Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

ESET: Našla sa hrozba

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
psychoSVK
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 08 čer 2007 17:47

ESET: Našla sa hrozba

#1 Příspěvek od psychoSVK »

Zdravím, zapol som PC a eset mi zrazu vyhodil túto hlášku.


RSIT log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Matúš at 2016-08-21 15:57:18
Microsoft Windows 10 Home
System drive C: has 57 GB (25%) free of 228 GB
Total RAM: 7605 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:57:20, on 21.8.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Realtek\LanOptimizer\LanOptimizer.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Users\Matúš\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\ProgramData\Oracle\Java\javapath\javaw.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_242.exe
C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_242.exe
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.24\deploy\LoLLauncher.exe
C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.64\deploy\LoLPatcher.exe
C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.212\deploy\LolClient.exe
C:\Program Files\trend micro\Matúš.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo15.msn.com/?pc=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://xn--koa.net/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Matúš\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [AirDroid 3] C:\Program Files (x86)\AirDroid\AirDroid.exe /start
O4 - HKCU\..\Run: [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Matúš\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_242_Plugin.exe -update plugin
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIILE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-205 207 Series" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIILE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-205 207 Series" (User 'Default user')
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O4 - Global Startup: SACRA tray icon.lnk = C:\Program Files (x86)\Dynafleet Stand Alone Card Reader Application\bat\startTrayIcon.bat
O8 - Extra context menu item: Clip bookmark - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
O8 - Extra context menu item: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
O9 - Extra button: @C:\WINDOWS\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\WINDOWS\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.hola.org
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\WINDOWS\system32\EscSvc64.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Smart TimeLock Service (Smart TimeLock) - Gigabyte Technology CO., LTD. - C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13287 bytes

======Listing Processes======







C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork

C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
dashost.exe {690ab54f-b768-4ae1-a5f5c4f4bb79201f}

C:\WINDOWS\system32\EscSvc64.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\AUDIODG.EXE 0x414

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"dwm.exe"
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\Realtek\LanOptimizer\LanOptimizer.exe" /hw
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
igfxEM.exe
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe"
"C:\Program Files (x86)\Steam\Steam.exe" -silent
C:\WINDOWS\system32\wbem\WmiApSrv.exe
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" "-cachedir=C:\Users\Matúš\AppData\Local\Steam\htmlcache" "-steampid=7972" "-buildid=1468023330" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Users\Matúš\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
javaw -classpath "../lib/cra/companycardreader.jar;../lib/cra/spring-core.jar;../lib/cra/spring-aop.jar;../lib/cra/spring-context.jar;../lib/cra/spring-beans.jar;../lib/cra/spring-expression.jar;../lib/cra/spring-web.jar;../lib/cra/aopalliance-1.0.jar;../lib/core/commons/commons-logging-1.1.jar;../lib/core/commons/commons-httpclient-3.1.jar;../lib/core/commons/commons-codec-1.2.jar;../lib/cra/tddportal-common.jar;../lib/cra/wcar-common.jar;../lib/cra/jnlp-api-1.6.0.jar;../lib/core/netty/netty-3.3.1.Final.jar" com.wirelesscar.dynafleet.cardreader.LaunchCraTrayIcon
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"fontdrvhost.exe"
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}
C:\Windows\System32\smartscreen.exe -Embedding
taskhostw.exe
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" "-osint" "-url" "http://go.eset.eu/alertinfo?lng=1051&pr ... NNT64&id=0"
"C:\WINDOWS\system32\nvvsvc.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe"
C:\WINDOWS\system32\msiexec.exe /V

"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="5448.0.1206101465\961336401" "C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5448 "\\.\pipe\gecko-crash-server-pipe.5448" plugin
"C:\WINDOWS\System32\Macromed\Flash\FlashPlayerPlugin_21_0_0_242.exe" --proxy-stub-channel=Flash1804.55ACCFD0.9402 --host-broker-channel=Flash1804.55ACCFD0.16585 --host-pid=1804 --host-npapi-version=29 --plugin-path="C:\WINDOWS\System32\Macromed\Flash\NPSWF32_21_0_0_242.dll"
"C:\WINDOWS\System32\Macromed\Flash\FlashPlayerPlugin_21_0_0_242.exe" --channel=600.004FF58C.1247267775 --proxy-stub-channel=Flash1804.55ACCFD0.9402 --plugin-path="C:\WINDOWS\System32\Macromed\Flash\NPSWF32_21_0_0_242.dll" --host-npapi-version=29 --type=renderer
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe" updateandrun lol_launcher LoLLauncher.exe
LoLLauncher.exe
"C:/Riot Games/League of Legends/RADS/projects/lol_patcher/releases/0.0.0.64/deploy/LoLPatcher.exe" ""
"C:/Riot Games/League of Legends/RADS/projects/lol_air_client/releases/0.0.1.212/deploy//LolClient.exe" "-runtime" ".\\" "-nodebug" "META-INF\AIR\application.xml" ".\\" "--" "8393"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 660 664 672 8192 668
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Matúš\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ashampoo Burning Studio Update.job - C:\Windows\system32\wscript.exe //nologo //B //E:jscript "C:\Users\Matúš\AppData\Roaming\Ashampoo Burning Studio\settings.ini"
C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe /NOUACCHECK
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\RtlLanOptimizerVistaStart.job - C:\Program Files (x86)\Realtek\LanOptimizer\LanOptimizer.exe /hw

=========Mozilla firefox=========

ProfilePath - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default

prefs.js - "browser.startup.homepage" - "www.google.sk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.242 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.101.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.101.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.242 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll


C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\extensions\
{6AC85730-7D0F-4de0-B3FA-21142DD85326}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-24 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-09-03 629256]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-24 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-07-07 8497368]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-06-14 2397120]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-06-14 1767944]
"CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2014-09-08 464608]
"Windows Mobile Device Center"=C:\WINDOWS\WindowsMobile\wmdc.exe [2007-05-31 660360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-08-03 2852128]
"OneDrive"=C:\Users\Matúš\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-08-03 554184]
"AirDroid 3"=C:\Program Files (x86)\AirDroid\AirDroid.exe [2016-06-21 8679424]
"Overwolf"=C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [2016-07-17 247344]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2016-01-15 4177784]
"Spotify Web Helper"=C:\Users\Matúš\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-07-13 1554032]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-06-10 8810200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_242_Plugin.exe [2016-05-13 1173184]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-06-22 598552]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SACRA tray icon.lnk - C:\Program Files (x86)\Dynafleet Stand Alone Card Reader Application\bat\startTrayIcon.bat

C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CurseClientStartup.ccip
EvernoteClipper.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-08-21 15:52:10 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2016-08-21 15:51:43 ----D---- C:\WINDOWS\LastGood
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFThevc.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvDecMFTMjpeg.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvmcumd.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvEncMFThevc.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvdispgenco6437254.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvdispco6437254.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-08-21 15:50:42 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-08-21 15:44:06 ----HD---- C:\OneDriveTemp
2016-08-10 17:18:50 ----A---- C:\WINDOWS\system32\win32u.dll
2016-08-10 17:18:50 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-08-10 17:18:50 ----A---- C:\WINDOWS\system32\win32k.sys
2016-08-10 17:18:49 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-08-10 17:18:49 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2016-08-10 17:18:49 ----A---- C:\WINDOWS\system32\shell32.dll
2016-08-10 17:18:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2016-08-10 17:18:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2016-08-10 17:18:46 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2016-08-10 17:18:46 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-08-10 17:18:45 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-08-10 17:18:45 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2016-08-10 17:18:45 ----A---- C:\WINDOWS\SYSWOW64\Chakrathunk.dll
2016-08-10 17:18:45 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-08-10 17:18:45 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-08-10 17:18:45 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-08-10 17:18:44 ----A---- C:\WINDOWS\SYSWOW64\win32u.dll
2016-08-10 17:18:44 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2016-08-10 17:18:44 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys
2016-08-10 17:18:44 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2016-08-10 17:18:44 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-08-10 17:18:43 ----A---- C:\WINDOWS\system32\Chakrathunk.dll
2016-08-10 17:18:43 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2016-08-10 17:18:42 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\mspaint.exe
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2016-08-10 17:18:41 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-08-10 17:18:40 ----A---- C:\WINDOWS\system32\twinui.dll
2016-08-10 17:18:40 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-08-10 17:18:40 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-08-10 17:18:40 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-08-10 17:18:40 ----A---- C:\WINDOWS\system32\aclui.dll
2016-08-10 17:18:39 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-08-10 17:18:39 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-08-09 19:55:19 ----D---- C:\Program Files (x86)\Ubisoft
2016-08-03 17:06:38 ----D---- C:\ProgramData\Microsoft OneDrive
2016-08-03 16:22:17 ----DC---- C:\WINDOWS\Panther
2016-08-03 16:20:57 ----D---- C:\Windows.old
2016-08-03 16:20:53 ----A---- C:\WINDOWS\SYSWOW64\wevtapi.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\wevtapi.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\user32.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\msctf.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\cdd.dll
2016-08-03 16:20:53 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-08-03 16:20:44 ----A---- C:\WINDOWS\SYSWOW64\NlsLexicons0009.dll
2016-08-03 16:20:44 ----A---- C:\WINDOWS\SYSWOW64\NlsData0009.dll
2016-08-03 16:20:44 ----A---- C:\WINDOWS\system32\prm0009.dll
2016-08-03 16:20:44 ----A---- C:\WINDOWS\system32\NlsLexicons0009.dll
2016-08-03 16:20:44 ----A---- C:\WINDOWS\system32\NlsData0009.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsRemoteEngine.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsProxyStub.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsExperiment.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsDesktopEngine.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsCapture.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VSD3DWARPDebug.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\VSD3DWARP12Debug.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\perf_gputiming.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXToolsReporting.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DxToolsReportGenerator.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXToolsOfflineAnalysis.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXToolsMonitor.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXGIDebug.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXCpl.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXCaptureReplay.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\DXCap.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\d3d12warp.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\d3d12SDKLayers.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\d3d11_3SDKLayers.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\SYSWOW64\d2d1debug3.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\perf_gputiming.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXToolsReporting.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXToolsMonitor.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXGIDebug.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXCpl.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXCaptureReplay.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\DXCap.exe
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\d3d12warp.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-08-03 16:20:42 ----A---- C:\WINDOWS\system32\d2d1debug3.dll
2016-08-03 16:20:23 ----D---- C:\WINDOWS\system32\Microsoft
2016-08-03 16:20:23 ----D---- C:\WINDOWS\ServiceProfiles
2016-08-03 16:19:13 ----D---- C:\Program Files\Reference Assemblies
2016-08-03 16:19:13 ----D---- C:\Program Files\MSBuild
2016-08-03 16:19:13 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-08-03 16:19:13 ----D---- C:\Program Files (x86)\MSBuild
2016-08-03 16:19:02 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2016-08-03 16:19:02 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2016-08-03 16:19:02 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-08-03 16:19:01 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2016-08-03 16:19:01 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-08-03 16:19:01 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-08-03 15:32:19 ----D---- C:\ProgramData\USOShared
2016-08-03 15:26:22 ----ASH---- C:\hiberfil.sys
2016-08-03 15:24:00 ----SD---- C:\Users\Matúš\AppData\Roaming\Microsoft
2016-08-03 15:23:27 ----AS---- C:\WINDOWS\bootstat.dat
2016-08-03 15:23:25 ----D---- C:\ProgramData\NVIDIA
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-08-03 15:23:24 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-08-03 15:23:22 ----HD---- C:\Program Files (x86)\Uninstall Information
2016-08-03 15:23:18 ----D---- C:\ProgramData\NVIDIA Corporation
2016-08-03 15:23:14 ----D---- C:\Program Files\NVIDIA Corporation
2016-08-03 15:23:14 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-08-03 15:23:12 ----A---- C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-08-03 15:23:12 ----A---- C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-03 15:23:11 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.DLL
2016-08-03 15:23:11 ----A---- C:\WINDOWS\system32\OpenCL.DLL
2016-08-03 15:23:10 ----D---- C:\Program Files\Intel
2016-08-03 15:23:01 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2016-08-03 15:23:01 ----D---- C:\Program Files\Realtek
2016-08-03 15:22:58 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-08-03 15:22:55 ----D---- C:\WINDOWS\Prefetch
2016-08-03 15:22:46 ----D---- C:\WINDOWS\system32\SleepStudy
2016-08-03 15:22:39 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-02 14:45:00 ----D---- C:\ProgramData\ESET
2016-07-25 11:37:49 ----D---- C:\Users\Matúš\AppData\Roaming\TeamViewer

======List of files/folders modified in the last 1 month======

2016-08-21 15:57:19 ----D---- C:\Program Files\trend micro
2016-08-21 15:57:02 ----D---- C:\WINDOWS\Temp
2016-08-21 15:52:30 ----D---- C:\WINDOWS\SysWOW64
2016-08-21 15:52:30 ----D---- C:\WINDOWS\System32
2016-08-21 15:52:29 ----SHD---- C:\WINDOWS\Installer
2016-08-21 15:52:29 ----D---- C:\Windows
2016-08-21 15:52:26 ----D---- C:\WINDOWS\INF
2016-08-21 15:52:09 ----D---- C:\WINDOWS\system32\DriverStore
2016-08-21 15:52:09 ----D---- C:\WINDOWS\system32\CatRoot
2016-08-21 15:52:08 ----D---- C:\WINDOWS\system32\drivers
2016-08-21 15:52:07 ----D---- C:\Program Files (x86)\VulkanRT
2016-08-21 15:51:40 ----D---- C:\WINDOWS\system32\catroot2
2016-08-21 15:46:49 ----HD---- C:\Program Files\WindowsApps
2016-08-21 15:43:58 ----D---- C:\Program Files (x86)\Steam
2016-08-16 07:45:24 ----A---- C:\WINDOWS\system32\nvhdagenco6420103.dll
2016-08-13 11:41:00 ----D---- C:\WINDOWS\system32\sru
2016-08-13 10:37:59 ----D---- C:\WINDOWS\AppReadiness
2016-08-13 09:16:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-13 08:44:13 ----AD---- C:\Program Files (x86)\World of Warcraft
2016-08-13 08:42:41 ----AD---- C:\Program Files (x86)\Battle.net
2016-08-12 16:53:55 ----RD---- C:\WINDOWS\Microsoft.NET
2016-08-12 16:02:15 ----D---- C:\Users\Matúš\AppData\Roaming\vlc
2016-08-12 16:01:39 ----D---- C:\Users\Matúš\AppData\Roaming\AIMP3
2016-08-12 10:35:56 ----D---- C:\WINDOWS\system32\config
2016-08-11 21:28:14 ----D---- C:\WINDOWS\WinSxS
2016-08-11 16:33:58 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-08-11 16:33:58 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-08-10 18:06:43 ----D---- C:\WINDOWS\system32\WDI
2016-08-10 18:04:52 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-10 18:04:28 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\zh-TW
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\zh-HK
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\zh-CN
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\uk-UA
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\tr-TR
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\th-TH
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\sv-SE
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\sl-SI
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\sk-SK
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\ru-RU
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\ro-RO
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\pt-PT
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\pt-BR
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\pl-PL
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\nl-NL
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\nb-NO
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\lv-LV
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\lt-LT
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\ko-KR
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\ja-jp
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\it-IT
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\hu-HU
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\hr-HR
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\he-IL
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\fr-FR
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\fr-CA
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\fi-FI
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\et-EE
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\es-MX
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\es-ES
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\en-US
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\en-GB
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\el-GR
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\de-DE
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\da-DK
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\cs-CZ
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\bg-BG
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\ar-SA
2016-08-10 18:04:28 ----D---- C:\WINDOWS\system32\appraiser
2016-08-10 18:04:28 ----D---- C:\WINDOWS\ShellExperiences
2016-08-10 18:04:28 ----D---- C:\Program Files\Windows Mail
2016-08-10 18:04:28 ----D---- C:\Program Files (x86)\Windows Mail
2016-08-10 17:21:30 ----D---- C:\WINDOWS\CbsTemp
2016-08-10 17:21:26 ----D---- C:\WINDOWS\system32\MRT
2016-08-10 17:18:53 ----AC---- C:\WINDOWS\system32\MRT.exe
2016-08-10 15:50:31 ----D---- C:\WINDOWS\Logs
2016-08-10 15:28:54 ----SHD---- C:\System Volume Information
2016-08-10 15:28:48 ----D---- C:\WINDOWS\system32\restore
2016-08-10 08:57:50 ----AD---- C:\Program Files (x86)\Overwatch
2016-08-09 19:55:19 ----RD---- C:\Program Files (x86)
2016-08-07 19:24:50 ----RD---- C:\WINDOWS\assembly
2016-08-05 12:43:13 ----D---- C:\WINDOWS\system32\Tasks
2016-08-05 12:43:13 ----AD---- C:\Program Files (x86)\Opera
2016-08-05 08:51:13 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-08-04 20:36:27 ----D---- C:\WINDOWS\system32\LogFiles
2016-08-04 15:53:08 ----D---- C:\WINDOWS\debug
2016-08-04 14:36:05 ----D---- C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller
2016-08-04 08:28:36 ----D---- C:\WINDOWS\appcompat
2016-08-03 17:07:42 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-08-03 17:06:38 ----HD---- C:\ProgramData
2016-08-03 16:20:46 ----D---- C:\WINDOWS\OCR
2016-08-03 15:32:19 ----D---- C:\ProgramData\USOPrivate
2016-08-03 15:30:31 ----D---- C:\WINDOWS\system32\wbem
2016-08-03 15:29:03 ----D---- C:\WINDOWS\rescache
2016-08-03 15:28:32 ----D---- C:\WINDOWS\SoftwareDistribution
2016-08-03 15:28:20 ----D---- C:\WINDOWS\Registration
2016-08-03 15:28:01 ----RSD---- C:\WINDOWS\Fonts
2016-08-03 15:28:01 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-08-03 15:28:01 ----D---- C:\WINDOWS\system32\Tasks_Migrated
2016-08-03 15:27:18 ----D---- C:\WINDOWS\Tasks
2016-08-03 15:27:13 ----SD---- C:\ProgramData\Microsoft
2016-08-03 15:27:11 ----D---- C:\WINDOWS\system32\drivers\etc
2016-08-03 15:26:04 ----D---- C:\WINDOWS\WindowsMobile
2016-08-03 15:26:04 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-08-03 15:26:04 ----AD---- C:\WINDOWS\SYSWOW64\GBT_DL_OBJ
2016-08-03 15:24:44 ----D---- C:\WINDOWS\twain_32
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\zh-TW
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\zh-HK
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\zh-CN
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\uk-UA
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\tr-TR
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\th-TH
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\sv-SE
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-RS
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\sl-SI
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\ro-RO
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\pt-PT
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\pt-BR
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\nl-NL
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\nb-NO
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\lv-LV
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\lt-LT
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\ko-KR
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\ja-JP
2016-08-03 15:24:44 ----D---- C:\WINDOWS\SYSWOW64\it-IT
2016-08-03 15:24:43 ----SHD---- C:\WINDOWS\SYSWOW64\AI_RecycleBin
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\hr-HR
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\he-IL
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\fr-FR
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\fi-FI
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\et-EE
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\es-ES
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\en-US
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\el-GR
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\de-DE
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\da-DK
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\bg-BG
2016-08-03 15:24:43 ----D---- C:\WINDOWS\SYSWOW64\ar-SA
2016-08-03 15:24:42 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-08-03 15:24:42 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-08-03 15:24:42 ----D---- C:\WINDOWS\system32\spool
2016-08-03 15:24:42 ----D---- C:\WINDOWS\system32\slmgr
2016-08-03 15:24:42 ----D---- C:\WINDOWS\system32\oobe
2016-08-03 15:24:42 ----D---- C:\WINDOWS\system32\NDF
2016-08-03 15:24:41 ----D---- C:\WINDOWS\system32\InputMethod
2016-08-03 15:24:32 ----D---- C:\WINDOWS\LiveKernelReports
2016-08-03 15:24:32 ----D---- C:\WINDOWS\InputMethod
2016-08-03 15:24:31 ----RD---- C:\Users
2016-08-03 15:24:28 ----RD---- C:\Program Files
2016-08-03 15:24:28 ----D---- C:\Program Files\Common Files\microsoft shared
2016-08-03 15:24:28 ----D---- C:\Program Files\Common Files
2016-08-03 15:24:28 ----D---- C:\Program Files (x86)\Common Files
2016-08-03 15:24:25 ----D---- C:\WINDOWS\system32\Recovery
2016-08-03 15:23:50 ----SHD---- C:\Recovery
2016-08-03 15:23:50 ----D---- C:\WINDOWS\system32\Sysprep
2016-08-03 15:23:32 ----RD---- C:\WINDOWS\PrintDialog
2016-08-03 15:23:32 ----RD---- C:\WINDOWS\MiracastView
2016-08-03 15:23:23 ----D---- C:\WINDOWS\Help
2016-08-03 15:14:57 ----HD---- C:\$WINDOWS.~BT
2016-08-01 22:57:38 ----D---- C:\Users\Matúš\AppData\Roaming\OBS
2016-07-28 20:08:21 ----D---- C:\Users\Matúš\AppData\Roaming\TS3Client
2016-07-27 19:31:49 ----D---- C:\Users\Matúš\AppData\Roaming\uTorrent
2016-07-24 17:09:59 ----D---- C:\ProgramData\Oracle
2016-07-24 16:40:17 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2016-07-24 16:40:06 ----D---- C:\Program Files (x86)\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2014-09-22 241368]
R0 epfwwfp;epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [2016-06-28 84640]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-07-16 45920]
R0 pwdrvio;pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [2013-09-30 19152]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2016-06-28 263336]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2016-06-28 197288]
R1 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2016-06-28 208552]
R1 EpfwLWF;@oem18.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [2016-06-28 61608]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-07-16 88576]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-07-16 8192]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [2015-10-30 31648]
R1 ndisrd;@oem47.inf,%ndisrd_Desc%;WinpkFilter LightWeight Filter; C:\WINDOWS\system32\DRIVERS\ndisrd.sys [2014-03-27 33496]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 ekbdflt;ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [2016-06-28 153248]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2016-07-16 48128]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [2014-05-07 11576]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2016-07-16 78336]
R3 dtlitescsibus;@oem31.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2016-01-26 30264]
R3 dtliteusbbus;@oem33.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2016-01-26 47672]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2016-05-27 7936600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-07-07 4514008]
R3 iwdbus;@oem37.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2015-05-26 30512]
R3 MEIx64;@oem44.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NVHDA;@oem1.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2016-08-16 223304]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_72b89f8d71abda5d\nvlddmkm.sys [2016-08-16 14199352]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-06-14 26560]
R3 nvvad_WaveExtensible;@oem45.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2016-04-14 56384]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2016-07-16 589824]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2016-06-28 15488]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-07-16 105824]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-07-16 101216]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2016-07-16 58720]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2016-07-16 61792]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2016-07-16 32096]
S2 GhFlt;GhFlt; \??\C:\Windows\system32\drivers\ghflt.sys [2015-08-25 16856]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2016-07-16 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-07-16 38912]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-07-16 117248]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2015-11-05 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2016-06-01 26192]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-07-16 20480]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-07-16 50016]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-07-16 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2016-07-16 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-07-16 176384]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2016-07-16 526176]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 IntcDAud;@oem21.inf,%IntcDAud.SvcDesc%;Intel(R) Zvuk pre obrazovky; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-10-28 474376]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-07-16 842584]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2016-07-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2013-09-30 12504]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2016-07-16 928608]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2016-07-16 95744]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [2016-07-16 108544]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2016-07-16 50688]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2016-07-16 45568]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-06-10 2542216]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [2006-12-19 94208]
R2 EpsonScanSvc;Epson Scanner Service; C:\WINDOWS\system32\EscSvc64.exe [2011-12-12 135824]
R2 GamingApp_Service;GamingApp_Service; C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [2014-03-13 20512]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-06-14 1163712]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2016-05-27 374360]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-06-14 1879488]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-06-14 2521024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-08-11 1365048]
R2 OneSyncSvc_16748ae;Sync Host_16748ae; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [2013-02-22 102400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [2016-08-11 426040]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-06-14 3632576]
R3 PimIndexMaintenanceSvc_16748ae;Kontaktné údaje_16748ae; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-03 1452320]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 CDPUserSvc_16748ae;CDPUserSvc_16748ae; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-04-26 1860616]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2016-05-27 302176]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-07-16 93184]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2016-01-15 1369464]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2016-04-23 243984]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-10-24 143872]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService_16748ae;MessagingService_16748ae; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-08-03 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-07-17 1309936]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2016-07-16 1312768]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2015-02-26 122368]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2016-07-16 287744]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]

-----------------EOF-----------------
Přílohy
Bez názvu.png
Bez názvu.png (9.29 KiB) Zobrazeno 1862 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: ESET: Našla sa hrozba

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

psychoSVK
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 08 čer 2007 17:47

Re: ESET: Našla sa hrozba

#3 Příspěvek od psychoSVK »

# AdwCleaner v6.000 - *Logfile created 21/08/2016 *at 17:44:54
# *Updated on 12/08/2016 by ToolsLib
# *Database : 2016-08-21.1 [*Server]
# *Operating System : Windows 10 Home (X64)
# *Username : Matúš - MATÚŠ_PC
# *Running from : C:\Users\Matúš\Desktop\adwcleaner_6.000.exe
# *Mode: Clean
# *Support : https://toolslib.net/forum



***** [ *Services ] *****



***** [ *Folders ] *****

[-] *Folder deleted: C:\Users\Matúš\AppData\Local\Hola
[-] *Folder deleted: C:\Users\Matúš\AppData\Roaming\Hola
[-] *Folder deleted: C:\Program Files\Hola


***** [ *Files ] *****

[-] *File deleted: C:\END


***** [ DLL ] *****



***** [ WMI ] *****



***** [ *Shortcuts ] *****



***** [ *Scheduled Tasks ] *****



***** [ *Registry ] *****

[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] *Key deleted: HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] *Key deleted: HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] *Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] *Key deleted: [x64] HKLM\SOFTWARE\Hola
[-] *Key deleted: HKU\.DEFAULT\Software\Hola
[#] *Key deleted on reboot: HKU\S-1-5-18\Software\Hola
[-] *Value deleted: HKU\S-1-5-21-261918569-4590217-2918759245-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [TC Login]
[-] *Key deleted: HKCU\Software\MozillaPlugins\@hola.org/FlashPlayer
[-] *Key deleted: HKCU\Software\MozillaPlugins\@hola.org/vlc


***** [ *Browsers ] *****



*************************

:: *"Tracing" keys deleted
:: *Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1822 *Bytes] - [21/08/2016 17:44:54]
C:\AdwCleaner\AdwCleaner[S0].txt - [2043 *Bytes] - [21/08/2016 17:44:36]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1970 *Bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: ESET: Našla sa hrozba

#4 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

psychoSVK
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 08 čer 2007 17:47

Re: ESET: Našla sa hrozba

#5 Příspěvek od psychoSVK »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01
Ran by Matúš (administrator) on MATÚŠ_PC (21-08-2016 17:58:00)
Running from C:\Users\Matúš\Desktop
Loaded Profiles: Matúš (Available Profiles: Matúš)
Platform: Windows 10 Home Version 1607 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\Gigabyte\Smart TimeLock\TimeMgmtDaemon.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Realtek Semiconductor) C:\Program Files (x86)\Realtek\LanOptimizer\LanOptimizer.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Oracle Corporation) C:\Program Files (x86)\Java\jre1.8.0_101\bin\javaw.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_242.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_242.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\Gigabyte\Smart TimeLock\AlarmClock.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(forum.viry.cz) C:\Users\Matúš\Desktop\FRSTLauncher.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\reader_sl.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1767944 2016-06-14] (NVIDIA Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] ()
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKU\S-1-5-21-261918569-4590217-2918759245-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2857248 2016-08-16] (Valve Corporation)
HKU\S-1-5-21-261918569-4590217-2918759245-1001\...\Run: [AirDroid 3] => C:\Program Files (x86)\AirDroid\AirDroid.exe [8679424 2016-06-21] (Sand Studio)
HKU\S-1-5-21-261918569-4590217-2918759245-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [247344 2016-07-17] ()
HKU\S-1-5-21-261918569-4590217-2918759245-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4177784 2016-01-15] (Disc Soft Ltd)
HKU\S-1-5-21-261918569-4590217-2918759245-1001\...\Run: [Spotify Web Helper] => C:\Users\Matúš\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1554032 2016-07-13] (Spotify Ltd)
HKU\S-1-5-21-261918569-4590217-2918759245-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8810200 2016-06-10] (Piriform Ltd)
HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIILE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-05-17] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SACRA tray icon.lnk [2016-04-07]
ShortcutTarget: SACRA tray icon.lnk -> C:\Program Files (x86)\Dynafleet Stand Alone Card Reader Application\bat\startTrayIcon.bat ()
Startup: C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2015-08-25] ()
Startup: C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2015-09-23]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 8.8.8.8 8.8.4.4 192.168.2.1
Tcpip\..\Interfaces\{bb48478c-e774-4317-bd29-a6ac483ec721}: [DhcpNameServer] 192.168.2.1 8.8.8.8 8.8.4.4 192.168.2.1

Internet Explorer:
==================
HKU\S-1-5-21-261918569-4590217-2918759245-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-261918569-4590217-2918759245-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-24] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-09-03] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-24] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default
FF Homepage: http://www.google.sk
FF Session Restore: -> is enabled.
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Extension: ColorZilla - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2015-09-03]
FF Extension: HTML5 Notifications - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\extensions\html5notifications@paxal.net.xpi [2016-04-27]
FF Extension: Tile Tabs - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\extensions\tiletabs@DW-dev.xpi [2016-08-21]
FF Extension: YouTube mp3 - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\Extensions\info@youtube-mp3.org.xpi [2016-04-27]
FF Extension: Twoo Notifications - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\Extensions\twoo@twoo.com.xpi [2016-04-28]
FF Extension: Adblock Plus - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\hmmt7dj6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-29]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Matúš\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Matúš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2016-08-21]
CHR Extension: (IE Tab) - C:\Users\Matúš\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2016-08-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Matúš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-19]
CHR Extension: (Chrome Media Router) - C:\Users\Matúš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-11]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1860616 2016-04-26] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369464 2016-01-15] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [243984 2016-04-23] (EasyAntiCheat Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2542216 2016-06-10] (ESET)
R2 EpsonBidirectionalService; C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [143872 2014-10-24] (Microsoft Corporation) [File not signed]
R2 GamingApp_Service; C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [20512 2014-03-13] (Micro-Star Int'l Co., Ltd.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [374360 2016-05-27] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-06-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-06-14] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1309936 2016-07-17] (Overwolf LTD)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [122368 2015-02-26] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-01-26] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-01-26] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [263336 2016-06-28] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [241368 2014-09-22] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2016-06-28] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [197288 2016-06-28] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [153248 2016-06-28] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [208552 2016-06-28] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [61608 2016-06-28] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [84640 2016-06-28] (ESET)
S2 GhFlt; C:\Windows\system32\drivers\ghflt.sys [16856 2015-08-25] ()
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [31648 2015-10-30] (REALiX(tm))
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
R1 ndisrd; C:\Windows\system32\DRIVERS\ndisrd.sys [33496 2014-03-27] (Realtek)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_72b89f8d71abda5d\nvlddmkm.sys [14199352 2016-08-16] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-06-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-21 17:58 - 2016-08-21 17:58 - 00017388 _____ C:\Users\Matúš\Desktop\FRST.txt
2016-08-21 17:57 - 2016-08-21 17:58 - 00000000 ____D C:\FRST
2016-08-21 17:57 - 2016-08-21 17:57 - 00112640 _____ (forum.viry.cz) C:\Users\Matúš\Desktop\FRSTLauncher.exe
2016-08-21 17:56 - 2016-08-21 17:56 - 00112640 _____ (forum.viry.cz) C:\Users\Matúš\Downloads\Nepotvrdené 179199.crdownload
2016-08-21 17:52 - 2016-08-21 17:52 - 02396672 _____ (Farbar) C:\Users\Matúš\Desktop\FRST64.exe
2016-08-21 17:43 - 2016-08-21 17:44 - 00000000 ____D C:\AdwCleaner
2016-08-21 17:43 - 2016-08-21 17:43 - 03784256 _____ C:\Users\Matúš\Desktop\adwcleaner_6.000.exe
2016-08-21 16:28 - 2016-08-21 16:28 - 00000000 ___HD C:\OneDriveTemp
2016-08-21 15:52 - 2016-08-11 13:30 - 00138808 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-08-21 15:51 - 2016-08-21 15:52 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-08-21 15:50 - 2016-08-16 07:45 - 00054728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 40070200 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 35182648 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 34837952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 28236856 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 10728856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 10530960 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 10273096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 09086344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 08681720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 08644456 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 02914752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 02553912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 01922616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437254.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 01585088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437254.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 01023544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00961080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00945088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00897592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00803096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00802072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00694952 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00644648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00642904 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00612528 _____ C:\WINDOWS\system32\nvmcumd.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00584712 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00442816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00413256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00393664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00386104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00348728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00345936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-08-21 15:50 - 2016-08-11 16:33 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-08-21 15:50 - 2016-08-11 16:33 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2016-08-12 15:51 - 2016-08-12 16:01 - 00000000 ____D C:\Users\Matúš\Desktop\energy
2016-08-11 19:57 - 2016-08-11 19:57 - 00000000 ____D C:\Users\Matúš\Documents\DyingLight
2016-08-10 17:18 - 2016-08-02 10:58 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-08-10 17:18 - 2016-08-02 10:53 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-08-10 17:18 - 2016-08-02 10:52 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-08-10 17:18 - 2016-08-02 10:48 - 22219328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-08-10 17:18 - 2016-08-02 10:48 - 00241496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-08-10 17:18 - 2016-08-02 10:44 - 00151232 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-08-10 17:18 - 2016-08-02 10:44 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-08-10 17:18 - 2016-08-02 10:23 - 22572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-08-10 17:18 - 2016-08-02 10:21 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-08-10 17:18 - 2016-08-02 10:21 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-08-10 17:18 - 2016-08-02 10:20 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-08-10 17:18 - 2016-08-02 10:20 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-08-10 17:18 - 2016-08-02 10:15 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-08-10 17:18 - 2016-08-02 10:15 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-08-10 17:18 - 2016-08-02 10:14 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-08-10 17:18 - 2016-08-02 10:13 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-08-10 17:18 - 2016-08-02 10:12 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-08-10 17:18 - 2016-08-02 10:11 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-08-10 17:18 - 2016-08-02 10:11 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-08-10 17:18 - 2016-08-02 10:10 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-08-10 17:18 - 2016-08-02 10:09 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-08-10 17:18 - 2016-08-02 10:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-08-10 17:18 - 2016-08-02 10:07 - 09125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-08-10 17:18 - 2016-08-02 10:03 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-08-10 17:18 - 2016-08-02 10:00 - 05511168 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-08-10 17:18 - 2016-08-02 09:59 - 08124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-08-10 17:18 - 2016-08-02 09:58 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-08-10 17:18 - 2016-08-02 09:57 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-08-10 17:18 - 2016-08-02 09:56 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-08-10 17:18 - 2016-08-02 09:56 - 01785856 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-08-10 17:18 - 2016-08-02 09:56 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-08-10 17:18 - 2016-08-02 09:55 - 03617280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-08-10 17:18 - 2016-08-02 09:55 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-08-10 17:18 - 2016-08-02 09:52 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-08-10 17:18 - 2016-08-02 06:56 - 02251440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-08-10 17:18 - 2016-08-02 06:51 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-08-10 17:18 - 2016-08-02 06:47 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2016-08-10 17:18 - 2016-08-02 06:39 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-08-10 17:18 - 2016-08-02 06:37 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-08-10 17:18 - 2016-08-02 06:37 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-08-10 17:18 - 2016-08-02 06:36 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2016-08-10 17:18 - 2016-08-02 06:33 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2016-08-10 17:18 - 2016-08-02 06:30 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-08-10 17:18 - 2016-08-02 06:28 - 19423232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-08-10 17:18 - 2016-08-02 06:27 - 07623168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-08-10 17:18 - 2016-08-02 06:26 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-08-10 17:18 - 2016-08-02 06:26 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-08-10 17:18 - 2016-08-02 06:25 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-08-10 17:18 - 2016-08-02 06:25 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-08-10 17:18 - 2016-08-02 06:23 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2016-08-10 17:18 - 2016-08-02 06:16 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-08-10 17:18 - 2016-08-02 06:13 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-08-10 17:18 - 2016-08-02 06:13 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2016-08-10 17:18 - 2016-08-02 06:12 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-08-10 17:18 - 2016-08-02 06:09 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-08-09 19:55 - 2016-08-09 20:01 - 00000000 ____D C:\Users\Matúš\Documents\Assassin's Creed IV Black Flag
2016-08-09 19:55 - 2016-08-09 20:01 - 00000000 ____D C:\Users\Matúš\AppData\Local\Ubisoft Game Launcher
2016-08-09 19:55 - 2016-08-09 19:55 - 00001270 _____ C:\Users\Matúš\Desktop\Uplay.lnk
2016-08-09 19:55 - 2016-08-09 19:55 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2016-08-09 19:55 - 2016-08-09 19:55 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2016-08-04 15:40 - 2016-08-21 15:43 - 00000000 ____D C:\Users\Matúš\AppData\Local\Deployment
2016-08-03 17:06 - 2016-08-03 17:06 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-08-03 17:05 - 2016-08-03 17:05 - 00000020 ___SH C:\Users\Matúš\ntuser.ini
2016-08-03 16:22 - 2016-08-03 15:28 - 00000000 ___DC C:\WINDOWS\Panther
2016-08-03 16:20 - 2016-08-03 16:21 - 00000000 ____D C:\Windows.old
2016-08-03 16:20 - 2016-08-03 16:20 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-08-03 16:20 - 2016-08-03 16:20 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 01418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 01265424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 01260384 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 00843104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-08-03 16:20 - 2016-08-03 16:20 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-08-03 16:20 - 2016-08-03 16:20 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-08-03 16:20 - 2016-08-03 16:20 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-08-03 16:20 - 2016-08-03 16:20 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-08-03 16:20 - 2016-08-03 15:22 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-08-03 16:20 - 2016-07-15 20:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-08-03 16:20 - 2016-07-15 20:29 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2016-08-03 16:20 - 2016-07-15 20:29 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2016-08-03 16:20 - 2016-07-15 20:28 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-08-03 16:20 - 2016-07-15 20:28 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-08-03 16:20 - 2016-07-15 20:26 - 00376320 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2016-08-03 16:20 - 2016-07-15 20:26 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-08-03 16:20 - 2016-07-15 20:25 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2016-08-03 16:20 - 2016-07-15 20:23 - 14388224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2016-08-03 16:20 - 2016-07-15 20:22 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2016-08-03 16:20 - 2016-07-15 20:22 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2016-08-03 16:20 - 2016-07-15 20:19 - 01323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-08-03 16:20 - 2016-07-15 20:16 - 05850624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-08-03 16:20 - 2016-07-15 20:16 - 04969472 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-08-03 16:20 - 2016-07-15 20:15 - 06582784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2016-08-03 16:20 - 2016-07-15 20:14 - 06354944 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2016-08-03 16:20 - 2016-07-15 20:14 - 02485760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-08-03 16:20 - 2016-07-15 20:13 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-08-03 16:20 - 2016-07-15 20:13 - 01198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2016-08-03 16:20 - 2016-07-15 20:13 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-08-03 16:20 - 2016-07-15 20:12 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-08-03 16:20 - 2016-07-15 20:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2016-08-03 16:20 - 2016-07-15 20:11 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2016-08-03 16:20 - 2016-07-15 19:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2016-08-03 16:20 - 2016-07-15 19:45 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2016-08-03 16:20 - 2016-07-15 19:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2016-08-03 16:20 - 2016-07-15 19:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll
2016-08-03 16:20 - 2016-07-15 19:42 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2016-08-03 16:20 - 2016-07-15 19:41 - 00355840 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2016-08-03 16:20 - 2016-07-15 19:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2016-08-03 16:20 - 2016-07-15 19:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2016-08-03 16:20 - 2016-07-15 19:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2016-08-03 16:20 - 2016-07-15 19:37 - 01935360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2016-08-03 16:20 - 2016-07-15 19:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2016-08-03 16:20 - 2016-07-15 19:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2016-08-03 16:20 - 2016-07-15 19:32 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2016-08-03 16:20 - 2016-07-15 19:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2016-08-03 16:20 - 2016-07-15 19:31 - 04977664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll
2016-08-03 16:20 - 2016-07-15 19:29 - 05489664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2016-08-03 16:20 - 2016-07-15 19:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2016-08-03 16:20 - 2016-07-15 19:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2016-08-03 16:20 - 2016-07-15 19:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2016-08-03 16:20 - 2016-07-15 19:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2016-08-03 16:20 - 2016-07-15 19:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2016-08-03 16:20 - 2016-07-15 19:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2016-08-03 16:19 - 2016-08-03 16:19 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-08-03 16:19 - 2016-08-03 16:19 - 00000000 ____D C:\Program Files\MSBuild
2016-08-03 16:19 - 2016-08-03 16:19 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-08-03 16:19 - 2016-08-03 16:19 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-08-03 16:19 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-08-03 16:19 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-08-03 16:19 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-08-03 16:19 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-08-03 16:19 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-08-03 16:19 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-08-03 15:32 - 2016-08-03 15:32 - 00000000 ____D C:\ProgramData\USOShared
2016-08-03 15:28 - 2016-08-03 15:28 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-08-03 15:28 - 2016-08-03 15:28 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-08-03 15:27 - 2016-08-21 17:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-08-03 15:27 - 2016-08-05 12:43 - 00003968 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1440538626
2016-08-03 15:27 - 2016-08-03 15:27 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-08-03 15:27 - 2016-08-03 15:27 - 00003474 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-03 15:27 - 2016-08-03 15:27 - 00003250 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-03 15:27 - 2016-08-03 15:27 - 00003234 _____ C:\WINDOWS\System32\Tasks\Ashampoo Burning Studio Update
2016-08-03 15:27 - 2016-08-03 15:27 - 00002908 _____ C:\WINDOWS\System32\Tasks\ReasonSecurityScheduledScan
2016-08-03 15:27 - 2016-08-03 15:27 - 00002872 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-261918569-4590217-2918759245-1001
2016-08-03 15:27 - 2016-08-03 15:27 - 00002668 _____ C:\WINDOWS\System32\Tasks\Overwolf Updater Task
2016-08-03 15:27 - 2016-08-03 15:27 - 00002598 _____ C:\WINDOWS\System32\Tasks\ReasonSecurityStart
2016-08-03 15:27 - 2016-08-03 15:27 - 00002250 _____ C:\WINDOWS\System32\Tasks\RtlLanOptimizerVistaStart
2016-08-03 15:27 - 2016-08-03 15:27 - 00002212 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-08-03 15:25 - 2016-08-03 15:25 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-03 15:25 - 2016-08-03 15:25 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-08-03 15:25 - 2016-08-03 15:25 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2016-08-03 15:25 - 2016-08-03 15:25 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-08-03 15:25 - 2016-08-03 15:25 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2016-08-03 15:24 - 2016-08-21 17:45 - 00000000 ____D C:\Users\Matúš
2016-08-03 15:24 - 2016-08-03 15:26 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-08-03 15:23 - 2016-08-21 17:45 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-03 15:23 - 2016-08-21 17:45 - 00000000 ____D C:\ProgramData\NVIDIA
2016-08-03 15:23 - 2016-08-21 15:52 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-08-03 15:23 - 2016-08-11 14:27 - 06386048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-08-03 15:23 - 2016-08-11 14:27 - 02468288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-08-03 15:23 - 2016-08-11 14:27 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-08-03 15:23 - 2016-08-11 14:27 - 01365048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-08-03 15:23 - 2016-08-11 14:27 - 00548920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-08-03 15:23 - 2016-08-11 14:27 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-08-03 15:23 - 2016-08-11 14:27 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-08-03 15:23 - 2016-08-11 14:27 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-08-03 15:23 - 2016-08-09 18:06 - 07255045 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-08-03 15:23 - 2016-08-03 15:24 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-08-03 15:23 - 2016-08-03 15:24 - 00000000 ____D C:\Program Files\Intel
2016-08-03 15:23 - 2016-08-03 15:24 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-08-03 15:23 - 2016-08-03 15:23 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-08-03 15:23 - 2016-08-03 15:23 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_11_00.Wdf
2016-08-03 15:23 - 2016-08-03 15:23 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2016-08-03 15:23 - 2016-08-03 15:23 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-08-03 15:23 - 2016-08-03 15:23 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-08-03 15:23 - 2016-08-03 15:23 - 00000000 ____D C:\Program Files\Realtek
2016-08-03 15:23 - 2016-08-03 15:23 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2016-08-03 15:23 - 2016-05-27 15:50 - 00104584 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2016-08-03 15:23 - 2016-05-27 15:50 - 00100488 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-08-03 15:22 - 2016-08-12 23:40 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-08-03 15:22 - 2016-08-10 18:04 - 00259008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-03 15:22 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-08-02 14:45 - 2016-08-03 15:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2016-08-02 14:45 - 2016-08-02 14:45 - 00000000 ____D C:\ProgramData\ESET
2016-07-25 17:48 - 2016-07-25 17:48 - 01672139 _____ C:\Users\Matúš\Desktop\img047.pdf
2016-07-25 11:42 - 2016-07-25 11:42 - 00905305 _____ C:\Users\Matúš\Desktop\img046.pdf
2016-07-25 11:37 - 2016-07-25 11:37 - 09799360 _____ (TeamViewer GmbH) C:\Users\Matúš\Desktop\TeamViewer_Setup_sk.exe
2016-07-25 11:37 - 2016-07-25 11:37 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\TeamViewer

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-21 17:46 - 2015-08-25 23:21 - 00000000 ____D C:\Program Files (x86)\Steam
2016-08-21 17:46 - 2015-08-25 23:04 - 00000000 ___RD C:\Users\Matúš\OneDrive
2016-08-21 17:45 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-08-21 17:45 - 2015-08-25 23:16 - 00000000 __SHD C:\Users\Matúš\IntelGraphicsProfiles
2016-08-21 17:42 - 2016-05-05 12:11 - 00000000 ____D C:\Program Files (x86)\Overwatch
2016-08-21 17:42 - 2015-08-25 23:20 - 00000000 ____D C:\Users\Matúš\AppData\Local\Battle.net
2016-08-21 16:49 - 2015-08-31 15:04 - 01108832 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-21 16:49 - 2015-08-25 23:39 - 00153010 _____ C:\WINDOWS\system32\perfh01B.dat
2016-08-21 16:49 - 2015-08-25 23:39 - 00043944 _____ C:\WINDOWS\system32\perfc01B.dat
2016-08-21 16:28 - 2016-03-07 14:31 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2016-08-21 16:28 - 2015-08-25 23:20 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-08-21 15:57 - 2016-02-28 11:19 - 00000000 ____D C:\Program Files\trend micro
2016-08-21 15:57 - 2016-02-28 11:18 - 01222144 _____ C:\Users\Matúš\Desktop\RSITx64.exe
2016-08-21 15:52 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2016-08-21 15:52 - 2016-03-10 20:37 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-08-21 15:52 - 2015-08-26 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-08-21 15:46 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-21 15:46 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-08-16 07:45 - 2016-07-15 08:42 - 01588688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2016-08-16 07:45 - 2016-07-15 08:42 - 00223304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2016-08-12 16:02 - 2015-08-27 18:02 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\vlc
2016-08-12 16:01 - 2015-10-06 19:17 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\AIMP3
2016-08-11 18:58 - 2015-09-30 08:32 - 00000000 ____D C:\Users\Matúš\AppData\Local\IE Tab
2016-08-11 16:33 - 2016-07-15 08:42 - 03901520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-08-11 16:33 - 2016-07-15 08:42 - 03443152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-08-11 16:33 - 2016-07-15 08:42 - 00040827 _____ C:\WINDOWS\system32\nvinfo.pb
2016-08-10 18:05 - 2015-08-31 15:01 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-08-10 18:04 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-08-10 18:04 - 2015-08-25 23:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-10 17:21 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-08-10 17:21 - 2015-08-26 00:19 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-08-10 17:18 - 2015-08-26 00:19 - 147640136 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-08-10 13:39 - 2015-08-31 15:05 - 00000000 ____D C:\Users\Matúš\Desktop\Dovolenkoy listok
2016-08-10 08:45 - 2015-09-03 13:35 - 00000000 ____D C:\Users\Matúš\Documents\AirDroid
2016-08-08 21:36 - 2015-12-01 18:14 - 00000000 ____D C:\Users\Matúš\AppData\Local\Purplizer
2016-08-08 16:10 - 2015-12-01 18:12 - 00000000 ____D C:\Users\Matúš\AppData\Local\Overwolf
2016-08-08 12:24 - 2015-08-31 15:06 - 00000000 ____D C:\Users\Matúš\Desktop\objednavky vystavene
2016-08-05 12:43 - 2015-08-25 23:37 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-08-05 12:43 - 2015-08-25 23:35 - 00000000 ____D C:\Program Files (x86)\Opera
2016-08-05 08:54 - 2015-08-25 23:23 - 00000000 ____D C:\Users\Matúš\AppData\Local\Adobe
2016-08-04 14:36 - 2015-09-07 12:40 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller
2016-08-04 08:28 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-08-03 17:39 - 2015-08-25 23:01 - 00000000 ____D C:\Users\Matúš\AppData\Local\Packages
2016-08-03 17:18 - 2015-08-31 15:10 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-03 17:07 - 2015-08-25 23:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-03 17:06 - 2015-08-31 15:03 - 00002401 _____ C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-08-03 16:22 - 2016-07-16 13:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-08-03 16:20 - 2016-07-17 00:02 - 00000000 ____D C:\WINDOWS\OCR
2016-08-03 15:32 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-08-03 15:29 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2016-08-03 15:28 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-08-03 15:28 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Registration
2016-08-03 15:28 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-08-03 15:27 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-08-03 15:27 - 2015-08-31 14:59 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-08-03 15:26 - 2016-07-11 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.1
2016-08-03 15:26 - 2016-06-26 00:05 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software
2016-08-03 15:26 - 2016-06-20 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft Public Test
2016-08-03 15:26 - 2016-05-18 16:12 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2016-08-03 15:26 - 2016-05-05 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch
2016-08-03 15:26 - 2016-04-04 16:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-08-03 15:26 - 2016-03-07 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2016-08-03 15:26 - 2016-02-28 13:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-08-03 15:26 - 2016-02-27 13:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-08-03 15:26 - 2016-01-26 13:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2016-08-03 15:26 - 2016-01-16 23:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2016-08-03 15:26 - 2016-01-07 12:00 - 00000000 ____D C:\WINDOWS\WindowsMobile
2016-08-03 15:26 - 2015-12-02 15:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Simulationcraft(x64)
2016-08-03 15:26 - 2015-10-30 21:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LAN Optimizer
2016-08-03 15:26 - 2015-10-06 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
2016-08-03 15:26 - 2015-10-05 09:47 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-03 15:26 - 2015-10-05 09:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-03 15:26 - 2015-09-08 15:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2016-08-03 15:26 - 2015-09-07 12:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
2016-08-03 15:26 - 2015-09-03 13:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bonjour
2016-08-03 15:26 - 2015-09-03 13:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid
2016-08-03 15:26 - 2015-08-27 17:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OCCT
2016-08-03 15:26 - 2015-08-26 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
2016-08-03 15:26 - 2015-08-26 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 2.5
2016-08-03 15:26 - 2015-08-26 21:59 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2016-08-03 15:26 - 2015-08-26 08:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-08-03 15:26 - 2015-08-25 23:54 - 00000000 ____D C:\WINDOWS\SysWOW64\GBT_DL_OBJ
2016-08-03 15:26 - 2015-08-25 23:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-08-03 15:26 - 2015-08-25 23:40 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
2016-08-03 15:26 - 2015-08-25 23:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2016-08-03 15:26 - 2015-08-25 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-03 15:26 - 2015-08-25 23:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2016-08-03 15:26 - 2015-08-25 23:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Free 9.1
2016-08-03 15:26 - 2015-08-25 23:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-08-03 15:25 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-08-03 15:25 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated
2016-08-03 15:24 - 2016-07-17 00:01 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-08-03 15:24 - 2016-07-17 00:01 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\InputMethod
2016-08-03 15:24 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-08-03 15:24 - 2016-06-10 10:56 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TimoCom
2016-08-03 15:24 - 2016-03-10 20:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.0
2016-08-03 15:24 - 2016-01-25 13:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2016-08-03 15:24 - 2016-01-07 13:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4Tech Software
2016-08-03 15:24 - 2015-12-01 18:13 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2016-08-03 15:24 - 2015-09-23 09:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2016-08-03 15:24 - 2015-08-27 18:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2016-08-03 15:24 - 2015-08-26 22:10 - 00000000 __SHD C:\WINDOWS\SysWOW64\AI_RecycleBin
2016-08-03 15:24 - 2015-08-26 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2016-08-03 15:24 - 2015-08-26 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tukui
2016-08-03 15:24 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-08-03 15:24 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-08-03 15:23 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-08-03 15:23 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-08-03 15:23 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Help
2016-08-03 15:23 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-08-03 15:14 - 2016-07-17 00:47 - 00000000 ___HD C:\$WINDOWS.~BT
2016-08-03 15:12 - 2015-10-30 21:16 - 00000302 _____ C:\WINDOWS\Tasks\RtlLanOptimizerVistaStart.job
2016-08-03 14:48 - 2015-08-25 23:08 - 00000962 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-03 08:39 - 2015-08-25 23:08 - 00000958 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-01 22:57 - 2016-03-13 18:18 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\OBS
2016-08-01 22:57 - 2015-11-01 12:54 - 00000000 ____D C:\Users\Matúš\Desktop\flv
2016-08-01 20:08 - 2015-08-26 08:22 - 00000000 ____D C:\Users\Matúš\Documents\My Games
2016-07-28 20:08 - 2015-08-25 23:40 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\TS3Client
2016-07-27 19:31 - 2015-09-02 14:05 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\uTorrent
2016-07-25 22:15 - 2016-01-06 18:49 - 00000000 ____D C:\Users\Matúš\AppData\Local\CrashDumps
2016-07-25 19:47 - 2016-06-24 10:59 - 00000000 ____D C:\Users\Matúš\Desktop\Tacho
2016-07-24 17:09 - 2016-04-04 16:32 - 00000000 ____D C:\ProgramData\Oracle
2016-07-24 16:40 - 2016-04-04 16:32 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-07-24 16:40 - 2016-04-04 16:32 - 00000000 ____D C:\Users\Matúš\.oracle_jre_usage
2016-07-24 16:40 - 2016-04-04 16:32 - 00000000 ____D C:\Program Files (x86)\Java

==================== Files in the root of some directories =======

2015-08-26 17:52 - 2015-08-26 17:52 - 0000017 _____ () C:\Users\Matúš\AppData\Local\resmon.resmoncfg
2016-08-03 15:23 - 2016-08-03 15:23 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Matúš\AppData\Local\Temp\libeay32.dll
C:\Users\Matúš\AppData\Local\Temp\msvcr120.dll
C:\Users\Matúš\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Matúš\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Matúš\AppData\Local\Temp\nvStInst.exe
C:\Users\Matúš\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-03 15:22

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:222.6 GB) (Free:56.2 GB) NTFS
Drive d: (Fun) (Fixed) (Total:931.51 GB) (Free:259.79 GB) NTFS

Available physical RAM: 4942.67 MB
Total physical RAM: 7605.34 MB
Percentage of memory in use: 35%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E61988B9)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=OF Extended)
Disk: 1 (Size: 223.6 GB) (Disk ID: BABE1B37)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Ashampoo Burning Studio Update.job => Wscript.exe _/nologo /B /E:jscript C:\Users\Matúa\AppData\Roaming\Ashampoo Burning Studio\settings.ini <==== ATTENTION
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\RtlLanOptimizerVistaStart.job => C:\Program Files (x86)\Realtek\LanOptimizer\LanOptimizer.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Mount:$WIMMOUNTDATA [802]

==================== Security Center ==================

AV: ESET Smart Security 9.0.385.1 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.385.1 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personálny firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Mat��\Desktop" je 21076 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================
Přílohy
Addition.rar
(13.37 KiB) Staženo 60 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: ESET: Našla sa hrozba

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => No File
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\ProgramData\DP45977C.lfl
C:\Users\Matúš\AppData\Local\Temp
AlternateDataStreams: C:\Mount:$WIMMOUNTDATA [802]
Task: {013C8743-1936-498C-A5B3-4A2AF2D71EAB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {3AF6335B-5A8E-4FD2-9240-B3ABAA2EA917} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {3D7D01B4-A6F1-4D52-967C-7018BDA584BF} - System32\Tasks\Ashampoo Burning Studio Update => Wscript.exe //nologo //B //E:jscript "C:\Users\Matúš\AppData\Roaming\Ashampoo Burning Studio\settings.ini" <==== ATTENTION
Task: {407465A6-9E04-4C96-8FF1-E19C98EEE122} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4541428D-BF13-4543-8EB7-F60A8C45FA34} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {5F4DAC82-E3EF-48A7-AE50-7255F418AF46} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {5FB0422C-2199-4BEB-8665-7B3C3654DAC7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {65707986-923A-4DA7-BB09-55DC72D5DB4F} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {663EA3CA-0384-4C11-9595-477CD14C78E0} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {9D95BEE5-4972-4A7D-8C76-8A958E2255EF} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {BA4F3169-D322-43C1-80B9-7FFE5551EB3E} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {CA3881A5-9A4F-4325-8D66-07697E371DBC} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION

ResetHosts:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

psychoSVK
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 08 čer 2007 17:47

Re: ESET: Našla sa hrozba

#7 Příspěvek od psychoSVK »

Fix result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01
Ran by Matúš (21-08-2016 18:49:10) Run:1
Running from C:\Users\Matúš\Desktop
Loaded Profiles: Matúš (Available Profiles: Matúš)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => No File
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\ProgramData\DP45977C.lfl
C:\Users\Matúš\AppData\Local\Temp
AlternateDataStreams: C:\Mount:$WIMMOUNTDATA [802]
Task: {013C8743-1936-498C-A5B3-4A2AF2D71EAB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {3AF6335B-5A8E-4FD2-9240-B3ABAA2EA917} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {3D7D01B4-A6F1-4D52-967C-7018BDA584BF} - System32\Tasks\Ashampoo Burning Studio Update => Wscript.exe //nologo //B //E:jscript "C:\Users\Matúš\AppData\Roaming\Ashampoo Burning Studio\settings.ini" <==== ATTENTION
Task: {407465A6-9E04-4C96-8FF1-E19C98EEE122} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4541428D-BF13-4543-8EB7-F60A8C45FA34} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {5F4DAC82-E3EF-48A7-AE50-7255F418AF46} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {5FB0422C-2199-4BEB-8665-7B3C3654DAC7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {65707986-923A-4DA7-BB09-55DC72D5DB4F} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {663EA3CA-0384-4C11-9595-477CD14C78E0} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {9D95BEE5-4972-4A7D-8C76-8A958E2255EF} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {BA4F3169-D322-43C1-80B9-7FFE5551EB3E} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {CA3881A5-9A4F-4325-8D66-07697E371DBC} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION

ResetHosts:
End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => key removed successfully
HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => key not found.
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully

"C:\Users\Matúš\AppData\Local\Temp" folder move:

Could not move "C:\Users\Matúš\AppData\Local\Temp" => Scheduled to move on reboot.

C:\Mount => ":$WIMMOUNTDATA" ADS removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{013C8743-1936-498C-A5B3-4A2AF2D71EAB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{013C8743-1936-498C-A5B3-4A2AF2D71EAB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3AF6335B-5A8E-4FD2-9240-B3ABAA2EA917}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AF6335B-5A8E-4FD2-9240-B3ABAA2EA917}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D7D01B4-A6F1-4D52-967C-7018BDA584BF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D7D01B4-A6F1-4D52-967C-7018BDA584BF}" => key removed successfully
C:\WINDOWS\System32\Tasks\Ashampoo Burning Studio Update => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ashampoo Burning Studio Update" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{407465A6-9E04-4C96-8FF1-E19C98EEE122}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{407465A6-9E04-4C96-8FF1-E19C98EEE122}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4541428D-BF13-4543-8EB7-F60A8C45FA34}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4541428D-BF13-4543-8EB7-F60A8C45FA34}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F4DAC82-E3EF-48A7-AE50-7255F418AF46}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F4DAC82-E3EF-48A7-AE50-7255F418AF46}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5FB0422C-2199-4BEB-8665-7B3C3654DAC7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FB0422C-2199-4BEB-8665-7B3C3654DAC7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65707986-923A-4DA7-BB09-55DC72D5DB4F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65707986-923A-4DA7-BB09-55DC72D5DB4F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{663EA3CA-0384-4C11-9595-477CD14C78E0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{663EA3CA-0384-4C11-9595-477CD14C78E0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9D95BEE5-4972-4A7D-8C76-8A958E2255EF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D95BEE5-4972-4A7D-8C76-8A958E2255EF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA4F3169-D322-43C1-80B9-7FFE5551EB3E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA4F3169-D322-43C1-80B9-7FFE5551EB3E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA3881A5-9A4F-4325-8D66-07697E371DBC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA3881A5-9A4F-4325-8D66-07697E371DBC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
ResetHosts: => Error: No automatic fix found for this entry.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 21-08-2016 18:49:58)

C:\Users\Matúš\AppData\Local\Temp => moved successfully

==== End of Fixlog 18:49:58 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: ESET: Našla sa hrozba

#8 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

psychoSVK
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 08 čer 2007 17:47

Re: ESET: Našla sa hrozba

#9 Příspěvek od psychoSVK »

Zatiaľ to vyzerá dobre, eset od reštartu zatiaľ nič nezahlásil.
Ďakujem za pomoc

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: ESET: Našla sa hrozba

#10 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno