Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola Notebooku

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Kontrola Notebooku

#1 Příspěvek od nobody »

Dobrý den,

prosím o kontrolu notebooku. Potřebuju si stáhnout na pevný disk důležité soubory ze školy, ale nechci to přetáhnout s nějakým virem. Nedávno jsem nějaký asi stáhla a potřebovala bych zjistit jestli je vše ok.

Mockrát děkuji :)


Logfile of random's system information tool 1.10 (written by random/random)
Run by Ludmila at 2017-11-16 11:20:10
Microsoft Windows 8.1
System drive C: has 37 GB (30%) free of 121 GB
Total RAM: 12211 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:20:14, on 16. 11. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18817)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\Ludmila.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com/?pc=ACJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = https://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto2bL_V27kBru9MY2V1evwpcLaiY-8Q3bn9WJflnmTT4tDDZ0_MdeEe8o4HgnxcaOe-VJ7dXrKUZNjlhethJ9-wvXmQfH9UUmZ51wn4ovwDclMqAwck1SCaG5o-fe_gdwCVNSGs7QjPBIi9rfugZWLwI198l7o&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto2bL_V27kBru9MY2V1evwpcLaiY-8Q3bn9WJflnmTT4tDDZ0_MdeEe8o4HgnxcaOe-VJ7dXrKUZNjlhethJ9-wvXmQfH9UUmZ51wn4ovwDclMqAwck1SCaG5o-fe_gdwCVNSGs7QjPBIi9rfugZWLwI198l7o&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto2bL_V27kBru9MY2V1evwpcLaiY-8Q3bn9WJflnmTT4tDDZ0_MdeEe8o4HgnxcaOe-VJ7dXrKUZNjlhethJ9-wvXmQfH9UUmZ51wn4ovwDclMqAwck1SCaG5o-fe_gdwCVNSGs7QjPBIi9rfugZWLwI198l7o&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto2bL_V27kBru9MY2V1evwpcLaiY-8Q3bn9WJflnmTT4tDDZ0_MdeEe8o4HgnxcaOSvslQyiWAYCrkwIoShiP4uN0uk2ojjgNQZq4dZ1trLL5qv8pZY1ROKWA5V9WyDTdyxymjWgfzuRWdT2SLSr9nHYzdoNbY
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = https://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto2bL_V27kBru9MY2V1evwpcLaiY-8Q3bn9WJflnmTT4tDDZ0_MdeEe8o4HgnxcaOe-VJ7dXrKUZNjlhethJ9-wvXmQfH9UUmZ51wn4ovwDclMqAwck1SCaG5o-fe_gdwCVNSGs7QjPBIi9rfugZWLwI198l7o&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: YoutubeAdBlock - {C0D38E5A-7CF8-4105-8FE8-31B81443A114} - C:\Program Files (x86)\ZfJRwqLPhIE\kgBrHZDL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SafeQClient] C:\Program Files (x86)\SafeQ\SafeQ_cli.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user')
O4 - Global Startup: CodeMeter Control Center.lnk = C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
O4 - Global Startup: Network Server.lnk = C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Qualcomm Atheros - C:\Program Files (x86)\Qualcomm Atheros\Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer\Bluetooth Suite\adminservice.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: Background Logic Handler (backlh) - Unknown owner - C:\ProgramData\Logic Cramble\set.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) - WIBU-SYSTEMS AG - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel® ME Service (Intel(R) ME Service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: PDFsam Manager - ANDREA VACONDIO - C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe
O23 - Service: Windows Service Host (py007) - Unknown owner - C:\ProgramData\py007\lib.exe
O23 - Service: Quick Access Service (QASvc) - Acer Incorporate - C:\Program Files\Acer\Acer Quick Access\QASvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Quick Access RadioMgr Service (RMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: User Experience Improvement Program (UEIPSvc) - acer - C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Wisaroc - Remak - C:\WINDOWS\Wisaroc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15800 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\WLANExt.exe 774093254608
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\ProgramData\Logic Cramble\set.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {c8a4fec3-abe0-4aa6-9279c45553f097a0}
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
"C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
"C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe"
"C:\ProgramData\py007\lib.exe"
"C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Acer\Acer Quick Access\QASvc.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
"C:\Program Files\Acer\Acer Quick Access\RMSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
taskeng.exe {E6843975-680F-4757-A5D4-608375785C47}
"C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe"
"C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe" -r "C:\Users\Ludmila\AppData\Local\AOP SDK\Acer Infra\acer\SyncAgent" -u S-1-5-21-3497575666-2220848565-2583033622-1001 -c 448 -s 541 -g "C:\ProgramData\acer\CCD"
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
taskhostex.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%dSPUser.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\SPUser" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
C:\WINDOWS\Explorer.EXE
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Launch Manager\LMTray.exe"
"C:\Program Files\Acer\Acer Quick Access\QAEvent.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Quick Access\QAMsg.exe"
"C:\Program Files\Dolby Digital Plus\ddp.exe" -autostart
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Windows Defender\\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 32B58F2F-1B02-C734-B351-888684D5A6AB -Reinvoke
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
"C:\Windows\system32\igfxext.exe" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
"C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe"
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --disable-gpu-compositing --no-sandbox --service-pipe-token=D372B65C3C99E8CE36BBA5011BEE87EC --lang=en-US --lang=en-US --log-file="C:\Users\Ludmila\AppData\Local\NVIDIA Corporation\NVIDIA Share\CefCache\debug.log" --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --disable-accelerated-video-decode --disable-gpu-compositing --service-request-channel-token=D372B65C3C99E8CE36BBA5011BEE87EC --renderer-client-id=2 --mojo-platform-channel-handle=1672 /prefetch:1
"C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe" task
"C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe" task
"C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe" task
"C:\Program Files (x86)\Acer\Care Center\ACCStd.exe"
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 60
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 69
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\Ludmila\Desktop\Program-4.docx
C:\WINDOWS\splwow64.exe 8192
"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 61
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" %SNF%
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 62

"D:\Ludmilka\Škola\programy\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Online Application V2G1.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 69
C:\WINDOWS\tasks\Online Application V2G2.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 70
C:\WINDOWS\tasks\Online Application V2G3.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 71
C:\WINDOWS\tasks\Online Application V2G4.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 60
C:\WINDOWS\tasks\Online Application V2G5.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 61
C:\WINDOWS\tasks\Online Application V2G6.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 62
C:\WINDOWS\tasks\PjDfytumxbayONn.job - rundll32 "C:\Program Files (x86)\kqEuPYMaU\pHPQue.dll",#1
C:\WINDOWS\tasks\Updater_Online_Application.job - C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe /silentall -nofreqcheck

=========Mozilla firefox=========

ProfilePath - C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873

prefs.js - "browser.startup.homepage" - "https://www.google.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 27.0.0.187 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 27.0.0.187 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\searchplugins\
google-lavasoft.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23 217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]
YoutubeAdBlock - C:\Program Files (x86)\ZfJRwqLPhIE\tQcuIsC3Y.dll [2017-11-09 646144]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23 184488]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-24 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24 343456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]
YoutubeAdBlock - C:\Program Files (x86)\ZfJRwqLPhIE\kgBrHZDL.dll [2017-11-09 535040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-24 186944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24 343456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23 6149288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24 343456]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23 4452504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-05-26 13672152]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-05-13 1387376]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"SERVICE"= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2017-05-19 9773272]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SafeQClient"=C:\Program Files (x86)\SafeQ\SafeQ_cli.exe [2014-08-22 493056]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-06-22 598552]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2015-09-24 41360]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2015-09-24 840592]
"CanonQuickMenu"=C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [2012-04-03 1273448]
"IJNetworkScannerSelectorEX"=C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2012-03-26 449168]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
CodeMeter Control Center.lnk - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2017-11-13 18:07:52 ----D---- C:\ProgramData\Apple
2017-11-13 18:07:29 ----SHDC---- C:\Config.Msi
2017-11-09 20:04:19 ----D---- C:\Program Files (x86)\JIdcnntTvnKU2
2017-11-09 20:04:17 ----D---- C:\Program Files (x86)\zTWnHlzwjSUn
2017-11-09 20:04:14 ----D---- C:\Program Files (x86)\ZfJRwqLPhIE
2017-11-09 20:04:12 ----D---- C:\Program Files (x86)\kqEuPYMaU
2017-11-09 20:04:00 ----D---- C:\ProgramData\Microleaves
2017-11-09 20:03:26 ----D---- C:\ProgramData\py007
2017-11-09 20:03:06 ----A---- C:\ProgramData\lib.exe
2017-11-09 20:03:02 ----D---- C:\ProgramData\Logic Cramble
2017-11-09 20:03:00 ----D---- C:\ProgramData\Quoteexs
2017-11-09 20:01:54 ----D---- C:\Program Files (x86)\Microleaves
2017-11-09 20:01:50 ----D---- C:\Users\Ludmila\AppData\Roaming\Microleaves
2017-11-09 20:01:39 ----DC---- C:\WinSys
2017-11-09 20:01:38 ----DC---- C:\Applications
2017-11-09 20:01:33 ----DC---- C:\Windat
2017-11-09 20:01:33 ----DC---- C:\Disk
2017-11-09 10:04:37 ----A---- C:\WINDOWS\Wisaroc.exe
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\zlib.dll
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\vbar332.dll
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\ODBCTL32.DLL
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\ODBC32GT.DLL
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\ODBC16GT.DLL
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\MSVBVM50.DLL
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\msrpjt40.dll
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\msrecr40.dll
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\DS32GT.DLL
2017-11-09 10:04:32 ----A---- C:\WINDOWS\SYSWOW64\DS16GT.DLL
2017-11-09 10:04:25 ----DC---- C:\AeroCAD
2017-11-09 00:00:27 ----DC---- C:\ATREA
2017-11-09 00:00:27 ----D---- C:\ProgramData\ATREA
2017-11-09 00:00:27 ----D---- C:\Program Files (x86)\ATREA
2017-11-08 15:03:51 ----A---- C:\WINDOWS\SYSWOW64\WkExt32.dll
2017-11-08 15:03:51 ----A---- C:\WINDOWS\SYSWOW64\wibuKJni.dll
2017-11-08 15:03:51 ----A---- C:\WINDOWS\system32\WkExt64.dll
2017-11-08 15:03:51 ----A---- C:\WINDOWS\system32\wibuKJni64.dll
2017-11-08 15:03:49 ----A---- C:\WINDOWS\system32\drivers\Wibukey2_64.sys
2017-11-08 15:03:48 ----A---- C:\WINDOWS\SYSWOW64\WkWin32.dll
2017-11-08 15:03:48 ----A---- C:\WINDOWS\system32\WkWin64.dll
2017-11-08 15:03:48 ----A---- C:\WINDOWS\system32\drivers\WibuKey64.sys
2017-11-08 15:03:45 ----D---- C:\Program Files (x86)\WIBU-SYSTEMS
2017-11-08 15:03:45 ----D---- C:\Program Files (x86)\WIBUKEY
2017-11-08 15:02:03 ----D---- C:\ProgramData\ARCHICAD
2017-10-30 13:41:53 ----D---- C:\Program Files\WIBU-SYSTEMS
2017-10-30 13:41:50 ----D---- C:\ProgramData\CodeMeter
2017-10-30 13:41:50 ----D---- C:\Program Files\CodeMeter
2017-10-30 13:41:50 ----D---- C:\Program Files (x86)\CodeMeter
2017-10-30 10:57:27 ----D---- C:\Program Files (x86)\VulkanRT
2017-10-30 10:57:27 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2017-10-30 10:57:27 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2017-10-30 10:57:27 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2017-10-30 10:57:27 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nvshext.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nvmctray.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nvcpl.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2017-10-30 10:57:25 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2017-10-30 10:57:18 ----A---- C:\WINDOWS\NvContainerRecovery.bat
2017-10-30 10:55:49 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2017-10-30 10:55:49 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvopencl.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvinitx.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvdispgenco6438800.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvdispco6438800.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvcuda.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\nvapi64.dll
2017-10-30 10:55:48 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2017-10-30 10:42:57 ----A---- C:\WINDOWS\system32\drivers\nvvad64v.sys

======List of files/folders modified in the last 1 month======

2017-11-16 11:20:12 ----D---- C:\Program Files\trend micro
2017-11-16 11:03:04 ----D---- C:\WINDOWS\Prefetch
2017-11-16 11:00:00 ----D---- C:\WINDOWS\system32\sru
2017-11-16 10:52:01 ----RD---- C:\WINDOWS\System32
2017-11-16 10:52:01 ----D---- C:\WINDOWS\Inf
2017-11-16 10:52:01 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-16 06:27:08 ----D---- C:\ProgramData\NVIDIA
2017-11-16 06:25:52 ----D---- C:\WINDOWS\Temp
2017-11-16 06:25:43 ----D---- C:\Users\Ludmila\AppData\Roaming\Mozilla
2017-11-16 06:25:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-11-16 06:25:41 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-11-15 23:56:35 ----D---- C:\Users\Ludmila\AppData\Roaming\vlc
2017-11-15 16:31:45 ----D---- C:\WINDOWS\system32\config
2017-11-15 16:31:03 ----SHD---- C:\WINDOWS\Installer
2017-11-15 16:31:02 ----D---- C:\WINDOWS\system32\Tasks
2017-11-15 16:30:49 ----D---- C:\WINDOWS\SysWOW64
2017-11-15 16:29:23 ----D---- C:\WINDOWS\CbsTemp
2017-11-15 16:29:15 ----D---- C:\WINDOWS\system32\catroot2
2017-11-15 16:29:03 ----D---- C:\WINDOWS\WinSxS
2017-11-15 16:25:05 ----D---- C:\WINDOWS
2017-11-15 09:38:41 ----D---- C:\WINDOWS\Microsoft.NET
2017-11-14 22:43:06 ----D---- C:\ProgramData\Microsoft Help
2017-11-14 19:33:51 ----D---- C:\WINDOWS\debug
2017-11-14 18:26:07 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-11-14 18:26:07 ----D---- C:\WINDOWS\system32\Macromed
2017-11-14 16:36:11 ----D---- C:\WINDOWS\SoftwareDistribution
2017-11-13 21:27:12 ----RD---- C:\Program Files
2017-11-13 21:23:40 ----SHD---- C:\System Volume Information
2017-11-13 21:23:27 ----D---- C:\Program Files (x86)
2017-11-13 18:10:08 ----HD---- C:\ProgramData
2017-11-13 18:06:47 ----D---- C:\Program Files (x86)\Acer
2017-11-13 18:06:25 ----RSD---- C:\WINDOWS\assembly
2017-11-13 18:06:25 ----HD---- C:\OEM
2017-11-10 05:17:57 ----D---- C:\WINDOWS\system32\wdi
2017-11-09 20:04:12 ----D---- C:\WINDOWS\Tasks
2017-11-09 20:03:59 ----D---- C:\Program Files (x86)\Common Files
2017-11-09 20:01:12 ----D---- C:\WINDOWS\system32\drivers
2017-11-09 19:47:24 ----D---- C:\Program Files\GRAPHISOFT
2017-11-09 19:47:22 ----D---- C:\Users\Ludmila\AppData\Roaming\Graphisoft
2017-11-09 19:37:12 ----D---- C:\Users\Ludmila\AppData\Roaming\MAXON
2017-11-08 15:03:51 ----D---- C:\WINDOWS\system32\DriverStore
2017-11-08 15:03:25 ----D---- C:\Users\Ludmila\AppData\Roaming\Install.GS
2017-10-30 13:53:06 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-10-30 13:27:12 ----D---- C:\Users\Ludmila\AppData\Roaming\Abvent_Artlantis5
2017-10-30 13:26:50 ----D---- C:\Program Files\Artlantis Studio 5
2017-10-30 10:57:28 ----D---- C:\Program Files\NVIDIA Corporation
2017-10-30 10:57:24 ----D---- C:\WINDOWS\Help
2017-10-30 10:57:13 ----D---- C:\ProgramData\NVIDIA Corporation
2017-10-30 10:35:52 ----D---- C:\ProgramData\Package Cache
2017-10-25 21:42:52 ----D---- C:\ProgramData\CanonIJPLM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R1 MpKsl23a7d51d;MpKsl23a7d51d; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{205B05EA-6C09-4A85-9A82-679FB43C4433}\MpKsl23a7d51d.sys [2017-11-15 58120]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R1 wfcre;wfcre; C:\WINDOWS\system32\drivers\wfcre.sys [2017-07-04 124288]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey64.sys [2016-12-22 118200]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-08-26 47720]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-06-16 3793408]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-06-03 3986392]
R3 iwdbus;@oem4.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-05-06 27032]
R3 LMDriver;@oem14.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys [2013-07-18 21360]
R3 MEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-02-20 116736]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2017-10-12 16750528]
R3 nvvad_WaveExtensible;@oem47.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2017-10-11 50624]
R3 nvvhci;@oem43.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2017-01-20 57792]
R3 Qcamain;@oem7.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\Qcamainx64.sys [2014-08-26 2220544]
R3 RadioShim;@oem14.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys [2013-07-18 14680]
R3 RTL8168;@oem6.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2014-05-08 871640]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2017-07-06 119296]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-05-11 1201664]
S3 dg_ssudbus;@oem39.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 intaud_WaveExtensible;@oem3.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2014-05-06 38296]
S3 IntcDAud;@oem1.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2014-06-16 450520]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-10-11 30144]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBVSTOR;@oem12.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2014-03-27 331992]
S3 ssudmdm;@oem17.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-10-29 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2016-02-24 1145928]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-09-27 83984]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer\Bluetooth Suite\adminservice.exe [2014-08-22 305664]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2014-02-07 31192]
R2 backlh;Background Logic Handler; C:\ProgramData\Logic Cramble\set.exe [2017-08-17 3780096]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2017-09-26 2278688]
R2 CodeMeter.exe;CodeMeter Runtime Server; C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2017-02-21 4817896]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-06-16 315352]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2012-03-28 140456]
R2 Intel(R) ME Service;Intel® ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2014-02-20 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-02-20 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-02-20 398296]
R2 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2014-12-30 455912]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11 518080]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-10-12 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-10-11 460736]
R2 PDFsam Manager;PDFsam Manager; C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe [2015-11-13 1050224]
R2 py007;Windows Service Host; C:\ProgramData\py007\lib.exe [2017-11-09 10697216]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2012-04-24 254512]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2014-07-22 2573032]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
R3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-09-12 185048]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 QASvc;Quick Access Service; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [2014-10-17 458984]
R3 RMSvc;Quick Access RadioMgr Service; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [2014-10-17 449768]
R3 UEIPSvc;User Experience Improvement Program; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [2014-06-24 233216]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-14 272384]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-06-16 279000]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2016-02-29 1357104]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-02-01 887232]
S3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12 177376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-11-16 194000]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11 518080]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#2 Příspěvek od Márty84 »

Zdravim :)

Broucci tam stale jsou :boxed:

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Cleaning
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner[C?].txt ). Ten mi sem zkopirujte.

:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Re: Kontrola Notebooku

#3 Příspěvek od nobody »

# AdwCleaner 7.0.4.0 - Logfile created on Thu Nov 16 23:18:15 2017
# Updated on 2017/27/10 by Malwarebytes
# Running on Windows 8.1 (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

Deleted: backlh
Deleted: py007


***** [ Folders ] *****

Deleted: C:\Users\Public\Pokki
Deleted: C:\Users\Ludmila\AppData\Local\AdvinstAnalytics
Deleted: C:\Users\Public\Documents\XMUpdate
Deleted: C:\ProgramData\Logic Cramble
Deleted: C:\ProgramData\Logic Cramble
Deleted: C:\Program Files\Booking.com
Deleted: C:\Program Files (x86)\zTWnHlzwjSUn
Deleted: C:\Windows\System32\config\systemprofile\AppData\Local\LavasoftTcpService
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\LavasoftTcpService
Deleted: C:\ProgramData\Microleaves
Deleted: C:\Program Files (x86)\Microleaves
Deleted: C:\Users\Ludmila\AppData\Roaming\Microleaves
Deleted: C:\ProgramData\py007
Deleted: C:\Program Files (x86)\kqEuPYMaU
Deleted: C:\Program Files (x86)\ZfJRwqLPhIE
Deleted: C:\Program Files (x86)\JIdcnntTvnKU2
Deleted: C:\ProgramData\Quoteexs
Deleted: C:\\Users\Public\Documents\XMUpdate


***** [ Files ] *****

Deleted: C:\Users\Ludmila\AppData\Local\Main.dat
Deleted: C:\Windows\System32\lavasofttcpservice.dll
Deleted: C:\Windows\SysWOW64\lavasofttcpservice.dll
Deleted: C:\Windows\System32\LavasoftTcpServiceOff.ini
Deleted: C:\Windows\SysNative\LavasoftTcpServiceOff.ini
Deleted: C:\Windows\SysWOW64\LavasoftTcpServiceOff.ini
Deleted: C:\Windows\SysNative\LavasoftTcpService64.dll
Deleted: C:\Windows\System32\config\systemprofile\appdata\local\installationconfiguration.xml
Deleted: C:\Users\Ludmila\appdata\local\installationconfiguration.xml
Deleted: C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\searchplugins\google-lavasoft.xml
Deleted: C:\Windows\SysNative\drivers\wfcre.sys
Deleted: C:\Windows\System32\config\systemprofile\AppData\Local\PO.DB
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PO.DB
Deleted: C:\Users\Ludmila\AppData\Local\PO.DB
Deleted: C:\ProgramData\\lib.exe
Deleted: C:\Windows\System32\findit.xml
Deleted: C:\Windows\SysWOW64\findit.xml


***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

Cleaned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk[%SNF%]
Cleaned: C:\Users\Ludmila\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk[%SNF%]
Cleaned: C:\Users\Public\Desktop\Mozilla Firefox.lnk[%SNF%]


***** [ Tasks ] *****

Deleted: Online Application V2G1
Deleted: Online Application V2G3
Deleted: Online Application V2G2
Deleted: LaCieS
Deleted: ShadowsocksS
Deleted: snf
Deleted: snp
Deleted: zjwPaeaadZaNwF
Deleted: PjDfytumxbayONn2
Deleted: PjDfytumxbayONn
Deleted: Updater_Online_Application
Deleted: Updater_Online_Application
Deleted: psv_Fasenix
Deleted: psv_Istex
Deleted: psv_KayDinlex
Deleted: psv_SubLax


***** [ Registry ] *****

Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope
Deleted: [Key] - HKLM\SOFTWARE\Lavasoft\Web Companion
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{7BCA6879-A9F8-47DE-AE05-F5CE7EA3A474}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{ADF1FA2A-6EAA-4A97-A55F-3C8B92843EF5}
Deleted: [Value] - HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\OverlayIcon.DLL
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{2CE0F1DC-C504-4B7B-A385-D94A2531DFFB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\LavasoftTcpService.exe
Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe
Deleted: [Key] - HKLM\SOFTWARE\Microleaves
Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quoteex.exe
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [6431 B] - [2017/11/16 23:17:47]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########




Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 17.11.17
Čas skenování: 0:29
Logovací soubor: f95c5ade-cb25-11e7-b0fa-3065ec69064b.json
Správce: Ano

-Informace o softwaru-
Verze: 3.3.1.2183
Verze komponentů: 1.0.236
Aktualizovat verzi balíku komponent: 1.0.3276
Licence: Zkušební

-Systémová informace-
OS: Windows 8.1
CPU: x64
Systém souborů: NTFS
Uživatel: LUDMILKA\Ludmila

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 592248
Zjištěné hrozby: 203
Hrozby umístěné do karantény: 0
(Nebyly zjištěny žádné škodlivé položky)
Uplynulý čas: 1 hod, 56 min, 32 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 10
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{19B90926-91BD-4407-AE91-BF6695289FFE}, Žádná uživatelská akce, [558], [317311],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9CEC90D6-E6C4-41B6-91BC-330192E9DC16}, Žádná uživatelská akce, [558], [317311],1.0.3276
PUP.Optional.ChinAd, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wfcre, Žádná uživatelská akce, [94], [417525],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F8FF4B66-C47F-46B2-ADFE-B6669A286672}, Žádná uživatelská akce, [558], [317311],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G4, Žádná uživatelská akce, [558], [317313],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G5, Žádná uživatelská akce, [558], [317313],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G6, Žádná uživatelská akce, [558], [317313],1.0.3276
Adware.NeoBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}, Žádná uživatelská akce, [525], [420739],1.0.3276
Adware.NeoBar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}, Žádná uživatelská akce, [525], [420739],1.0.3276
Adware.NeoBar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}, Žádná uživatelská akce, [525], [420739],1.0.3276

Hodnota v registru: 6
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Žádná uživatelská akce, [234], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Žádná uživatelská akce, [234], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, Žádná uživatelská akce, [234], [259988],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{19B90926-91BD-4407-AE91-BF6695289FFE}|PATH, Žádná uživatelská akce, [558], [317311],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9CEC90D6-E6C4-41B6-91BC-330192E9DC16}|PATH, Žádná uživatelská akce, [558], [317311],1.0.3276
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F8FF4B66-C47F-46B2-ADFE-B6669A286672}|PATH, Žádná uživatelská akce, [558], [317311],1.0.3276

Data registrů: 5
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|DEFAULT_SEARCH_URL, Žádná uživatelská akce, [234], [293486],1.0.3276
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH PAGE, Žádná uživatelská akce, [234], [293485],1.0.3276
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Žádná uživatelská akce, [234], [293485],1.0.3276
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH BAR, Žádná uživatelská akce, [234], [293485],1.0.3276
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCHASSISTANT, Žádná uživatelská akce, [234], [293485],1.0.3276

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 66
Adware.NeoBar, C:\Users\Ludmila\AppData\LocalLow\CelGrfgXIrZdI, Žádná uživatelská akce, [525], [449611],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, Žádná uživatelská akce, [558], [391425],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\es_419, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en_US, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en_GB, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pt_BR, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pt_PT, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\zh_CN, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\zh_TW, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fil, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\be, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\bg, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\bn, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ca, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\cs, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\da, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\de, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\el, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\es, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\et, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fa, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fi, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fr, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\gu, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\he, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\hr, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\hu, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\id, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\it, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ja, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\kn, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ko, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\lt, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\lv, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\mk, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ml, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\mr, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ms, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\nl, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\no, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pl, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pt, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\hi, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ro, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ru, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sk, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sl, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sq, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sr, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sv, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sw, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ta, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\te, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\th, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\tr, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\uk, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\vi, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\am, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ar, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\icons, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\BROWSER\FEATURES\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}, Žádná uživatelská akce, [525], [450127],1.0.3276
PUP.Optional.MindSpark, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\FROMDOCTOPDF_65, Žádná uživatelská akce, [260], [240302],1.0.3276
PUP.Optional.MindSpark, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\INBOXACE_1G, Žádná uživatelská akce, [260], [240302],1.0.3276
PUP.Optional.MindSpark, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\RADIORAGE_4J, Žádná uživatelská akce, [260], [240302],1.0.3276

Soubor: 116
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\8YFOGKJXRR\CPUHOPVQFUWEG.DLL, Žádná uživatelská akce, [279], [455948],1.0.3276
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\SMLAZTXC1O\TQCUISC3Y.DLL, Žádná uživatelská akce, [392], [455949],1.0.3276
Adware.NeoBar, C:\ADWCLEANER\QUARANTINE\SMLAZTXC1O\CVJUD.DLL, Žádná uživatelská akce, [525], [410496],1.0.3276
PUP.Optional.OnlineIO, C:\ADWCLEANER\QUARANTINE\BBSQWY6YHK\ONLINE APPLICATION\ONLINE APPLICATION UPDATER.EXE, Žádná uživatelská akce, [558], [407216],1.0.3276
Adware.Neoreklami.TskLnk, C:\ADWCLEANER\QUARANTINE\ZDGC81TBDK\PHPQUE.DLL, Žádná uživatelská akce, [279], [439662],1.0.3276
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\SMLAZTXC1O\PSJVNHWAON.EXE, Žádná uživatelská akce, [392], [455945],1.0.3276
Adware.NeoBar, C:\ADWCLEANER\QUARANTINE\3SOLBPH71Y\VHSNDVCRDU.EXE, Žádná uživatelská akce, [525], [455870],1.0.3276
PUP.Optional.LogicHandler, C:\ADWCLEANER\QUARANTINE\RQF69AZBLA\SET.EXE, Žádná uživatelská akce, [3690], [24306],1.0.3276
Adware.Neoreklami, C:\ADWCLEANER\QUARANTINE\SMLAZTXC1O\KGBRHZDL.DLL, Žádná uživatelská akce, [392], [455944],1.0.3276
RiskWare.BitCoinMiner, C:\APPLICATIONS\WEBSOCK.EXE, Žádná uživatelská akce, [92], [440074],1.0.3276
RiskWare.BitCoinMiner, C:\APPLICATIONS\SERVICE.EXE, Žádná uživatelská akce, [92], [440353],1.0.3276
RiskWare.BitCoinMiner, C:\DISK\SECUREDISK.EXE, Žádná uživatelská akce, [92], [440074],1.0.3276
Adware.NeoBar, C:\Users\Ludmila\AppData\LocalLow\CelGrfgXIrZdI\Storage.db, Žádná uživatelská akce, [525], [449611],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\online.exe, Žádná uživatelská akce, [558], [391425],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\SystemFoldermsiexec.exe, Žádná uživatelská akce, [558], [391425],1.0.3276
Adware.NeoBar, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\BROWSER\FEATURES\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\MANIFEST.JSON, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\icons\icon128.png, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\icons\icon16.png, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\icons\icon48.png, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\hi\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\am\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ar\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\be\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\bg\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\bn\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ca\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\cs\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\da\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\de\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\el\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en\background.js, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en\Content.js, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en\foreground.js, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en\Kernel.js, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en\main.css, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en_GB\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\en_US\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\es\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\es_419\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\et\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fa\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fi\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fil\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\fr\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\gu\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\he\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\hr\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\hu\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\id\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\it\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ja\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\kn\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ko\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\lt\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\lv\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\mk\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ml\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\mr\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ms\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\nl\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\no\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pl\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pt\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pt_BR\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\pt_PT\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ro\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ru\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sk\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sl\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sq\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sr\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sv\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\sw\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\ta\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\te\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\th\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\tr\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\uk\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\vi\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\zh_CN\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.NeoBar, C:\Program Files (x86)\Mozilla Firefox\browser\features\{5C3FD6D1-9185-4195-B5E1-FAB622427F59}\_locales\zh_TW\messages.json, Žádná uživatelská akce, [525], [450127],1.0.3276
Adware.Linkury.Generic, C:\USERS\LUDMILA\APPDATA\LOCAL\MD.XML, Žádná uživatelská akce, [1927], [404866],1.0.3276
Adware.Linkury.Generic, C:\USERS\LUDMILA\APPDATA\LOCAL\AGENT.DAT, Žádná uživatelská akce, [1927], [404872],1.0.3276
Adware.Linkury.Generic, C:\USERS\LUDMILA\APPDATA\LOCAL\NOAH.DAT, Žádná uživatelská akce, [1927], [404865],1.0.3276
PUP.Optional.LogicHandler, C:\USERS\LUDMILA\APPDATA\LOCAL\INDIGONIMFIND.BIN, Žádná uživatelská akce, [3690], [24306],1.0.3276
Adware.Linkury.Generic, C:\USERS\LUDMILA\APPDATA\LOCAL\RAN-ITY.TST, Žádná uživatelská akce, [1927], [404871],1.0.3276
PUP.Optional.MindSpark, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\FROMDOCTOPDF_65\88F7FD49-462C-4A6A-AAE2-BB9EF69E43DA.SQLITE, Žádná uživatelská akce, [260], [240302],1.0.3276
PUP.Optional.Linkury.ACMB1, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [234], [302805],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3276
PUP.Optional.MindSpark, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\INBOXACE_1G\C2EB1FE9-BB30-40A9-BDDC-C651DFF87C05.SQLITE, Žádná uživatelská akce, [260], [240302],1.0.3276
Adware.Linkury, C:\USERS\LUDMILA\APPDATA\LOCAL\KINLAB.EXE, Žádná uživatelská akce, [2038], [448342],1.0.3276
Adware.Linkury.Generic, C:\USERS\LUDMILA\APPDATA\LOCAL\UNINSTALL_TEMP.ICO, Žádná uživatelská akce, [1927], [404862],1.0.3276
PUP.Optional.MindSpark, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\RADIORAGE_4J\C6FA46FA-6EE7-4C94-B271-3E1A5FDDAF8F.SQLITE, Žádná uživatelská akce, [260], [240302],1.0.3276
Adware.Linkury.Generic, C:\USERS\LUDMILA\APPDATA\LOCAL\CONFIG.XML, Žádná uživatelská akce, [1927], [404859],1.0.3276
Adware.Linkury, C:\USERS\LUDMILA\APPDATA\LOCAL\RAN-ITY.EXE, Žádná uživatelská akce, [2038], [448342],1.0.3276
RiskWare.BitCoinMiner, C:\WINDAT\SYSLOG.BAT, Žádná uživatelská akce, [92], [440074],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\INSTALLER\SOURCEHASH{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, Žádná uživatelská akce, [558], [391431],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\ONLINE APPLICATION V2G4, Žádná uživatelská akce, [558], [317314],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\ONLINE APPLICATION V2G6, Žádná uživatelská akce, [558], [317314],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\ONLINE APPLICATION V2G5, Žádná uživatelská akce, [558], [317314],1.0.3276
Adware.Linkury.TskLnk, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, Žádná uživatelská akce, [3936], [444922],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\TASKS\ONLINE APPLICATION V2G6.JOB, Žádná uživatelská akce, [558], [382506],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\TASKS\ONLINE APPLICATION V2G5.JOB, Žádná uživatelská akce, [558], [382506],1.0.3276
PUP.Optional.OnlineIO, C:\WINDOWS\TASKS\ONLINE APPLICATION V2G4.JOB, Žádná uživatelská akce, [558], [382506],1.0.3276
RiskWare.BitCoinMiner, C:\WINSYS\SYSCONFIG.BAT, Žádná uživatelská akce, [92], [440074],1.0.3276
RiskWare.Tool.HCK, D:\LUDMILKA\ŠKOLA\PROGRAMY\AUTOCAD 2015 CZ (X64)\CRACK\XF-ADSK2015_X64.EXE, Žádná uživatelská akce, [2123], [65468],1.0.3276
PUP.Optional.InstallCore, D:\LUDMILKA\ŠKOLA\PROGRAMY\STAžENé SOUBORY\NEPOTVRZENO 510576.CRDOWNLOAD, Žádná uživatelská akce, [2], [78222],1.0.3276
CrackTool.Agent.Keygen, D:\LUDMILKA\ŠKOLA\PROGRAMY\___INSTALAČKY\3DS MAX\AUTODESK.3DS.MAX.2010.KEYGEN.ONLY.BY._PAULF\XF-A2010-32BITS\XF-A2010.EXE, Žádná uživatelská akce, [333], [355559],1.0.3276

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#4 Příspěvek od Márty84 »

Vsechny nalezy nechte odstranit. Po odstraneni a restartu pc test s MBAM zopakujte, at vime, jestli se to nevraci. Napiste vysledek testu a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Re: Kontrola Notebooku

#5 Příspěvek od nobody »

Tady to je :)

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 17.11.17
Čas skenování: 15:41
Logovací soubor: 6d74d2d2-cba5-11e7-a573-3065ec69064b.json
Správce: Ano

-Informace o softwaru-
Verze: 3.3.1.2183
Verze komponentů: 1.0.236
Aktualizovat verzi balíku komponent: 1.0.3282
Licence: Zkušební

-Systémová informace-
OS: Windows 8.1
CPU: x64
Systém souborů: NTFS
Uživatel: LUDMILKA\Ludmila

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 512427
Zjištěné hrozby: 11
Hrozby umístěné do karantény: 0
(Nebyly zjištěny žádné škodlivé položky)
Uplynulý čas: 1 hod, 3 min, 4 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 2
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Žádná uživatelská akce, [234], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Žádná uživatelská akce, [234], [-1],0.0.0

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 9
PUP.Optional.Linkury.ACMB1, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [234], [302805],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282
PUP.Optional.MindSpark.Generic, C:\USERS\LUDMILA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\G3H8NC6W.DEFAULT-1456023389873\PREFS.JS, Žádná uživatelská akce, [849], [319354],1.0.3282

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#6 Příspěvek od Márty84 »

:arrow: Nalezy MBAM nechte odstranit.


:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Zoek.exe http://download.bleepingcomputer.com/smeenk/zoek.exe a ulozte jej na plochu
  • Kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Re: Kontrola Notebooku

#7 Příspěvek od nobody »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 8.1 x64
Ran by Ludmila (Administrator) on p  17. 11. 2017 at 21:41:15,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  17. 11. 2017 at 21:42:26,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




Zoek.exe v5.0.0.1 Updated 24-October-2017
Tool run by Ludmila on p  17. 11. 2017 at 21:45:21,16.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Ludmila\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

17. 11. 2017 21:46:45 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== FireFox Fix ======================

Deleted from C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.cz/");
user_pref("browser.newtab.url", "C:\\ProgramData\\Quoteexs\\ff.NT");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");

Added to C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"web2pdfextension@web2pdf.adobedotcom"="C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn" [02. 03. 2017 12:41]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873
- Undetermined - %ProfilePath%\extensions\s3google@translator.xpi
- Undetermined - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Use Search Asst"="yes"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{32BA9D18-348F-45DE-ABA9-82271F93E43A}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Use Search Asst"="no"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{32BA9D18-348F-45DE-ABA9-82271F93E43A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - No_Url_Value
HKLM\SearchScopes\{32BA9D18-348F-45DE-ABA9-82271F93E43A} - http://www.bing.com/search?q={searchTer ... TR&pc=ACJB
HKLM\Wow6432Node\SearchScopes\{32BA9D18-348F-45DE-ABA9-82271F93E43A} - http://www.bing.com/search?q={searchTer ... TR&pc=ACJB
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
HKCU\SearchScopes\{32BA9D18-348F-45DE-ABA9-82271F93E43A} - http://www.bing.com/search?q={searchTer ... TR&pc=ACJB
HKCU\SearchScopes\{BD0AAAEA-4786-4F35-A31F-7E136F2920F3} - http://tv.seznam.cz/hledej?w={searchTer ... arch_27368

==== Reset Google Chrome ======================

Nothing found to reset

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ludmila\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Ludmila\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Ludmila\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Ludmila\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Ludmila\AppData\Local\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\cache2 emptied successfully
C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\storage\default\https+++www.youtube.com\cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Ludmila\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Ludmila\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on p  17. 11. 2017 at 21:53:48,93 ======================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#8 Příspěvek od Márty84 »

:arrow: Dejte logy podle tohoto navodu https://forum.viry.cz/viewtopic.php?f=13&t=152707 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach :)
(Kdyby nesel Launcher stahnout, dejte logy jen ze samotneho FRST, tedy bez pouziti Launcheru)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Re: Kontrola Notebooku

#9 Příspěvek od nobody »

tady to je :)

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-11-2017
Ran by Ludmila (administrator) on LUDMILKA (18-11-2017 22:50:54)
Running from C:\Users\Ludmila\Desktop
Loaded Profiles: Ludmila (Available Profiles: Ludmila & Administrator)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\WINDOWS\System32\igfxCUIService.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Qualcomm Atheros) C:\Program Files (x86)\Qualcomm Atheros\Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer\Bluetooth Suite\AdminService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(ANDREA VACONDIO) C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Intel Corporation) C:\WINDOWS\System32\igfxEM.exe
(Intel Corporation) C:\WINDOWS\System32\igfxHK.exe
(Intel Corporation) C:\WINDOWS\System32\igfxTray.exe
(Microsoft Corporation) C:\WINDOWS\System32\SkyDrive.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\WINDOWS\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
() C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Users\Ludmila\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-05-26] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1387376 2014-05-13] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SERVICE] => [X]
HKLM-x32\...\Run: [SafeQClient] => C:\Program Files (x86)\SafeQ\SafeQ_cli.exe [493056 2014-08-22] (VŠB-TU Ostrava)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-19] (Piriform Ltd)
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Policies\Explorer: []
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\MountPoints2: {819c33b2-4fb4-11e7-82a1-3065ec69064b} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [132608 2014-10-29] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1235336 2014-08-28] (Autodesk, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2017-11-08]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Network Server.lnk [2017-11-08]
ShortcutTarget: Network Server.lnk -> C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe (WIBU-SYSTEMS AG)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{49C370AF-3C9D-4CF8-BEF2-D8361B1638A7}: [DhcpNameServer] 10.100.1.234 8.8.8.8
Tcpip\..\Interfaces\{C3F2636B-CC0C-4C68-AAF0-0FF680AA163A}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001 -> {BD0AAAEA-4786-4F35-A31F-7E136F2920F3} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_27368
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-24] (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-24] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File

FireFox:
========
FF ProfilePath: C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873 [2017-11-18]
FF Homepage: Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873 -> https://www.google.cz/
FF NewTab: Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873 -> C:\\ProgramData\\Quoteexs\\ff.NT
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873 -> Google
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873 -> Google
FF Extension: (S3.Translator) - C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\Extensions\s3google@translator.xpi [2017-11-14]
FF Extension: (Adblock Plus) - C:\Users\Ludmila\AppData\Roaming\Mozilla\Firefox\Profiles\g3h8nc6w.default-1456023389873\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-11-09]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2017-03-02] [Lagacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-11-14] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-02-20] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-02-20] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer\Bluetooth Suite\adminservice.exe [305664 2014-08-22] (Qualcomm Atheros) [File not signed]
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2278688 2017-09-26] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-07-22] (Acer Incorporated)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [315352 2014-06-16] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-02-01] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-02-20] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-02-20] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [455912 2014-12-30] (Acer Incorporate)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-10-12] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-10-11] (NVIDIA Corporation)
R2 PDFsam Manager; C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe [1050224 2015-11-13] (ANDREA VACONDIO)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-10-17] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-10-17] (Acer Incorporate)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [233216 2014-06-24] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
S2 Wisaroc; C:\WINDOWS\Wisaroc.exe [1686020 2010-11-08] (Remak) [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77432 2017-11-01] ()
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [21360 2013-07-18] (Acer Incorporated)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [193464 2017-11-17] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2017-11-18] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [46008 2017-11-17] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2017-11-17] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2017-11-18] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [116736 2014-02-20] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-11] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation)
R3 Qcamain; C:\WINDOWS\system32\DRIVERS\Qcamainx64.sys [2220544 2014-08-26] (Qualcomm Atheros, Inc.)
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [14680 2013-07-18] (Acer Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
R2 WIBUKEY; C:\WINDOWS\System32\DRIVERS\WibuKey64.sys [118200 2016-12-22] (WIBU-SYSTEMS AG)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-18 22:50 - 2017-11-18 22:51 - 000020362 ____C C:\Users\Ludmila\Desktop\FRST.txt
2017-11-18 22:49 - 2017-11-18 22:50 - 000000000 ___DC C:\FRST
2017-11-18 22:48 - 2017-11-18 22:48 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-11-18 22:48 - 2017-11-18 22:48 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-11-18 22:47 - 2017-11-18 22:47 - 000112640 ____C (forum.viry.cz) C:\Users\Ludmila\Desktop\FRSTLauncher.exe
2017-11-18 22:46 - 2017-11-18 22:46 - 002392064 ____C (Farbar) C:\Users\Ludmila\Desktop\FRST64.exe
2017-11-18 00:29 - 2017-11-18 00:29 - 000007181 ____C C:\Users\Ludmila\Desktop\zoek-results.txt
2017-11-17 21:49 - 2017-11-17 21:49 - 000000004 ____H C:\ProgramData\cm-lock
2017-11-17 21:48 - 2017-11-17 21:45 - 000024064 _____ C:\WINDOWS\zoek-delete.exe
2017-11-17 21:45 - 2017-11-17 21:45 - 000000000 ___DC C:\zoek_backup
2017-11-17 21:43 - 2017-11-17 21:43 - 001313792 _____ C:\Users\Ludmila\Desktop\zoek.exe
2017-11-17 21:42 - 2017-11-17 21:42 - 000000555 ____C C:\Users\Ludmila\Desktop\JRT.txt
2017-11-17 21:38 - 2017-11-17 21:38 - 001663040 _____ (Malwarebytes) C:\Users\Ludmila\Desktop\JRT.exe
2017-11-17 20:57 - 2017-11-17 20:57 - 000017284 ____C C:\Users\Ludmila\Desktop\TZB - vytápění-Model.pdf
2017-11-17 18:26 - 2017-11-17 18:26 - 000003494 ____C C:\Users\Ludmila\Desktop\2.txt
2017-11-17 08:04 - 2017-11-17 08:04 - 000036819 ____C C:\Users\Ludmila\Desktop\1.txt
2017-11-17 00:25 - 2017-11-17 21:49 - 000046008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-11-17 00:25 - 2017-11-17 00:25 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2017-11-17 00:25 - 2017-11-17 00:25 - 000193464 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2017-11-17 00:25 - 2017-11-17 00:25 - 000001887 ____C C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-17 00:25 - 2017-11-17 00:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-17 00:25 - 2017-11-17 00:25 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-17 00:25 - 2017-11-17 00:25 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-17 00:25 - 2017-11-01 08:54 - 000077432 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-11-17 00:23 - 2017-11-17 00:24 - 078346672 _____ (Malwarebytes ) C:\Users\Ludmila\Desktop\mb3-setup-consumer-3.3.1.2183.exe
2017-11-17 00:16 - 2017-11-17 00:17 - 000000000 ___DC C:\AdwCleaner
2017-11-17 00:15 - 2017-11-17 00:16 - 008261584 _____ (Malwarebytes) C:\Users\Ludmila\Desktop\adwcleaner_7.0.4.0.exe
2017-11-15 16:39 - 2017-10-17 20:11 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-11-15 16:39 - 2017-10-16 19:38 - 002013016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-11-15 16:39 - 2017-10-14 14:04 - 001548624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-11-15 16:39 - 2017-10-14 09:38 - 025731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-11-15 16:39 - 2017-10-14 09:23 - 004168704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2017-11-15 16:39 - 2017-10-14 09:13 - 002903552 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-11-15 16:39 - 2017-10-14 09:11 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-11-15 16:39 - 2017-10-14 09:09 - 005979648 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-11-15 16:39 - 2017-10-14 09:01 - 000816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-11-15 16:39 - 2017-10-14 08:36 - 001033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2017-11-15 16:39 - 2017-10-14 08:31 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-11-15 16:39 - 2017-10-14 08:30 - 015266816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-11-15 16:39 - 2017-10-14 08:30 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-11-15 16:39 - 2017-10-14 08:30 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-11-15 16:39 - 2017-10-14 08:29 - 000807936 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-11-15 16:39 - 2017-10-14 08:27 - 002134528 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-11-15 16:39 - 2017-10-14 08:21 - 003241472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-11-15 16:39 - 2017-10-14 08:14 - 020269056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-11-15 16:39 - 2017-10-14 08:09 - 001544704 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-11-15 16:39 - 2017-10-14 08:05 - 015431680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-11-15 16:39 - 2017-10-14 07:58 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-11-15 16:39 - 2017-10-14 07:53 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-11-15 16:39 - 2017-10-14 07:50 - 002293760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-11-15 16:39 - 2017-10-14 07:45 - 000662016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-11-15 16:39 - 2017-10-14 07:33 - 004542464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-11-15 16:39 - 2017-10-14 07:28 - 013680128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-11-15 16:39 - 2017-10-14 07:28 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2017-11-15 16:39 - 2017-10-14 07:25 - 000230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-11-15 16:39 - 2017-10-14 07:24 - 000694272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-11-15 16:39 - 2017-10-14 07:24 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-11-15 16:39 - 2017-10-14 07:23 - 002058752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-11-15 16:39 - 2017-10-14 07:14 - 013317632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-11-15 16:39 - 2017-10-14 07:10 - 002767872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-11-15 16:39 - 2017-10-14 07:07 - 001314304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-11-15 16:39 - 2017-10-14 07:04 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-11-15 16:39 - 2017-10-10 17:36 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2017-11-15 16:39 - 2017-10-10 16:38 - 003631616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-11-15 16:39 - 2017-10-10 16:38 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPTpm12.dll
2017-11-15 16:39 - 2017-10-10 16:11 - 002749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-11-15 16:39 - 2017-10-10 16:08 - 000367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPTpm12.dll
2017-11-15 16:39 - 2017-10-05 08:17 - 000380248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-11-15 16:39 - 2017-09-15 00:52 - 000986968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2017-11-15 16:39 - 2017-09-08 18:14 - 003084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-11-15 16:39 - 2017-09-08 17:50 - 002471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-11-15 16:39 - 2017-09-08 04:31 - 000685440 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2017-11-15 16:39 - 2017-09-08 04:28 - 000507176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2017-11-15 16:39 - 2017-09-07 22:31 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mgmtapi.dll
2017-11-15 16:39 - 2017-09-07 20:20 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mgmtapi.dll
2017-11-15 16:39 - 2017-09-07 18:20 - 000513456 _____ C:\WINDOWS\SysWOW64\locale.nls
2017-11-15 16:39 - 2017-09-07 18:20 - 000513456 _____ C:\WINDOWS\system32\locale.nls
2017-11-15 16:39 - 2017-09-07 14:40 - 000995272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-11-15 16:39 - 2017-09-07 14:40 - 000922432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-11-15 16:39 - 2017-09-07 00:07 - 000158552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2017-11-15 16:39 - 2017-09-06 22:17 - 000461144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2017-11-15 16:39 - 2017-09-06 22:17 - 000443224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2017-11-15 16:39 - 2017-09-06 15:14 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\regsvc.dll
2017-11-15 16:39 - 2017-08-11 02:39 - 002779136 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2017-11-15 16:39 - 2017-08-11 02:30 - 002464256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2017-11-15 16:29 - 2017-10-11 08:35 - 000143016 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-11-15 16:29 - 2017-10-10 16:21 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 002023936 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-11-15 16:29 - 2017-10-10 14:18 - 001570304 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000603648 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\system32\centel.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-11-15 16:29 - 2017-10-10 14:18 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-11-14 23:39 - 2017-11-14 23:39 - 005007360 ____C C:\Users\Ludmila\Desktop\Slaba Radioaktivita .ppt
2017-11-13 18:10 - 2017-11-13 18:10 - 000003334 _____ C:\WINDOWS\System32\Tasks\AcerCloud
2017-11-13 18:07 - 2017-11-13 18:07 - 000000000 ____D C:\ProgramData\Apple
2017-11-13 18:06 - 2017-11-13 18:06 - 000003338 _____ C:\WINDOWS\System32\Tasks\abDocsDllLoader
2017-11-13 18:06 - 2017-11-13 18:06 - 000001929 ____C C:\Users\Public\Desktop\abDocs.lnk
2017-11-09 21:50 - 2017-11-09 21:50 - 000242788 _____ C:\Users\Ludmila\Desktop\BUFET.pdf
2017-11-09 20:19 - 2017-11-10 06:12 - 011946080 ____C C:\Users\Ludmila\Desktop\BUFET1.pln
2017-11-09 20:02 - 2017-11-09 20:02 - 000140800 _____ C:\Users\Ludmila\AppData\Local\installer.dat
2017-11-09 20:01 - 2017-11-17 14:29 - 000000000 ___DC C:\WinSys
2017-11-09 20:01 - 2017-11-17 14:29 - 000000000 ___DC C:\Windat
2017-11-09 20:01 - 2017-11-17 14:29 - 000000000 ___DC C:\Disk
2017-11-09 20:01 - 2017-11-17 14:29 - 000000000 ___DC C:\Applications
2017-11-09 10:06 - 2017-11-09 10:06 - 000000000 ____D C:\Users\Ludmila\AppData\Local\CrashRpt
2017-11-09 10:05 - 2017-11-09 10:05 - 000008604 ____C C:\AeroCAD.tlb
2017-11-09 10:05 - 2017-11-09 10:05 - 000001968 ____C C:\HovalWrapper.tlb
2017-11-09 10:04 - 2017-11-09 10:15 - 000000000 ___DC C:\AeroCAD
2017-11-09 10:04 - 2017-11-09 10:04 - 000001452 ____C C:\Users\Public\Desktop\AeroCAD.lnk
2017-11-09 10:04 - 2017-11-09 10:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeroCAD
2017-11-09 10:04 - 2010-11-08 11:06 - 001686020 _____ (Remak) C:\WINDOWS\Wisaroc.exe
2017-11-09 10:04 - 2001-08-16 16:07 - 000053760 _____ C:\WINDOWS\SysWOW64\zlib.dll
2017-11-09 10:04 - 1999-12-07 15:00 - 000028944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrecr40.dll
2017-11-09 10:04 - 1999-01-22 15:04 - 000026224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ODBC16GT.DLL
2017-11-09 10:04 - 1999-01-22 15:04 - 000007952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ODBCCP32.CPL
2017-11-09 10:04 - 1999-01-22 15:04 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ODBC32GT.DLL
2017-11-09 10:04 - 1999-01-22 15:04 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DS32GT.DLL
2017-11-09 10:04 - 1999-01-22 15:04 - 000004656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DS16GT.DLL
2017-11-09 10:04 - 1998-11-11 22:51 - 000098576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrpjt40.dll
2017-11-09 10:04 - 1998-07-30 08:23 - 001347344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVBVM50.DLL
2017-11-09 10:04 - 1998-06-30 16:16 - 000026858 _____ C:\WINDOWS\SysWOW64\odbcinst.hlp
2017-11-09 10:04 - 1998-06-30 16:16 - 000000244 _____ C:\WINDOWS\SysWOW64\odbcinst.cnt
2017-11-09 10:04 - 1998-06-30 16:14 - 000368912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbar332.dll
2017-11-09 10:04 - 1998-06-30 16:14 - 000162850 _____ C:\WINDOWS\SysWOW64\Odbcjet.hlp
2017-11-09 10:04 - 1998-06-30 16:14 - 000062863 _____ C:\WINDOWS\SysWOW64\Odbcjtnw.hlp
2017-11-09 10:04 - 1998-06-30 16:14 - 000006870 _____ C:\WINDOWS\SysWOW64\Odbcjet.cnt
2017-11-09 10:04 - 1998-06-30 16:14 - 000003176 _____ C:\WINDOWS\SysWOW64\Odbcjtnw.cnt
2017-11-09 10:04 - 1998-05-31 02:00 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ODBCTL32.DLL
2017-11-09 00:00 - 2017-11-09 00:01 - 000001914 ____C C:\Users\Public\Desktop\ATREA DUPLEX 8.70.lnk
2017-11-09 00:00 - 2017-11-09 00:00 - 000000000 ___DC C:\ATREA
2017-11-09 00:00 - 2017-11-09 00:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATREA
2017-11-09 00:00 - 2017-11-09 00:00 - 000000000 ____D C:\ProgramData\ATREA
2017-11-09 00:00 - 2017-11-09 00:00 - 000000000 ____D C:\Program Files (x86)\ATREA
2017-11-08 23:59 - 2017-11-08 23:59 - 000000000 ____D C:\Users\Ludmila\AppData\Local\ATREA
2017-11-08 15:03 - 2017-11-08 15:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WibuKey
2017-11-08 15:03 - 2017-11-08 15:03 - 000000000 ____D C:\Program Files (x86)\WIBU-SYSTEMS
2017-11-08 15:03 - 2017-11-08 15:03 - 000000000 ____D C:\Program Files (x86)\WIBUKEY
2017-11-08 15:03 - 2016-12-22 06:47 - 000118200 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\Drivers\WibuKey64.sys
2017-11-08 15:03 - 2016-12-22 06:47 - 000042936 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\Drivers\Wibukey2_64.sys
2017-11-08 15:03 - 2016-12-22 06:40 - 000606232 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\wibuKJni64.dll
2017-11-08 15:03 - 2016-12-22 06:40 - 000501272 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\wibuKJni.dll
2017-11-08 15:03 - 2016-12-22 06:40 - 000433112 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkExt64.dll
2017-11-08 15:03 - 2016-12-22 06:40 - 000366552 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkExt32.dll
2017-11-08 15:03 - 2016-12-22 06:40 - 000222688 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.dll
2017-11-08 15:03 - 2016-12-22 06:40 - 000192480 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.dll
2017-11-08 15:03 - 2016-12-22 06:40 - 000022528 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.lfr
2017-11-08 15:03 - 2016-12-22 06:40 - 000022528 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.les
2017-11-08 15:03 - 2016-12-22 06:40 - 000022528 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.lde
2017-11-08 15:03 - 2016-12-22 06:40 - 000022016 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.lfr
2017-11-08 15:03 - 2016-12-22 06:40 - 000022016 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.les
2017-11-08 15:03 - 2016-12-22 06:40 - 000022016 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.lde
2017-11-08 15:03 - 2016-12-22 06:40 - 000022016 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.lit
2017-11-08 15:03 - 2016-12-22 06:40 - 000021504 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.lit
2017-11-08 15:03 - 2016-12-22 06:40 - 000021504 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.lbr
2017-11-08 15:03 - 2016-12-22 06:40 - 000020992 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.ljp
2017-11-08 15:03 - 2016-12-22 06:40 - 000020992 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.lhu
2017-11-08 15:03 - 2016-12-22 06:40 - 000020480 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.ljp
2017-11-08 15:03 - 2016-12-22 06:40 - 000020480 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.lhu
2017-11-08 15:03 - 2016-12-22 06:40 - 000015360 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WkWin64.lcn
2017-11-08 15:03 - 2016-12-22 06:40 - 000014848 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WkWin32.lcn
2017-11-08 15:02 - 2017-11-09 19:44 - 000000000 ____D C:\ProgramData\ARCHICAD
2017-10-30 13:43 - 2017-10-30 13:43 - 000001078 ____C C:\Users\Public\Desktop\ARCHICAD 20.lnk
2017-10-30 13:41 - 2017-11-08 15:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeMeter
2017-10-30 13:41 - 2017-11-08 15:04 - 000000000 ____D C:\Program Files (x86)\CodeMeter
2017-10-30 13:41 - 2017-10-30 13:41 - 000000000 ____D C:\ProgramData\CodeMeter
2017-10-30 13:41 - 2017-10-30 13:41 - 000000000 ____D C:\Program Files\WIBU-SYSTEMS
2017-10-30 13:41 - 2017-10-30 13:41 - 000000000 ____D C:\Program Files\CodeMeter
2017-10-30 10:57 - 2017-10-30 10:57 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-10-30 10:57 - 2017-10-12 21:25 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-10-30 10:57 - 2017-10-12 20:55 - 005960824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 002587584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 001766520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 000607352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 000449472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 000122816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 000081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-10-30 10:57 - 2017-10-12 20:54 - 007799931 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-10-30 10:57 - 2017-09-14 00:20 - 000798008 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-10-30 10:57 - 2017-09-14 00:20 - 000490296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-10-30 10:57 - 2017-09-14 00:19 - 000927544 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-10-30 10:57 - 2017-09-14 00:19 - 000591160 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-10-30 10:55 - 2017-10-12 22:33 - 040237176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 036185208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 035156600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 029229504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 023261256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 021738976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 019035344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 019008952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 018203640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 016750528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2017-10-30 10:55 - 2017-10-12 22:33 - 015024912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 013863184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 013251240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 011777768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 010880856 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 004283120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 003807864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 003796776 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 003346368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 001988032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438800.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 001606592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438800.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 001135464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 001098176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 001030264 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000981112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000932472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000885496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000615360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000527288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000505792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000444144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000171896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000149552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2017-10-30 10:55 - 2017-10-12 22:33 - 000046182 _____ C:\WINDOWS\system32\nvinfo.pb
2017-10-30 10:55 - 2017-10-12 22:33 - 000000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-10-30 10:55 - 2017-10-12 22:33 - 000000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-10-30 10:42 - 2017-10-11 02:05 - 000050624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-18 22:42 - 2015-01-23 21:57 - 000740822 _____ C:\WINDOWS\system32\perfh005.dat
2017-11-18 22:42 - 2015-01-23 21:57 - 000151948 _____ C:\WINDOWS\system32\perfc005.dat
2017-11-18 22:42 - 2014-03-18 11:03 - 001748728 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-18 22:42 - 2013-08-22 14:36 - 000000000 ____D C:\WINDOWS\Inf
2017-11-18 22:41 - 2016-07-16 16:08 - 000000000 ____D C:\ProgramData\NVIDIA
2017-11-18 11:48 - 2015-09-21 21:13 - 000000000 _RDOC C:\Users\Ludmila\OneDrive
2017-11-17 21:49 - 2013-08-22 15:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-17 15:35 - 2016-02-21 00:48 - 000003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3497575666-2220848565-2583033622-1001
2017-11-17 15:26 - 2016-02-21 01:15 - 000000000 ____D C:\Users\Ludmila\AppData\Local\CrashDumps
2017-11-17 00:19 - 2016-12-13 23:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-11-17 00:19 - 2016-02-21 03:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-11-17 00:19 - 2013-08-22 15:44 - 005117648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-11-17 00:19 - 2013-08-22 14:25 - 000262144 ___SH C:\WINDOWS\system32\config\BBI
2017-11-17 00:18 - 2016-02-28 18:19 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-11-17 00:18 - 2016-02-21 03:55 - 000001155 ____C C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-11-17 00:18 - 2016-02-21 03:55 - 000001155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-11-16 11:44 - 2013-08-22 16:20 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-11-16 11:20 - 2016-02-21 11:52 - 000000000 ____D C:\Program Files\trend micro
2017-11-16 06:25 - 2016-02-21 01:08 - 000000000 ____D C:\Users\Ludmila\AppData\Roaming\Mozilla
2017-11-15 23:56 - 2016-03-02 11:46 - 000000000 ____D C:\Users\Ludmila\AppData\Roaming\vlc
2017-11-15 16:31 - 2016-03-09 19:40 - 000004476 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-11-15 16:30 - 2016-03-09 19:40 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-11-14 18:26 - 2016-05-05 14:11 - 000004372 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-11-14 18:26 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-11-14 18:26 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-11-13 18:10 - 2016-02-21 00:43 - 000000000 ____D C:\Users\Ludmila\AppData\Local\clear.fi
2017-11-13 18:09 - 2015-01-23 21:36 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2017-11-13 18:06 - 2016-02-21 00:46 - 000003442 _____ C:\WINDOWS\System32\Tasks\BacKGroundAgent
2017-11-13 18:06 - 2015-01-23 21:36 - 000000000 ____D C:\Program Files (x86)\Acer
2017-11-13 18:06 - 2014-07-14 19:33 - 000000000 ___HD C:\OEM
2017-11-13 06:45 - 2017-03-02 15:22 - 000000000 ____D C:\Users\Ludmila\Graphisoft
2017-11-09 20:04 - 2016-02-21 00:42 - 000001058 _____ C:\Users\Ludmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-11-09 20:04 - 2014-07-14 18:37 - 000001058 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-11-09 19:47 - 2017-09-05 22:22 - 000026544 _____ C:\WINDOWS\vpd.properties
2017-11-09 19:47 - 2017-09-05 22:17 - 000000000 ____D C:\Program Files\GRAPHISOFT
2017-11-09 19:47 - 2017-03-02 15:22 - 000000000 ____D C:\Users\Ludmila\AppData\Roaming\Graphisoft
2017-11-09 19:46 - 2017-09-05 22:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GRAPHISOFT
2017-11-09 19:45 - 2016-11-19 17:25 - 000000000 ___DC C:\Users\Ludmila\AppData\LocalLow\Mozilla
2017-11-09 19:37 - 2017-09-06 12:57 - 000000000 ____D C:\Users\Ludmila\AppData\Roaming\MAXON
2017-11-09 19:37 - 2017-03-02 15:22 - 000000000 ____D C:\Users\Ludmila\AppData\Local\Graphisoft
2017-11-08 19:54 - 2016-02-21 00:41 - 000000000 ____D C:\Users\Ludmila
2017-11-08 15:03 - 2017-09-05 22:27 - 000000000 ___DC C:\Users\Ludmila\Documents\BIMx
2017-11-08 15:03 - 2017-09-05 22:16 - 000000000 ____D C:\Users\Ludmila\AppData\Roaming\Install.GS
2017-11-08 15:02 - 2016-01-18 01:03 - 000000000 ___DC C:\Users\Ludmila\.oracle_jre_usage
2017-11-04 01:41 - 2014-07-14 18:54 - 000835568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-11-04 01:41 - 2014-07-14 18:54 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-30 13:54 - 2016-02-21 00:42 - 000000000 ____D C:\Users\Ludmila\AppData\Local\NVIDIA
2017-10-30 13:53 - 2015-01-23 21:26 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-10-30 13:28 - 2016-02-21 03:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Artlantis Studio 5 (64 bit)
2017-10-30 13:27 - 2016-02-21 03:50 - 000000000 ____D C:\Users\Ludmila\AppData\Roaming\Abvent_Artlantis5
2017-10-30 13:26 - 2016-02-21 03:46 - 000000000 ____D C:\Program Files\Artlantis Studio 5
2017-10-30 10:57 - 2015-01-23 21:26 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-10-30 10:57 - 2015-01-23 21:26 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-10-30 10:57 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\Help
2017-10-30 10:43 - 2017-05-18 20:12 - 000003814 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:37 - 000003798 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:37 - 000001396 ____C C:\Users\Public\Desktop\GeForce Experience.lnk
2017-10-30 10:43 - 2017-01-24 01:36 - 000004146 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:36 - 000003738 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:36 - 000003738 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:36 - 000003730 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:36 - 000003554 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:43 - 2017-01-24 01:36 - 000003494 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 10:35 - 2015-01-23 21:17 - 000000000 ____D C:\ProgramData\Package Cache
2017-10-25 21:42 - 2017-05-09 22:36 - 000000000 ____D C:\ProgramData\CanonIJPLM

==================== Files in the root of some directories =======

2016-03-06 02:57 - 2017-04-10 20:29 - 000000132 _____ () C:\Users\Ludmila\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2016-06-12 18:28 - 2017-01-23 08:47 - 000000132 _____ () C:\Users\Ludmila\AppData\Roaming\Filtr IIIExport Adobe CS6 – předvolby
2017-11-09 20:02 - 2017-11-09 20:02 - 000140800 _____ () C:\Users\Ludmila\AppData\Local\installer.dat
2016-07-12 06:06 - 2016-07-12 06:06 - 000007399 _____ () C:\Users\Ludmila\AppData\Local\recently-used.xbel

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-12 16:44

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (Acer) (Fixed) (Total:118.43 GB) (Free:35.22 GB) NTFS
Drive d: (DATA) (Fixed) (Total:916.12 GB) (Free:486.49 GB) NTFS

Available physical RAM: 9359.16 MB
Total physical RAM: 12211.27 MB
Percentage of memory in use: 23%

==================== MBR and Partition Table ==================

Reduce PDF Size (HKLM-x32\...\{32BD8FD9-8990-46A0-B86B-857F11014DF6}_is1) (Version: - reducepdfsize.com)
Disk: 0 (Size: 119.2 GB) (Disk ID: F0F28B29)
Disk: 1 (Size: 931.5 GB) (Disk ID: F0F28B3E)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Users\Ludmila\Local Settings:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\Local Settings:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikací:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikací:PKmMZuWDEw7N85o2LAYBSNm [2090]

==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Ludmila\Desktop" je 150 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"="C:\\Program Files (x86)\\CodeMeter\\Runtime\\bin\\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"="C:\\Program Files (x86)\\CodeMeter\\Runtime\\bin\\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#10 Příspěvek od Márty84 »

:arrow: FRST vytvari dva logy, hodil by se i ten druhy.

Pokud ho nenajdete, pokracujte rovnou dalsim krokem...


:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SERVICE] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-19] (Piriform Ltd)
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Policies\Explorer: []

SearchScopes: HKLM-x32 -> DefaultScope value is missing
Toolbar: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File

AlternateDataStreams: C:\Users\Ludmila\Local Settings:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\Local Settings:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikací:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikací:PKmMZuWDEw7N85o2LAYBSNm [2090]

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Re: Kontrola Notebooku

#11 Příspěvek od nobody »

Tady je ten druhý soubor:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-11-2017
Ran by Ludmila (18-11-2017 22:51:17)
Running from C:\Users\Ludmila\Desktop
Windows 8.1 (Update) (X64) (2016-02-20 23:42:34)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3497575666-2220848565-2583033622-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-3497575666-2220848565-2583033622-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3497575666-2220848565-2583033622-1003 - Limited - Enabled)
Ludmila (S-1-5-21-3497575666-2220848565-2583033622-1001 - Administrator - Enabled) => C:\Users\Ludmila

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.10.2002 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.02.2001 - Acer Incorporated)
abFiles (HKLM-x32\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3002 - Acer Incorporated)
abMusic (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 3.01.2003.6 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 4.00.2001.1 - Acer Incorporated)
Acer Care Center (HKLM\...\{1AF41E84-3408-499A-8C93-8891F0612719}) (Version: 2.00.3021 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8115 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.12.2006 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8106.0 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3018 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3004 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3004 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.009.20044 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - Eastern European (Group 1) (HKLM-x32\...\{AC76BA86-1029-4770-7760-000000000005}) (Version: 10.1.16 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
AeroCAD 6 (HKLM-x32\...\REMAK.AeroCAD_is1) (Version: 6.5 - REMAK a.s.)
Aktualizace NVIDIA 29.1.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 29.1.0.0 - NVIDIA Corporation) Hidden
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 388.00 - NVIDIA Corporation) Hidden
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.25.2001.0 - Acer Incorporated)
ARCHICAD 20 CZE (HKLM\...\001FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
ARCHICAD 20 Goodies Suite CZE (HKLM\...\050FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
Artlantis 5 Exporter for SketchUp Pro 2014 (HKLM-x32\...\Abvent_SkpPro2014toATL5) (Version: - )
Artlantis Studio 5.1.2.2 (64 bit) (HKLM\...\Artlantis Studio 5 (64 bit)) (Version: 5.1.2.2 - Abvent R&D)
Astra MS Software - BuildingDesign (HKLM\...\{688BD477-4391-42D6-AA76-6F9B4355D3C8}_is1) (Version: 168 - Astra MS Software s.r.o)
Astra MS Software - BuildingDesign Sunlis (HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\{42413D84-659A-41AA-9430-261795371B17}_is1) (Version: 5.0.14.3 - Astra MS Software s.r.o)
AutoCAD 2015 – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0000-0102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
AutoCAD 2015 – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0405-2102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
AutoCAD 2015 Language Pack – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0405-1102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
Autodesk 360 (HKLM\...\{556966D9-F7F6-421B-9707-D07901604DDF}) (Version: 5.2.3.1000 - Autodesk)
Autodesk App Manager (HKLM-x32\...\{C8125548-F2D5-4059-823F-1F3C5BBD9F19}) (Version: 1.2.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD 2015 – Čeština (Czech) (HKLM\...\AutoCAD 2015 – Čeština (Czech)) (Version: 20.0.51.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool Version 1.2.2 (HKLM-x32\...\{85735431-6CD3-4B16-BEC8-95332034E53B}) (Version: 1.2.2.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit (HKLM\...\{9D589081-AFC2-4932-9071-AC585AC1EA83}) (Version: 3.32.3004 - Autodesk)
Autodesk Content Service (HKLM-x32\...\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service (HKLM-x32\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM-x32\...\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2015 (HKLM-x32\...\{427F733F-4D6C-45BC-9324-EB743104C321}) (Version: 5.2.9.100 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2015 (HKLM-x32\...\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}) (Version: 5.2.9.100 - Autodesk)
Autodesk ReCap (HKLM\...\{31ABA3F2-0000-1033-0102-111D43815377}) (Version: 1.3.1.39 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap) (Version: 1.3.1.39 - Autodesk)
Balík TT 2010 (HKLM-x32\...\{91CA3F48-5DAD-4147-AECE-C7219C4B2562}) (Version: 2010.0.0.0 - Svoboda Software (svoboda.zbynek@quick.cz, mobile +420 606 227 420))
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ‪Canon Inc.‬)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - ‪Canon Inc.‬)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.0.0 - Canon Inc.)
Canon MG4200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG4200_series) (Version: 1.01 - Canon Inc.)
Canon MG4200 series On-screen Manual (HKLM-x32\...\Canon MG4200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.0.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.30 - Piriform)
CodeMeter Runtime Kit v6.40b (HKLM\...\{B886AE2E-9106-44C4-BE91-7A7F2EF5962F}) (Version: 6.40.2405.502 - WIBU-SYSTEMS AG)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.6.3.1 - Dolby Laboratories Inc)
GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team)
GRAPHISOFT BIM Server 20 CZE (HKLM\...\116FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
GRAPHISOFT BIMcloud - BIM Server modul 20 CZE (HKLM\...\110FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
GRAPHISOFT BIMcloud - BIM server správce 20 CZE (HKLM\...\109FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
GRAPHISOFT BIMx Desktop Viewer (HKLM-x32\...\103FFFFFFF21FF00FF2801F01F02F000-R1) (Version: 21.0 - GRAPHISOFT)
GRAPHISOFT License Manager Tool (HKLM\...\118FFF2FFF20FF00FF0701F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
Import souborů SketchUp (HKLM-x32\...\{C403E867-FCF1-432B-BCC1-8FFD40A10A6E}) (Version: 1.2.0 - Autodesk)
Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel(R) Chipset Device Software (HKLM-x32\...\{d370215a-d003-43ae-a3b6-1028af64d5a1}) (Version: 10.0.20 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3643 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Kompaktní jednotky DUPLEX - návrhový program (HKLM-x32\...\Atrea.Application_400) (Version: 8.70.610 - ATREA s.r.o.)
Malwarebytes verze 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Manager (HKLM-x32\...\{3802F563-BAD7-47F3-AF91-ED1C9467B224}) (Version: 3.0.7.25771 - ANDREA VACONDIO) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office 2010 pro studenty a domácnosti (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 57.0 (x64 cs) (HKLM\...\Mozilla Firefox 57.0 (x64 cs)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.0.6525 - Mozilla)
NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 388.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.00 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Ovládací panel NVIDIA 388.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.00 - NVIDIA Corporation) Hidden
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
PdfMerge (HKLM-x32\...\{238BE990-A412-4129-A434-D03B1A9E396E}) (Version: 1.22.0 - PdfMerge)
PDFsam Basic (HKLM-x32\...\{0F7F1493-D16D-4C7B-A271-17A12168CCC4}) (Version: 3.30.2.0 - Andrea Vacondio)
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer (HKLM-x32\...\{3241744A-BA36-41F0-B4AA-EF3946D00632}) (Version: 11.0.0.619A - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39059 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.32.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7260 - Realtek Semiconductor Corp.)
Reduce PDF Size (HKLM-x32\...\{32BD8FD9-8990-46A0-B86B-857F11014DF6}_is1) (Version: - reducepdfsize.com)
Registrace uživatele zařízení Canon MG4200 series (HKLM-x32\...\Registrace uživatele zařízení Canon MG4200 series) (Version: - Canon Inc.‎)
SafeQ (HKLM-x32\...\SafeQ) (Version: 0.9 - VŠB-TUO)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
SketchUp 2015 (HKLM-x32\...\{72FCCE6E-98AB-4953-AF89-772DF0704E11}) (Version: 15.1.105 - Trimble Navigation Limited)
Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.)
Speciální aplikace Autodesk (HKLM-x32\...\{EDDEE94B-214D-4B07-9727-A3E46F3E379A}) (Version: 1.2.0 - Autodesk)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.0.631 - Electronic Arts)
TZB modelár AC20 CZE (HKLM\...\042FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.2 - VideoLAN)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WibuKey Setup (WibuKey Remove) (HKLM\...\{00060000-0000-1004-8002-0000C06B5161}) (Version: Version 6.40 of 2016-Dec-22 (Build 2402) (Setup) - WIBU-SYSTEMS AG)
WinRAR 5.31 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.1 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2015\cs-CZ\acadficn.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-01-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-01-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-01-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2014-02-07] (Autodesk, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2014-02-07] (Autodesk)
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2015-09-24] (Adobe Systems Inc.)
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-01-21] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-01-21] (Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-06-16] (Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2014-06-16] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-12] (NVIDIA Corporation)
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2015-09-24] (Adobe Systems Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-01-21] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-01-21] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01996250-C2DA-43B6-AE84-4AA1F196C9DA} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2015-07-17] (Acer Incorporated)
Task: {0A8CD8F0-F26C-4E74-AB5E-B266174B1242} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2014-04-08] (Dolby Laboratories Inc.)
Task: {0FBB7C95-D94D-4E34-9ACA-A1090BFDCB14} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2016-01-20] ()
Task: {13D62EE0-F09B-4888-B7B3-3C9BF171ADF8} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {1BE108C9-F0FB-435D-9CE8-474FCE515DAD} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-17] (Acer Incorporated)
Task: {1DFE6DDB-A644-4394-A1FA-25DE31DF98AE} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-10-17] (Acer Incorporate)
Task: {245562D4-3721-4E30-BA1C-620856231B22} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation)
Task: {25495086-2290-4A26-97D7-26B4F9C3ED98} - System32\Tasks\abDocsDllLoader => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe [2017-09-28] ()
Task: {301CDFB7-F34E-4D67-A691-30B0C92FE9CC} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2015-07-17] ()
Task: {339F3FFC-83C7-4318-BE6C-DF18D5201BBD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-14] (Adobe Systems Incorporated)
Task: {4E79AF40-8072-43D7-9E24-F35BAD574F80} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation)
Task: {50AA6259-338B-4846-915E-F013E4F6FB71} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [2016-01-20] ()
Task: {51623AB3-B32C-4188-B825-9614F76158A6} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-10-11] (NVIDIA Corporation)
Task: {6930BEEA-D9B4-4B27-86B8-7AB4E6890A2C} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-10-17] (Acer Incorporate)
Task: {78E74B4C-3EC1-42E9-8281-95B4E63A0F85} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-10-12] (Microsoft Corporation)
Task: {79B0F50A-52CF-4602-AAF0-BDFC915E5CD5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {7AD07647-B3C6-4676-BFE2-C7F83BC125C8} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-11] (NVIDIA Corporation)
Task: {81E5611F-2E93-4354-B8E8-122F25ED4774} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-12-30] (Acer Incorporate)
Task: {8D512A4C-C46A-4A5F-9C7F-E7C18B2B6668} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation)
Task: {97A26C61-A74C-408C-999B-43231EA75FA6} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11] (NVIDIA Corporation)
Task: {A008F27F-8A1C-4B36-8E48-38D7CF0C5A9C} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-10-11] (NVIDIA Corporation)
Task: {A0F1B18B-0D18-4BE2-9755-6D07DD0F7CA0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-05-19] (Piriform Ltd)
Task: {CD169B55-EA2B-4400-BE46-DBA58507ABAC} - System32\Tasks\{8CDC3342-FAE5-4282-B8B2-E686F8AB84BD} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Sims 3\Game\Bin\TS3.exe" -d "C:\Program Files (x86)\Electronic Arts\The Sims 3\Game\Bin"
Task: {E79E559D-BB61-4E1D-8E51-F2C4EEA3EEA4} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation)
Task: {E7A2CED6-B3B7-4C08-9D8F-81041CB80963} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2017-09-26] (Acer Incorporated)
Task: {E949C164-8DEF-4E89-AF78-B17ED4324F35} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-07-22] (Acer Incorporated)
Task: {EE5AA936-9D46-4342-AC43-2D048659A96E} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {F0301614-816C-4CD0-9DE2-773E324B730E} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: <Company name>)
Task: {FA4FDCB5-C773-4C2D-A0DD-B0A4FB6990BE} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2017-10-02] (Acer)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2014-08-22 07:48 - 2014-08-22 07:48 - 000139264 _____ () C:\Windows\system32\ihvmanager\AthIHVManager.dll
2017-05-09 22:37 - 2012-03-28 13:49 - 000140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2017-01-24 01:36 - 2017-10-11 02:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2015-01-23 21:39 - 2012-04-24 11:43 - 000254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2017-11-17 00:25 - 2017-11-01 08:55 - 002299344 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-11-17 00:25 - 2017-11-01 08:54 - 002358736 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-10-30 10:57 - 2017-10-12 20:55 - 000133568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-01-23 21:44 - 2014-07-01 23:13 - 000111872 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
2017-09-28 17:21 - 2017-09-28 17:21 - 001769312 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
2016-01-20 11:50 - 2016-01-20 11:50 - 004644256 _____ () C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
2016-02-29 23:10 - 2016-02-24 05:48 - 000062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll
2016-02-29 23:10 - 2016-02-24 05:47 - 000110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll
2014-02-20 03:51 - 2014-02-20 03:51 - 001241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-01-24 01:36 - 2017-10-11 02:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-01-24 01:37 - 2017-10-11 02:05 - 070805952 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2017-09-22 15:14 - 2017-09-22 15:14 - 000202528 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2017-09-22 15:17 - 2017-09-22 15:17 - 000654072 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2017-09-22 15:17 - 2017-09-22 15:17 - 000641312 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2017-09-22 15:16 - 2017-09-22 15:16 - 000119072 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2017-11-13 18:06 - 2017-11-13 18:06 - 000015136 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2017-09-26 12:35 - 2017-09-26 12:35 - 000013088 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2017-09-26 12:34 - 2017-09-26 12:34 - 000277856 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
2017-10-02 14:56 - 2017-10-02 14:56 - 000202456 _____ () C:\Program Files (x86)\Acer\Acer Portal\curllib.dll
2017-10-02 14:56 - 2017-10-02 14:56 - 000119000 _____ () C:\Program Files (x86)\Acer\Acer Portal\OpenLDAP.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Ludmila\Local Settings:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\Local Settings:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikací:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikací:PKmMZuWDEw7N85o2LAYBSNm [2090]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Classes\.scr: AutoCADScriptFile => C:\WINDOWS\system32\notepad.exe "%1"

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\vsb.cz -> hxxps://vpn.vsb.cz

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2017-11-17 21:47 - 000000753 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ludmila\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\acer01.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\StartupFolder: => "CodeMeter Control Center.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Network Server.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "WindowsDefender"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
HKLM\...\StartupApproved\Run32: => "AdobeCS6ServiceManager"
HKLM\...\StartupApproved\Run32: => "ADSKAppManager"
HKLM\...\StartupApproved\Run32: => "SafeQClient"
HKLM\...\StartupApproved\Run32: => "SwitchBoard"
HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX"
HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\StartupApproved\Run: => "cz.seznam.software.szndesktop"
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\StartupApproved\Run: => "CCleaner Monitoring"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{85B9AFD4-91CB-4550-B893-DDF2144F209B}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{B8139DD8-F0A3-4AC1-8BF4-50AE95DFC933}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{950EEB59-C9D7-486F-BA17-2EC6199A4589}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{835B0EA4-FD28-4448-A2B1-B8F20059BCB2}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{23633245-53FE-4344-BB99-118BA1B87E17}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{9813C324-C566-4631-B025-6BB1D26E104B}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{04DF8B48-A601-4C99-90D6-EBE1A5247E77}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{409BC53E-C8F0-4903-912A-9E31372BB401}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{A01FE9C5-6865-41DF-BD59-92FDECC3DD11}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{C506204A-E5F8-4CF2-8302-ACBD44CCA36D}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{A40481E5-2AE9-4C73-ABCB-082C08EDCDB0}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{E568FFA9-D3E4-48EE-A628-18219312F284}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{48CE9B26-3A8D-48C2-9932-7A7FB2129312}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{4C6757C9-7871-499C-8F15-111BF33160AA}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{E795EBAC-546C-453E-B21F-716A397FB2A9}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{FCFCE770-C386-4AFB-B339-D54B0FE6BE42}] => (Allow) LPort=7935
FirewallRules: [{D59C8040-1A8D-484A-A424-A162B784D057}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{945535EB-E362-4F15-B675-E99B3EEED2FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6631AC43-8529-4551-BFD0-C61A6E9986CD}] => (Allow) LPort=50248
FirewallRules: [{A179E488-C681-43BF-94EC-57128DB240C0}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{3890C53C-F376-48C9-A10E-1DE17F57E752}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{48CD6F92-C641-4211-BB3F-E07FB3F0C976}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{11CC3F11-9E41-4DE3-9475-FB53F46D6111}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{6B60BF11-C9D9-404D-86A4-79420E6D406B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{AB86AD15-3B10-4496-878E-3FE9786ECDA6}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{AD7BC019-080F-41BF-A4A4-A6F707A6B83E}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{D1D9637C-08E6-4447-9F59-00AA8D88B58A}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{D0F2E4C8-6F96-4FB0-AE9A-5AAFFEAB7844}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{787356F9-2351-46CF-8108-EDE01CD3FD0A}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{3A3D9573-FE2F-45D4-820E-44DEB10654F4}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{C23B4F1B-5BAB-4881-83E0-9C08FB55A255}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{EFCE69FE-3037-46BD-ABDA-872C0BDAC30E}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{4F7A1796-1C36-4B31-A8F8-94A656F54170}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{FD5CEAEB-3D0B-4456-864B-E632820CF711}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{D74F2466-EDFC-4BE0-8E6F-1CB973C915B1}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{44525154-4DA5-4DCE-8E8A-5EB11777E4DB}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{B5651027-0F45-44DB-8228-FA820764E7B9}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{9D0572C1-70AA-45C3-A5E7-11E6C7249B6B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{D6E7C677-7940-4C7E-8E56-8D568692B6B3}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{2F4AB64C-153D-4D39-B22B-4BC1C4D0B8BE}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{D93E3FA6-0C39-46A3-B630-4E9437FD4E01}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{CFE8E1AB-6726-47FB-8945-E6DD06261DC7}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{AFA9C197-4C7B-43CB-8819-F11D7DD4D4FC}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [TCP Query User{A6B18182-E23C-4982-98F4-27BD2C7A348E}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{8531EBED-59EA-4429-8D57-D34B04B7B6FB}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{AD3ADAFB-2232-424B-B5AF-0FF313387E8D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{942C148A-5703-4A26-9FD2-2991C1640C2B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{A3EA0ECB-77F3-428C-B5C9-B0FD3B9CD235}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A53C5C91-07F8-4634-94B4-F7E95B0E1BC2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{891FEB53-22FD-4F93-90F5-C6F014870221}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{26D909BF-869C-4821-8682-A1B68BB43244}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{21B820FA-14A2-433F-9798-94C78E97FE08}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{769B11BE-B673-4680-9D5F-70F4A1A7A276}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{8F374351-91A0-4D32-910C-6BC22937F2F1}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{E977D367-B194-4F48-B584-CBD3C7259AF7}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [TCP Query User{48C625D6-FDB7-4731-8BB5-549A52F0B9FA}C:\program files\graphisoft\archicad 20\licensefilegenerator.exe] => (Allow) C:\program files\graphisoft\archicad 20\licensefilegenerator.exe
FirewallRules: [UDP Query User{5DA03ADF-3058-42F9-9936-63750A32BA7B}C:\program files\graphisoft\archicad 20\licensefilegenerator.exe] => (Allow) C:\program files\graphisoft\archicad 20\licensefilegenerator.exe
FirewallRules: [{68668AA0-BFDF-43E8-9E3B-1F21EDAD20B9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{657D334F-90CD-47A8-9B25-5AC499CD087E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{AE43ADE1-37AF-4606-850F-30ABDF9D1BDA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{9A6E363F-4B63-46A8-B1D1-4AF757B07C5F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9C28B82C-8235-40C8-AA82-51809818789B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{322986E5-DCE5-46F7-A77C-65D090448CC7}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\ARCHICAD.exe
FirewallRules: [{5FD0EBFF-C6D9-478C-B45A-902DCE3EB3EF}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\CineRender\CineRender 64bit.exe
FirewallRules: [{82B6063C-DFC8-47CC-A0B6-576112AA0146}] => (Allow) C:\Program Files\GRAPHISOFT\ARCHICAD 20\BIMxUploader.exe
FirewallRules: [{15285DBC-F75D-40AC-9A8F-E4C78264CAE2}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\OverwatchServer.exe
FirewallRules: [{4DBD1885-3D32-47C2-BAD3-B32CA6691FF0}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{976D94A8-3C56-49D7-8BAB-29F669508FF1}] => (Allow) C:\Program Files\GRAPHISOFT\BIM Server 20\BIMcloud Manager\BIMcloud Manager Configurator.exe
FirewallRules: [{7E12E427-259E-4321-88D8-82BD6D7F2380}] => (Allow) C:\Program Files\GRAPHISOFT\BIM Server 20\BIMcloud Manager\BIMcloudMonitor.exe
FirewallRules: [{A2F4FFE3-AFF0-4F7C-B824-4A47F18E89DC}] => (Allow) C:\Program Files\GRAPHISOFT\BIM Server 20\BIMcloud Manager\UpgradeTool.exe
FirewallRules: [{81C41CCC-EBC1-4779-9232-CBD0640BC009}] => (Allow) C:\Program Files\GRAPHISOFT\BIM Server 20\BIMcloud Server 20\BIMcloud Server Configurator.exe
FirewallRules: [{6BC7100C-AC21-42A8-B885-2C28745DA548}] => (Allow) C:\Program Files\GRAPHISOFT\BIM Server 20\BIMcloud Server 20\BIMcloudMonitor.exe
FirewallRules: [TCP Query User{EFBB6864-78B7-4ECD-9826-A8BBFC785E0C}C:\program files\graphisoft\archicad 20\doplnky archicadu\speciality\archicad youtube channel.exe] => (Block) C:\program files\graphisoft\archicad 20\doplnky archicadu\speciality\archicad youtube channel.exe
FirewallRules: [UDP Query User{B048EFEE-3E84-49A9-9593-C484EAD395AA}C:\program files\graphisoft\archicad 20\doplnky archicadu\speciality\archicad youtube channel.exe] => (Block) C:\program files\graphisoft\archicad 20\doplnky archicadu\speciality\archicad youtube channel.exe
FirewallRules: [{76E6E7CB-19A2-40B4-964B-2BA36C1ADDB9}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{034F09DD-59B1-42D1-82B8-374A5CFAF599}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{E69F12ED-C14A-4295-8699-B637536E359F}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{7E47A580-781C-4F92-B457-D2661C0E04CC}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{F29C9EDD-08F2-4B3E-8CCA-08B0FFB05E8F}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{5FD83D3A-8FFD-438A-B1C6-A2221FF03D6B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{3834C304-9974-48B9-90F8-8C9D3DF44A2C}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{832524C8-4860-4DEF-A112-F8CB2D821E13}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server

==================== Restore Points =========================

17-11-2017 21:39:57 JRT Pre-Junkware Removal
17-11-2017 21:41:15 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/18/2017 03:01:14 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: Problém zabránil odeslání dat programu Zlepšování softwaru a služeb na základě zkušeností uživatelů společnosti Microsoft, (chyba 80070005).

Error: (11/17/2017 07:46:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x2f0c
Čas spuštění chybující aplikace: 0x01d35fd4207560d6
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: aeba572d-cbc7-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 07:44:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x4a74
Čas spuštění chybující aplikace: 0x01d35fd30cfbec23
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: 5d9176fe-cbc7-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 07:36:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x3d88
Čas spuštění chybující aplikace: 0x01d35fcfbdf6ba31
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: 4a0117ba-cbc6-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 07:13:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x288c
Čas spuštění chybující aplikace: 0x01d35fce1b6726d0
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: faf66a9b-cbc2-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 07:01:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x2864
Čas spuštění chybující aplikace: 0x01d35fcde3d71d26
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: 58645837-cbc1-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 07:00:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x4a0c
Čas spuštění chybující aplikace: 0x01d35fcd7fc46c28
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: 20c08379-cbc1-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 06:57:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x2638
Čas spuštění chybující aplikace: 0x01d35fcd268be29c
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: bcb65d89-cbc0-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 06:54:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x3f90
Čas spuštění chybující aplikace: 0x01d35fbb008b680d
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: 6365768d-cbc0-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/17/2017 04:22:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: NVDisplay.Container.exe, verze: 1.2.0.0, časové razítko: 0x59dfcd96
Název chybujícího modulu: nvxdapix.dll, verze: 8.17.13.8800, časové razítko: 0x59dfc263
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000305c35
ID chybujícího procesu: 0x1fc
Čas spuštění chybující aplikace: 0x01d35fa817489cec
Cesta k chybující aplikaci: C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
Cesta k chybujícímu modulu: C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
ID zprávy: 150d2c1a-cbab-11e7-82b0-3065ec69064b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (11/17/2017 09:41:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (11/17/2017 09:41:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (11/17/2017 09:40:19 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (11/17/2017 09:40:19 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (11/17/2017 03:50:45 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a119\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3497575666-2220848565-2583033622-1001-11172017155045546-ntuser.dat

Error: (11/17/2017 03:41:55 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a119\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3497575666-2220848565-2583033622-1001-11172017154154882-ntuser.dat

Error: (11/17/2017 02:46:36 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a119\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3497575666-2220848565-2583033622-1001-11172017144636110-ntuser.dat

Error: (11/17/2017 02:31:27 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a119\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3497575666-2220848565-2583033622-1001-11172017143127407-ntuser.dat

Error: (11/17/2017 02:28:50 PM) (Source: DCOM) (EventID: 10010) (User: LUDMILKA)
Description: Server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} se v daném časovém limitu neregistroval u služby DCOM.

Error: (11/17/2017 12:29:37 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a119\??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3497575666-2220848565-2583033622-1001-11172017002937534-ntuser.dat


CodeIntegrity:
===================================
Date: 2017-11-10 22:46:21.349
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\WINDOWS\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-11-10 18:15:19.002
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-11-03 19:03:53.157
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\WINDOWS\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-11-03 19:03:52.839
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-10-23 10:58:51.278
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\WINDOWS\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-10-23 10:58:50.950
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-10-16 15:48:03.671
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\WINDOWS\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-10-16 15:48:03.187
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-10-07 11:20:31.674
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\WINDOWS\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-10-07 11:20:31.409
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-4720HQ CPU @ 2.60GHz
Percentage of memory in use: 23%
Total physical RAM: 12211.27 MB
Available physical RAM: 9359.16 MB
Total Virtual: 14067.27 MB
Available Virtual: 11168.46 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:118.43 GB) (Free:35.22 GB) NTFS
Drive d: (DATA) (Fixed) (Total:916.12 GB) (Free:486.49 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: F0F28B29)

Partition: GPT.

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: F0F28B3E)

Partition: GPT.

==================== End of Addition.txt ============================





Fix result of Farbar Recovery Scan Tool (x64) Version: 19-11-2017
Ran by Ludmila (19-11-2017 17:51:30) Run:1
Running from C:\Users\Ludmila\Desktop
Loaded Profiles: Ludmila (Available Profiles: Ludmila & Administrator)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SERVICE] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-19] (Piriform Ltd)
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\...\Policies\Explorer: []

SearchScopes: HKLM-x32 -> DefaultScope value is missing
Toolbar: HKU\S-1-5-21-3497575666-2220848565-2583033622-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File

AlternateDataStreams: C:\Users\Ludmila\Local Settings:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\Local Settings:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local:PKmMZuWDEw7N85o2LAYBSNm [2090]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikac�:MZMS7yU1fgNVDN8Z [2080]
AlternateDataStreams: C:\Users\Ludmila\AppData\Local\Data aplikac�:PKmMZuWDEw7N85o2LAYBSNm [2090]

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SERVICE => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS6ServiceManager => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe Acrobat Speed Launcher => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Acrobat Assistant 8.0 => value removed successfully
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-3497575666-2220848565-2583033622-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value removed successfully
HKLM\Software\Classes\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => key not found.
C:\Users\Ludmila\Local Settings => ":MZMS7yU1fgNVDN8Z" ADS removed successfully.
C:\Users\Ludmila\Local Settings => ":PKmMZuWDEw7N85o2LAYBSNm" ADS removed successfully.
"C:\Users\Ludmila\AppData\Local" => ":MZMS7yU1fgNVDN8Z" ADS not found.
"C:\Users\Ludmila\AppData\Local" => ":PKmMZuWDEw7N85o2LAYBSNm" ADS not found.
"C:\Users\Ludmila\AppData\Local\Data aplikac�" => ":MZMS7yU1fgNVDN8Z" ADS not found.
"C:\Users\Ludmila\AppData\Local\Data aplikac�" => ":PKmMZuWDEw7N85o2LAYBSNm" ADS not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 31931357 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 941144 B
Edge => 0 B
Chrome => 0 B
Firefox => 396771714 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 4958 B
NetworkService => 0 B
Ludmila => 27455070 B
Administrator => 12373 B

RecycleBin => 33699 B
EmptyTemp: => 444 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:51:54 ====

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#12 Příspěvek od Márty84 »

:!: Vsechny tyto programy - vcetne pripadne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)

:arrow:
vyosek píše: :arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remove disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner http://www.filehippo.com/download_ccleaner a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!
(Pokud je v pc vice uzivatelskych uctu, pouzijte program i v nich)

:arrow: Defragmentujte disk(y) (SSD Disky ne!)
Stahnete program Defraggler https://www.piriform.com/defraggler/download/standard
Pri instalaci opet pozor na toolbar a dalsi nesmysly.
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak to s pc vypada.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

nobody
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 17 úno 2015 20:04

Re: Kontrola Notebooku

#13 Příspěvek od nobody »

Dobrý den,

pokud je počítač s vaší strany čistý, pak je asi vše ok. Nic mi tu nebliká, ani nehlásí žádnou chybu a jede to jak má :)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Kontrola Notebooku

#14 Příspěvek od Márty84 »

Vse co jsem tam videl jsme odstranili, takze pokud neni zadny problem, melo by to byt ciste ;-)

Mejte se krasne a treba zase nekdy :bye:

:closed:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno