Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

PUP - pomoc prosím

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

PUP - pomoc prosím

#1 Příspěvek od FineSelection »

Dobrý den,

přítelkyně mi dala notebook na promazání. Je zpomalený, výkon procesoru je mezi 95 - 100% aniž by bylo cokoliv spuštěno, je velmi hlučný a na internetu se neustále otevírají nechtěné pochybné weby. Našel jsem PUP.Optional.Crossrider. Sice to smažu v karanténě, ale v počítači zůstane. Projížděl jsem i adwcleanerem a Hitmanem, ale výsledek žádný :(

Mnohokrát předem děkuji

RSIT:

Logfile of random's system information tool 1.14 (written by random/random)
Run by MaI at 2017-01-09 11:19:41
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 234 GB (81%) free of 288 GB
Total RAM: 2810 MB (22% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:20:32, on 9.1.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\MaI\Downloads\RSIT.exe
C:\Program Files\trend micro\MaI_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O3 - Toolbar: (no name) - {8dcb7100-df86-4384-8842-8fa844297b3f} - (no file)
O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [estar] C:\System.Sav\Util\HideDOS.EXE C:\System.Sav\util\estartwk\twk7.bat
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe
O4 - HKLM\..\Run: [PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe
O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Malwarebytes TrayApp] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - res://C:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll /100
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE

--
End of file - 10856 bytes

======Scheduled tasks folder======

C:\windows\tasks\HPCeeScheduleForMaI.job - C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForMaI (null)
C:\windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\windows\system32\tasks\CreateChoiceProcessTask - C:\Windows\System32\browserchoice.exe /launch
C:\windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\system32\tasks\HPCeeScheduleForMaI - C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForMaI (null)
C:\windows\system32\tasks\Registration - "C:\Program Files\Hewlett-Packard\HP Setup\RemEngine.exe" Registration ShowMessageTask2D
C:\windows\system32\tasks\WPD\SqmUpload_S-1-5-21-3103529041-4251153409-2491265020-1001 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\windows\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\windows\System32\lpksetup.exe -v
C:\windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\windows\System32\mcbuilder.exe
C:\windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
C:\windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\windows\system32\tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan - c:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges
C:\windows\system32\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start - C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe /taskrestart
C:\windows\system32\tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report - C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send
C:\windows\system32\tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /u
C:\windows\system32\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis - C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe /L Analysis
C:\windows\system32\tasks\Hewlett-Packard\HP Support Assistant\Product Configurator - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe /noreport
C:\windows\system32\tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe -task -source HPSA

=========Google Chrome=========

C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension bgjpfhpjcgdppjbgnpnjllokbmcdllig 1 Seznam Lištička - Email 1.3.19
Extension blmojkbhnkkphngknkmgccmlenfaelkd 1 Seznam Lištička - Slovník 1.4.3
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Vyhledávání Google 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg Settings 0.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension gibbofpfifeklicllnimkipggbodbegj 1 Canonical Url 0.8
Extension gighmmpiobklfepjocnamgkkbiglidom 1 AdBlock 3.8.4
Extension kamfkajbgmjkfmfgcikbmbmpjfokfijk 1 Awesome Reload All Tabs Button 1.2.0.0
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension mkggleleindffinefpajdemfpncccgoo 1 URL to QRCode 0.8
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.1
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension olfeabkoenfaoljndfecamgilllcpiak 1 Seznam Lištička - Rychlá volba 1.8.5
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5516.1005.0.3
Homepage: http://www.seznam.cz/?clid=12454
default_search_provider.search_url:
C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={CC02B300-11D7-44F2-A42E-34353E7C1697}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC02B300-11D7-44F2-A42E-34353E7C1697}]
"URL"=http://www.bing.com/search?q={searchTer ... -SearchBox

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-03-01 256056]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2010-03-06 563736]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2010-04-05 8192]
"estar"=C:\System.Sav\Util\HideDOS.EXE [2006-11-28 77824]
"PDFHook"=C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [2009-11-13 1277952]
"PDF6 Registry Controller"=C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [2009-11-03 110880]
"Nuance PDF Reader-reminder"=C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe [2008-11-03 328992]
"NortonOnlineBackupReminder"=C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [2009-12-03 3331944]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-16 98304]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [2013-10-02 6510592]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-08-12 995176]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2013-10-31 495708]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2016-12-14 2776528]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2009-05-05 222496]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2010-02-22 2363392]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-12-06 7175384]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"StubPath"="C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files\Google\Chrome\Application\55.0.2883.87\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-01-09 11:19:41 ----D---- C:\rsit
2017-01-09 11:19:41 ----D---- C:\Program Files\trend micro
2017-01-09 10:23:14 ----D---- C:\Program Files\HitmanPro
2017-01-09 10:22:42 ----D---- C:\ProgramData\HitmanPro
2017-01-08 20:00:59 ----D---- C:\AdwCleaner
2017-01-08 15:46:01 ----A---- C:\windows\system32\wups2.dll
2017-01-08 15:46:00 ----A---- C:\windows\system32\wucltux.dll
2017-01-08 15:46:00 ----A---- C:\windows\system32\wuaueng.dll
2017-01-08 15:46:00 ----A---- C:\windows\system32\wuauclt.exe
2017-01-08 15:45:43 ----A---- C:\windows\system32\wups.dll
2017-01-08 15:45:43 ----A---- C:\windows\system32\wudriver.dll
2017-01-08 15:45:43 ----A---- C:\windows\system32\wuapi.dll
2017-01-08 15:45:16 ----A---- C:\windows\system32\wuwebv.dll
2017-01-08 15:45:16 ----A---- C:\windows\system32\wuapp.exe
2017-01-08 15:16:52 ----D---- C:\Program Files\CCleaner
2017-01-08 14:59:15 ----D---- C:\Users\MaI\AppData\Roaming\Roxio Log Files
2017-01-08 14:36:42 ----A---- C:\windows\system32\drivers\MBAMChameleon.sys
2017-01-08 14:36:28 ----A---- C:\windows\system32\drivers\mwac.sys
2017-01-08 14:36:28 ----A---- C:\windows\system32\drivers\farflt.sys
2017-01-08 14:36:21 ----A---- C:\windows\system32\drivers\mbam.sys
2017-01-08 14:36:12 ----A---- C:\windows\system32\drivers\MBAMSwissArmy.sys
2017-01-08 14:35:51 ----A---- C:\windows\system32\drivers\mbae.sys
2017-01-08 14:35:37 ----D---- C:\ProgramData\Malwarebytes
2017-01-08 14:35:37 ----D---- C:\Program Files\Malwarebytes

======List of files/folders modified in the last 1 month======

2017-01-09 11:20:12 ----D---- C:\windows\system32\config
2017-01-09 11:20:05 ----D---- C:\windows\Temp
2017-01-09 11:19:41 ----RD---- C:\Program Files
2017-01-09 11:09:11 ----D---- C:\windows\System32
2017-01-09 11:09:11 ----D---- C:\windows\inf
2017-01-09 11:09:11 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-01-09 11:03:34 ----D---- C:\windows\system32\catroot2
2017-01-09 11:02:49 ----SHD---- C:\windows\Installer
2017-01-09 11:02:49 ----SHD---- C:\Config.Msi
2017-01-09 10:53:22 ----SHD---- C:\System Volume Information
2017-01-09 10:52:58 ----D---- C:\windows\system32\drivers
2017-01-09 10:22:42 ----HD---- C:\ProgramData
2017-01-08 20:38:51 ----D---- C:\windows\system32\Macromed
2017-01-08 20:31:57 ----D---- C:\Windows
2017-01-08 15:58:59 ----D---- C:\windows\winsxs
2017-01-08 15:58:35 ----D---- C:\windows\system32\cs-CZ
2017-01-08 15:46:32 ----D---- C:\windows\system32\catroot
2017-01-08 15:21:32 ----D---- C:\windows\Panther
2017-01-08 15:21:32 ----D---- C:\windows\Logs
2017-01-08 15:21:31 ----D---- C:\windows\debug
2017-01-08 15:17:07 ----D---- C:\windows\system32\Tasks
2017-01-08 15:01:42 ----D---- C:\Program Files\Common Files\PX Storage Engine
2017-01-08 15:01:36 ----D---- C:\Program Files\Common Files\Sonic Shared
2017-01-06 10:15:07 ----D---- C:\ProgramData\PDFC
2017-01-04 17:26:42 ----D---- C:\Users\MaI\AppData\Roaming\Seznam.cz
2017-01-04 17:26:35 ----D---- C:\Program Files\Seznam.cz
2017-01-03 21:30:28 ----SD---- C:\Users\MaI\AppData\Roaming\Microsoft
2016-12-30 20:56:47 ----D---- C:\windows\Tasks
2016-12-20 21:23:00 ----RSD---- C:\windows\assembly
2016-12-15 13:59:03 ----D---- C:\windows\Prefetch

File C:\windows\system32\winlogon.exe is digitally signed
File C:\windows\system32\wininit.exe is digitally signed
File C:\windows\explorer.exe is digitally signed
File C:\windows\system32\svchost.exe is digitally signed
File C:\windows\system32\services.exe is digitally signed
File C:\windows\system32\User32.dll is digitally signed
File C:\windows\system32\userinit.exe is digitally signed
File C:\windows\system32\rpcss.dll is digitally signed
File C:\windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2010-03-09 14392]
R0 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2013-06-18 211560]
R0 PxHelp20;PxHelp20; C:\windows\System32\Drivers\PxHelp20.sys [2009-07-09 45200]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\windows\system32\drivers\mbae.sys [2016-12-14 59968]
R1 MpKsle3af3898;MpKsle3af3898; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98A2886D-637D-47D1-833D-8E6A4980B666}\MpKsle3af3898.sys [2017-01-09 39168]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 MBAMChameleon;MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [2017-01-08 153024]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-11-02 1163328]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-03-16 5590016]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-03-16 210432]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW73.sys [2010-11-17 101392]
R3 BCM42RLY;BCM42RLY; C:\windows\system32\drivers\BCM42RLY.sys [2013-10-02 18536]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\windows\system32\DRIVERS\bcmwl6.sys [2013-10-02 4269160]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2010-01-07 86056]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2010-01-07 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2010-01-07 29472]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2010-01-07 18472]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-16 21560]
R3 MBAMFarflt;MBAMFarflt; \??\C:\windows\system32\drivers\farflt.sys [2017-01-09 87496]
R3 MBAMProtection;MBAMProtection; \??\C:\windows\system32\drivers\mbam.sys [2017-01-09 39360]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2017-01-09 219072]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\windows\system32\drivers\mwac.sys [2017-01-09 63264]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2011-05-09 1763968]
R3 STHDA;@%SystemRoot%\system32\stlang.dll,-10322; C:\windows\system32\DRIVERS\stwrt.sys [2013-10-31 431616]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-06-04 1303728]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-03-09 107024]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 sisagp;Filtr SIS sběrnice AGP; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\aestsrv.exe [2013-10-31 81920]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-11-02 14336]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-03-16 176128]
R2 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-12-29 595232]
R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2017-01-09 113632]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-05 103992]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-03-01 264248]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2016-12-07 31776]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-02-22 73728]
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2016-12-14 3381200]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-08-12 22208]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2010-03-06 635416]
R2 PDFProFiltSrv;PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-11-03 134944]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 STacSV;@%SystemRoot%\system32\stlang.dll,-10122; C:\Program Files\IDT\WDM\STacSV.exe [2013-10-31 254034]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE [2013-10-02 40960]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2015-04-28 1102472]
S2 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28 144200]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-08-12 295376]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-11-23 1120752]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2013-10-02 1343400]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2012-07-09 46528]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#2 Příspěvek od JaRon »

ahoj,
pouzi navod kolegu http://forum.viry.cz/viewtopic.php?f=13 ... e#p1471056
oba kroky a napis, ci lepsie :???:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#3 Příspěvek od FineSelection »

Zoek.exe v5.0.0.1 Updated 19-September-2016
Tool run by MaI on po 09.01.2017 at 20:04:28,21.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\MaI\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

9.1.2017 20:05:30 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Program Files\MSXML 4.0 deleted successfully
C:\Program Files\Seznam.cz deleted successfully
C:\Users\MaI\AppData\Local\PDFC deleted successfully
C:\Users\MaI\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8DCB7100-DF86-4384-8842-8FA844297B3F} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\wltrysvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wltrysvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\wltrysvc deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wltrysvc deleted successfully

==== Deleting Files \ Folders ======================

C:\Program Files\Seznam.cz not found
C:\PROGRA~2\{18165758-115C-4DC0-9EC2-FF89F725767F} deleted
C:\Users\MaI\Downloads\bsplayer269-1079.exe deleted
C:\windows\system32\GroupPolicy\Machine deleted
C:\windows\system32\GroupPolicy\User deleted
C:\windows\system32\GroupPolicy\gpt.ini deleted

==== Chromium Look ======================

Canonical Url - MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\gibbofpfifeklicllnimkipggbodbegj
Awesome Reload All Tabs Button - MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\kamfkajbgmjkfmfgcikbmbmpjfokfijk
URL to QRCode - MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkggleleindffinefpajdemfpncccgoo
Chrome Media Router - MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.bing.com"
"Default_Page_URL"="http://www.bing.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.bing.com"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{CC02B300-11D7-44F2-A42E-34353E7C1697}"
HKLM\SearchScopes\{CC02B300-11D7-44F2-A42E-34353E7C1697} - http://www.bing.com/search?q={searchTer ... -SearchBox
HKCU\SearchScopes "DefaultScope"="{CC02B300-11D7-44F2-A42E-34353E7C1697}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{85F2B77E-8880-420A-B3FB-786E15336B4B} - http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
HKCU\SearchScopes\{CC02B300-11D7-44F2-A42E-34353E7C1697} - http://www.bing.com/search?q={searchTer ... -SearchBox

==== Reset Google Chrome ======================

C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\MaI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\MaI\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=6 folders=3 56084654 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\MaI\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

C:\windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\windows\Temp successfully emptied
C:\Users\MaI\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on po 09.01.2017 at 20:54:00,72 ======================


JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 7 Home Premium x86
Ran by MaI (Administrator) on po 09.01.2017 at 20:59:52,65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 09.01.2017 at 21:04:03,76
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#4 Příspěvek od JaRon »

nenapisal si, ci sa stav zlepsil :???:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#5 Příspěvek od FineSelection »

No přestaly otravovat ty webový stránky.. samo se už nic neotvírá. Počítač je však stále zpomalený a velmi hlučný. Když počítač restartuju, nebo vypínám, trvá to 5 - 10 minut. Malwarebytes si čas od času napíše, že se vypnula aktivní ochrana. To samý u windows defenderu. Po přihlášení do windows zčerná obrazovka a objeví se okno:

Hp support assistnat

The feature you are trying to use is on a network resource that is unavaiable. Click ok to try again or enter analternate path to a folder containing instalation package:

"nabídka adresáře"
C:\Program\data\{c595BE0A-1215-4A80-8765-23AOAAAE14EE}


Když dám try again tak to háže eror. Když dám cancel tak se spustí windows

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#6 Příspěvek od JaRon »

Pouzi delfix http://forum.viry.cz/viewtopic.php?f=30 ... x#p1469265
a potom vycisti registre CCleanerom
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#7 Příspěvek od FineSelection »

Provedl jsem. Počítač se zdá co se týče rychlosti v pořádku. Stále má však výkon procesoru na 95 - 100% a je hodně hlučný. Restartuje se už dobře, ale zapíná se dost pomalu. Malwarebytes ve scanu nic nenašel (předtím vždycky ano).

Problém s černou obrazovkou a hp asistance updatem přetrvává



Jaký je ještě možný postup?

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#8 Příspěvek od JaRon »

doinstaluj MSIE11 a dostupne aktualizacie OS
co sa tyka HP hlasky: bud preinstalovat, alebo najst v msconfig a zakazat pri spustani
+
vloz na kontrolu oba logy FRST
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#9 Příspěvek od FineSelection »

Ahoj,

na windowsech jsem provedl 1 důležitou aktualizaci, co mi to nabízelo. Když jsem chtěl vyhledat další aktualizace tak mi to ukázalo error že to není schopný (error number 8007000E).

Tady jsou logy:
FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-01-2017
Ran by MaI (administrator) on MAI-HP (12-01-2017 17:38:29)
Running from C:\Users\MaI\Desktop
Loaded Profiles: MaI (Available Profiles: MaI)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AEstSrv.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(HP Inc.) C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc.) C:\Windows\System32\atibtmon.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [estar] => C:\System.Sav\Util\HideDOS.EXE [77824 2006-11-28] ()
HKLM\...\Run: [PDFHook] => C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [1277952 2009-11-13] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF6 Registry Controller] => C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [110880 2009-11-03] (Nuance Communications, Inc.)
HKLM\...\Run: [Nuance PDF Reader-reminder] => "C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
HKLM\...\Run: [NortonOnlineBackupReminder] => C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2011-03-16] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [6510592 2013-10-02] (Broadcom Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2013-10-31] (IDT, Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7175384 2016-12-06] (Piriform Ltd)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\System32\scrnsave.scr [10240 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [280576 2013-10-14] (Microsoft Corporation)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-10-02]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{009832BA-93BE-4C55-AC5A-7C801D36A1DC}: [DhcpNameServer] 192.168.2.1 10.0.0.138
Tcpip\..\Interfaces\{D1CD6C39-B0D5-4995-BE66-0AA076AB1429}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
SearchScopes: HKLM -> DefaultScope {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> DefaultScope {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> {85F2B77E-8880-420A-B3FB-786E15336B4B} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)

FireFox:
========
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Users\MaI\Desktop\Picasa3\npPicasa3.dll [No File]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-22] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin: ZEON/PDF,version=2.0 -> C:\Program Files\Nuance\PDF Reader\bin\nppdf.dll [2010-01-23] (Zeon Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default [2017-01-12]
CHR Extension: (Prezentace Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-09]
CHR Extension: (Dokumenty Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-09]
CHR Extension: (Disk Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-09]
CHR Extension: (YouTube) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-09]
CHR Extension: (Tabulky Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-09]
CHR Extension: (Gmail) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-09]
CHR Extension: (Chrome Media Router) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-09]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-11-02] (LSI Corporation)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [113632 2017-01-09] (SurfRight B.V.)
R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard)
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3381200 2016-12-14] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc)
R2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [134944 2009-11-03] (Nuance Communications, Inc.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [254034 2013-10-31] (IDT, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BCM42RLY; C:\windows\System32\drivers\BCM42RLY.sys [18536 2013-10-02] (Broadcom Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae.sys [59968 2016-12-14] ()
R2 MBAMChameleon; C:\windows\system32\drivers\MBAMChameleon.sys [153024 2017-01-08] (Malwarebytes)
R3 MBAMFarflt; C:\windows\system32\drivers\farflt.sys [87496 2017-01-12] (Malwarebytes)
R3 MBAMProtection; C:\windows\system32\drivers\mbam.sys [39360 2017-01-12] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [219072 2017-01-12] (Malwarebytes)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
R1 MpKsl235bead4; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98A2886D-637D-47D1-833D-8E6A4980B666}\MpKsl235bead4.sys [39168 2017-01-12] (Microsoft Corporation)
R1 MpKslbfa14ee8; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98A2886D-637D-47D1-833D-8E6A4980B666}\MpKslbfa14ee8.sys [39168 2017-01-11] (Microsoft Corporation)
R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2011-05-09] ()

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-12 17:35 - 2017-01-12 17:38 - 00026539 _____ C:\Users\MaI\Desktop\Addition.txt
2017-01-12 17:33 - 2017-01-12 17:38 - 00014587 _____ C:\Users\MaI\Desktop\FRST.txt
2017-01-12 17:33 - 2017-01-12 17:38 - 00000000 ____D C:\FRST
2017-01-12 17:32 - 2017-01-12 17:32 - 01761280 _____ (Farbar) C:\Users\MaI\Desktop\FRST.exe
2017-01-12 17:24 - 2017-01-12 17:24 - 00313366 _____ C:\Users\MaI\Downloads\WindowsUpdate (1).diagcab
2017-01-12 17:17 - 2017-01-12 17:17 - 00000000 ____D C:\Users\MaI\AppData\Local\ElevatedDiagnostics
2017-01-12 17:14 - 2017-01-12 17:14 - 00313366 _____ C:\Users\MaI\Downloads\WindowsUpdate.diagcab
2017-01-12 17:07 - 2017-01-12 17:07 - 00000000 ____D C:\f9c97888b8c880888daa
2017-01-12 17:06 - 2017-01-12 17:07 - 02751664 _____ C:\Users\MaI\Downloads\Windows6.1-KB3102810-x86.msu
2017-01-12 17:06 - 2017-01-12 17:06 - 00369364 _____ C:\Users\MaI\Downloads\IE11-Windows6.1-KB3025390-x64.msu
2017-01-11 19:18 - 2017-01-11 19:56 - 00000259 _____ C:\DelFix.txt
2017-01-09 20:54 - 2017-01-09 20:54 - 00000000 ____D C:\Users\MaI\AppData\Local\PDFC
2017-01-09 20:53 - 2017-01-09 20:53 - 00000000 ____D C:\Users\MaI\AppData\Local\VirtualStore
2017-01-09 20:47 - 2017-01-09 20:04 - 00024064 _____ C:\windows\zoek-delete.exe
2017-01-09 20:26 - 2017-01-09 20:26 - 00000000 ____D C:\Users\MaI\AppData\Local\Microsoft Games
2017-01-09 11:19 - 2017-01-09 11:20 - 00000000 ____D C:\Program Files\trend micro
2017-01-09 10:23 - 2017-01-09 10:23 - 00001897 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2017-01-09 10:23 - 2017-01-09 10:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2017-01-09 10:23 - 2017-01-09 10:23 - 00000000 ____D C:\Program Files\HitmanPro
2017-01-09 10:22 - 2017-01-09 10:27 - 00000000 ____D C:\ProgramData\HitmanPro
2017-01-09 10:21 - 2017-01-09 10:22 - 11005320 _____ (SurfRight B.V.) C:\Users\MaI\Downloads\hitmanpro.exe
2017-01-08 20:00 - 2017-01-08 20:01 - 02953520 _____ (AVAST Software) C:\Users\MaI\Desktop\avast-browser-cleanup.exe
2017-01-08 15:46 - 2014-05-14 17:23 - 01973728 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-01-08 15:46 - 2014-05-14 17:23 - 00054240 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-01-08 15:46 - 2014-05-14 17:23 - 00045536 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2017-01-08 15:46 - 2014-05-14 17:17 - 02425856 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-01-08 15:45 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-01-08 15:45 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2017-01-08 15:45 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-01-08 15:45 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-01-08 15:45 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-01-08 15:17 - 2017-01-08 15:17 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-01-08 15:17 - 2017-01-08 15:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-01-08 15:16 - 2017-01-08 15:17 - 00000000 ____D C:\Program Files\CCleaner
2017-01-08 15:16 - 2017-01-08 15:16 - 08805960 _____ (Piriform Ltd) C:\Users\MaI\Downloads\ccsetup525pro.exe
2017-01-08 14:59 - 2017-01-08 14:59 - 00000000 ____D C:\Users\MaI\AppData\Roaming\Roxio Log Files
2017-01-08 14:36 - 2017-01-12 12:42 - 00087496 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2017-01-08 14:36 - 2017-01-12 12:42 - 00063264 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2017-01-08 14:36 - 2017-01-12 12:42 - 00039360 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2017-01-08 14:36 - 2017-01-12 12:41 - 00219072 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2017-01-08 14:36 - 2017-01-08 14:36 - 00153024 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMChameleon.sys
2017-01-08 14:35 - 2017-01-08 14:35 - 00002024 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-01-08 14:35 - 2017-01-08 14:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-01-08 14:35 - 2017-01-08 14:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-08 14:35 - 2017-01-08 14:35 - 00000000 ____D C:\Program Files\Malwarebytes
2017-01-08 14:35 - 2016-12-14 12:55 - 00059968 _____ C:\windows\system32\Drivers\mbae.sys
2017-01-08 14:34 - 2017-01-08 14:35 - 54199488 _____ (Malwarebytes ) C:\Users\MaI\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-08 14:32 - 2017-01-08 14:32 - 00000000 ____D C:\Users\MaI\Documents\Složka Bluetooth Exchange
2017-01-01 21:10 - 2017-01-01 21:10 - 00000000 _____ C:\Users\MaI\Downloads\BBID-01-01580154089041045
2017-01-01 20:29 - 2017-01-01 20:29 - 01185074 _____ C:\Users\MaI\Downloads\KC Arnold _final (1).pdf
2017-01-01 20:28 - 2017-01-01 20:28 - 01185074 _____ C:\Users\MaI\Downloads\Arnoldova vila - Kulturní centrum Josefa Arnolda.pdf
2017-01-01 19:29 - 2017-01-01 19:29 - 01185074 _____ C:\Users\MaI\Downloads\KC Arnold _final .pdf
2016-12-24 12:42 - 2016-12-24 12:43 - 00141578 _____ C:\Users\MaI\Downloads\161224_PosledniPrujezdy.pdf
2016-12-23 18:33 - 2016-12-23 18:33 - 00048885 _____ C:\Users\MaI\Documents\třídíme.docx

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-12 12:49 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-12 12:49 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-12 12:47 - 2010-06-01 01:31 - 07116424 _____ C:\windows\system32\perfh005.dat
2017-01-12 12:47 - 2010-06-01 01:31 - 02332100 _____ C:\windows\system32\perfc005.dat
2017-01-12 12:47 - 2010-06-01 01:09 - 00391852 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-12 12:47 - 2009-07-14 03:37 - 00000000 ____D C:\windows\inf
2017-01-12 12:40 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-12 12:32 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF
2017-01-12 09:58 - 2013-10-03 07:01 - 00000000 ____D C:\Program Files\Microsoft Office
2017-01-12 09:54 - 2016-01-01 18:26 - 00000312 _____ C:\windows\Tasks\HPCeeScheduleForMaI.job
2017-01-11 19:38 - 2013-10-02 21:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-01-11 16:20 - 2013-10-02 19:28 - 00002057 _____ C:\windows\epplauncher.mif
2017-01-11 16:19 - 2013-10-02 19:28 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2017-01-11 16:19 - 2013-10-02 19:27 - 00000000 ____D C:\Program Files\Microsoft Security Client
2017-01-11 16:16 - 2013-10-02 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-01-10 20:28 - 2014-12-01 17:57 - 00000000 ____D C:\Users\MaI\Documents\učitelství estet.výchovy
2017-01-09 20:53 - 2013-10-02 18:18 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-01-09 20:37 - 2009-07-14 03:37 - 00000000 ___HD C:\windows\system32\GroupPolicy
2017-01-08 20:38 - 2010-06-01 01:27 - 00000000 ____D C:\windows\system32\Macromed
2017-01-08 15:21 - 2010-04-25 09:41 - 00000000 ____D C:\windows\Panther
2017-01-08 15:01 - 2010-06-01 01:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio
2017-01-08 15:01 - 2010-06-01 01:44 - 00000000 ____D C:\Program Files\Common Files\Sonic Shared
2017-01-08 15:01 - 2010-06-01 01:44 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine
2017-01-08 14:45 - 2009-07-14 05:53 - 00032614 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-07 15:50 - 2016-11-10 16:27 - 00000000 ____D C:\Users\MaI\Desktop\státnice
2017-01-06 10:15 - 2010-06-01 01:25 - 00000000 ____D C:\ProgramData\PDFC
2017-01-04 17:26 - 2013-12-27 10:26 - 00000000 ____D C:\Users\MaI\AppData\Roaming\Seznam.cz
2017-01-01 22:57 - 2016-11-01 14:16 - 00000000 ____D C:\Users\MaI\Documents\KC Josefa A
2017-01-01 22:57 - 2015-05-15 19:41 - 00000000 ____D C:\Users\MaI\Documents\managment
2016-12-30 20:56 - 2013-10-02 22:32 - 00000052 _____ C:\windows\system32\DOErrors.log
2016-12-30 20:56 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Tasks
2016-12-20 21:23 - 2009-07-14 03:37 - 00000000 __RSD C:\windows\assembly
2016-12-15 13:59 - 2013-10-03 18:10 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-15 13:59 - 2013-10-03 18:10 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-15 13:59 - 2013-10-03 03:00 - 00000000 ____D C:\windows\Prefetch

==================== Files in the root of some directories =======

2013-12-02 21:41 - 2016-10-11 18:30 - 0000088 __RSH () C:\ProgramData\A7B4674B71.sys
2013-12-02 21:41 - 2016-10-11 18:30 - 0002828 ___SH () C:\ProgramData\KGyGaAvL.sys

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-04 16:08

==================== End of FRST.txt ============================

Addition
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-01-2017
Ran by MaI (12-01-2017 17:40:26)
Running from C:\Users\MaI\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2013-10-02 17:11:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3103529041-4251153409-2491265020-500 - Administrator - Disabled)
Guest (S-1-5-21-3103529041-4251153409-2491265020-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3103529041-4251153409-2491265020-1003 - Limited - Enabled)
MaI (S-1-5-21-3103529041-4251153409-2491265020-1001 - Administrator - Enabled) => C:\Users\MaI

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
ATI Catalyst Install Manager (HKLM\...\{992F7E6B-58D4-428A-B574-082C0884423E}) (Version: 3.0.778.0 - ATI Technologies, Inc.)
Bing Bar (HKLM\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation)
Broadcom 2070 Bluetooth 2.1 + EDR (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.1100 - Broadcom Corporation)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.143 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.100.82.143 - Broadcom Corporation)
BS.Player FREE (HKLM\...\BSPlayerf) (Version: 2.69.1079 - AB Team, d.o.o.)
ccc-core-static (Version: 2011.0316.116.298 - Název společnosti:) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform)
Corel Home Office - CS Templates (Version: 5.6.5 - 公司名称) Hidden
Corel Home Office - CT Templates (Version: 5.6.5 - 您的公司名稱) Hidden
Corel Home Office - IPM (Version: 5.6.5 - Corel Corporation) Hidden
Corel Home Office - JP Templates (Version: 5.6.5 - 会社名) Hidden
Corel Home Office - KR Templates (Version: 5.6.5 - 회사명) Hidden
Corel Home Office - Launcher (Version: 5.6.5 - Corel Corporation) Hidden
Corel Home Office - Templates RU (Version: 5.6.5 - Название организации) Hidden
Corel Home Office - Templates1 (Version: 5.6.5 - Your Company Name) Hidden
Corel Home Office (HKLM\...\_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}) (Version: 5.0.87.621 - Corel Corporation)
Corel Home Office (Version: 5.6.5 - Corel Corporation) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DirectX 9 Runtime (Version: 1.00.0000 - Sonic Solutions) Hidden
Energy Star Digital Logo (HKLM\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Google Chrome (HKLM\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.32.7 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.15.281 - SurfRight B.V.)
HP Advisor (HKLM\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard)
HP ESU for Microsoft Windows 7 (HKLM\...\{C2686567-5A9A-4B6D-B965-7A5E26F73A25}) (Version: 1.1.3.1 - Hewlett-Packard Company)
HP HotKey Support (HKLM\...\{4BBA5224-C5B1-4B8C-AAA4-68DA6654B9C1}) (Version: 3.5.15.1 - Hewlett-Packard Company)
HP Setup (HKLM\...\{96AC1B0B-02D1-4FAA-9C1E-C92ECA74921A}) (Version: 8.2.4130.3367 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM\...\{2DA697D7-FED3-4DE2-A174-92A2A12F9688}) (Version: 3.0.5.0 - Hewlett-Packard Company)
HP Software Framework (HKLM\...\{DA200FDD-DE3D-4958-8465-C4FBC869544B}) (Version: 3.5.20.1 - Hewlett-Packard Company)
HP Software Setup (HKLM\...\{04801E42-B1A6-4C52-9F3D-CADB5A050433}) (Version: 7.0.1.6 - Hewlett-Packard Company)
HP Support Assistant (HKLM\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM\...\{79CA8D8A-8371-4146-8920-C1405318E65E}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP User Guides 0190 (HKLM\...\{5B0D9F1A-425E-46C4-B06D-2C0736C1E804}) (Version: 1.00.0000 - Hewlett-Packard)
HP Webcam (HKLM\...\{1D61E881-43CD-447B-9E6B-D2C6138B2862}) (Version: 1.0.19.5 - Roxio)
HP Webcam Driver (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.50018.0 - Sonix)
HP Wireless Assistant (HKLM\...\{EC720706-3F19-4B7F-BDDD-E31D9B3921D2}) (Version: 4.0.6.0 - Hewlett-Packard)
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6300.0 - IDT)
LightScribe System Software (HKLM\...\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
Malwarebytes verze 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
Microsoft .NET Framework 4 Client Profile CSY Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile CSY Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton Online Backup (HKLM\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 2.0.0.34 - Symantec)
Nuance PDF Professional 6 (HKLM\...\{BDB494AE-3597-41E7-8B6A-F6BAF4E514EE}) (Version: 6.00.3205 - Nuance Communications, Inc)
Nuance PDF Reader (HKLM\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0043 - Nuance Communications, Inc.)
PDF Complete Special Edition (HKLM\...\PDF Complete) (Version: 3.5.117 - PDF Complete, Inc)
Polda III (HKLM\...\Polda III_is1) (Version: - )
Realtek Ethernet Controller All-In-One Windows Driver (HKLM\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0011 - Realtek)
Roxio Creator Business (HKLM\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.20 - Roxio)
Scansoft PDF Professional (Version: - ) Hidden
Skype™ 5.10 (HKLM\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
Sonic CinePlayer Decoder Pack (Version: 4.3.0 - Sonic Solutions) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Windows 7 Default Setting (HKLM\...\{5BF8E079-D6E2-4323-B794-75152371122A}) (Version: 1.0.1.7 - Hewlett-Packard Company)
Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (HKLM\...\A6A8668C0A13640CA28FE2A7D9654BE4AE478B13) (Version: 07/30/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom Bluetooth (12/16/2009 6.2.0.9414) (HKLM\...\0973B297E079B467E3776E59F763D63FD557795B) (Version: 12/16/2009 6.2.0.9414 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\BF20603967CFDCB2BBF91950E8A56DFBC5C833FE) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 14.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}) (Version: 14.0.9029 - WinZip Computing, S.L. )
WMV9/VC-1 Video Playback (Version: 1.0.60316.0158 - ATI Technologies Inc.) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0656594F-49A0-4410-87E4-7F0A563FCBC3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {10AF39E4-DE3B-4F9E-BCE5-575BCFCEDB90} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {380E1BD1-3ABD-4858-962C-C425ECD0BC3B} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {7672DADF-481C-4923-BD98-0EF29869B837} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {87D5DC35-D787-48DA-8F8A-EA2FB9966F63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {8DFFAE46-548B-41A0-BCA1-ABF7DCFBAEB3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28] (Google Inc.)
Task: {920A5F0C-195D-4987-BEBA-EA202DBDABC5} - System32\Tasks\HPCeeScheduleForMaI => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {93ACE22A-79AF-4AC6-83B1-7C1578040E36} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28] (Google Inc.)
Task: {AA107988-8DDB-403F-A81D-BA18C76D094F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {D5A6D9EC-3912-4045-ADBB-09C37C684A9E} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\HP Setup\RemEngine.exe [2010-04-22] ()
Task: {DA0A0308-41C7-4559-AB8B-49F1B94DEF87} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {E24FFC34-474B-4E35-A129-DB6FD71A991A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {EC9B1383-411C-4802-892C-1307E321CF4E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2016-12-15] (HP Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\HPCeeScheduleForMaI.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2017-01-08 14:35 - 2016-12-14 12:55 - 01729312 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-01-08 14:35 - 2016-12-14 12:55 - 02084304 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2017-01-08 14:35 - 2016-12-14 12:55 - 01713104 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2009-12-29 12:31 - 2009-12-29 12:31 - 00132384 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2016-01-06 17:41 - 2016-01-06 17:41 - 00062168 _____ () C:\Program Files\CCleaner\branding.dll
2010-04-05 19:12 - 2010-04-05 19:12 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2010-04-05 19:11 - 2010-04-05 19:11 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-04-05 19:12 - 2010-04-05 19:12 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2011-03-14 13:20 - 2011-03-14 13:20 - 00098304 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-03-16 00:14 - 2011-03-16 00:14 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2016-12-15 13:59 - 2016-12-08 08:29 - 01829208 _____ () C:\Program Files\Google\Chrome\Application\55.0.2883.87\libglesv2.dll
2016-12-15 13:59 - 2016-12-08 08:29 - 00085848 _____ () C:\Program Files\Google\Chrome\Application\55.0.2883.87\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2017-01-09 20:06 - 00000841 ____A C:\windows\system32\Drivers\etc\hosts

127.0.0.1 localhost
::1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\MaI\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{3BC922FA-3FC8-434D-A8E8-7944F731C212}] => C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{4714EE87-05C4-42C0-A832-69EAFE04A57D}] => C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{6AE3781C-A131-4CEB-8E7A-53986F766A8C}] => LPort=2869
FirewallRules: [{3A9DAA3B-A3E2-44ED-B5B0-D4EA648D8F5E}] => LPort=1900
FirewallRules: [{79344688-EB0B-46A8-9531-897D2B20A8D3}] => C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{88A398DA-4099-4CC5-B509-2F0FF8BD7284}] => C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

08-01-2017 15:44:52 Windows Update
08-01-2017 21:29:18 JRT Pre-Junkware Removal
09-01-2017 10:53:12 JRT Pre-Junkware Removal
09-01-2017 20:05:10 zoek.exe restore point
09-01-2017 20:59:56 JRT Pre-Junkware Removal
11-01-2017 16:14:07 Windows Update
12-01-2017 09:58:14 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/12/2017 05:02:53 PM) (Source: ESENT) (EventID: 489) (User: )
Description: CCleaner (3008) Pokus o otevření souboru C:\Users\MaI\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat jen pro čtení se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru se nezdaří a dojde k chybě -1032 (0xfffffbf8).

Error: (01/12/2017 12:47:14 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (01/12/2017 12:42:28 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.

Error: (01/11/2017 07:54:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (01/11/2017 07:39:37 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.

Error: (01/11/2017 07:20:42 PM) (Source: ESENT) (EventID: 489) (User: )
Description: CCleaner (3196) Pokus o otevření souboru C:\Users\MaI\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat jen pro čtení se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru se nezdaří a dojde k chybě -1032 (0xfffffbf8).

Error: (01/11/2017 04:20:37 PM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: NT AUTHORITY)
Description: HRESULT:0x8004FF06
Description:Microsoft Security Essentials is already installed. A newer version of Security Essentials is already installed on your computer. Error code:0x8004FF06.

Error: (01/11/2017 04:15:53 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (01/11/2017 04:10:06 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.

Error: (01/10/2017 08:24:24 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.


System errors:
=============
Error: (01/12/2017 05:17:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem

Fáze aktualizace: Instalovat

Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ podpisu: Antispywarový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\NETWORK SERVICE

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8000ffff

Popis chyby: Katastrofální selhání

Error: (01/12/2017 05:17:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem

Fáze aktualizace: Instalovat

Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ podpisu: Antivirový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\NETWORK SERVICE

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8000ffff

Popis chyby: Katastrofální selhání

Error: (01/12/2017 05:16:12 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/12/2017 05:15:42 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Server Microsoft Update

Fáze aktualizace: Vyhledat

Zdrojová cesta: http://www.microsoft.com

Typ podpisu: Antivirový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\SYSTEM

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8024001e

Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Error: (01/12/2017 05:02:32 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby ShellHWDetection bylo dosaženo časového limitu (30000 ms).

Error: (01/12/2017 05:02:36 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {995C996E-D918-4A8C-A302-45719A6F4EA7} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/12/2017 01:02:43 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače PAVEL-PC,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{D1CD6C39-B0D5-4995-BE66-0AA076AB1.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (01/12/2017 12:36:06 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby Winmgmt bylo dosaženo časového limitu (30000 ms).

Error: (01/12/2017 12:35:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby MBAMService bylo dosaženo časového limitu (30000 ms).

Error: (01/12/2017 12:35:04 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Služba Windows Update se po přijetí pokynu pro vypnutí neukončila správně.


==================== Memory info ===========================

Processor: AMD Athlon(tm) II P320 Dual-Core Processor
Percentage of memory in use: 83%
Total physical RAM: 2809.56 MB
Available physical RAM: 473.78 MB
Total Virtual: 5617.41 MB
Available Virtual: 2720.37 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:280.79 GB) (Free:226.99 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: BF357B7B)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=280.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)

==================== End of Addition.txt ============================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#10 Příspěvek od JaRon »

Preco tam nie je MSIE 11 :???:
Odinstaluj Hitman a MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#11 Příspěvek od FineSelection »

MSIE 11 by tam už měl být. Hitmana i MBytes jsem odinstaloval. Udělal jsem ještě jednou FRST (snad zbytečně nespamuju):

FRST log
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2017
Ran by MaI (administrator) on MAI-HP (13-01-2017 18:09:11)
Running from C:\Users\MaI\Desktop
Loaded Profiles: MaI (Available Profiles: MaI)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AEstSrv.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\BBSvc.EXE
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(HP Inc.) C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(HP Inc.) C:\ProgramData\Hewlett-Packard\UninstallHPSA.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [estar] => C:\System.Sav\Util\HideDOS.EXE [77824 2006-11-28] ()
HKLM\...\Run: [PDFHook] => C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [1277952 2009-11-13] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF6 Registry Controller] => C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [110880 2009-11-03] (Nuance Communications, Inc.)
HKLM\...\Run: [Nuance PDF Reader-reminder] => "C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
HKLM\...\Run: [NortonOnlineBackupReminder] => C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2011-03-16] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [6510592 2013-10-02] (Broadcom Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2013-10-31] (IDT, Inc.)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7175384 2016-12-06] (Piriform Ltd)
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\System32\scrnsave.scr [10240 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [280576 2013-10-14] (Microsoft Corporation)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-10-02]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{009832BA-93BE-4C55-AC5A-7C801D36A1DC}: [DhcpNameServer] 192.168.2.1 10.0.0.138
Tcpip\..\Interfaces\{D1CD6C39-B0D5-4995-BE66-0AA076AB1429}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
SearchScopes: HKLM -> DefaultScope {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> DefaultScope {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> {85F2B77E-8880-420A-B3FB-786E15336B4B} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
SearchScopes: HKU\S-1-5-21-3103529041-4251153409-2491265020-1001 -> {CC02B300-11D7-44F2-A42E-34353E7C1697} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)

FireFox:
========
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Users\MaI\Desktop\Picasa3\npPicasa3.dll [No File]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-22] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-18] (Google Inc.)
FF Plugin: ZEON/PDF,version=2.0 -> C:\Program Files\Nuance\PDF Reader\bin\nppdf.dll [2010-01-23] (Zeon Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default [2017-01-13]
CHR Extension: (Prezentace Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-09]
CHR Extension: (Dokumenty Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-09]
CHR Extension: (Disk Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-09]
CHR Extension: (YouTube) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-09]
CHR Extension: (Tabulky Google) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-09]
CHR Extension: (Gmail) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-09]
CHR Extension: (Chrome Media Router) - C:\Users\MaI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-09]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-11-02] (LSI Corporation)
R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard)
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc)
R2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [134944 2009-11-03] (Nuance Communications, Inc.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [254034 2013-10-31] (IDT, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BCM42RLY; C:\windows\System32\drivers\BCM42RLY.sys [18536 2013-10-02] (Broadcom Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
R1 MpKsl38e9fa03; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98A2886D-637D-47D1-833D-8E6A4980B666}\MpKsl38e9fa03.sys [39168 2017-01-13] (Microsoft Corporation)
R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2011-05-09] ()

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-13 18:09 - 2017-01-13 18:10 - 00014130 _____ C:\Users\MaI\Desktop\FRST.txt
2017-01-13 18:02 - 2017-01-13 18:02 - 00000000 ____D C:\Users\MaI\Desktop\FRST-OlderVersion
2017-01-13 17:25 - 2017-01-13 17:25 - 19607040 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 12829696 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 04305920 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2017-01-13 17:25 - 2017-01-13 17:25 - 02278912 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2017-01-13 17:25 - 2017-01-13 17:25 - 01950720 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 01309696 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00664064 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00645120 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2017-01-13 17:25 - 2017-01-13 17:25 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00342728 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2017-01-13 17:25 - 2017-01-13 17:25 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00233472 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00208384 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00151552 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2017-01-13 17:25 - 2017-01-13 17:25 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2017-01-13 17:25 - 2017-01-13 17:25 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2017-01-13 17:25 - 2017-01-13 17:25 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2017-01-13 17:21 - 2017-01-13 17:21 - 32528592 _____ (Microsoft Corporation) C:\Users\MaI\Downloads\IE11-Windows6.1-x86-cs-cz.exe
2017-01-12 17:33 - 2017-01-13 18:02 - 00000000 ____D C:\FRST
2017-01-12 17:32 - 2017-01-13 18:02 - 01761280 _____ (Farbar) C:\Users\MaI\Desktop\FRST.exe
2017-01-12 17:24 - 2017-01-12 17:24 - 00313366 _____ C:\Users\MaI\Downloads\WindowsUpdate (1).diagcab
2017-01-12 17:17 - 2017-01-12 17:17 - 00000000 ____D C:\Users\MaI\AppData\Local\ElevatedDiagnostics
2017-01-12 17:14 - 2017-01-12 17:14 - 00313366 _____ C:\Users\MaI\Downloads\WindowsUpdate.diagcab
2017-01-12 17:07 - 2017-01-12 17:07 - 00000000 ____D C:\f9c97888b8c880888daa
2017-01-12 17:06 - 2017-01-12 17:07 - 02751664 _____ C:\Users\MaI\Downloads\Windows6.1-KB3102810-x86.msu
2017-01-12 17:06 - 2017-01-12 17:06 - 00369364 _____ C:\Users\MaI\Downloads\IE11-Windows6.1-KB3025390-x64.msu
2017-01-11 19:18 - 2017-01-11 19:56 - 00000259 _____ C:\DelFix.txt
2017-01-09 20:54 - 2017-01-09 20:54 - 00000000 ____D C:\Users\MaI\AppData\Local\PDFC
2017-01-09 20:53 - 2017-01-09 20:53 - 00000000 ____D C:\Users\MaI\AppData\Local\VirtualStore
2017-01-09 20:47 - 2017-01-09 20:04 - 00024064 _____ C:\windows\zoek-delete.exe
2017-01-09 20:26 - 2017-01-09 20:26 - 00000000 ____D C:\Users\MaI\AppData\Local\Microsoft Games
2017-01-09 11:19 - 2017-01-09 11:20 - 00000000 ____D C:\Program Files\trend micro
2017-01-09 10:23 - 2017-01-13 17:18 - 00000000 ____D C:\Program Files\HitmanPro
2017-01-09 10:22 - 2017-01-09 10:27 - 00000000 ____D C:\ProgramData\HitmanPro
2017-01-09 10:21 - 2017-01-09 10:22 - 11005320 _____ (SurfRight B.V.) C:\Users\MaI\Downloads\hitmanpro.exe
2017-01-08 20:00 - 2017-01-08 20:01 - 02953520 _____ (AVAST Software) C:\Users\MaI\Desktop\avast-browser-cleanup.exe
2017-01-08 15:46 - 2014-05-14 17:23 - 01973728 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2017-01-08 15:46 - 2014-05-14 17:23 - 00054240 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2017-01-08 15:46 - 2014-05-14 17:23 - 00045536 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2017-01-08 15:46 - 2014-05-14 17:17 - 02425856 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2017-01-08 15:45 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2017-01-08 15:45 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2017-01-08 15:45 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2017-01-08 15:45 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2017-01-08 15:45 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2017-01-08 15:17 - 2017-01-08 15:17 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-01-08 15:17 - 2017-01-08 15:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-01-08 15:16 - 2017-01-08 15:17 - 00000000 ____D C:\Program Files\CCleaner
2017-01-08 15:16 - 2017-01-08 15:16 - 08805960 _____ (Piriform Ltd) C:\Users\MaI\Downloads\ccsetup525pro.exe
2017-01-08 14:59 - 2017-01-08 14:59 - 00000000 ____D C:\Users\MaI\AppData\Roaming\Roxio Log Files
2017-01-08 14:34 - 2017-01-08 14:35 - 54199488 _____ (Malwarebytes ) C:\Users\MaI\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2017-01-08 14:32 - 2017-01-08 14:32 - 00000000 ____D C:\Users\MaI\Documents\Složka Bluetooth Exchange
2017-01-01 21:10 - 2017-01-01 21:10 - 00000000 _____ C:\Users\MaI\Downloads\BBID-01-01580154089041045
2017-01-01 20:29 - 2017-01-01 20:29 - 01185074 _____ C:\Users\MaI\Downloads\KC Arnold _final (1).pdf
2017-01-01 20:28 - 2017-01-01 20:28 - 01185074 _____ C:\Users\MaI\Downloads\Arnoldova vila - Kulturní centrum Josefa Arnolda.pdf
2017-01-01 19:29 - 2017-01-01 19:29 - 01185074 _____ C:\Users\MaI\Downloads\KC Arnold _final .pdf
2016-12-24 12:42 - 2016-12-24 12:43 - 00141578 _____ C:\Users\MaI\Downloads\161224_PosledniPrujezdy.pdf
2016-12-23 18:33 - 2016-12-23 18:33 - 00048885 _____ C:\Users\MaI\Documents\třídíme.docx

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-13 18:09 - 2010-06-01 01:07 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2017-01-13 17:58 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-13 17:58 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-13 17:57 - 2010-06-01 01:31 - 07141284 _____ C:\windows\system32\perfh005.dat
2017-01-13 17:57 - 2010-06-01 01:31 - 02340532 _____ C:\windows\system32\perfc005.dat
2017-01-13 17:57 - 2010-06-01 01:09 - 00391852 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-13 17:57 - 2010-04-25 09:41 - 00000000 ____D C:\windows\Panther
2017-01-13 17:57 - 2009-07-14 03:37 - 00000000 ____D C:\windows\inf
2017-01-13 17:52 - 2016-01-01 18:26 - 00000312 _____ C:\windows\Tasks\HPCeeScheduleForMaI.job
2017-01-13 17:52 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-13 17:51 - 2009-07-14 03:37 - 00000000 ____D C:\windows\PolicyDefinitions
2017-01-13 17:16 - 2010-06-01 01:25 - 00000000 ____D C:\ProgramData\PDFC
2017-01-12 12:32 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\NDF
2017-01-12 09:58 - 2013-10-03 07:01 - 00000000 ____D C:\Program Files\Microsoft Office
2017-01-11 19:38 - 2013-10-02 21:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-01-11 16:20 - 2013-10-02 19:28 - 00002057 _____ C:\windows\epplauncher.mif
2017-01-11 16:19 - 2013-10-02 19:28 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2017-01-11 16:19 - 2013-10-02 19:27 - 00000000 ____D C:\Program Files\Microsoft Security Client
2017-01-11 16:16 - 2013-10-02 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-01-10 20:28 - 2014-12-01 17:57 - 00000000 ____D C:\Users\MaI\Documents\učitelství estet.výchovy
2017-01-09 20:53 - 2013-10-02 18:18 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-01-09 20:37 - 2009-07-14 03:37 - 00000000 ___HD C:\windows\system32\GroupPolicy
2017-01-08 20:38 - 2010-06-01 01:27 - 00000000 ____D C:\windows\system32\Macromed
2017-01-08 15:01 - 2010-06-01 01:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio
2017-01-08 15:01 - 2010-06-01 01:44 - 00000000 ____D C:\Program Files\Common Files\Sonic Shared
2017-01-08 15:01 - 2010-06-01 01:44 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine
2017-01-08 14:45 - 2009-07-14 05:53 - 00032614 _____ C:\windows\Tasks\SCHEDLGU.TXT
2017-01-07 15:50 - 2016-11-10 16:27 - 00000000 ____D C:\Users\MaI\Desktop\státnice
2017-01-04 17:26 - 2013-12-27 10:26 - 00000000 ____D C:\Users\MaI\AppData\Roaming\Seznam.cz
2017-01-01 22:57 - 2016-11-01 14:16 - 00000000 ____D C:\Users\MaI\Documents\KC Josefa A
2017-01-01 22:57 - 2015-05-15 19:41 - 00000000 ____D C:\Users\MaI\Documents\managment
2016-12-20 21:23 - 2009-07-14 03:37 - 00000000 __RSD C:\windows\assembly
2016-12-15 13:59 - 2013-10-03 18:10 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-15 13:59 - 2013-10-03 18:10 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-15 13:59 - 2013-10-03 03:00 - 00000000 ____D C:\windows\Prefetch

==================== Files in the root of some directories =======

2013-12-02 21:41 - 2016-10-11 18:30 - 0000088 __RSH () C:\ProgramData\A7B4674B71.sys
2013-12-02 21:41 - 2016-10-11 18:30 - 0002828 ___SH () C:\ProgramData\KGyGaAvL.sys

Some files in TEMP:
====================
C:\Users\MaI\AppData\Local\Temp\HitmanPro.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-04 16:08

==================== End of FRST.txt ============================

Addition
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-01-2017
Ran by MaI (13-01-2017 18:11:16)
Running from C:\Users\MaI\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2013-10-02 17:11:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3103529041-4251153409-2491265020-500 - Administrator - Disabled)
Guest (S-1-5-21-3103529041-4251153409-2491265020-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3103529041-4251153409-2491265020-1003 - Limited - Enabled)
MaI (S-1-5-21-3103529041-4251153409-2491265020-1001 - Administrator - Enabled) => C:\Users\MaI

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
ATI Catalyst Install Manager (HKLM\...\{992F7E6B-58D4-428A-B574-082C0884423E}) (Version: 3.0.778.0 - ATI Technologies, Inc.)
Bing Bar (HKLM\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation)
Broadcom 2070 Bluetooth 2.1 + EDR (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.1100 - Broadcom Corporation)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.143 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.100.82.143 - Broadcom Corporation)
BS.Player FREE (HKLM\...\BSPlayerf) (Version: 2.69.1079 - AB Team, d.o.o.)
ccc-core-static (Version: 2011.0316.116.298 - Název společnosti:) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform)
Corel Home Office - CS Templates (Version: 5.6.5 - 公司名称) Hidden
Corel Home Office - CT Templates (Version: 5.6.5 - 您的公司名稱) Hidden
Corel Home Office - IPM (Version: 5.6.5 - Corel Corporation) Hidden
Corel Home Office - JP Templates (Version: 5.6.5 - 会社名) Hidden
Corel Home Office - KR Templates (Version: 5.6.5 - 회사명) Hidden
Corel Home Office - Launcher (Version: 5.6.5 - Corel Corporation) Hidden
Corel Home Office - Templates RU (Version: 5.6.5 - Название организации) Hidden
Corel Home Office - Templates1 (Version: 5.6.5 - Your Company Name) Hidden
Corel Home Office (HKLM\...\_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}) (Version: 5.0.87.621 - Corel Corporation)
Corel Home Office (Version: 5.6.5 - Corel Corporation) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DirectX 9 Runtime (Version: 1.00.0000 - Sonic Solutions) Hidden
Energy Star Digital Logo (HKLM\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Google Chrome (HKLM\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.32.7 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Advisor (HKLM\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard)
HP ESU for Microsoft Windows 7 (HKLM\...\{C2686567-5A9A-4B6D-B965-7A5E26F73A25}) (Version: 1.1.3.1 - Hewlett-Packard Company)
HP HotKey Support (HKLM\...\{4BBA5224-C5B1-4B8C-AAA4-68DA6654B9C1}) (Version: 3.5.15.1 - Hewlett-Packard Company)
HP Setup (HKLM\...\{96AC1B0B-02D1-4FAA-9C1E-C92ECA74921A}) (Version: 8.2.4130.3367 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM\...\{2DA697D7-FED3-4DE2-A174-92A2A12F9688}) (Version: 3.0.5.0 - Hewlett-Packard Company)
HP Software Framework (HKLM\...\{DA200FDD-DE3D-4958-8465-C4FBC869544B}) (Version: 3.5.20.1 - Hewlett-Packard Company)
HP Software Setup (HKLM\...\{04801E42-B1A6-4C52-9F3D-CADB5A050433}) (Version: 7.0.1.6 - Hewlett-Packard Company)
HP Support Assistant (HKLM\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM\...\{79CA8D8A-8371-4146-8920-C1405318E65E}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP User Guides 0190 (HKLM\...\{5B0D9F1A-425E-46C4-B06D-2C0736C1E804}) (Version: 1.00.0000 - Hewlett-Packard)
HP Webcam (HKLM\...\{1D61E881-43CD-447B-9E6B-D2C6138B2862}) (Version: 1.0.19.5 - Roxio)
HP Webcam Driver (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.50018.0 - Sonix)
HP Wireless Assistant (HKLM\...\{EC720706-3F19-4B7F-BDDD-E31D9B3921D2}) (Version: 4.0.6.0 - Hewlett-Packard)
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6300.0 - IDT)
LightScribe System Software (HKLM\...\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
Microsoft .NET Framework 4 Client Profile CSY Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile CSY Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton Online Backup (HKLM\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 2.0.0.34 - Symantec)
Nuance PDF Professional 6 (HKLM\...\{BDB494AE-3597-41E7-8B6A-F6BAF4E514EE}) (Version: 6.00.3205 - Nuance Communications, Inc)
Nuance PDF Reader (HKLM\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0043 - Nuance Communications, Inc.)
PDF Complete Special Edition (HKLM\...\PDF Complete) (Version: 3.5.117 - PDF Complete, Inc)
Polda III (HKLM\...\Polda III_is1) (Version: - )
Realtek Ethernet Controller All-In-One Windows Driver (HKLM\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0011 - Realtek)
Roxio Creator Business (HKLM\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.20 - Roxio)
Scansoft PDF Professional (Version: - ) Hidden
Skype™ 5.10 (HKLM\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
Sonic CinePlayer Decoder Pack (Version: 4.3.0 - Sonic Solutions) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Windows 7 Default Setting (HKLM\...\{5BF8E079-D6E2-4323-B794-75152371122A}) (Version: 1.0.1.7 - Hewlett-Packard Company)
Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (HKLM\...\A6A8668C0A13640CA28FE2A7D9654BE4AE478B13) (Version: 07/30/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom Bluetooth (12/16/2009 6.2.0.9414) (HKLM\...\0973B297E079B467E3776E59F763D63FD557795B) (Version: 12/16/2009 6.2.0.9414 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\BF20603967CFDCB2BBF91950E8A56DFBC5C833FE) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 14.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}) (Version: 14.0.9029 - WinZip Computing, S.L. )
WMV9/VC-1 Video Playback (Version: 1.0.60316.0158 - ATI Technologies Inc.) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0656594F-49A0-4410-87E4-7F0A563FCBC3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {273A1446-4104-473A-8F38-B37001F598EA} - System32\Tasks\HPCeeScheduleForMaI => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {74471BE3-5F46-4672-B4A2-644B1310AB45} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {87D5DC35-D787-48DA-8F8A-EA2FB9966F63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {8DFFAE46-548B-41A0-BCA1-ABF7DCFBAEB3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28] (Google Inc.)
Task: {93ACE22A-79AF-4AC6-83B1-7C1578040E36} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28] (Google Inc.)
Task: {D5A6D9EC-3912-4045-ADBB-09C37C684A9E} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\HP Setup\RemEngine.exe [2010-04-22] ()
Task: {E24FFC34-474B-4E35-A129-DB6FD71A991A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {FAAF6875-FC25-4126-AF4C-14D0C10A69D3} - System32\Tasks\Microsoft\Microsoft Antimalware\MpIdleTask => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\HPCeeScheduleForMaI.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2010-04-05 19:12 - 2010-04-05 19:12 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2010-02-22 19:19 - 2010-02-22 19:19 - 02121728 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2010-02-22 19:19 - 2010-02-22 19:19 - 07745536 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2010-02-22 19:19 - 2010-02-22 19:19 - 00135168 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2009-12-29 12:31 - 2009-12-29 12:31 - 00132384 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2016-01-06 17:41 - 2016-01-06 17:41 - 00062168 _____ () C:\Program Files\CCleaner\branding.dll
2011-03-14 13:20 - 2011-03-14 13:20 - 00098304 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-03-16 00:14 - 2011-03-16 00:14 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2010-04-05 19:11 - 2010-04-05 19:11 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-04-05 19:12 - 2010-04-05 19:12 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2016-12-15 13:59 - 2016-12-08 08:29 - 01829208 _____ () C:\Program Files\Google\Chrome\Application\55.0.2883.87\libglesv2.dll
2016-12-15 13:59 - 2016-12-08 08:29 - 00085848 _____ () C:\Program Files\Google\Chrome\Application\55.0.2883.87\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2017-01-09 20:06 - 00000841 ____A C:\windows\system32\Drivers\etc\hosts

127.0.0.1 localhost
::1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3103529041-4251153409-2491265020-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\MaI\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{3BC922FA-3FC8-434D-A8E8-7944F731C212}] => C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{4714EE87-05C4-42C0-A832-69EAFE04A57D}] => C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{6AE3781C-A131-4CEB-8E7A-53986F766A8C}] => LPort=2869
FirewallRules: [{3A9DAA3B-A3E2-44ED-B5B0-D4EA648D8F5E}] => LPort=1900
FirewallRules: [{79344688-EB0B-46A8-9531-897D2B20A8D3}] => C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{88A398DA-4099-4CC5-B509-2F0FF8BD7284}] => C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

08-01-2017 15:44:52 Windows Update
08-01-2017 21:29:18 JRT Pre-Junkware Removal
09-01-2017 10:53:12 JRT Pre-Junkware Removal
09-01-2017 20:05:10 zoek.exe restore point
09-01-2017 20:59:56 JRT Pre-Junkware Removal
11-01-2017 16:14:07 Windows Update
12-01-2017 09:58:14 Windows Update
13-01-2017 17:22:46 Instalační služba modulů systému Windows
13-01-2017 18:06:53 Removed HP Support Assistant.

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/13/2017 06:08:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Explorer.EXE verze 6.1.7601.17567 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 2b8

Čas spuštění: 01d26dbda6b87414

Čas ukončení: 47

Cesta k aplikaci: C:\windows\Explorer.EXE

ID hlášení:

Error: (01/13/2017 06:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program FRST.exe verze 12.1.2017.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: bc8

Čas spuštění: 01d26dbed6cdc85b

Čas ukončení: 16

Cesta k aplikaci: C:\Users\MaI\Desktop\FRST.exe

ID hlášení:

Error: (01/13/2017 05:57:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (01/13/2017 05:55:05 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.

Error: (01/13/2017 05:33:55 PM) (Source: MsiInstaller) (EventID: 1002) (User: MaI-HP)
Description: Neočekávaná nebo chybějící hodnota (název: PackageName, hodnota: ) v klíči HKLM\Software\Classes\Installer\Products\FD862D959ACC5C44F869E215BB438C92\SourceList

Error: (01/13/2017 05:22:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (01/13/2017 05:16:29 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.

Error: (01/12/2017 05:02:53 PM) (Source: ESENT) (EventID: 489) (User: )
Description: CCleaner (3008) Pokus o otevření souboru C:\Users\MaI\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat jen pro čtení se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru se nezdaří a dojde k chybě -1032 (0xfffffbf8).

Error: (01/12/2017 12:47:14 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (01/12/2017 12:42:28 PM) (Source: MsiInstaller) (EventID: 11706) (User: MaI-HP)
Description: Product: HP Support Assistant -- Error 1706.No valid source could be found for product HP Support Assistant. The Windows Installer cannot continue.


System errors:
=============
Error: (01/13/2017 05:51:02 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Server Microsoft Update

Fáze aktualizace: Vyhledat

Zdrojová cesta: http://www.microsoft.com

Typ podpisu: Antivirový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\SYSTEM

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8024001e

Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Error: (01/13/2017 05:18:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba HP Support Solutions Framework Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (01/13/2017 05:18:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby HP Support Solutions Framework Service bylo dosaženo časového limitu (30000 ms).

Error: (01/12/2017 05:56:35 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby Winmgmt bylo dosaženo časového limitu (30000 ms).

Error: (01/12/2017 05:56:04 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby MBAMService bylo dosaženo časového limitu (30000 ms).

Error: (01/12/2017 05:17:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem

Fáze aktualizace: Instalovat

Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ podpisu: Antispywarový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\NETWORK SERVICE

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8000ffff

Popis chyby: Katastrofální selhání

Error: (01/12/2017 05:17:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem

Fáze aktualizace: Instalovat

Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ podpisu: Antivirový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\NETWORK SERVICE

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8000ffff

Popis chyby: Katastrofální selhání

Error: (01/12/2017 05:16:12 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: Server {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/12/2017 05:15:42 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware zjistil chybu při pokusu o aktualizaci podpisů.

Nová verze podpisu:

Předchozí verze podpisu: 1.233.4175.0

Zdroj aktualizace: Server Microsoft Update

Fáze aktualizace: Vyhledat

Zdrojová cesta: http://www.microsoft.com

Typ podpisu: Antivirový program

Typ aktualizace: Úplné

Uživatel: NT AUTHORITY\SYSTEM

Aktuální verze modulu:

Předchozí verze modulu: 1.1.13303.0

Kód chyby: 0x8024001e

Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Error: (01/12/2017 05:02:32 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby ShellHWDetection bylo dosaženo časového limitu (30000 ms).


==================== Memory info ===========================

Processor: AMD Athlon(tm) II P320 Dual-Core Processor
Percentage of memory in use: 63%
Total physical RAM: 2809.56 MB
Available physical RAM: 1014.72 MB
Total Virtual: 5617.41 MB
Available Virtual: 3438.45 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:280.79 GB) (Free:226.76 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: BF357B7B)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=280.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0C)

==================== End of Addition.txt ============================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#12 Příspěvek od JaRon »

Log vypada dobre
Doporucujem vycistit registre CCleanerom a napis ako sa sprava PC ?
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#13 Příspěvek od FineSelection »

Počítač funguje velmi plynule a na své původní rychlosti. Jenom mě zaráží jeho hlučnost (není to tak hrozný, jako před tím čištěním, ale je to rozhodně hlučnější než obvykle). Využití procesoru je taky zvláštní.. chvíli kolísá mezi 10 - 60%, potom se drží na 80 - 90% (aniž by se něco dělalo).

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: PUP - pomoc prosím

#14 Příspěvek od JaRon »

Ked bude vytazennost 90% pozri cez taskmagr, ktore procesy CPU najviac zatazuju ?
Na skusku mozes vypnut automaticke aktualizacie OS
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

FineSelection
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 led 2017 11:16

Re: PUP - pomoc prosím

#15 Příspěvek od FineSelection »

no třeba teď je to na 92%.. 795 000 kb paměti žere schvost.exe.. to budou ty aktualizace ne?

ještě je tu MsMPng.exe s 63 000 kb paměti.. má to u sebe popisek anti-malware service executable. Když dám vypnout proces tak to napíše "přístup byl odepřen"

Odpovědět