Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Hardstyle
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 03 úno 2011 21:36

Preventivka

#1 Příspěvek od Hardstyle »

Dobrý den,
prosím o preventivku, zdá se mi občas, že je pomalejší.
Děkuji

Log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-12-2017
Ran by Admin (administrator) on ADMIN-HP (27-12-2017 18:13:22)
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin (Available Profiles: Admin & Mamka)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Hi-Rez Studios) C:\Games\Smite\HiPatchService.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
( ) C:\Windows\System32\lxbkcoms.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TeamSpeak Systems GmbH) C:\Games\TS 3\ts3client_win64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Allstar) C:\Games\GP klient\GamePark\GameparkClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-04-24] (IDT, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2017-12-22] (AVAST Software)
HKLM-x32\...\Run: [HP KEYBOARDx] => C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE [710656 2010-02-11] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] => C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-08-25] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2511427519-1358874845-2993194906-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-31] (Valve Corporation)
Startup: C:\Users\Mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2012-04-26]
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5E38DBE4-AEC6-477F-A330-FC8A947B3849}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A6A3926B-C598-4AF8-B811-D281D1412BBA}: [DhcpNameServer] 7.254.254.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-2511427519-1358874845-2993194906-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {3CFF406E-8715-43AD-8253-D32BFEDBA9B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> {3CFF406E-8715-43AD-8253-D32BFEDBA9B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2511427519-1358874845-2993194906-1000 -> {3CFF406E-8715-43AD-8253-D32BFEDBA9B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2511427519-1358874845-2993194906-1000 -> {6B906846-E7D3-436D-AF21-BE31CA8A4830} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_14875
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll [2011-06-09] (HP)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-09] (AVAST Software)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-11-07] (Oracle Corporation)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll [2011-06-09] (HP)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-09] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-07] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)

FireFox:
========
FF DefaultProfile: zjypvzcb.default-1440534247601
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\6jpf71t2.default [not found] <==== ATTENTION
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\zjypvzcb.default-1440534247601 [2016-12-01]
FF Homepage: Mozilla\Firefox\Profiles\zjypvzcb.default-1440534247601 -> hxxp://www.google.cz/
FF Extension: (Adblock Plus) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\zjypvzcb.default-1440534247601\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-15] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-07] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-12-15] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-12-15] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2012-06-04] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2511427519-1358874845-2993194906-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-18] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2511427519-1358874845-2993194906-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2012-06-04] (Pando Networks)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default [2017-12-27]
CHR Extension: (Slides) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-06]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-06]
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-06]
CHR Extension: (Adobe Acrobat) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05]
CHR Extension: (Avast SafePrice) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-12-23]
CHR Extension: (Sheets) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-12-08]
CHR Extension: (Avast Online Security) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-06]
CHR Extension: (Chrome Media Router) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-12]
CHR HKU\S-1-5-21-2511427519-1358874845-2993194906-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jpgfhihjicjofdejkbjgnjlaglaciobe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-06-03]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2017-12-22] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2017-12-22] (AVAST Software)
U2 HiPatchService; C:\Games\Smite\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
R2 lxbk_device; C:\Windows\system32\lxbkcoms.exe [565928 2008-02-19] ( )
R2 lxbk_device; C:\Windows\SysWOW64\lxbkcoms.exe [537256 2008-02-19] ( )
R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [40999448 2008-07-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation)
S3 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-12-16] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-12-16] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [463856 2017-12-16] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-12-16] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2017-12-23] ()
S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [369688 2008-07-10] (Microsoft Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [873968 2017-06-30] (Tunngle.net GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 NvStreamNetworkSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" [X]
S2 NvStreamSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [185096 2017-12-22] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2017-12-22] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2017-12-22] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2017-12-22] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2017-12-22] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [149344 2017-12-22] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46976 2017-12-22] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-08-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146664 2017-12-22] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110336 2017-12-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84384 2017-12-22] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1025176 2017-12-22] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [457400 2017-12-22] (AVAST Software)
S2 aswStm; C:\Windows\System32\drivers\aswStm.sys [204456 2017-12-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [358672 2017-12-22] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [279616 2012-01-09] (DT Soft Ltd)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-12-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-12-16] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-12-16] (NVIDIA Corporation)
S3 OxPPort; C:\Windows\system32\drivers\OxPPort.sys [98304 2008-07-31] (OEM)
S3 OxSer; C:\Windows\system32\drivers\OxSer.sys [98352 2009-09-16] (OEM)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-11-22] ()
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11973 2017-12-27] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [39464 2016-04-27] (Tunngle.net GmbH)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-27 18:13 - 2017-12-27 18:14 - 000020918 _____ C:\Users\Admin\Desktop\FRST.txt
2017-12-27 18:12 - 2017-12-27 18:12 - 000112640 _____ (forum.viry.cz) C:\Users\Admin\Desktop\FRSTLauncher.exe
2017-12-27 18:12 - 2017-12-27 18:12 - 000029696 _____ C:\Users\Admin\AppData\Local\MSGBOX.EXE
2017-12-27 18:12 - 2017-12-27 18:12 - 000015327 _____ C:\Users\Admin\Desktop\LM.bat
2017-12-27 18:12 - 2017-12-27 18:12 - 000000000 ____D C:\Users\Admin\Desktop\FRST-OlderVersion
2017-12-27 18:11 - 2017-12-27 18:11 - 000112640 _____ (forum.viry.cz) C:\Users\Admin\Downloads\Unconfirmed 173211.crdownload
2017-12-27 13:51 - 2017-12-27 13:51 - 000000842 _____ C:\Users\Admin\Downloads\start (8).GP1
2017-12-27 13:48 - 2017-12-27 13:48 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-12-26 19:24 - 2017-12-26 19:24 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-12-26 19:24 - 2017-12-15 23:47 - 000143960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-12-26 19:24 - 2017-09-14 00:20 - 000798008 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-12-26 19:24 - 2017-09-14 00:20 - 000490296 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-12-26 19:24 - 2017-09-14 00:19 - 000927544 _____ C:\Windows\system32\vulkan-1.dll
2017-12-26 19:24 - 2017-09-14 00:19 - 000591160 _____ C:\Windows\system32\vulkaninfo.exe
2017-12-26 19:21 - 2017-12-16 01:21 - 040237456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 036305200 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 035157488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 023266400 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 019039976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 018208784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 016854840 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-12-26 19:21 - 2017-12-16 01:21 - 013867656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 013255032 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 011782096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 010883744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 003809072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 003799032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 003347952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 001990128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438871.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 001674736 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438871.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 001135464 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 001100600 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 001031984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000981816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000933168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000885680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000171896 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000154392 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000149552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000132072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-12-26 19:21 - 2017-12-16 01:21 - 000057792 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2017-12-26 19:21 - 2017-12-16 01:21 - 000050624 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-12-24 14:24 - 2017-12-24 14:26 - 000000000 ____D C:\Users\Admin\Desktop\1.0
2017-12-24 14:24 - 2009-06-21 20:34 - 000000000 ____D C:\Users\Admin\Desktop\1.3
2017-12-24 14:24 - 2009-06-21 20:34 - 000000000 ____D C:\Users\Admin\Desktop\1.2
2017-12-24 14:21 - 2017-12-24 14:23 - 059839133 _____ C:\Users\Admin\Downloads\cod2ps11.zip
2017-12-23 22:55 - 2017-12-23 22:55 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashRpt
2017-12-23 22:55 - 2017-12-23 22:55 - 000000000 ____D C:\Users\Admin\AppData\Local\CallofDuty4MW
2017-12-23 20:15 - 2017-12-23 20:15 - 000180934 _____ C:\Users\Admin\Downloads\Do baru (3).zip
2017-12-23 20:01 - 2017-12-23 20:01 - 000144119 _____ C:\Users\Admin\Downloads\Do baru (2).zip
2017-12-23 19:42 - 2017-12-23 19:42 - 000113497 _____ C:\Users\Admin\Downloads\Do baru (1).zip
2017-12-23 19:39 - 2017-12-23 19:39 - 000119289 _____ C:\Users\Admin\Downloads\Do baru.zip
2017-12-22 01:50 - 2017-12-22 01:50 - 000365680 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-12-22 01:50 - 2017-12-22 01:50 - 000149344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2017-12-19 17:58 - 2017-12-19 17:58 - 001205232 _____ (Adobe Systems Incorporated) C:\Users\Admin\Downloads\flashplayer28au_ga_install.exe
2017-12-17 18:18 - 2017-12-17 18:18 - 000325637 _____ C:\Users\Admin\Downloads\Doplňkové_pojistné_podmínky_pro_doplňková_pojištění_vozidel.pdf
2017-12-17 18:17 - 2017-12-17 18:17 - 000288179 _____ C:\Users\Admin\Downloads\Všeobecné_pojistné_podmínky_pro_pojištění_vozidel.pdf
2017-12-17 18:16 - 2017-12-17 18:16 - 000180776 _____ C:\Users\Admin\Downloads\Doplňkové_pojistné_podmínky_pro_povinné_ručení.pdf
2017-12-13 17:28 - 2017-11-17 05:23 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-12-13 17:28 - 2017-11-15 02:27 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-12-13 17:28 - 2017-11-15 01:36 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-12-13 17:28 - 2017-11-14 04:57 - 025731072 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-12-13 17:28 - 2017-11-14 04:43 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-12-13 17:28 - 2017-11-14 04:43 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-12-13 17:28 - 2017-11-14 04:32 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-12-13 17:28 - 2017-11-14 04:31 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-12-13 17:28 - 2017-11-14 04:31 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-12-13 17:28 - 2017-11-14 04:30 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-12-13 17:28 - 2017-11-14 04:30 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-12-13 17:28 - 2017-11-14 04:30 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-12-13 17:28 - 2017-11-14 04:25 - 005925888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-12-13 17:28 - 2017-11-14 04:24 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-12-13 17:28 - 2017-11-14 04:24 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-12-13 17:28 - 2017-11-14 04:21 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-12-13 17:28 - 2017-11-14 04:20 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-12-13 17:28 - 2017-11-14 04:20 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-12-13 17:28 - 2017-11-14 04:20 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-12-13 17:28 - 2017-11-14 04:20 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-12-13 17:28 - 2017-11-14 04:15 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-12-13 17:28 - 2017-11-14 04:12 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-12-13 17:28 - 2017-11-14 04:06 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-12-13 17:28 - 2017-11-14 04:06 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-12-13 17:28 - 2017-11-14 04:05 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-12-13 17:28 - 2017-11-14 04:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-12-13 17:28 - 2017-11-14 04:02 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-12-13 17:28 - 2017-11-14 04:00 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-12-13 17:28 - 2017-11-14 03:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-12-13 17:28 - 2017-11-14 03:51 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-12-13 17:28 - 2017-11-14 03:48 - 015267328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-12-13 17:28 - 2017-11-14 03:48 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-12-13 17:28 - 2017-11-14 03:48 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-12-13 17:28 - 2017-11-14 03:47 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-12-13 17:28 - 2017-11-14 03:46 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-12-13 17:28 - 2017-11-14 03:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-12-13 17:28 - 2017-11-14 03:27 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-12-13 17:28 - 2017-11-14 03:16 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-12-13 17:28 - 2017-11-14 02:37 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-12-13 17:28 - 2017-11-14 02:15 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-12-13 17:28 - 2017-11-14 02:15 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-12-13 17:28 - 2017-11-14 02:15 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-12-13 17:28 - 2017-11-14 02:10 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-12-13 17:28 - 2017-11-14 01:32 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-12-13 17:28 - 2017-11-14 01:31 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-12-13 17:28 - 2017-11-07 21:56 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-12-13 17:28 - 2017-11-07 21:46 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-12-13 17:28 - 2017-11-07 21:46 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-12-13 17:28 - 2017-11-07 21:46 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-12-13 17:28 - 2017-11-07 21:44 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-12-13 17:28 - 2017-11-07 21:41 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-12-13 17:28 - 2017-11-07 21:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-12-13 17:28 - 2017-11-07 21:40 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-12-13 17:28 - 2017-11-07 21:39 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-12-13 17:28 - 2017-11-07 21:38 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-12-13 17:28 - 2017-11-07 21:38 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-12-13 17:28 - 2017-11-07 21:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-12-13 17:28 - 2017-11-07 21:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-12-13 17:28 - 2017-11-07 21:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-12-13 17:28 - 2017-11-07 21:27 - 004509696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-12-13 17:28 - 2017-11-07 21:26 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-12-13 17:28 - 2017-11-07 21:24 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-12-13 17:28 - 2017-11-07 21:19 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-12-13 17:28 - 2017-11-07 21:18 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-12-13 17:28 - 2017-11-07 21:17 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-12-13 17:28 - 2017-11-07 21:17 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-12-13 17:28 - 2017-11-07 21:04 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-12-13 17:28 - 2017-11-07 21:01 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-12-13 17:28 - 2017-11-07 20:58 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-12-13 17:28 - 2017-11-07 17:31 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-12-13 17:28 - 2017-11-07 17:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-12-13 17:28 - 2017-11-04 16:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2017-12-13 17:28 - 2017-11-04 16:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2017-12-13 17:28 - 2017-11-04 16:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2017-12-13 17:28 - 2017-11-04 16:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll
2017-12-13 17:28 - 2017-11-02 16:11 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2017-12-13 17:28 - 2017-11-02 16:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll
2017-12-13 17:28 - 2017-11-02 16:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2017-12-13 17:28 - 2017-11-02 15:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll
2017-12-13 17:28 - 2017-10-17 00:04 - 001001984 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2017-12-13 17:28 - 2017-10-16 23:46 - 000953344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2017-12-13 17:28 - 2017-10-12 01:20 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-12-12 21:56 - 2017-12-12 21:56 - 000000000 ____D C:\Users\Admin\Desktop\Vuch - Amanda - VUCH - Fairy Tale Collection - Peněženky_files
2017-12-11 18:10 - 2017-12-11 18:10 - 000000842 _____ C:\Users\Admin\Downloads\start (7).GP1
2017-12-10 22:30 - 2017-12-10 22:33 - 052026995 _____ C:\Users\Admin\Downloads\nazi_zombie_the_river_v0.6.zip
2017-12-10 22:09 - 2017-12-10 22:11 - 050705789 _____ C:\Users\Admin\Downloads\nazi_zombie_underground.zip
2017-12-10 21:39 - 2009-05-23 22:30 - 000003578 _____ C:\Users\Admin\AppData\Roaming\readme.txt
2017-12-10 21:39 - 2009-05-23 22:28 - 075170144 _____ C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 005565632 _____ C:\Users\Admin\AppData\Roaming\mod.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 000435936 _____ C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.iwd
2017-12-10 21:39 - 2009-05-23 22:28 - 000000848 _____ C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.files
2017-12-10 21:39 - 2009-05-23 22:28 - 000000650 _____ C:\Users\Admin\AppData\Roaming\mod.csv
2017-12-10 21:39 - 2009-05-23 22:28 - 000000330 _____ C:\Users\Admin\AppData\Roaming\mod.arena
2017-12-10 21:39 - 2009-05-19 18:21 - 000484064 _____ C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.iwd
2017-12-10 21:39 - 2009-05-14 15:31 - 000000800 _____ C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan_load.ff
2017-12-10 21:38 - 2009-05-23 22:30 - 000003578 _____ C:\Users\readme.txt
2017-12-10 21:21 - 2017-12-10 21:25 - 081663546 _____ C:\Users\Admin\Desktop\nazi_zombie_carenten.zip
2017-12-10 17:44 - 2017-12-10 17:58 - 000000000 ____D C:\Users\Default\AppData\Local\LogMeIn Hamachi
2017-12-10 17:44 - 2017-12-10 17:58 - 000000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Hamachi
2017-12-10 17:44 - 2017-12-10 17:44 - 000000153 _____ C:\Users\Default\BullseyeCoverageError.txt
2017-12-10 17:44 - 2017-06-29 12:31 - 000035648 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2017-12-10 17:42 - 2017-12-10 17:42 - 000000000 ____D C:\Users\Admin\AppData\Local\LogMeIn
2017-12-10 17:42 - 2017-12-10 17:42 - 000000000 ____D C:\ProgramData\LogMeIn
2017-12-10 17:41 - 2017-12-10 17:44 - 000000166 _____ C:\Users\Admin\BullseyeCoverageError.txt
2017-12-10 17:40 - 2017-12-10 17:41 - 010412032 _____ C:\Users\Admin\Downloads\hamachi.msi
2017-12-10 16:51 - 2017-12-18 18:43 - 000000000 ____D C:\ProgramData\Tunngle
2017-12-10 16:51 - 2017-12-10 16:53 - 000000000 ____D C:\Program Files (x86)\Tunngle
2017-12-10 16:51 - 2017-12-10 16:51 - 000000997 _____ C:\Users\Public\Desktop\Tunngle.lnk
2017-12-10 16:51 - 2017-12-10 16:51 - 000000000 ____D C:\Users\Public\Documents\Tunngle
2017-12-10 16:51 - 2017-12-10 16:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2017-12-10 16:49 - 2017-12-10 16:49 - 004879400 _____ (Tunngle.net GmbH ) C:\Users\Admin\Downloads\Tunngle_Setup_v5.8.9 (1).exe
2017-12-09 19:27 - 2017-12-09 19:27 - 000000000 ____D C:\Users\Admin\AppData\Local\Activision
2017-12-09 18:00 - 2017-12-09 18:00 - 000682280 _____ C:\Windows\SysWOW64\pbsvc.exe
2017-12-09 17:19 - 2016-04-27 00:49 - 000039464 _____ (Tunngle.net GmbH) C:\Windows\system32\Drivers\tap0901t.sys
2017-12-09 17:17 - 2017-12-09 17:17 - 004879400 _____ (Tunngle.net GmbH ) C:\Users\Admin\Downloads\Tunngle_Setup_v5.8.9.exe
2017-12-09 17:12 - 2017-12-09 17:39 - 000000000 ____D C:\Users\Admin\Desktop\Call.Of.Duty.World.At.War-RELOADED
2017-12-06 18:04 - 2017-12-06 18:04 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2017-12-02 16:48 - 2017-12-02 16:48 - 000004751 _____ C:\Users\Admin\AppData\Local\recently-used.xbel

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-27 18:13 - 2015-12-25 13:28 - 000000000 ____D C:\FRST
2017-12-27 18:12 - 2016-12-01 17:59 - 002391552 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2017-12-27 17:52 - 2012-01-05 18:40 - 000000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2017-12-27 16:51 - 2016-04-24 12:15 - 000011973 _____ (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) C:\Windows\SysWOW64\Drivers\SECDRV.SYS
2017-12-27 16:51 - 2012-01-06 12:48 - 000202448 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2017-12-27 16:51 - 2012-01-06 12:48 - 000202448 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2017-12-27 13:57 - 2009-07-14 05:45 - 000027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-12-27 13:57 - 2009-07-14 05:45 - 000027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-12-27 13:50 - 2012-07-27 21:55 - 000000000 ____D C:\Program Files (x86)\Steam
2017-12-27 13:49 - 2012-01-05 15:16 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\AuthenTec
2017-12-27 13:48 - 2011-11-22 08:10 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-27 13:47 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-27 11:59 - 2012-01-06 11:05 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2017-12-27 00:49 - 2011-11-22 08:25 - 000000000 ____D C:\ProgramData\truesuite
2017-12-26 19:27 - 2011-11-22 07:56 - 000735038 _____ C:\Windows\system32\perfh005.dat
2017-12-26 19:27 - 2011-11-22 07:56 - 000166788 _____ C:\Windows\system32\perfc005.dat
2017-12-26 19:27 - 2009-07-14 06:13 - 001771280 _____ C:\Windows\system32\PerfStringBackup.INI
2017-12-26 19:27 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2017-12-26 19:25 - 2017-11-07 20:46 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:25 - 2017-11-07 20:46 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:25 - 2015-12-25 12:27 - 000000000 ____D C:\Users\Admin\AppData\Local\NVIDIA
2017-12-26 19:24 - 2017-11-07 20:46 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:24 - 2017-11-07 20:46 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:24 - 2017-11-07 20:46 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:24 - 2017-11-07 20:46 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:24 - 2017-11-07 20:46 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:24 - 2017-11-07 20:46 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-26 19:24 - 2014-11-27 21:15 - 000000000 ____D C:\temp
2017-12-26 19:24 - 2011-11-22 08:10 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-12-26 19:24 - 2011-11-22 08:09 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-12-26 19:24 - 2011-11-22 08:09 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-12-26 19:23 - 2012-01-06 15:31 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2017-12-25 16:40 - 2017-04-12 16:56 - 000003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-12-25 16:40 - 2017-04-12 16:56 - 000003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-12-25 16:40 - 2015-12-03 13:45 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2017-12-25 16:40 - 2014-12-26 11:53 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-12-24 14:17 - 2012-01-09 22:23 - 000214520 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2017-12-23 22:54 - 2012-01-06 12:48 - 000075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2017-12-23 19:17 - 2017-11-02 20:02 - 000000000 ____D C:\Users\Admin\.gimp-2.8
2017-12-22 01:50 - 2017-11-09 17:33 - 000185096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 001025176 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000457400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000358672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000343768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000321512 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000204456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000199448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000110336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000084384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000057696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000046976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-12-18 19:32 - 2012-08-25 16:56 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Tunngle
2017-12-16 01:21 - 2017-11-07 20:46 - 002404800 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 002070976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 001309120 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 000186304 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 000152512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-12-16 01:21 - 2017-11-07 20:44 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2017-12-16 01:21 - 2017-11-07 20:42 - 029347640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-12-16 01:21 - 2017-11-07 20:42 - 015028168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-12-16 01:21 - 2016-11-14 18:43 - 000492232 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-12-16 01:21 - 2015-06-02 17:49 - 000046182 _____ C:\Windows\system32\nvinfo.pb
2017-12-16 01:21 - 2014-10-29 20:53 - 019526512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-12-16 01:21 - 2013-02-25 23:32 - 022257256 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2017-12-16 01:21 - 2013-02-25 23:32 - 004285520 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-12-15 23:34 - 2015-12-25 12:33 - 000608056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-12-15 23:34 - 2015-12-25 12:33 - 000082928 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-12-15 23:34 - 2011-03-30 10:45 - 005964688 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2017-12-15 23:34 - 2011-03-30 10:45 - 001767408 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2017-12-15 23:34 - 2011-03-30 10:45 - 000450544 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2017-12-15 23:34 - 2011-03-30 10:45 - 000123704 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2017-12-15 23:34 - 2011-03-30 10:44 - 002589168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2017-12-14 19:29 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2017-12-14 19:17 - 2012-11-19 01:03 - 007917671 _____ C:\Windows\system32\nvcoproc.bin
2017-12-14 18:25 - 2009-07-14 05:45 - 000450184 _____ C:\Windows\system32\FNTCACHE.DAT
2017-12-14 18:22 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2017-12-14 18:22 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\Setup
2017-12-13 19:19 - 2013-08-15 01:00 - 000000000 ____D C:\Windows\system32\MRT
2017-12-13 19:16 - 2017-11-19 11:01 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-12-13 19:16 - 2012-01-05 18:57 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-12-12 17:13 - 2016-01-06 17:09 - 000002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-12-12 17:13 - 2016-01-06 17:09 - 000002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-12-10 17:41 - 2012-01-05 15:16 - 000000000 ____D C:\Users\Admin
2017-12-10 17:29 - 2012-01-05 15:27 - 000116200 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2017-12-10 17:13 - 2012-08-25 16:56 - 000000000 ____D C:\Users\Admin\Documents\Tunngle
2017-12-09 19:27 - 2012-01-06 12:48 - 000000000 ____D C:\Users\Admin\AppData\Local\PunkBuster
2017-12-09 18:48 - 2012-01-09 15:39 - 000000000 ____D C:\Users\Admin\AppData\Roaming\uTorrent
2017-12-09 18:48 - 2011-11-22 08:15 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-12-09 18:02 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-12-09 17:56 - 2012-01-09 21:46 - 000000000 ____D C:\Program Files (x86)\Activision
2017-12-09 17:39 - 2012-01-05 18:53 - 000000000 ____D C:\Games
2017-12-02 16:48 - 2017-11-02 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\gtk-2.0
2017-12-02 01:46 - 2016-07-13 17:24 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

==================== Files in the root of some directories =======

2011-11-22 08:24 - 2011-06-10 00:44 - 000002792 _____ () C:\Program Files\HP SimplePass 2011
2015-08-14 21:27 - 2015-08-14 21:27 - 000000046 _____ () C:\Users\Admin\AppData\Roaming\Camdata.ini
2015-08-14 21:27 - 2015-08-14 21:27 - 000000408 _____ () C:\Users\Admin\AppData\Roaming\CamLayout.ini
2015-08-14 21:27 - 2015-08-14 21:27 - 000000408 _____ () C:\Users\Admin\AppData\Roaming\CamShapes.ini
2015-08-14 21:27 - 2015-08-14 21:27 - 000004536 _____ () C:\Users\Admin\AppData\Roaming\CamStudio.cfg
2017-12-10 21:39 - 2009-05-23 22:28 - 000000330 _____ () C:\Users\Admin\AppData\Roaming\mod.arena
2017-12-10 21:39 - 2009-05-23 22:28 - 000000650 _____ () C:\Users\Admin\AppData\Roaming\mod.csv
2017-12-10 21:39 - 2009-05-23 22:28 - 005565632 _____ () C:\Users\Admin\AppData\Roaming\mod.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 075170144 _____ () C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.ff
2017-12-10 21:39 - 2009-05-19 18:21 - 000484064 _____ () C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.iwd
2017-12-10 21:39 - 2009-05-14 15:31 - 000000800 _____ () C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan_load.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 000000848 _____ () C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.files
2017-12-10 21:39 - 2009-05-23 22:28 - 000435936 _____ () C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.iwd
2017-12-10 21:39 - 2009-05-23 22:30 - 000003578 _____ () C:\Users\Admin\AppData\Roaming\readme.txt
2015-08-14 21:25 - 2015-08-14 21:25 - 000000096 _____ () C:\Users\Admin\AppData\Roaming\version2.xml
2017-12-27 18:12 - 2017-12-27 18:12 - 000029696 _____ () C:\Users\Admin\AppData\Local\MSGBOX.EXE
2017-12-02 16:48 - 2017-12-02 16:48 - 000004751 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
2015-04-15 21:38 - 2015-04-29 15:30 - 000007606 _____ () C:\Users\Admin\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2017-12-10 17:41 - 2017-12-10 17:41 - 000010256 _____ () C:\Users\Admin\AppData\Local\Temp\BullseyeCoverage-2-x64.dll
2017-12-10 17:41 - 2017-12-10 17:41 - 000008720 _____ () C:\Users\Admin\AppData\Local\Temp\BullseyeCoverage-2-x86.dll
2016-11-14 18:48 - 2016-10-25 21:00 - 000860776 _____ (NVIDIA Corporation) C:\Users\Admin\AppData\Local\Temp\nvSCPAPI64.dll
2017-11-07 20:42 - 2017-10-27 17:06 - 000370296 _____ (NVIDIA Corporation) C:\Users\Admin\AppData\Local\Temp\nvStInst.exe
2017-04-07 07:25 - 2017-04-19 17:35 - 000040960 _____ (Realtek) C:\Users\Admin\AppData\Local\Temp\rtdrvmon.exe
2017-07-09 16:19 - 2017-07-09 16:19 - 014773216 _____ (Microsoft Corporation) C:\Users\Admin\AppData\Local\Temp\vcredist_x64.exe
2017-03-15 18:57 - 2017-03-15 18:57 - 014456872 _____ (Microsoft Corporation) C:\Users\Admin\AppData\Local\Temp\vc_redist.x86.exe
2017-01-23 14:38 - 2017-05-17 10:40 - 000040960 _____ (Realtek) C:\Users\Mamka\AppData\Local\Temp\rtdrvmon.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-12-20 15:10

==================== End of FRST.txt ============================
Přílohy
Addition.rar
(20.4 KiB) Staženo 33 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 112452
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hardstyle
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 03 úno 2011 21:36

Re: Preventivka

#3 Příspěvek od Hardstyle »

Rudy píše:Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
# AdwCleaner 7.0.6.0 - Logfile created on Fri Dec 29 20:29:30 2017
# Updated on 2017/21/12 by Malwarebytes
# Running on Windows 7 Professional (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@pandonetworks.com\PandoWebPlugin
Deleted: [Key] - HKLM\SOFTWARE\Applian Technologies
Deleted: [Key] - HKLM\SOFTWARE\Classes\Applications\amp.exe
Deleted: [Value] - HKLM\SOFTWARE\RegisteredApplications|FLV and Media Player
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayDVDAudioOnArrival
Deleted: [Key] - HKLM\SOFTWARE\Clients\Media\ApplianMP
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayMusicFilesOnArrival
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayVCDMovieOnArrival
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlaySVCDMovieOnArrival
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayVideoFilesOnArrival
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayDVDMovieOnArrival
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayCDAudioOnArrival


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C1].txt - [2581 B] - [2015/12/25 18:47:55]
C:/AdwCleaner/AdwCleaner[C2].txt - [1548 B] - [2016/12/1 18:5:35]
C:/AdwCleaner/AdwCleaner[C3].txt - [1486 B] - [2017/1/17 18:4:47]
C:/AdwCleaner/AdwCleaner[C4].txt - [1622 B] - [2017/1/18 19:42:44]
C:/AdwCleaner/AdwCleaner[S1].txt - [3838 B] - [2015/12/25 18:45:5]
C:/AdwCleaner/AdwCleaner[S2].txt - [1781 B] - [2016/12/1 18:4:29]
C:/AdwCleaner/AdwCleaner[S3].txt - [1707 B] - [2016/12/22 17:2:3]
C:/AdwCleaner/AdwCleaner[S4].txt - [1781 B] - [2016/12/24 12:15:55]
C:/AdwCleaner/AdwCleaner[S5].txt - [1855 B] - [2017/1/17 18:4:4]
C:/AdwCleaner/AdwCleaner[S6].txt - [1968 B] - [2017/1/18 19:42:30]
C:/AdwCleaner/AdwCleaner[S7].txt - [3100 B] - [2017/5/31 19:16:23]


########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 112452
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#4 Příspěvek od Rudy »

Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hardstyle
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 03 úno 2011 21:36

Re: Preventivka

#5 Příspěvek od Hardstyle »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-12-2017
Ran by Admin (administrator) on ADMIN-HP (29-12-2017 22:45:11)
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin (Available Profiles: Admin & Mamka)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Hi-Rez Studios) C:\Games\Smite\HiPatchService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
( ) C:\Windows\System32\lxbkcoms.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Allstar) C:\Games\GP klient\GamePark\GameparkClient.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-04-24] (IDT, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2017-12-22] (AVAST Software)
HKLM-x32\...\Run: [HP KEYBOARDx] => C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE [710656 2010-02-11] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Remote Solution] => C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896 2009-08-25] (Hewlett-Packard)
HKLM-x32\...\Run: [BATINDICATOR] => C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2511427519-1358874845-2993194906-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3111712 2017-12-15] (Valve Corporation)
Startup: C:\Users\Mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2012-04-26]
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5E38DBE4-AEC6-477F-A330-FC8A947B3849}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A6A3926B-C598-4AF8-B811-D281D1412BBA}: [DhcpNameServer] 7.254.254.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-2511427519-1358874845-2993194906-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {3CFF406E-8715-43AD-8253-D32BFEDBA9B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> {3CFF406E-8715-43AD-8253-D32BFEDBA9B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2511427519-1358874845-2993194906-1000 -> {3CFF406E-8715-43AD-8253-D32BFEDBA9B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-2511427519-1358874845-2993194906-1000 -> {6B906846-E7D3-436D-AF21-BE31CA8A4830} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_14875
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll [2011-06-09] (HP)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-09] (AVAST Software)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-11-07] (Oracle Corporation)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll [2011-06-09] (HP)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-09] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-07] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)

FireFox:
========
FF DefaultProfile: zjypvzcb.default-1440534247601
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\6jpf71t2.default [not found] <==== ATTENTION
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\zjypvzcb.default-1440534247601 [2016-12-01]
FF Homepage: Mozilla\Firefox\Profiles\zjypvzcb.default-1440534247601 -> hxxp://www.google.cz/
FF Extension: (Adblock Plus) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\zjypvzcb.default-1440534247601\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-15] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-07] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-12-15] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-12-15] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2511427519-1358874845-2993194906-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-18] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2511427519-1358874845-2993194906-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2012-06-04] (Pando Networks)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default [2017-12-29]
CHR Extension: (Slides) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-06]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-06]
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-06]
CHR Extension: (Adobe Acrobat) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-05]
CHR Extension: (Avast SafePrice) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-12-23]
CHR Extension: (Sheets) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-12-08]
CHR Extension: (Avast Online Security) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-06]
CHR Extension: (Chrome Media Router) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-12]
CHR HKU\S-1-5-21-2511427519-1358874845-2993194906-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jpgfhihjicjofdejkbjgnjlaglaciobe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-06-03]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2017-12-22] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2017-12-22] (AVAST Software)
U2 HiPatchService; C:\Games\Smite\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
R2 lxbk_device; C:\Windows\system32\lxbkcoms.exe [565928 2008-02-19] ( )
R2 lxbk_device; C:\Windows\SysWOW64\lxbkcoms.exe [537256 2008-02-19] ( )
R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [40999448 2008-07-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation)
S3 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-12-16] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-12-16] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [463856 2017-12-16] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-12-16] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2017-12-23] ()
S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [369688 2008-07-10] (Microsoft Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [873968 2017-06-30] (Tunngle.net GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 NvStreamNetworkSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" [X]
S2 NvStreamSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [185096 2017-12-22] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2017-12-22] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2017-12-22] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2017-12-22] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2017-12-22] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [149344 2017-12-22] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46976 2017-12-22] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-08-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146664 2017-12-22] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110336 2017-12-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84384 2017-12-22] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1025176 2017-12-22] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [457400 2017-12-22] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [204456 2017-12-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [358672 2017-12-22] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [279616 2012-01-09] (DT Soft Ltd)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-12-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-12-16] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-12-16] (NVIDIA Corporation)
S3 OxPPort; C:\Windows\system32\drivers\OxPPort.sys [98304 2008-07-31] (OEM)
S3 OxSer; C:\Windows\system32\drivers\OxSer.sys [98352 2009-09-16] (OEM)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-11-22] ()
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11973 2017-12-28] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [39464 2016-04-27] (Tunngle.net GmbH)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-29 22:44 - 2017-12-29 22:44 - 000059418 _____ C:\Users\Admin\Desktop\FRST3.txt
2017-12-29 22:43 - 2017-12-29 22:44 - 000079208 _____ C:\Users\Admin\Desktop\Addition.txt
2017-12-29 22:41 - 2017-12-29 22:45 - 000020636 _____ C:\Users\Admin\Desktop\FRST.txt
2017-12-29 21:31 - 2017-12-29 21:31 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-12-29 18:51 - 2017-12-29 18:51 - 000000842 _____ C:\Users\Admin\Downloads\start (9).GP1
2017-12-29 18:10 - 2017-12-29 18:10 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-12-29 18:10 - 2017-12-15 23:47 - 000143960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2017-12-29 18:10 - 2017-09-14 00:20 - 000798008 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-12-29 18:10 - 2017-09-14 00:20 - 000490296 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-12-29 18:10 - 2017-09-14 00:19 - 000927544 _____ C:\Windows\system32\vulkan-1.dll
2017-12-29 18:10 - 2017-09-14 00:19 - 000591160 _____ C:\Windows\system32\vulkaninfo.exe
2017-12-29 18:09 - 2017-12-16 01:21 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2017-12-29 18:09 - 2017-12-15 23:34 - 000608056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-12-29 18:09 - 2017-12-15 23:34 - 000082928 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 040237456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 036305200 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 035157488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 029347640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 023266400 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 019039976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 018208784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 016854840 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-12-29 18:07 - 2017-12-16 01:21 - 015028168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 013867656 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 013255032 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 011782096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 010883744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 004285520 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 003809072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 003799032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 003347952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 001990128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438871.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 001674736 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438871.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 001135464 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 001100600 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 001031984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000981816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000933168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000885680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000492232 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000171896 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000154392 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000149552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000132072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-12-29 18:07 - 2017-12-16 01:21 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-12-29 18:07 - 2017-12-16 01:21 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2017-12-29 17:17 - 2017-12-29 17:17 - 008198432 _____ (Malwarebytes) C:\Users\Admin\Desktop\adwcleaner_7.0.6.0.exe
2017-12-29 17:13 - 2017-12-29 17:13 - 000156854 _____ C:\Users\Admin\Downloads\Motherboard_ID_Tool.zip
2017-12-29 16:50 - 2017-12-29 16:50 - 000407120 _____ ( ) C:\Users\Admin\Downloads\sp55325.exe
2017-12-29 16:50 - 2010-10-04 12:02 - 000053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
2017-12-29 16:49 - 2017-12-29 16:50 - 002480952 _____ ( ) C:\Users\Admin\Downloads\sp50888.exe
2017-12-29 16:49 - 2017-12-29 16:49 - 004423072 _____ ( ) C:\Users\Admin\Downloads\sp55326.exe
2017-12-29 16:47 - 2017-12-29 16:47 - 004409544 _____ ( ) C:\Users\Admin\Downloads\sp53951.exe
2017-12-29 16:47 - 2017-12-29 16:47 - 000000000 ____D C:\Intel
2017-12-29 16:43 - 2017-12-29 18:10 - 000000000 ____D C:\Users\Admin\AppData\Roaming\NVIDIA
2017-12-29 16:11 - 2017-12-16 01:21 - 000532792 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2017-12-29 16:11 - 2017-12-16 01:21 - 000438584 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2017-12-29 16:11 - 2017-12-15 23:34 - 005964688 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2017-12-29 16:11 - 2017-12-15 23:34 - 002589168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2017-12-29 16:11 - 2017-12-15 23:34 - 001767408 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2017-12-29 16:11 - 2017-12-15 23:34 - 000450544 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2017-12-29 16:11 - 2017-12-15 23:34 - 000123704 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2017-12-29 16:11 - 2017-12-14 19:17 - 007917671 _____ C:\Windows\system32\nvcoproc.bin
2017-12-27 18:12 - 2017-12-27 18:12 - 000112640 _____ (forum.viry.cz) C:\Users\Admin\Desktop\FRSTLauncher.exe
2017-12-27 18:12 - 2017-12-27 18:12 - 000000000 ____D C:\Users\Admin\Desktop\FRST-OlderVersion
2017-12-27 13:51 - 2017-12-27 13:51 - 000000842 _____ C:\Users\Admin\Downloads\start (8).GP1
2017-12-26 19:21 - 2017-12-16 01:21 - 000057792 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
2017-12-26 19:21 - 2017-12-16 01:21 - 000050624 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-12-24 14:24 - 2017-12-24 14:26 - 000000000 ____D C:\Users\Admin\Desktop\1.0
2017-12-24 14:24 - 2009-06-21 20:34 - 000000000 ____D C:\Users\Admin\Desktop\1.3
2017-12-24 14:24 - 2009-06-21 20:34 - 000000000 ____D C:\Users\Admin\Desktop\1.2
2017-12-24 14:21 - 2017-12-24 14:23 - 059839133 _____ C:\Users\Admin\Downloads\cod2ps11.zip
2017-12-23 22:55 - 2017-12-23 22:55 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashRpt
2017-12-23 22:55 - 2017-12-23 22:55 - 000000000 ____D C:\Users\Admin\AppData\Local\CallofDuty4MW
2017-12-23 20:15 - 2017-12-23 20:15 - 000180934 _____ C:\Users\Admin\Downloads\Do baru (3).zip
2017-12-23 20:01 - 2017-12-23 20:01 - 000144119 _____ C:\Users\Admin\Downloads\Do baru (2).zip
2017-12-23 19:42 - 2017-12-23 19:42 - 000113497 _____ C:\Users\Admin\Downloads\Do baru (1).zip
2017-12-23 19:39 - 2017-12-23 19:39 - 000119289 _____ C:\Users\Admin\Downloads\Do baru.zip
2017-12-22 01:50 - 2017-12-22 01:50 - 000365680 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-12-22 01:50 - 2017-12-22 01:50 - 000149344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2017-12-19 17:58 - 2017-12-19 17:58 - 001205232 _____ (Adobe Systems Incorporated) C:\Users\Admin\Downloads\flashplayer28au_ga_install.exe
2017-12-17 18:18 - 2017-12-17 18:18 - 000325637 _____ C:\Users\Admin\Downloads\Doplňkové_pojistné_podmínky_pro_doplňková_pojištění_vozidel.pdf
2017-12-17 18:17 - 2017-12-17 18:17 - 000288179 _____ C:\Users\Admin\Downloads\Všeobecné_pojistné_podmínky_pro_pojištění_vozidel.pdf
2017-12-17 18:16 - 2017-12-17 18:16 - 000180776 _____ C:\Users\Admin\Downloads\Doplňkové_pojistné_podmínky_pro_povinné_ručení.pdf
2017-12-13 17:28 - 2017-11-17 05:23 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-12-13 17:28 - 2017-11-15 02:27 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-12-13 17:28 - 2017-11-15 01:36 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-12-13 17:28 - 2017-11-14 04:57 - 025731072 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-12-13 17:28 - 2017-11-14 04:43 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-12-13 17:28 - 2017-11-14 04:43 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-12-13 17:28 - 2017-11-14 04:32 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-12-13 17:28 - 2017-11-14 04:31 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-12-13 17:28 - 2017-11-14 04:31 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-12-13 17:28 - 2017-11-14 04:30 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-12-13 17:28 - 2017-11-14 04:30 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-12-13 17:28 - 2017-11-14 04:30 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-12-13 17:28 - 2017-11-14 04:25 - 005925888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-12-13 17:28 - 2017-11-14 04:24 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-12-13 17:28 - 2017-11-14 04:24 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-12-13 17:28 - 2017-11-14 04:21 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-12-13 17:28 - 2017-11-14 04:20 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-12-13 17:28 - 2017-11-14 04:20 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-12-13 17:28 - 2017-11-14 04:20 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-12-13 17:28 - 2017-11-14 04:20 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-12-13 17:28 - 2017-11-14 04:15 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-12-13 17:28 - 2017-11-14 04:12 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-12-13 17:28 - 2017-11-14 04:06 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-12-13 17:28 - 2017-11-14 04:06 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-12-13 17:28 - 2017-11-14 04:05 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-12-13 17:28 - 2017-11-14 04:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-12-13 17:28 - 2017-11-14 04:02 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-12-13 17:28 - 2017-11-14 04:00 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-12-13 17:28 - 2017-11-14 03:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-12-13 17:28 - 2017-11-14 03:51 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-12-13 17:28 - 2017-11-14 03:48 - 015267328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-12-13 17:28 - 2017-11-14 03:48 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-12-13 17:28 - 2017-11-14 03:48 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-12-13 17:28 - 2017-11-14 03:47 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-12-13 17:28 - 2017-11-14 03:46 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-12-13 17:28 - 2017-11-14 03:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-12-13 17:28 - 2017-11-14 03:27 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-12-13 17:28 - 2017-11-14 03:16 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-12-13 17:28 - 2017-11-14 02:37 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-12-13 17:28 - 2017-11-14 02:15 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-12-13 17:28 - 2017-11-14 02:15 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-12-13 17:28 - 2017-11-14 02:15 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-12-13 17:28 - 2017-11-14 02:10 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-12-13 17:28 - 2017-11-14 01:32 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-12-13 17:28 - 2017-11-14 01:31 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-12-13 17:28 - 2017-11-07 21:56 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-12-13 17:28 - 2017-11-07 21:46 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-12-13 17:28 - 2017-11-07 21:46 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-12-13 17:28 - 2017-11-07 21:46 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-12-13 17:28 - 2017-11-07 21:44 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-12-13 17:28 - 2017-11-07 21:41 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-12-13 17:28 - 2017-11-07 21:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-12-13 17:28 - 2017-11-07 21:40 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-12-13 17:28 - 2017-11-07 21:39 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-12-13 17:28 - 2017-11-07 21:38 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-12-13 17:28 - 2017-11-07 21:38 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-12-13 17:28 - 2017-11-07 21:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-12-13 17:28 - 2017-11-07 21:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-12-13 17:28 - 2017-11-07 21:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-12-13 17:28 - 2017-11-07 21:27 - 004509696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-12-13 17:28 - 2017-11-07 21:26 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-12-13 17:28 - 2017-11-07 21:24 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-12-13 17:28 - 2017-11-07 21:19 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-12-13 17:28 - 2017-11-07 21:18 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-12-13 17:28 - 2017-11-07 21:17 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-12-13 17:28 - 2017-11-07 21:17 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-12-13 17:28 - 2017-11-07 21:04 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-12-13 17:28 - 2017-11-07 21:01 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-12-13 17:28 - 2017-11-07 20:58 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-12-13 17:28 - 2017-11-07 17:31 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-12-13 17:28 - 2017-11-07 17:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-12-13 17:28 - 2017-11-04 16:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2017-12-13 17:28 - 2017-11-04 16:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2017-12-13 17:28 - 2017-11-04 16:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2017-12-13 17:28 - 2017-11-04 16:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2017-12-13 17:28 - 2017-11-02 17:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll
2017-12-13 17:28 - 2017-11-02 16:11 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2017-12-13 17:28 - 2017-11-02 16:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll
2017-12-13 17:28 - 2017-11-02 16:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2017-12-13 17:28 - 2017-11-02 15:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll
2017-12-13 17:28 - 2017-10-17 00:04 - 001001984 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2017-12-13 17:28 - 2017-10-16 23:46 - 000953344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2017-12-13 17:28 - 2017-10-12 01:20 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-12-12 21:56 - 2017-12-12 21:56 - 000000000 ____D C:\Users\Admin\Desktop\Vuch - Amanda - VUCH - Fairy Tale Collection - Peněženky_files
2017-12-11 18:10 - 2017-12-11 18:10 - 000000842 _____ C:\Users\Admin\Downloads\start (7).GP1
2017-12-10 22:30 - 2017-12-10 22:33 - 052026995 _____ C:\Users\Admin\Downloads\nazi_zombie_the_river_v0.6.zip
2017-12-10 22:09 - 2017-12-10 22:11 - 050705789 _____ C:\Users\Admin\Downloads\nazi_zombie_underground.zip
2017-12-10 21:39 - 2009-05-23 22:30 - 000003578 _____ C:\Users\Admin\AppData\Roaming\readme.txt
2017-12-10 21:39 - 2009-05-23 22:28 - 075170144 _____ C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 005565632 _____ C:\Users\Admin\AppData\Roaming\mod.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 000435936 _____ C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.iwd
2017-12-10 21:39 - 2009-05-23 22:28 - 000000848 _____ C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.files
2017-12-10 21:39 - 2009-05-23 22:28 - 000000650 _____ C:\Users\Admin\AppData\Roaming\mod.csv
2017-12-10 21:39 - 2009-05-23 22:28 - 000000330 _____ C:\Users\Admin\AppData\Roaming\mod.arena
2017-12-10 21:39 - 2009-05-19 18:21 - 000484064 _____ C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.iwd
2017-12-10 21:39 - 2009-05-14 15:31 - 000000800 _____ C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan_load.ff
2017-12-10 21:38 - 2009-05-23 22:30 - 000003578 _____ C:\Users\readme.txt
2017-12-10 21:21 - 2017-12-10 21:25 - 081663546 _____ C:\Users\Admin\Desktop\nazi_zombie_carenten.zip
2017-12-10 17:44 - 2017-12-10 17:58 - 000000000 ____D C:\Users\Default\AppData\Local\LogMeIn Hamachi
2017-12-10 17:44 - 2017-12-10 17:58 - 000000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Hamachi
2017-12-10 17:44 - 2017-12-10 17:44 - 000000153 _____ C:\Users\Default\BullseyeCoverageError.txt
2017-12-10 17:44 - 2017-06-29 12:31 - 000035648 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2017-12-10 17:42 - 2017-12-10 17:42 - 000000000 ____D C:\Users\Admin\AppData\Local\LogMeIn
2017-12-10 17:42 - 2017-12-10 17:42 - 000000000 ____D C:\ProgramData\LogMeIn
2017-12-10 17:41 - 2017-12-10 17:44 - 000000166 _____ C:\Users\Admin\BullseyeCoverageError.txt
2017-12-10 17:40 - 2017-12-10 17:41 - 010412032 _____ C:\Users\Admin\Downloads\hamachi.msi
2017-12-10 16:51 - 2017-12-18 18:43 - 000000000 ____D C:\ProgramData\Tunngle
2017-12-10 16:51 - 2017-12-10 16:53 - 000000000 ____D C:\Program Files (x86)\Tunngle
2017-12-10 16:51 - 2017-12-10 16:51 - 000000997 _____ C:\Users\Public\Desktop\Tunngle.lnk
2017-12-10 16:51 - 2017-12-10 16:51 - 000000000 ____D C:\Users\Public\Documents\Tunngle
2017-12-10 16:51 - 2017-12-10 16:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2017-12-10 16:49 - 2017-12-10 16:49 - 004879400 _____ (Tunngle.net GmbH ) C:\Users\Admin\Downloads\Tunngle_Setup_v5.8.9 (1).exe
2017-12-09 19:27 - 2017-12-09 19:27 - 000000000 ____D C:\Users\Admin\AppData\Local\Activision
2017-12-09 18:00 - 2017-12-09 18:00 - 000682280 _____ C:\Windows\SysWOW64\pbsvc.exe
2017-12-09 17:19 - 2016-04-27 00:49 - 000039464 _____ (Tunngle.net GmbH) C:\Windows\system32\Drivers\tap0901t.sys
2017-12-09 17:17 - 2017-12-09 17:17 - 004879400 _____ (Tunngle.net GmbH ) C:\Users\Admin\Downloads\Tunngle_Setup_v5.8.9.exe
2017-12-09 17:12 - 2017-12-09 17:39 - 000000000 ____D C:\Users\Admin\Desktop\Call.Of.Duty.World.At.War-RELOADED
2017-12-06 18:04 - 2017-12-06 18:04 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2017-12-02 16:48 - 2017-12-02 16:48 - 000004751 _____ C:\Users\Admin\AppData\Local\recently-used.xbel

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-29 22:45 - 2015-12-25 13:28 - 000000000 ____D C:\FRST
2017-12-29 22:37 - 2012-01-05 18:40 - 000000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2017-12-29 22:15 - 2012-01-06 11:05 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2017-12-29 21:39 - 2009-07-14 05:45 - 000027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-12-29 21:39 - 2009-07-14 05:45 - 000027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-12-29 21:32 - 2012-07-27 21:55 - 000000000 ____D C:\Program Files (x86)\Steam
2017-12-29 21:31 - 2012-01-05 15:16 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\AuthenTec
2017-12-29 21:30 - 2011-11-22 08:10 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-29 21:30 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-29 21:28 - 2015-12-25 19:45 - 000000000 ____D C:\AdwCleaner
2017-12-29 18:56 - 2012-01-06 12:48 - 000202448 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2017-12-29 18:56 - 2012-01-06 12:48 - 000202448 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2017-12-29 18:49 - 2015-12-25 12:27 - 000000000 ____D C:\Users\Admin\AppData\Local\NVIDIA
2017-12-29 18:13 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2017-12-29 18:10 - 2017-11-07 20:46 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2017-11-07 20:46 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 18:10 - 2014-11-27 21:15 - 000000000 ____D C:\temp
2017-12-29 18:10 - 2011-11-22 08:10 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-12-29 18:10 - 2011-11-22 08:09 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-12-29 18:10 - 2011-11-22 08:09 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-12-29 16:50 - 2011-11-22 08:15 - 000000000 ____D C:\Program Files (x86)\Intel
2017-12-29 16:50 - 2011-02-11 17:32 - 000000000 ____D C:\SWSETUP
2017-12-29 16:11 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\Help
2017-12-29 13:25 - 2017-04-12 16:56 - 000003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-12-29 13:25 - 2017-04-12 16:56 - 000003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-12-29 13:25 - 2015-12-03 13:45 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2017-12-29 13:25 - 2014-12-26 11:53 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-12-29 00:29 - 2011-11-22 08:25 - 000000000 ____D C:\ProgramData\truesuite
2017-12-28 22:25 - 2016-04-24 12:15 - 000011973 _____ (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) C:\Windows\SysWOW64\Drivers\SECDRV.SYS
2017-12-27 22:06 - 2012-12-16 00:23 - 000008832 _____ C:\Users\Admin\Desktop\config_mp.cfg
2017-12-27 18:12 - 2016-12-01 17:59 - 002391552 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2017-12-26 19:27 - 2011-11-22 07:56 - 000735038 _____ C:\Windows\system32\perfh005.dat
2017-12-26 19:27 - 2011-11-22 07:56 - 000166788 _____ C:\Windows\system32\perfc005.dat
2017-12-26 19:27 - 2009-07-14 06:13 - 001771280 _____ C:\Windows\system32\PerfStringBackup.INI
2017-12-26 19:23 - 2012-01-06 15:31 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2017-12-24 14:17 - 2012-01-09 22:23 - 000214520 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2017-12-23 22:54 - 2012-01-06 12:48 - 000075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2017-12-23 19:17 - 2017-11-02 20:02 - 000000000 ____D C:\Users\Admin\.gimp-2.8
2017-12-22 01:50 - 2017-11-09 17:33 - 000185096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 001025176 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000457400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000358672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000343768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000321512 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000204456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000199448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000110336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000084384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000057696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000046976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-12-22 01:50 - 2017-04-02 09:34 - 000003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-12-18 19:32 - 2012-08-25 16:56 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Tunngle
2017-12-16 01:21 - 2017-11-07 20:46 - 002404800 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 002070976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 001309120 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 000186304 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 000152512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-12-16 01:21 - 2017-11-07 20:46 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-12-16 01:21 - 2015-07-29 16:42 - 022257256 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2017-12-16 01:21 - 2015-07-29 16:42 - 019526512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-12-16 01:21 - 2015-07-29 16:42 - 000046182 _____ C:\Windows\system32\nvinfo.pb
2017-12-14 19:29 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2017-12-14 18:25 - 2009-07-14 05:45 - 000450184 _____ C:\Windows\system32\FNTCACHE.DAT
2017-12-14 18:22 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2017-12-14 18:22 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\Setup
2017-12-13 19:19 - 2013-08-15 01:00 - 000000000 ____D C:\Windows\system32\MRT
2017-12-13 19:16 - 2017-11-19 11:01 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-12-13 19:16 - 2012-01-05 18:57 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-12-12 17:13 - 2016-01-06 17:09 - 000002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-12-12 17:13 - 2016-01-06 17:09 - 000002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-12-10 17:41 - 2012-01-05 15:16 - 000000000 ____D C:\Users\Admin
2017-12-10 17:29 - 2012-01-05 15:27 - 000116200 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2017-12-10 17:13 - 2012-08-25 16:56 - 000000000 ____D C:\Users\Admin\Documents\Tunngle
2017-12-09 19:27 - 2012-01-06 12:48 - 000000000 ____D C:\Users\Admin\AppData\Local\PunkBuster
2017-12-09 18:48 - 2012-01-09 15:39 - 000000000 ____D C:\Users\Admin\AppData\Roaming\uTorrent
2017-12-09 18:48 - 2011-11-22 08:15 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-12-09 18:02 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-12-09 17:56 - 2012-01-09 21:46 - 000000000 ____D C:\Program Files (x86)\Activision
2017-12-09 17:39 - 2012-01-05 18:53 - 000000000 ____D C:\Games
2017-12-02 16:48 - 2017-11-02 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\gtk-2.0
2017-12-02 01:46 - 2016-07-13 17:24 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

==================== Files in the root of some directories =======

2011-11-22 08:24 - 2011-06-10 00:44 - 000002792 _____ () C:\Program Files\HP SimplePass 2011
2015-08-14 21:27 - 2015-08-14 21:27 - 000000046 _____ () C:\Users\Admin\AppData\Roaming\Camdata.ini
2015-08-14 21:27 - 2015-08-14 21:27 - 000000408 _____ () C:\Users\Admin\AppData\Roaming\CamLayout.ini
2015-08-14 21:27 - 2015-08-14 21:27 - 000000408 _____ () C:\Users\Admin\AppData\Roaming\CamShapes.ini
2015-08-14 21:27 - 2015-08-14 21:27 - 000004536 _____ () C:\Users\Admin\AppData\Roaming\CamStudio.cfg
2017-12-10 21:39 - 2009-05-23 22:28 - 000000330 _____ () C:\Users\Admin\AppData\Roaming\mod.arena
2017-12-10 21:39 - 2009-05-23 22:28 - 000000650 _____ () C:\Users\Admin\AppData\Roaming\mod.csv
2017-12-10 21:39 - 2009-05-23 22:28 - 005565632 _____ () C:\Users\Admin\AppData\Roaming\mod.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 075170144 _____ () C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.ff
2017-12-10 21:39 - 2009-05-19 18:21 - 000484064 _____ () C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan.iwd
2017-12-10 21:39 - 2009-05-14 15:31 - 000000800 _____ () C:\Users\Admin\AppData\Roaming\nazi_zombie_carentan_load.ff
2017-12-10 21:39 - 2009-05-23 22:28 - 000000848 _____ () C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.files
2017-12-10 21:39 - 2009-05-23 22:28 - 000435936 _____ () C:\Users\Admin\AppData\Roaming\Nazi_Zombie_Experience.iwd
2017-12-10 21:39 - 2009-05-23 22:30 - 000003578 _____ () C:\Users\Admin\AppData\Roaming\readme.txt
2015-08-14 21:25 - 2015-08-14 21:25 - 000000096 _____ () C:\Users\Admin\AppData\Roaming\version2.xml
2017-12-02 16:48 - 2017-12-02 16:48 - 000004751 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel
2015-04-15 21:38 - 2015-04-29 15:30 - 000007606 _____ () C:\Users\Admin\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2017-12-10 17:41 - 2017-12-10 17:41 - 000010256 _____ () C:\Users\Admin\AppData\Local\Temp\BullseyeCoverage-2-x64.dll
2017-12-10 17:41 - 2017-12-10 17:41 - 000008720 _____ () C:\Users\Admin\AppData\Local\Temp\BullseyeCoverage-2-x86.dll
2016-11-14 18:48 - 2016-10-25 21:00 - 000860776 _____ (NVIDIA Corporation) C:\Users\Admin\AppData\Local\Temp\nvSCPAPI64.dll
2017-11-07 20:42 - 2015-07-23 01:46 - 000783688 _____ (NVIDIA Corporation) C:\Users\Admin\AppData\Local\Temp\nvStInst.exe
2017-04-07 07:25 - 2017-04-19 17:35 - 000040960 _____ (Realtek) C:\Users\Admin\AppData\Local\Temp\rtdrvmon.exe
2017-07-09 16:19 - 2017-07-09 16:19 - 014773216 _____ (Microsoft Corporation) C:\Users\Admin\AppData\Local\Temp\vcredist_x64.exe
2017-03-15 18:57 - 2017-03-15 18:57 - 014456872 _____ (Microsoft Corporation) C:\Users\Admin\AppData\Local\Temp\vc_redist.x86.exe
2017-01-23 14:38 - 2017-05-17 10:40 - 000040960 _____ (Realtek) C:\Users\Mamka\AppData\Local\Temp\rtdrvmon.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-12-29 11:13

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 112452
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\6jpf71t2.default [not found] <==== ATTENTION
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Admin\AppData\Local\Temp

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hardstyle
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 03 úno 2011 21:36

Re: Preventivka

#7 Příspěvek od Hardstyle »

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-12-2017
Ran by Admin (30-12-2017 16:22:22) Run:4
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin (Available Profiles: Admin & Mamka)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\6jpf71t2.default [not found] <==== ATTENTION
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\Admin\AppData\Local\Temp

EmptyTemp:
End
*****************

"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" => removed successfully
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\6jpf71t2.default => path removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully

"C:\Users\Admin\AppData\Local\Temp" folder move:

Could not move "C:\Users\Admin\AppData\Local\Temp" => Scheduled to move on reboot.


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 32809561 B
Java, Flash, Steam htmlcache => 259689794 B
Windows/system/drivers => 47027830 B
Edge => 0 B
Chrome => 797960850 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Admin => 958282709 B
UpdatusUser => 0 B
Mamka => 20627656 B

RecycleBin => 3853982643 B
EmptyTemp: => 5.6 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 30-12-2017 16:25:17)

C:\Users\Admin\AppData\Local\Temp => moved successfully

==== End of Fixlog 16:25:20 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 112452
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#8 Příspěvek od Rudy »

Smazáno, log by již měl být OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hardstyle
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 03 úno 2011 21:36

Re: Preventivka

#9 Příspěvek od Hardstyle »

Rudy píše:Smazáno, log by již měl být OK.
Děkuji.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 112452
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#10 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno