 - 2017-03-25 18:10 - 01546240 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2017-04-12 19:31 - 2017-03-25 00:50 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2017-04-12 19:31 - 2017-03-25 00:42 - 00313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2017-04-12 19:31 - 2017-03-22 17:32 - 03165184 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-04-12 19:31 - 2017-03-22 17:17 - 02651136 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-04-12 19:31 - 2017-03-22 17:15 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-04-12 19:31 - 2017-03-22 17:05 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2017-04-12 19:31 - 2017-03-14 17:34 - 00986344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2017-04-12 19:31 - 2017-03-14 17:34 - 00265448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2017-04-12 19:31 - 2017-03-10 18:35 - 00382696 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2017-04-12 19:31 - 2017-03-10 18:27 - 00308456 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2017-04-12 19:31 - 2017-03-10 18:00 - 03219968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2017-04-12 19:31 - 2017-03-08 22:20 - 01133568 _____ (Microsoft Corporation) C:\windows\system32\cdosys.dll
2017-04-12 19:31 - 2017-03-08 22:10 - 00805376 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdosys.dll
2017-04-12 19:31 - 2017-03-08 06:37 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2017-04-12 19:31 - 2017-03-08 06:36 - 05548264 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2017-04-12 19:31 - 2017-03-08 06:36 - 00706792 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2017-04-12 19:31 - 2017-03-08 06:36 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2017-04-12 19:31 - 2017-03-08 06:36 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2017-04-12 19:31 - 2017-03-08 06:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2017-04-12 19:31 - 2017-03-08 06:33 - 02064384 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2017-04-12 19:31 - 2017-03-08 06:26 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2017-04-12 19:31 - 2017-03-08 06:26 - 03945192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2017-04-12 19:31 - 2017-03-08 06:24 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2017-04-12 19:31 - 2017-03-08 06:22 - 01416192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2017-04-12 19:31 - 2017-03-07 18:30 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2017-04-12 19:31 - 2017-03-07 18:17 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2017-04-12 19:31 - 2017-03-04 03:27 - 01574912 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2017-04-12 19:31 - 2017-03-04 03:27 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\mfmjpegdec.dll
2017-04-12 19:31 - 2017-03-04 03:14 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2017-04-12 19:31 - 2017-03-04 03:14 - 00077312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmjpegdec.dll
2017-04-12 19:31 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2017-04-12 19:31 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2017-04-12 19:31 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\samsrv.dll
2017-04-12 19:31 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\windows\system32\samlib.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 19:31 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 19:30 - 2017-03-25 20:48 - 00499200 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2017-04-12 19:30 - 2017-03-25 20:47 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2017-04-12 19:30 - 2017-03-25 20:47 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2017-04-12 19:30 - 2017-03-25 20:46 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2017-04-12 19:30 - 2017-03-25 20:46 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2017-04-12 19:30 - 2017-03-25 20:46 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2017-04-12 19:30 - 2017-03-25 20:46 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2017-04-12 19:30 - 2017-03-25 20:46 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-12 19:30 - 2017-03-25 20:46 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2017-04-12 19:30 - 2017-03-25 20:45 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2017-04-12 19:30 - 2017-03-25 20:45 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2017-04-12 19:30 - 2017-03-25 20:45 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2017-04-12 19:30 - 2017-03-25 20:45 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2017-04-12 19:30 - 2017-03-25 20:45 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2017-04-12 19:30 - 2017-03-25 20:45 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2017-04-12 19:30 - 2017-03-25 20:45 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2017-04-12 19:30 - 2017-03-25 20:44 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2017-04-12 19:30 - 2017-03-25 20:44 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2017-04-12 19:30 - 2017-03-25 20:35 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2017-04-12 19:30 - 2017-03-25 20:35 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2017-04-12 19:30 - 2017-03-25 20:16 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2017-04-12 19:30 - 2017-03-25 20:14 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2017-04-12 19:30 - 2017-03-25 20:14 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2017-04-12 19:30 - 2017-03-25 20:13 - 00576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2017-04-12 19:30 - 2017-03-25 20:13 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2017-04-12 19:30 - 2017-03-25 20:04 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2017-04-12 19:30 - 2017-03-25 20:02 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2017-04-12 19:30 - 2017-03-25 19:57 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2017-04-12 19:30 - 2017-03-25 19:56 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2017-04-12 19:30 - 2017-03-25 19:56 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2017-04-12 19:30 - 2017-03-25 19:56 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2017-04-12 19:30 - 2017-03-25 19:45 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2017-04-12 19:30 - 2017-03-25 19:41 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2017-04-12 19:30 - 2017-03-25 19:30 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2017-04-12 19:30 - 2017-03-25 19:29 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2017-04-12 19:30 - 2017-03-25 19:24 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2017-04-12 19:30 - 2017-03-25 19:23 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2017-04-12 19:30 - 2017-03-25 19:20 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2017-04-12 19:30 - 2017-03-25 19:19 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2017-04-12 19:30 - 2017-03-25 19:17 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2017-04-12 19:30 - 2017-03-25 19:06 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2017-04-12 19:30 - 2017-03-25 19:00 - 00725504 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2017-04-12 19:30 - 2017-03-25 18:57 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2017-04-12 19:30 - 2017-03-25 18:01 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2017-04-12 19:30 - 2017-03-22 17:32 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-04-12 19:30 - 2017-03-22 17:32 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-04-12 19:30 - 2017-03-22 17:30 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2017-04-12 19:30 - 2017-03-22 17:24 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2017-04-12 19:30 - 2017-03-22 17:15 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-04-12 19:30 - 2017-03-22 17:15 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2017-04-12 19:30 - 2017-03-22 17:15 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-04-12 19:30 - 2017-03-22 17:15 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2017-04-12 19:30 - 2017-03-22 17:15 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2017-04-12 19:30 - 2017-03-22 17:05 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2017-04-12 19:30 - 2017-03-22 17:05 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2017-04-12 19:30 - 2017-03-22 17:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2017-04-12 19:30 - 2017-03-14 17:30 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\cdd.dll
2017-04-12 19:30 - 2017-03-10 18:31 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2017-04-12 19:30 - 2017-03-10 18:31 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2017-04-12 19:30 - 2017-03-10 18:31 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2017-04-12 19:30 - 2017-03-10 18:31 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2017-04-12 19:30 - 2017-03-10 18:20 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2017-04-12 19:30 - 2017-03-10 18:19 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2017-04-12 19:30 - 2017-03-10 18:19 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2017-04-12 19:30 - 2017-03-10 17:53 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2017-04-12 19:30 - 2017-03-08 06:22 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 06:03 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2017-04-12 19:30 - 2017-03-08 06:03 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2017-04-12 19:30 - 2017-03-08 06:03 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2017-04-12 19:30 - 2017-03-08 06:03 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2017-04-12 19:30 - 2017-03-08 06:00 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2017-04-12 19:30 - 2017-03-08 05:59 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2017-04-12 19:30 - 2017-03-08 05:57 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2017-04-12 19:30 - 2017-03-08 05:56 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2017-04-12 19:30 - 2017-03-08 05:56 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2017-04-12 19:30 - 2017-03-08 05:56 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2017-04-12 19:30 - 2017-03-08 05:55 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2017-04-12 19:30 - 2017-03-08 05:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2017-04-12 19:30 - 2017-03-08 05:54 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2017-04-12 19:30 - 2017-03-08 05:54 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2017-04-12 19:30 - 2017-03-08 05:54 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2017-04-12 19:30 - 2017-03-08 05:54 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2017-04-12 19:30 - 2017-03-08 05:53 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2017-04-12 19:30 - 2017-03-08 05:53 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 05:53 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 05:53 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 19:30 - 2017-03-08 05:53 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-12 19:30 - 2017-03-07 16:05 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2017-04-12 19:30 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2017-04-12 19:30 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2017-04-12 19:30 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\samlib.dll
2017-04-12 19:30 - 2016-03-24 00:40 - 03181568 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2017-04-12 19:30 - 2016-03-24 00:40 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2017-04-12 19:26 - 2017-04-12 19:26 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign364cbb3e9eec4bfa
2017-04-12 18:44 - 2017-04-12 18:44 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignc7fde8b066d9f65e
2017-04-12 18:36 - 2017-04-12 18:36 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignea313b7f27c01594
2017-04-03 17:51 - 2017-04-17 17:01 - 00000000 _____ C:\windows\SysWOW64\last.dump
2017-04-02 21:45 - 2017-04-02 21:45 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign22f5e3d37ef340a8
2017-04-02 21:42 - 2017-04-02 21:42 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign70413eef3c044d87
2017-04-02 10:43 - 2017-04-02 10:43 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignab919d3e114b1764
2017-04-02 10:42 - 2017-04-02 10:42 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignb8bf486c6952dabc
2017-04-02 10:15 - 2017-04-02 10:15 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsigndbd478d75eb55156
2017-04-02 09:28 - 2017-04-02 09:28 - 00003900 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1460749724
2017-04-01 21:21 - 2017-04-01 21:21 - 00000000 ____D C:\Users\Thymallus\Documents\Poznámkové bloky aplikace OneNote
2017-04-01 20:19 - 2017-04-01 20:19 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign933d587ccce635c1
2017-04-01 20:17 - 2017-04-01 20:17 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsigncc8a626efc70aef2
2017-04-01 20:07 - 2017-04-01 20:06 - 00399944 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2017-04-01 19:11 - 2017-04-01 19:11 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignbcb5720719209296
2017-04-01 19:10 - 2017-04-01 19:10 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignc225988e249baf14
2017-03-28 21:07 - 2017-03-28 21:07 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign383b621f99337d37
2017-03-28 21:04 - 2017-03-28 21:04 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignf9bae05862ffd974
2017-03-27 20:24 - 2017-03-27 20:24 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignc391e143e5338d5e
2017-03-27 20:21 - 2017-03-27 20:21 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign9339b7fd111ee17e
2017-03-26 19:43 - 2017-03-26 19:43 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsign152f75f19cdd2599
2017-03-26 19:28 - 2017-03-26 19:28 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Tempzxpsignc6306599ef8a8a01

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-25 17:54 - 2009-07-14 06:45 - 00023024 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-25 17:54 - 2009-07-14 06:45 - 00023024 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-25 17:45 - 2016-11-16 19:50 - 00000000 ____D C:\Users\Thymallus\AppData\LocalLow\Mozilla
2017-04-25 17:43 - 2011-05-10 22:10 - 00000000 ____D C:\ProgramData\PDFC
2017-04-25 17:40 - 2011-08-11 13:37 - 00000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2017-04-25 17:40 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-04-25 17:38 - 2014-01-02 21:02 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-04-25 17:36 - 2017-03-03 22:48 - 00004172 _____ C:\windows\System32\Tasks\Avast Emergency Update
2017-04-25 17:20 - 2015-04-07 21:12 - 00000000 ____D C:\Users\Thymallus\AppData\Local\LogMeIn Hamachi
2017-04-24 18:55 - 2011-05-10 22:12 - 00672408 _____ C:\windows\system32\perfh005.dat
2017-04-24 18:55 - 2011-05-10 22:12 - 00142972 _____ C:\windows\system32\perfc005.dat
2017-04-24 18:55 - 2009-07-14 07:13 - 01593302 _____ C:\windows\system32\PerfStringBackup.INI
2017-04-24 18:55 - 2009-07-14 05:20 - 00000000 ____D C:\windows\inf
2017-04-24 17:57 - 2011-10-11 11:03 - 00013030 _____ C:\PDOXUSRS.NET
2017-04-22 10:34 - 2013-09-19 19:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-04-22 10:34 - 2011-10-16 22:30 - 00000000 ____D C:\Program Files (x86)\Java
2017-04-22 10:33 - 2014-08-23 12:16 - 00000000 ____D C:\Program Files\Java
2017-04-22 10:30 - 2015-05-05 20:09 - 00110144 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2017-04-22 10:27 - 2016-01-24 14:12 - 00097856 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2017-04-22 07:24 - 2011-10-09 20:58 - 2048386048 _____ C:\Users\Thymallus\Documents\archive.pst
2017-04-21 20:55 - 2014-12-22 15:42 - 00003210 _____ C:\windows\System32\Tasks\HPCeeScheduleForThymallus
2017-04-21 20:55 - 2014-12-22 15:42 - 00000348 _____ C:\windows\Tasks\HPCeeScheduleForThymallus.job
2017-04-20 17:01 - 2016-11-16 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-04-20 17:01 - 2012-08-28 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-18 21:12 - 2011-10-08 09:11 - 00003226 _____ C:\windows\System32\Tasks\HPCeeScheduleForTHYMALLUS-HP$
2017-04-18 21:12 - 2011-10-08 09:11 - 00000350 _____ C:\windows\Tasks\HPCeeScheduleForTHYMALLUS-HP$.job
2017-04-18 20:00 - 2011-10-11 18:21 - 00000000 ____D C:\Users\Thymallus\AppData\Roaming\Skype
2017-04-18 19:03 - 2015-03-15 22:18 - 00000000 ____D C:\AdwCleaner
2017-04-18 19:03 - 2011-10-09 23:05 - 00000000 ____D C:\Users\Thymallus\AppData\Local\CrashDumps
2017-04-15 23:23 - 2011-10-27 22:33 - 00000000 ____D C:\Program Files\trend micro
2017-04-15 23:03 - 2011-10-08 12:32 - 00000000 ___SD C:\Users\Thymallus\Documents\Weby
2017-04-15 21:48 - 2017-02-26 17:14 - 00004396 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-04-15 21:48 - 2012-04-04 19:36 - 00802904 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-04-15 21:48 - 2011-10-09 00:57 - 00144472 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-04-15 21:48 - 2011-10-08 12:50 - 00000000 ____D C:\windows\system32\Macromed
2017-04-15 21:47 - 2011-05-10 22:11 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-04-14 13:52 - 2009-07-14 06:45 - 05112112 _____ C:\windows\system32\FNTCACHE.DAT
2017-04-14 13:50 - 2011-10-08 10:18 - 00142648 _____ C:\Users\Thymallus\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-12 23:16 - 2012-08-30 19:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-12 23:16 - 2012-08-30 19:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 20:28 - 2012-08-30 20:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-04-12 20:14 - 2013-07-22 21:36 - 00000000 ____D C:\windows\system32\MRT
2017-04-12 19:59 - 2011-10-09 08:43 - 148601744 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2017-04-12 19:45 - 2011-05-10 21:40 - 01568952 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2017-04-12 18:41 - 2015-05-17 21:06 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-12 18:39 - 2016-10-13 16:31 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-04-02 12:49 - 2011-10-08 10:20 - 00000000 ____D C:\Users\Thymallus\Documents\Bluetooth Folder
2017-04-01 20:06 - 2016-04-14 21:03 - 00032600 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2017-04-01 20:06 - 2014-04-18 18:15 - 00038296 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2017-04-01 20:06 - 2013-12-25 19:29 - 00164064 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2017-04-01 20:06 - 2013-03-02 18:42 - 00339696 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2017-04-01 20:06 - 2013-03-02 18:42 - 00075704 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2017-04-01 20:06 - 2012-02-24 17:29 - 00101152 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2017-04-01 20:06 - 2011-10-08 10:45 - 01005048 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2017-04-01 20:06 - 2011-10-08 10:45 - 00556784 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2017-04-01 20:06 - 2011-10-08 10:45 - 00127112 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2017-04-01 20:05 - 2017-03-03 22:48 - 00334088 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbloga.sys
2017-04-01 20:05 - 2017-03-03 22:48 - 00307736 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsdrivera.sys
2017-04-01 20:05 - 2017-03-03 22:48 - 00189768 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbidsha.sys
2017-04-01 20:05 - 2017-03-03 22:48 - 00048528 _____ (AVAST Software s.r.o.) C:\windows\system32\Drivers\aswbuniva.sys
2017-04-01 19:15 - 2017-03-19 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2017-04-01 19:15 - 2013-05-01 20:42 - 00000000 ____D C:\Program Files (x86)\TomTom HOME 2
2017-04-01 19:12 - 2011-10-08 20:37 - 00000000 ____D C:\Users\Thymallus\AppData\Local\Downloaded Installations
2017-03-26 08:41 - 2011-10-09 23:29 - 00000000 ____D C:\Users\Thymallus\AppData\Roaming\Audacity

==================== Files in the root of some directories =======

2013-09-03 19:37 - 2013-12-22 19:28 - 0000132 _____ () C:\Users\Thymallus\AppData\Roaming\Adobe Formát GIF CS6 – předvolby
2012-03-07 19:17 - 2013-06-14 21:15 - 0000132 _____ () C:\Users\Thymallus\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
2013-08-12 13:32 - 2016-10-30 21:58 - 0000132 _____ () C:\Users\Thymallus\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2011-12-31 18:43 - 2011-12-31 18:43 - 0038435 _____ () C:\Users\Thymallus\AppData\Roaming\Hodnoty oddělené čárkami (DOS).ADR
2011-12-31 18:42 - 2011-12-31 18:42 - 0038428 _____ () C:\Users\Thymallus\AppData\Roaming\Microsoft Excel 97-2003.ADR
2011-10-10 18:04 - 2011-10-10 18:04 - 0007859 _____ () C:\Users\Thymallus\AppData\Roaming\pcouffin.cat
2011-10-10 18:04 - 2011-10-10 18:04 - 0001167 _____ () C:\Users\Thymallus\AppData\Roaming\pcouffin.inf
2011-10-10 18:05 - 2011-10-10 18:05 - 0000034 _____ () C:\Users\Thymallus\AppData\Roaming\pcouffin.log
2011-10-10 18:04 - 2011-10-10 18:04 - 0082816 _____ (VSO Software) C:\Users\Thymallus\AppData\Roaming\pcouffin.sys
2013-09-03 19:52 - 2015-02-13 21:31 - 0001480 _____ () C:\Users\Thymallus\AppData\Local\Adobe Uložit pro web 13.0 Prefs
2011-10-14 10:11 - 2017-02-12 11:58 - 0027136 _____ () C:\Users\Thymallus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-15 19:53 - 2014-01-15 19:53 - 0004096 ____H () C:\Users\Thymallus\AppData\Local\keyfile3.drm
2015-03-11 19:05 - 2016-04-04 19:01 - 0007594 _____ () C:\Users\Thymallus\AppData\Local\Resmon.ResmonCfg
2012-06-01 21:29 - 2012-06-02 09:39 - 0000254 _____ () C:\Users\Thymallus\AppData\Local\SRDownloader.err
2012-06-01 21:29 - 2012-12-24 20:17 - 0000992 _____ () C:\Users\Thymallus\AppData\Local\SRDownloader.nast
2011-12-30 20:35 - 2011-12-30 20:35 - 0000041 ___SH () C:\ProgramData\.zreglib

Some files in TEMP:
====================
2017-04-22 10:22 - 2017-04-22 10:22 - 0739904 _____ (Oracle Corporation) C:\Users\Thymallus\AppData\Local\Temp\jre-8u131-windows-au.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\HPCeeScheduleForTHYMALLUS-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForThymallus.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Thymallus\Desktop" je 394 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001


==================== End Of Log ==============================

Uživatelský avatar
gomik
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 04 lis 2010 19:50
Bydliště: Fýdlant n./O.

Re: Prosím o kontrolu logu - pomalejší noťas

#15 Příspěvek od gomik »

Addition.txt:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-04-2017 01
Ran by Thymallus (25-04-2017 18:03:29)
Running from C:\Users\Thymallus\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2011-10-08 07:11:27)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2229627116-1106471772-112158516-500 - Administrator - Disabled)
Guest (S-1-5-21-2229627116-1106471772-112158516-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2229627116-1106471772-112158516-1003 - Limited - Enabled)
Thymallus (S-1-5-21-2229627116-1106471772-112158516-1002 - Administrator - Enabled) => C:\Users\Thymallus

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

2X-iOfficeWorks 7.80 (HKLM\...\WheelMouse) (Version: - )
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
ACDSee Photo Manager 2009 (HKLM-x32\...\{300578F9-9EFF-4B93-9AB1-C0E5707EF463}) (Version: 11.0.85 - ACD Systems International)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 25.0.0.134 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.0.327 - Adobe Systems Incorporated)
Adobe Flash Player 16 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.7 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_0) (Version: 18.0.0 - Adobe Systems Incorporated)
Adresy CR v2 (HKLM-x32\...\{7A11431C-3B45-4932-9D83-2F4A609C18F3}) (Version: 1.00 - Picodas Praha, spol. s r.o.)
AdriaROUTE 3.30 NT (HKLM-x32\...\{828A3BA6-B5AB-4B03-AC13-443BE0C64C17}) (Version: 3.30 - Navigo Sistem d.o.o.)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
ArcSoft TotalMedia (HKLM-x32\...\ArcSoft TotalMedia) (Version: 2.0.39.12 - ArcSoft)
ArcSoft TotalMedia (x32 Version: 1.0.48.25 - ArcSoft) Hidden
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.30 - ArcSoft)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
ATI Catalyst Install Manager (HKLM\...\{63E42DE7-C468-31B0-E373-173C67C87B88}) (Version: 3.0.820.0 - ATI Technologies, Inc.)
ATLAS Czech 2013 NT (HKLM-x32\...\{7FE84B67-1C14-42E1-8749-101A0B0B7B34}) (Version: 12.00 - PICODAS PRAHA, spol. s r.o.)
Audacity 1.3.12 (Unicode) (HKLM-x32\...\Audacity 1.3 Beta (Unicode)_is1) (Version: - Audacity Team)
Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version: - Audacity Team)
AutoCAD 2010 - česky (HKLM\...\AutoCAD 2010 - česky) (Version: 18.0.55.0 - Autodesk)
AutoCAD 2010 - česky (Version: 18.0.55.0 - Autodesk) Hidden
Autodesk Design Review 2010 (HKLM-x32\...\Autodesk Design Review 2010) (Version: 10.0.0.108 - Autodesk, Inc.)
Autodesk Design Review 2010 (x32 Version: 10.0.0.108 - Autodesk, Inc.) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.3.2291 - AVAST Software)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.02.000.55 - Atheros Communications)
Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.56.1043 - Webteh, d.o.o.)
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\RAW Image Task) (Version: 2.7.0.3 - )
Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.14.40.0 - Canon Inc.)
Canon Utilities EOS Utility 2 (HKLM-x32\...\EOS Utility 2) (Version: 2.14.10.2 - Canon Inc.)
CanoScan Toolbox Ver4.9 (HKLM-x32\...\{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}) (Version: - )
Centrum zařízení Windows Mobile (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Crystal Button 2.8 (HKLM-x32\...\Crystal Button_is1) (Version: - Crystal Button Software)
CrystalDiskInfo 7.0.5 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.5 - Crystal Dew World)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dungeon Siege 2 (HKLM-x32\...\DungeonSiege2) (Version: - Microsoft)
DVDFab 6.2.0.5 (11/11/2009) (HKLM-x32\...\DVDFab 6_is1) (Version: - Fengtao Software Inc.)
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
EOSInfo (HKLM-x32\...\{CC23FF9A-989C-4DEB-8970-50E6E4862315}) (Version: 0.2.0 - astrojargon.net)
EPLAN Electric P8 1.9.10 (HKLM-x32\...\{E101823F-C3DE-4B43-9EB3-D36DEE6FCAA3}) (Version: 1.9.10.3725 - EPLAN Software & Service)
EPLAN License Client (HKLM-x32\...\{0100BD88-3990-431F-9175-AB60E31AFFDE}) (Version: 9.1.4.55800 - EPLAN Software & Service)
Epson Event Manager (HKLM-x32\...\{C9AC7ED6-FD1C-4E83-8553-ECF8BCA111E8}) (Version: 3.01.0007 - Seiko Epson Corporation)
EPSON L210 Series Printer Uninstall (HKLM\...\EPSON L210 Series) (Version: - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
Epson Uživatelská příručka L210 Series (HKLM-x32\...\L210 Series Useg) (Version: - )
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
FFmpeg v0.6.2 for Audacity (HKLM-x32\...\FFmpeg for Audacity_is1) (Version: - )
Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Fotolab Fotosvet (HKLM-x32\...\Fotolab Fotosvet) (Version: 6.1.5 - CEWE Stiftung u Co. KGaA)
Garmin City Navigator Europe NTU 2015.10 (HKLM-x32\...\{FB96D8EF-1EC6-4548-A65C-9485261262CC}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries)
Garmin MapSource (HKLM-x32\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
GPSBabel 1.4.4 (HKLM-x32\...\{1B8FE958-A304-4902-BF7A-4E2F0F5B7017}_is1) (Version: - GPSBabel)
HP 3D DriveGuard (HKLM\...\{83DA38AB-1014-41C2-A3CD-E2B93832A71A}) (Version: 4.1.4.1 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\...\{4B21E4B2-89B8-499D-803A-34ABF929401E}) (Version: 4.1.10.1 - Hewlett-Packard Company)
HP DayStarter (HKLM\...\{483D5A49-A26B-4CB8-AA2D-0D1811322061}) (Version: 2.0.0.12 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{6A9C9BE1-14A3-42ED-A388-42E30A1412E9}) (Version: 1.2.0.0 - Hewlett-Packard)
HP ESU for Microsoft Windows 7 (HKLM-x32\...\{CFC1988A-F492-4BC5-B6F7-683A95718AE9}) (Version: 1.1.11.1 - Hewlett-Packard Company)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
HP HD Webcam [Fixed] (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.3.4.07 - SunplusIT)
HP HotKey Support (HKLM\...\{7D1C63D1-6520-49DA-B738-958133526E80}) (Version: 4.0.10.1 - Hewlett-Packard Company)
HP Power Assistant (HKLM\...\{3D8EDF72-13CC-4E51-AAB6-32A20524D2E0}) (Version: 2.0.2.0 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{20976B1F-E910-404D-9261-C16EE7E12DC8}) (Version: 3.0.0.9057 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{344A1AA2-AC8E-4741-BDB0-65B68FDA883C}) (Version: 3.2.0.0 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{B7F60A16-7A7B-41FB-9AE3-DE9E324FBA06}) (Version: 4.0.112.1 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{531000B3-DBEE-4115-BBF3-DA48B67C053F}) (Version: 8.2.1.1 - Hewlett-Packard Company)
HP System Default Settings (HKLM-x32\...\{54C65FE7-83BD-4A5B-A9B4-41F793C5F241}) (Version: 2.1.2 - Hewlett-Packard Company)
HP Wallpaper (HKLM-x32\...\{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}) (Version: 2.00 - Hewlett-Packard Company)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6325.0 - IDT)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jazykový balíček aplikace AutoCAD 2010 - čeština (Version: 18.0.55.0 - Autodesk) Hidden
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.57.2 - JMicron Technology Corp.)
K-Lite Codec Pack 5.3.0 (64-bit) (HKLM\...\KLiteCodecPack64_is1) (Version: 5.3.0 - )
LADSPA_plugins-win-0.4.15 (HKLM-x32\...\LADSPA_plugins-win_is1) (Version: - Audacity Team)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
LightScribe System Software (HKLM-x32\...\{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}) (Version: 1.18.24.1 - LightScribe)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.328 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.328 - LogMeIn, Inc.) Hidden
MapReverseConverter 4.5 (HKLM-x32\...\{C38FFB73-2587-4697-BB64-F0D9E7393A0E}_is1) (Version: 4.5 - JaVaWa GPS-tools)
Microsoft .NET Framework 4.6.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office FrontPage 2003 (HKLM-x32\...\{90170405-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
Mozilla Firefox 53.0 (x86 cs) (HKLM-x32\...\Mozilla Firefox 53.0 (x86 cs)) (Version: 53.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 53.0.0.6312 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger)
Mystery P.I. - The London Caper (x32 Version: 2.2.0.95 - WildTangent) Hidden
Parrot Software Update Tool (HKLM-x32\...\Parrot Flash Update Wizard) (Version: - )
PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.33 - PDF Complete, Inc)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.0 - pdfforge)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.208.0 - Tracker Software Products Ltd)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Photomatix Pro version 4.2 (HKLM\...\PhotomatixPro42x64_is1) (Version: 4.2 - HDRsoft Sarl)
PIXELA AAC LC CODEC (HKLM-x32\...\PIXELA AAC LC CODEC) (Version: 1.1.0.1 - Canon Inc.)
PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: - )
PL-2303 Vista Driver Installer (HKLM-x32\...\{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}) (Version: 3.0.1.0 - Prolific)
Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.16.2.15545 - Sony Computer Entertainment Inc.)
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
rajče průvodce verze 1.59.38.253 (HKLM-x32\...\rajče.net_is1) (Version: - rajče.net)
ReadManiac 2.6 beta 13 (HKLM-x32\...\ReadManiac_is1) (Version: - Roman Lut)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0016 - Realtek)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.4.8.0 - SAMSUNG Electronics Co., Ltd.)
SDK (x32 Version: 2.24.025 - Portrait Displays, Inc.) Hidden
Sentinel HASP Run-time (HKLM-x32\...\{2A414CBE-CDF3-48C6-A91B-D3D4522F8EB5}) (Version: 5.0.1.14210 - SafeNet Inc.)
SIM MAX (HKLM-x32\...\{DAC0B889-5359-4FDC-893A-2B8EF6B71B6F}) (Version: 1.00.0000 - SIM MAX)
Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.)
Slovakia TOPO 3 STANDARD (HKLM-x32\...\{62A6DF1A-7FDA-4ADA-B7B1-0CE883662858}) (Version: 1.00 - CONAN s.r.o.)
Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.14.2.201402071544 - Sony Mobile Communications AB)
Sony PC Companion 2.10.303 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.303 - Sony)
Standard Mouse Driver (HKLM-x32\...\{6C4453CD-123A-40FB-8227-E23AF8748C5A}) (Version: - )
Svátky a výročí (HKLM-x32\...\{95B36346-D52C-440C-BC34-48276BE9F90B}) (Version: 2.03.0109 - Igor Gottwald - OKsoftware)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.18.8 - Synaptics Incorporated)
TomTom HOME (HKLM-x32\...\{30E6FC43-C31F-4968-9A06-AA38E3C3CF73}) (Version: 2.10.1 - Název společnosti:)
TomTom HOME (HKLM-x32\...\{C62E4A07-973C-4257-B034-F4F10F1124C3}) (Version: 2.10.1 - Název společnosti:)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
TOPO Czech PRO 2013 (HKLM-x32\...\{1278ABFC-E3E6-434B-A302-BB0E4949B87D}) (Version: 7.00 - PICODAS PRAHA, spol. s r.o.)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: - )
Ukraina_v_4.09_roads (HKLM-x32\...\{A1AFC49F-670A-4C28-B2E5-252F0CD219A1}) (Version: 4.09 - MPC Licensee)
Ukraine_Rel V.3.03 (HKLM-x32\...\{47165C96-FAF4-4170-953E-806A84EDD40E}) (Version: 3.03 - MPC Licensee)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Validity Fingerprint Sensor Driver (HKLM\...\{FFC3E41D-2C2B-45B7-9AD9-5EA19572DD26}) (Version: 4.3.117.0 - Validity Sensors, Inc.)
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
Vltava2000 FTP klient (HKLM-x32\...\ST6UNST #1) (Version: - )
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.13-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Winamp (remove only) (HKLM-x32\...\Winamp) (Version: - )
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WMV9/VC-1 Video Playback (Version: 1.00.0000 - ATI Technologies Inc.) Hidden
World Cup Cricket 20-20 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Xobni (HKLM-x32\...\XobniMain) (Version: 1.9.5.13282 - Xobni Corp.)
Xobni Core (x32 Version: 1.0.0 - Xobni, Inc.) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2229627116-1106471772-112158516-1002_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\AutoCAD 2010\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2229627116-1106471772-112158516-1002_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\AutoCAD 2010\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2229627116-1106471772-112158516-1002_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\AutoCAD 2010\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2229627116-1106471772-112158516-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {006ECD79-282B-4CAB-8600-0C41C6BAE9A1} - System32\Tasks\{C3505556-7328-4962-936F-077F87D9168C} => pcalua.exe -a Q:\PROGRAMY\NEW\install_flash_player.exe -d Q:\PROGRAMY\NEW
Task: {171F569D-BAD6-4FE5-8477-290510BC6A09} - System32\Tasks\HPCeeScheduleForThymallus => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {25EE5022-D725-4B41-A21F-3B4A2347E7E0} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software)
Task: {29CFBEC9-0D5A-4982-8560-9E64D38DC51B} - System32\Tasks\{DD57C5B1-2F68-493B-B2B9-43183C6A715C} => pcalua.exe -a Q:\PROGRAMY\OLD\Chaos&Fractal\uf304.exe -d Q:\PROGRAMY\OLD\Chaos&Fractal
Task: {2C3A93F6-E95C-4282-B5EC-01850E3A4C52} - System32\Tasks\HPCeeScheduleForTHYMALLUS-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {76F88FC5-BF41-43F1-855A-7962181A1A5C} - System32\Tasks\{6B9408BC-8080-4808-A40D-EB2E8DEF9004} => pcalua.exe -a "Q:\PROGRAMY\NEW\Myš a4tech\Vista X64 X6-80D driver\Setup.exe" -d "Q:\PROGRAMY\NEW\Myš a4tech\Vista X64 X6-80D driver"
Task: {7B5F99EC-B04C-4DAD-A812-69531FD7535F} - System32\Tasks\{EF7646F1-7FAA-479E-B1E1-0CAFD3712210} => pcalua.exe -a C:\Users\Thymallus\AppData\Local\Temp\Data\MapSource\MapSource_6163.exe -d C:\Users\Thymallus\AppData\Local\Temp\ <==== ATTENTION
Task: {7F33418F-8DB2-4585-92DC-A35D4F2248D4} - System32\Tasks\{462F37D2-5CF6-409E-8293-AE87426D43FC} => Q:\PROGRAMY\OLD\Adobe photoshop CS5 CZ\Set-up.exe
Task: {926596EE-0EA6-4535-A2C5-643ACB13C42F} - System32\Tasks\{67F060C3-CA91-4006-8D5E-3CAA782CF6A3} => pcalua.exe -a C:\Users\Thymallus\Desktop\silicon-power_Win98_driver\Setup.exe -d C:\Users\Thymallus\Desktop\silicon-power_Win98_driver
Task: {940DA38C-ECCE-4DD5-8EBC-51B46820990A} - System32\Tasks\{C09E72AE-E5FB-459D-A489-779F383D9B46} => pcalua.exe -a "Q:\PROGRAMY\NEW\SEUD-ovladace K750i.exe" -d Q:\PROGRAMY\NEW
Task: {958F600A-9673-41F1-800E-BAA72965B9C6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated)
Task: {98090092-E706-49C9-B564-8F77003EA164} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-04-01] (AVAST Software)
Task: {9B8BCD17-B7D7-4F00-948D-19B7E1C84C82} - System32\Tasks\SafeZone scheduled Autoupdate 1460749724 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-03-22] (Avast Software)
Task: {A69E81BB-EF66-4F6D-A096-21073D99C096} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-15] (Adobe Systems Incorporated)
Task: {A6D1C0B1-DCC7-42F5-A7B6-CD8A729E2431} - System32\Tasks\elbyExecuteWithUAC => C:\Program Files (x86)\SlySoft\CloneCD\ExecuteWithUAC.exe
Task: {AF359EE1-212C-4E3F-9B2C-D41AF421A056} - System32\Tasks\{E702BDF0-D85D-4B08-8119-1F1E29B5BAE1} => pcalua.exe -a "Q:\PROGRAMY\OLD\myš\a4tech - aktuální\Setup.exe" -d "Q:\PROGRAMY\OLD\myš\a4tech - aktuální"
Task: {DC4964DD-9D0C-47DE-AEDD-61988F71F3F0} - System32\Tasks\{F76B67E8-43C5-40CC-97C3-1D9713718C1A} => pcalua.exe -a "Q:\DOKUMENTY\Fotografování\Adobe Photoshop 10 CS3\Adobe photoshop Vyukovy kurz\Duležite\TSCC.exe" -d "Q:\DOKUMENTY\Fotografování\Adobe Photoshop 10 CS3\Adobe photoshop Vyukovy kurz\Duležite"
Task: {EEE2A094-E7C8-4491-9D23-1CDA40803296} - System32\Tasks\{9D54E6BE-F00B-4DE7-BFCF-0AF52BCD2099} => pcalua.exe -a "C:\Users\Thymallus\Desktop\SIM reader\CM106\Setup.exe" -d "C:\Users\Thymallus\Desktop\SIM reader\CM106"

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\HPCeeScheduleForTHYMALLUS-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForThymallus.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Zamčeno