Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka - děkuji

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Preventivka - děkuji

#1 Příspěvek od 3rw0sh »

Zdravím, poprosil bych o kontrolu logu. PC se někdy z ničeho nic odpojí od internetu a v Chrome to píše různé chyby s DNS. Jinak vše funguje normálně. Děkuji
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jan at 2017-01-12 20:29:59
Microsoft Windows 8.1 Pro
System drive C: has 113 GB (57%) free of 199 GB
Total RAM: 16347 MB (86% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:30:01, on 12. 1. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\muachost.exe
C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\CTHKSvr.exe
C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe
D:\Program Files (x86)\Steam\Steam.exe
D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer.exe
D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files\trend micro\Jan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [eperjavaapp] D:\Program Files (x86)\Fiat\ePER\j2sdk1.4.1 injavaw.exe
O4 - HKLM\..\Run: [Sound Blaster Tactic3D Control Panel] "C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe" /r
O4 - HKCU\..\Run: [Steam] "D:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [TomTom MySports Connect.exe] C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe --hideSplashScreen
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://files.creative.com/Web/softwareu ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://files.creative.com/Web/softwareu ... /CTPID.cab
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\Windows\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_ActiveX_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
O23 - Service: MSI_Driver_Service - MSI - C:\Program Files (x86)\MSI\MSI OC Kit\Driver_Service\MSI_Driver_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Origin Client Service - Electronic Arts - D:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11835 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\DbxSvc.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe"
dashost.exe {87b4634b-9c29-4041-b31c733cef4b5eef}

winlogon.exe
"dwm.exe"
taskeng.exe {141CED97-A734-49A8-BA1D-D6AAC982ED48}
"C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe"
"C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe"
"C:\Program Files (x86)\MSI\MSI OC Kit\Driver_Service\MSI_Driver_Service.exe"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_000006a4
"C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
taskhostex.exe
C:\Windows\SysWOW64\muachost.exe
"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /c
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe"
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe"
"C:\Program Files (x86)\EVGA\Precision XOC\PrecisionX_x64.exe" /s
C:\Windows\Explorer.EXE
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s

"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
"C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe" --hideSplashScreen
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe" /r
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
"C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\CTHKSvr.exe" -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe" -Embedding
"D:\Program Files (x86)\Steam\Steam.exe" -silent
"D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" "-cachedir=C:\Users\Jan\AppData\Local\Steam\htmlcache" "-steampid=5996" "-buildid=1482202200" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --disable-spell-checking --disable-out-of-process-pac --disable-smooth-scrolling --enable-direct-write
"D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Jan\AppData\Local\Chromium\User Data\Crashpad" "--metrics-dir=C:\Users\Jan\AppData\Local\Chromium\User Data" --annotation=channel= --annotation=plat=Win32 --annotation=prod= --annotation=ver=01.00.00.01-devel --handshake-handle=0x22c
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer.exe"
"C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer_x64.exe"
"C:\Program Files\HWiNFO64\HWiNFO64.EXE"
"D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe"
"D:/Program Files (x86)/Ubisoft/Ubisoft Game Launcher/UplayWebCore.exe" --type=renderer --disable-gpu-compositing --enable-smooth-scrolling --no-sandbox --lang=en-US --lang=en-US --locales-dir-path="D:/Program Files (x86)/Ubisoft/Ubisoft Game Launcher/locales/1/" --log-file="D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\debug.log" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="4448.0.1193479756\456377008" /prefetch:1
"C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Jan\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#2 Příspěvek od sorcer »

Dobrý den,

1) Zde je ke stahnutí AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
2) Utilitu uložte na plochu
3) Mate-li spuštěné, ukončete všechny otevřené programy
4) Následně klikněte nejprve na Skenování a poté Čistění
5) Po dokončení skenováni se objeví log, který sem vložte

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#3 Příspěvek od 3rw0sh »

# AdwCleaner v6.042 - Log vytvořen 13/01/2017 v 17:43:35
# Aktualizováno dne 06/01/2017 z Malwarebytes
# Databáze : 2017-01-11.1 [Server]
# Operační systém : Windows 8.1 Pro (X64)
# Uživatelské jméno : Jan - PC-I5
# Spuštěno z : C:\Users\Jan\Desktop\adwcleaner_6.042.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****



***** [ Prohlížeče ] *****

[-] [C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazáno: slunecnice.cz


*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1437 Bajty] - [26/12/2016 12:36:49]
C:\AdwCleaner\AdwCleaner[C2].txt - [975 Bajty] - [13/01/2017 17:43:35]
C:\AdwCleaner\AdwCleaner[S0].txt - [1659 Bajty] - [26/12/2016 12:36:28]
C:\AdwCleaner\AdwCleaner[S1].txt - [1549 Bajty] - [13/01/2017 17:43:10]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1193 Bajty] ##########

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#4 Příspěvek od sorcer »

Proveďte prosím sken FRST. http://forum.viry.cz/viewtopic.php?f=24&t=132509

Log z FRST i Addition vložte sem, do Vašeho topicu.


Při varování u stahování FRSTLauncheru, vyberte v pravém dolním rohu Ignorovat

Lépe vypnouti antivir, některé detekují utilitu jako závadnou, ač není!


Nepůjde-li Vám Launcher stáhnout, vytvořte logy, použitím samotného FRST (bez Launcheru)

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#5 Příspěvek od 3rw0sh »

Dnes ráno odjíždím pryč a vrátím se až ve čtvrtek k tomuhle pc.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-01-2017
Ran by Jan (administrator) on PC-I5 (15-01-2017 00:07:30)
Running from C:\Users\Jan\Desktop
Loaded Profiles: Jan (Available Profiles: Jan)
Platform: Windows 8.1 Pro (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
(MSI) C:\Program Files (x86)\MSI\MSI OC Kit\Driver_Service\MSI_Driver_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionX_x64.exe
(MSI) C:\Windows\SysWOW64\muachost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(TomTom) C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\CTHKSvr.exe
(Creative Technology Ltd.) C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe
() C:\Program Files (x86)\SpeedFan\speedfan.exe
(Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer_x64.exe
(Ubisoft) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
(Ubisoft) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(forum.viry.cz) C:\Users\Jan\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9181696 2016-12-09] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [60136 2016-11-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [917576 2016-12-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25424008 2016-10-24] (Dropbox, Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [eperjavaapp] => D:\Program Files (x86)\Fiat\ePER\j2sdk1.4.1 injavaw.exe
HKLM-x32\...\Run: [Sound Blaster Tactic3D Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe [2091008 2014-07-03] (Creative Technology Ltd)
HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [2876704 2016-12-20] (Valve Corporation)
HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818360 2016-11-30] (Google)
HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\...\Run: [TomTom MySports Connect.exe] => C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe [638464 2016-12-05] (TomTom)
HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\...\Run: [AdobeBridge] => [X]
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8DCDC419-E440-4A8D-B179-2EF574A08CBE}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{9D6ED7C4-D86A-4066-ABAC-6D69CD3940E3}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://files.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab

FireFox:
========
FF ProfilePath: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\1cChxAJa.default [2016-09-08]
FF Extension: (Avira Browser Safety) - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\1cChxAJa.default\Extensions\abs@avira.com [2016-09-08]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default [2017-01-15]
CHR Extension: (Prezentace Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-09]
CHR Extension: (Disk Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-09]
CHR Extension: (Web Developer) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2016-09-09]
CHR Extension: (James White) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm [2016-09-09]
CHR Extension: (YouTube) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-09]
CHR Extension: (Tabulky Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-09]
CHR Extension: (Avira Browser Safety) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-20]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-09]
CHR Extension: (AdBlock) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-28]
CHR Extension: (Uložit na Disk Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2016-09-09]
CHR Extension: (Mapy Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-09-09]
CHR Extension: (AirMirror) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\macmgoeeggnlnmpiojbcniblabkdjphe [2016-09-09]
CHR Extension: (Pocket) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2016-09-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-09]
CHR Extension: (Gmail) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-09]
CHR Extension: (Chrome Media Router) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-15]
CHR Profile: C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-12-30]
CHR Extension: (Prezentace Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-19]
CHR Extension: (Dokumenty Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-19]
CHR Extension: (Disk Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-19]
CHR Extension: (YouTube) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-19]
CHR Extension: (Tabulky Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-19]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-19]
CHR Extension: (AdBlock) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-19]
CHR Extension: (Gmail) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-19]
CHR Extension: (Chrome Media Router) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-26]
CHR Profile: C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2 [2016-12-30]
CHR Extension: (Prezentace Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-11-24]
CHR Extension: (Dokumenty Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-24]
CHR Extension: (Disk Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-24]
CHR Extension: (YouTube) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-24]
CHR Extension: (Tabulky Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-27]
CHR Extension: (AdBlock) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-11-24]
CHR Extension: (Mapy Google) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-11-24]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-24]
CHR Extension: (Spořič dat) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pfmgfdlgomnbgkofeojodiodmgpgmkac [2016-11-24]
CHR Extension: (Gmail) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-24]
CHR Extension: (Chrome Media Router) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-24]
CHR Profile: C:\Users\Jan\AppData\Local\Google\Chrome\User Data\System Profile [2016-12-30]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1089592 2016-12-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [476736 2016-12-14] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1490296 2016-12-14] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [350528 2016-11-24] (Avira Operations GmbH & Co. KG)
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2011-10-19] (Creative Technology Ltd) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-09-09] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-09-09] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [41576 2016-10-24] (Dropbox, Inc.)
R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [45008 2016-08-25] (Micro-Star Int'l Co., Ltd.)
R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-26] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-10-20] (Intel Corporation)
R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [58296 2016-08-12] (Micro-Star INT'L CO., LTD.)
R2 MSI_Driver_Service; C:\Program Files (x86)\MSI\MSI OC Kit\Driver_Service\MSI_Driver_Service.exe [54880 2016-09-08] (MSI)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-12-16] (Electronic Arts)
S2 Origin Web Helper Service; D:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2016-12-16] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-12-02] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [151352 2016-12-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [153904 2016-12-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2016-08-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [78208 2016-08-25] (Avira Operations GmbH & Co. KG)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2016-09-16] (REALiX(tm))
R3 I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.)
S3 iaLPSS2_GPIO2; C:\Windows\system32\DRIVERS\iaLPSS2_GPIO2.sys [88376 2016-09-20] (Intel Corporation)
S3 iaLPSS2_I2C; C:\Windows\system32\DRIVERS\iaLPSS2_I2C.sys [185144 2016-09-20] (Intel Corporation)
S3 iaLPSS2_UART2; C:\Windows\system32\DRIVERS\iaLPSS2_UART2.sys [281400 2016-09-20] (Intel Corporation)
R3 iusb3adp; C:\Windows\System32\drivers\iusb3adp.sys [29272 2016-11-04] (Intel)
R3 NTIOLib_ACTIVE_X; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\NTIOLib_X64.sys [13776 2016-04-12] (MSI)
R3 NTIOLib_OCKit_MB; C:\Program Files (x86)\MSI\MSI OC Kit\Driver_Service\NTIOLib_X64.sys [13776 2016-09-08] (MSI)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56376 2016-08-26] (NVIDIA Corporation)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [4664072 2015-12-22] (Realtek Semiconductor Corporation )
R3 UHSfiltv; C:\Windows\system32\drivers\UHSfiltv.sys [23552 2013-05-31] (Creative Technology Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R3 WinRing0_1_2_0; C:\Program Files (x86)\EVGA\Precision XOC\WinRing0\WinRing0x64.sys [14536 2015-10-20] (OpenLibSys.org)
S3 dbx; system32\DRIVERS\dbx.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-15 00:07 - 2017-01-15 00:08 - 00026473 _____ C:\Users\Jan\Desktop\FRST.txt
2017-01-15 00:07 - 2017-01-15 00:07 - 00000000 ____D C:\FRST
2017-01-15 00:06 - 2017-01-15 00:06 - 00112640 _____ (forum.viry.cz) C:\Users\Jan\Desktop\FRSTLauncher.exe
2017-01-15 00:04 - 2017-01-15 00:04 - 02419200 _____ (Farbar) C:\Users\Jan\Desktop\FRST64.exe
2017-01-14 13:46 - 2017-01-14 13:47 - 00413856 _____ C:\Windows\Minidump\011417-25109-01.dmp
2017-01-13 19:28 - 2017-01-13 19:28 - 00001765 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-01-13 19:28 - 2017-01-13 19:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-01-13 19:28 - 2017-01-13 19:28 - 00000000 ____D C:\Program Files\iTunes
2017-01-13 19:28 - 2017-01-13 19:28 - 00000000 ____D C:\Program Files\iPod
2017-01-13 17:42 - 2017-01-13 17:42 - 03988944 _____ C:\Users\Jan\Desktop\adwcleaner_6.042.exe
2017-01-13 17:40 - 2017-01-13 17:40 - 00000017 _____ C:\Users\Jan\AppData\Local\resmon.resmoncfg
2017-01-13 14:02 - 2017-01-13 14:02 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2017-01-13 14:02 - 2017-01-13 14:02 - 00000000 ____D C:\Windows\system32\RTCOM
2017-01-13 14:02 - 2017-01-13 14:02 - 00000000 ____D C:\Windows\system32\DAX3
2017-01-13 14:02 - 2017-01-13 14:02 - 00000000 ____D C:\ProgramData\Audyssey Labs
2017-01-13 14:02 - 2017-01-13 14:02 - 00000000 ____D C:\Program Files\Realtek
2017-01-13 14:01 - 2016-12-09 08:35 - 72520712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2017-01-13 14:01 - 2016-12-09 08:35 - 23547544 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRenderAVX64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 23447352 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRender64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 17398616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioCapture64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 15202032 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE3.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 14057248 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 13122576 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 12988336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 10531584 _____ (Intel Corporation) C:\Windows\system32\IntelSSTAPO.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 07890895 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2017-01-13 14:01 - 2016-12-09 08:35 - 07172912 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 06198136 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV3apo.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 05804772 _____ C:\Windows\system32\Drivers\rtvienna.dat
2017-01-13 14:01 - 2016-12-09 08:35 - 05793520 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 05593608 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 05539328 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2017-01-13 14:01 - 2016-12-09 08:35 - 03503048 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 03299816 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 03295064 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 03204096 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 03201368 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 03014144 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2017-01-13 14:01 - 2016-12-09 08:35 - 02995000 _____ (DTS, Inc.) C:\Windows\system32\slcnt64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02828432 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02706856 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02291304 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02201600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02190976 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02110592 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 02050176 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01920919 _____ C:\Windows\system32\Drivers\rtkSSTsetting.dat
2017-01-13 14:01 - 2016-12-09 08:35 - 01780616 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01435136 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01422920 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01382232 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01360512 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01337632 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaeapo64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01334376 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01213656 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01186832 _____ (Intel Corporation) C:\Windows\system32\IntelSstCApoPropPage.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01166152 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01003856 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 01003328 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDHF64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00999848 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00984912 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00965024 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00962120 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tosasfapo64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00931616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00923736 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00873456 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00865912 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SEHDHF32.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00859216 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00850408 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00727432 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00721800 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00708304 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00689880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00678176 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00677664 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00618176 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00601136 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaemaxapo64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00588032 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00571376 _____ (Intel Corporation) C:\Windows\system32\tbb_waves.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00532376 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00514520 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00500552 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00499152 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00467152 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00447712 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00447176 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\toseaeapo64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00428224 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00426560 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2APIPCLL.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00416504 _____ (Harman) C:\Windows\system32\HMUI.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00387312 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00381408 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00378384 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00366120 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HMAPO.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00360344 _____ (Harman) C:\Windows\system32\HMClariFi.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00343704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00341144 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00341144 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00330552 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00321712 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00321712 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00258864 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00231912 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00221960 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00214824 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00209528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00203840 _____ (Harman) C:\Windows\system32\HMHVS.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00192976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00190928 _____ (Harman) C:\Windows\system32\HMEQ_Voice.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00190928 _____ (Harman) C:\Windows\system32\HMEQ.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00179592 _____ (Harman) C:\Windows\system32\HMLimiter.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00166200 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00158688 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00154360 _____ (Harman) C:\Windows\system32\HarmanAudioInterface.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00151784 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00134192 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00110976 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00090912 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00088344 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00088312 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00084608 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00083624 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00075536 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2017-01-13 14:01 - 2016-12-09 08:35 - 00023688 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 07096184 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 06264632 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 05347000 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 02993720 _____ (Audyssey Labs) C:\Windows\system32\AudysseyEfx.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 02444688 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01965808 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01959600 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01615656 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01591056 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01529136 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64Proxy.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01516896 _____ (Dolby Laboratories) C:\Windows\system32\DAX3APOProp.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01508928 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01363096 _____ (Dolby Laboratories) C:\Windows\system32\DAX3APOv251.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 01133584 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00785608 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOvlldp.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00743960 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00574752 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00504304 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00445392 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00441264 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00438688 _____ (Conexant Systems, Inc.) C:\Windows\system32\CAF64APO2.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00362048 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00327448 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00310416 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00272712 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00253896 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00253856 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00252872 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00122320 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00118592 _____ C:\Windows\system32\AcpiServiceVnA64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00118584 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00112488 _____ (Conexant Systems, Inc.) C:\Windows\system32\Caf64api.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00105304 _____ C:\Windows\system32\audioLibVc.dll
2017-01-13 14:01 - 2016-12-09 08:34 - 00005604 _____ C:\Windows\system32\cxapo.lncs
2017-01-13 14:01 - 2016-12-09 08:34 - 00000736 _____ C:\Windows\system32\cxapo.prop
2017-01-13 13:38 - 2017-01-13 13:38 - 00003646 _____ C:\Windows\System32\Tasks\Intel PTT EK Recertification
2017-01-13 13:34 - 2016-08-23 15:10 - 00943112 _____ (Realtek ) C:\Windows\system32\Drivers\Rt630x64.sys
2017-01-13 13:34 - 2016-08-23 15:10 - 00082544 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2017-01-12 23:26 - 2017-01-14 13:46 - 923720127 _____ C:\Windows\MEMORY.DMP
2017-01-12 23:26 - 2017-01-14 13:46 - 00000000 ____D C:\Windows\Minidump
2017-01-12 23:26 - 2017-01-12 23:26 - 00414440 _____ C:\Windows\Minidump\011217-26968-01.dmp
2016-12-30 12:49 - 2017-01-14 19:16 - 00779650 _____ C:\Windows\WindowsUpdate.log
2016-12-30 12:44 - 2017-01-14 17:17 - 00004034 _____ C:\Windows\setupact.log
2016-12-30 12:44 - 2016-12-30 12:44 - 00000000 _____ C:\Windows\setuperr.log
2016-12-30 12:21 - 2017-01-12 20:30 - 00000000 ____D C:\Program Files\trend micro
2016-12-30 12:21 - 2016-12-30 12:21 - 00000000 ____D C:\rsit
2016-12-30 12:20 - 2016-12-30 12:21 - 01222144 _____ C:\Users\Jan\Desktop\RSITx64.exe
2016-12-26 12:35 - 2017-01-13 17:43 - 00000000 ____D C:\AdwCleaner
2016-12-26 10:58 - 2016-12-26 10:58 - 00000222 _____ C:\Users\Jan\Desktop\F1 2016.url
2016-12-24 20:16 - 2016-12-24 20:16 - 00000000 ____D C:\ProgramData\Creative
2016-12-24 20:12 - 2016-12-24 20:12 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2016-12-24 20:12 - 2016-12-24 20:12 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2016-12-24 20:12 - 2016-12-24 20:12 - 00123480 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2016-12-24 20:12 - 2016-12-24 20:12 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2016-12-24 20:12 - 2016-12-24 20:12 - 00000414 ___RH C:\Windows\ctfile.rfc
2016-12-24 20:12 - 2016-12-24 20:12 - 00000000 ___HD C:\Program Files (x86)\Creative Installation Information
2016-12-24 20:12 - 2014-06-03 16:32 - 00287744 _____ (Creative Technology Ltd.) C:\Windows\system32\UHSpld64.dll
2016-12-24 20:12 - 2014-06-03 16:31 - 02405144 _____ (Creative Technology Ltd.) C:\Windows\system32\UHSAPO64.dll
2016-12-24 20:12 - 2014-06-03 16:31 - 02016024 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\UHSAPO32.dll
2016-12-24 20:12 - 2014-06-03 16:30 - 00020161 _____ C:\Windows\UHSAPO64.ssc
2016-12-24 20:12 - 2014-06-03 16:15 - 00033735 _____ C:\Windows\system32\UHS.ini
2016-12-24 20:12 - 2014-04-25 16:33 - 01898496 ____N (Creative) C:\Windows\system32\Sens_oal.dll
2016-12-24 20:12 - 2014-04-25 16:29 - 01609728 ____N (Creative) C:\Windows\SysWOW64\Sens_oal.dll
2016-12-24 20:12 - 2014-04-23 10:48 - 00071569 _____ C:\Windows\Fury.ico
2016-12-24 20:12 - 2014-04-23 10:38 - 00011264 _____ (Creative Technology Ltd.) C:\Windows\UHSDefE.exe
2016-12-24 20:12 - 2014-04-23 10:38 - 00000387 _____ C:\Windows\UHSMCcfg.ini
2016-12-24 20:12 - 2014-04-23 10:38 - 00000373 _____ C:\Windows\UHSConfig.ini
2016-12-24 20:12 - 2014-03-24 10:38 - 00089600 _____ C:\Windows\system32\CmdRtr64.DLL
2016-12-24 20:12 - 2014-03-24 10:37 - 00074240 _____ C:\Windows\SysWOW64\CmdRtr.DLL
2016-12-24 20:12 - 2014-03-24 10:36 - 00366080 _____ C:\Windows\system32\APOMgr64.DLL
2016-12-24 20:12 - 2014-03-24 10:33 - 00274944 _____ C:\Windows\SysWOW64\APOMngr.DLL
2016-12-24 20:12 - 2013-05-31 16:43 - 00023552 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\UHSfiltv.sys
2016-12-24 20:12 - 2013-05-14 11:08 - 00170165 _____ C:\Windows\Evo.ico
2016-12-24 20:12 - 2013-04-17 15:20 - 00002413 _____ C:\Windows\UHScfg.ini
2016-12-24 20:12 - 2012-08-17 13:39 - 00083118 _____ C:\Windows\Rage.ico
2016-12-24 20:12 - 2012-04-18 11:39 - 00042496 _____ (Creative Technology Ltd.) C:\Windows\AddCat.exe
2016-12-24 20:12 - 2011-07-04 15:36 - 00093940 _____ C:\Windows\UHSICON.ico
2016-12-24 20:12 - 2011-06-29 18:36 - 00235520 _____ (Creative Technology Limited) C:\Windows\system32\UHScInst.dll
2016-12-24 20:11 - 2016-12-24 20:16 - 00000000 ____D C:\Users\Jan\AppData\Local\Creative
2016-12-24 20:11 - 2016-12-24 20:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2016-12-24 20:11 - 2016-12-24 20:12 - 00000000 ____D C:\Program Files\Creative
2016-12-24 20:11 - 2016-12-24 20:12 - 00000000 ____D C:\Program Files (x86)\Creative
2016-12-24 20:11 - 2006-10-06 14:17 - 00053248 ____N (Creative Technology Ltd ) C:\Windows\Ctregrun.exe
2016-12-24 20:11 - 2003-06-12 23:25 - 00007062 _____ C:\Windows\SysWOW64\audiopid.vxd
2016-12-19 22:24 - 2016-12-19 22:24 - 00000233 _____ C:\Users\Jan\Desktop\Tom Clancy's The Division.url
2016-12-19 22:24 - 2016-12-19 22:24 - 00000233 _____ C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tom Clancy's The Division.url
2016-12-16 22:37 - 2016-12-16 22:42 - 00000000 ____D C:\Users\Jan\AppData\Local\FileZilla
2016-12-16 22:07 - 2016-12-16 22:07 - 00000000 ____D C:\ProgramData\Electronic Arts
2016-12-16 22:07 - 2016-12-16 22:07 - 00000000 ____D C:\ProgramData\EA Core
2016-12-16 22:00 - 2016-12-16 22:07 - 00000000 ____D C:\ProgramData\EA Logs
2016-12-16 13:28 - 2016-12-16 13:28 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-12-16 13:28 - 2016-09-09 19:25 - 00269600 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-12-16 13:28 - 2016-09-09 19:25 - 00261920 _____ C:\Windows\system32\vulkan-1.dll
2016-12-16 13:28 - 2016-09-09 19:25 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-12-16 13:28 - 2016-09-09 19:24 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2016-12-16 13:26 - 2016-12-12 03:37 - 40125496 _____ C:\Windows\system32\nvcompiler.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 35222976 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 34703416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 28138432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 17376896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 14073400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-12-16 13:26 - 2016-12-12 03:37 - 10912744 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 10795312 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 10345696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 09151216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 08913328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 08753832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 03640376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 03206080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 01953336 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437633.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 01586744 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437633.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 01036224 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00975416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00944184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00896056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00894760 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00683640 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00572888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00521096 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00438208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00435904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00407248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00388544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00170688 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-12-16 13:26 - 2016-12-12 03:37 - 00131536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-01-15 00:04 - 2016-09-16 18:53 - 00000000 ____D C:\Users\Jan\AppData\Roaming\TS3Client
2017-01-15 00:01 - 2016-09-09 07:41 - 00000914 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-01-14 23:21 - 2016-09-15 02:37 - 00000000 ____D C:\Users\Jan\AppData\Local\Ubisoft Game Launcher
2017-01-14 17:31 - 2014-11-21 05:13 - 01745984 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-14 17:31 - 2014-11-21 04:17 - 00738682 _____ C:\Windows\system32\perfh005.dat
2017-01-14 17:31 - 2014-11-21 04:17 - 00151404 _____ C:\Windows\system32\perfc005.dat
2017-01-14 17:31 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Inf
2017-01-14 17:22 - 2016-09-08 23:29 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2017-01-14 17:21 - 2016-09-09 07:48 - 00000000 ___RD C:\Users\Jan\Dropbox
2017-01-14 17:21 - 2016-09-08 23:11 - 00000000 ___RD C:\Users\Jan\OneDrive
2017-01-14 17:20 - 2016-09-09 13:01 - 00000000 ___RD C:\Users\Jan\Disk Google
2017-01-14 17:19 - 2016-09-09 07:41 - 00000910 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-01-14 17:17 - 2016-09-09 07:13 - 00000000 ____D C:\ProgramData\NVIDIA
2017-01-14 17:17 - 2013-08-22 15:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-14 13:53 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-01-14 13:50 - 2016-09-08 23:05 - 00000000 ____D C:\Users\Jan
2017-01-13 20:19 - 2016-09-09 07:28 - 00000000 ____D C:\Program Files\Rockstar Games
2017-01-13 20:19 - 2016-09-09 07:28 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2017-01-13 20:12 - 2016-09-18 07:55 - 00000000 ____D C:\Users\Jan\AppData\Local\CrashDumps
2017-01-13 19:36 - 2016-09-08 23:20 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1071189237-3862994071-2567526139-1001
2017-01-13 19:28 - 2016-09-13 18:22 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-01-13 19:17 - 2016-09-08 23:40 - 00000000 ____D C:\MSI
2017-01-13 14:02 - 2016-09-09 08:04 - 00000000 ____D C:\Windows\system32\DAX2
2017-01-13 14:02 - 2016-09-09 08:03 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-01-13 14:01 - 2016-09-09 07:24 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-01-13 13:52 - 2016-09-08 23:13 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-13 13:52 - 2016-09-08 23:13 - 00000000 ____D C:\Program Files\Intel
2017-01-13 13:38 - 2016-09-09 08:11 - 00000000 ____D C:\Program Files (x86)\Intel
2017-01-13 13:38 - 2016-09-08 23:13 - 00000000 ____D C:\ProgramData\Intel
2017-01-13 13:34 - 2016-09-09 07:24 - 00000000 ____D C:\Program Files (x86)\Realtek
2017-01-13 09:45 - 2016-09-09 06:37 - 00000000 ____D C:\Users\Jan\AppData\Local\ElevatedDiagnostics
2017-01-13 09:21 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp
2017-01-12 23:45 - 2016-09-09 07:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-01-12 23:44 - 2016-09-10 02:06 - 00000000 ____D C:\Windows\system32\MRT
2017-01-12 23:44 - 2013-08-22 14:25 - 00000167 _____ C:\Windows\win.ini
2017-01-12 23:41 - 2016-09-10 02:05 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-01-12 23:25 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\system32\NDF
2017-01-12 19:40 - 2016-09-13 18:29 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-01-12 19:27 - 2016-09-13 18:56 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-01-12 19:02 - 2016-09-16 09:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64
2017-01-12 19:02 - 2016-09-16 09:48 - 00000000 ____D C:\Program Files\HWiNFO64
2017-01-06 20:13 - 2016-09-08 23:05 - 00000000 ____D C:\Users\Jan\AppData\Local\Packages
2016-12-30 12:49 - 2016-09-08 23:03 - 00000000 ____D C:\Windows\SoftwareDistribution
2016-12-30 12:39 - 2013-08-22 14:36 - 00000000 ____D C:\Windows\Logs
2016-12-30 12:31 - 2016-09-13 19:41 - 00226816 ___SH C:\Users\Jan\Desktop\Thumbs.db
2016-12-27 16:16 - 2016-09-22 17:03 - 00000000 ____D C:\Users\Jan\Documents\My Games
2016-12-27 16:16 - 2016-09-22 17:03 - 00000000 ____D C:\ProgramData\Codemasters
2016-12-27 16:16 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-12-26 12:56 - 2016-09-13 18:36 - 00000186 _____ C:\Users\Jan\AppData\Roaming\COPA_Last_Connected_Device.ini
2016-12-26 12:56 - 2016-09-08 23:05 - 00000000 ____D C:\Users\Jan\AppData\Roaming
2016-12-26 10:58 - 2016-09-16 21:11 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-12-26 02:46 - 2016-09-19 18:17 - 00000000 ____D C:\Users\Jan\AppData\Local\uTorrent
2016-12-26 01:05 - 2016-09-09 07:22 - 00000000 ____D C:\Users\Jan\AppData\Roaming\vlc
2016-12-24 20:24 - 2013-08-22 16:36 - 00000000 ___SD C:\Windows\Downloaded Program Files
2016-12-24 20:12 - 2013-08-22 14:36 - 00000000 ___RD C:\Program Files (x86)
2016-12-23 15:35 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness
2016-12-22 23:42 - 2016-09-09 09:04 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-12-22 23:42 - 2016-09-09 09:04 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-12-19 22:24 - 2016-09-08 23:05 - 00000000 ___RD C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
2016-12-19 11:42 - 2016-09-09 06:37 - 00003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-19 11:42 - 2016-09-09 06:37 - 00003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-19 11:42 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Tasks
2016-12-16 23:24 - 2016-09-17 06:32 - 00000000 ____D C:\ProgramData\Origin
2016-12-16 23:22 - 2016-09-17 07:03 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Origin
2016-12-16 22:42 - 2016-09-17 08:20 - 00000000 ____D C:\Users\Jan\AppData\Roaming\FileZilla
2016-12-16 22:37 - 2016-09-17 08:20 - 00001870 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2016-12-16 22:37 - 2016-09-17 08:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2016-12-16 22:37 - 2016-09-17 08:20 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2016-12-16 22:33 - 2016-09-13 18:03 - 00000000 ____D C:\Users\Jan\AppData\Local\Adobe
2016-12-16 22:33 - 2016-09-08 23:05 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Adobe
2016-12-16 14:03 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache
2016-12-16 14:00 - 2016-09-08 23:01 - 00524288 ___SH C:\Windows\system32\config\COMPONENTS{42b82173-0b2e-11e3-93f4-90b11c2eb9f2}.TMContainer00000000000000000002.regtrans-ms
2016-12-16 13:44 - 2016-09-09 13:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-12-16 12:40 - 2013-08-22 15:44 - 05034592 _____ C:\Windows\system32\FNTCACHE.DAT

==================== Files in the root of some directories =======

2016-09-19 16:53 - 2016-09-19 16:59 - 0000132 _____ () C:\Users\Jan\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
2016-09-13 18:36 - 2016-12-26 12:56 - 0000186 _____ () C:\Users\Jan\AppData\Roaming\COPA_Last_Connected_Device.ini
2016-09-13 18:27 - 2016-10-29 19:55 - 0000098 _____ () C:\Users\Jan\AppData\Roaming\SDC_Path.ini
2017-01-13 17:40 - 2017-01-13 17:40 - 0000017 _____ () C:\Users\Jan\AppData\Local\resmon.resmoncfg
2016-09-09 08:04 - 2016-09-09 08:04 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Jan\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Jan\AppData\Local\Temp\sfareca00001.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-01-14 12:02

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:194.8 GB) (Free:96.47 GB) NTFS
Drive d: (Data) (Fixed) (Total:736.2 GB) (Free:388.12 GB) NTFS
Drive g: (DISK) (Removable) (Total:0.96 GB) (Free:0.96 GB) FAT

Available physical RAM: 13878.47 MB
Total physical RAM: 16348.15 MB
Percentage of memory in use: 15%

==================== MBR and Partition Table ==================

Disk: 0 (Size: 931.5 GB) (Disk ID: D60014E3)
Disk: 1 (Size: 988 MB) (Disk ID: 6F20736B)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Jan\Desktop" je 7 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#6 Příspěvek od sorcer »

1) Obsah fixu níže, nakopírujte do Notepadu + uložte jej jako: fixlist.txt
2) Soubor uložte na stejné místo, kde má aktuálně utilitu FRST

Kód: Vybrat vše

Start
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
Hosts:

HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\...\Run: [AdobeBridge] => [X]

S3 dbx; system32\DRIVERS\dbx.sys [X]

END
3) Spusťte FRST a kliněte na tlačítko FIX
4) Restartujte PC.
5) Sledujte PC, jak se chová
5) Obsah FIXLOGU postněte sem do Vašeho topicu

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#7 Příspěvek od 3rw0sh »

Dobrý den, zde je log. PC budu sledovat zda se chová normálně.

Fix result of Farbar Recovery Scan Tool (x64) Version: 25-01-2017 01
Ran by Jan (27-01-2017 15:27:02) Run:1
Running from C:\Users\Jan\Desktop
Loaded Profiles: Jan (Available Profiles: Jan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
Hosts:

HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\...\Run: [AdobeBridge] => [X]

S3 dbx; system32\DRIVERS\dbx.sys [X]

END
*****************

Restore point was successfully created.
Processes closed successfully.
Could not move "C:\Windows\System32\Drivers\etc\hosts" => Scheduled to move on reboot.
HKU\S-1-5-21-1071189237-3862994071-2567526139-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
HKLM\System\CurrentControlSet\Services\dbx => key removed successfully
dbx => service removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 49231367 B
Java, Flash, Steam htmlcache => 112458385 B
Windows/system/drivers => 905809 B
Edge => 0 B
Chrome => 496576084 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 246073 B
systemprofile32 => 128 B
LocalService => 157246 B
NetworkService => 0 B
Jan => 717927383 B

RecycleBin => 0 B
EmptyTemp: => 1.3 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 27-01-2017 15:30:49)

"C:\Windows\System32\Drivers\etc\hosts" => Could not move
Could not restore Hosts.

==== End of Fixlog 15:30:49 ====

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#8 Příspěvek od sorcer »

Nyni prosím proveďte Sken a vložte log z programu MBAM.

Návod zde: http://forum.viry.cz/viewtopic.php?f=29&t=144868

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#9 Příspěvek od 3rw0sh »

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 30.01.17
Čas skenování: 20:15
Logovací soubor: 1.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentů: 1.0.50
Aktualizovat verzi balíku komponent: 1.0.1138
Licence: Zkušební

-Systémová informace-
OS: Windows 8.1
CPU: x64
Systém souborů: NTFS
Uživatel: PC-I5\Jan

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 380272
Uplynulý čas: 13 hod, 53 min, 56 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#10 Příspěvek od sorcer »

Máte nějaké další potíže?
Pc je nyní čisté.

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#11 Příspěvek od 3rw0sh »

PC už fungovala v pořádku, ale ted jsem ho zrestartoval a mám problém, že naskočilo do dočasného profilu a už jsem zkoušel i návody na netu, ale nenaskočí mi normální profil.

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#12 Příspěvek od sorcer »

Podivné.. Mbam, si troufnu tvrdit, svým skenováním nemohl toto zapříčinit.

Spusťte příkazový řádek jako správce (pravé tlačítko myši na nabídku Start)

Vepište tento příkaz:

Kód: Vybrat vše

sfc /scannow

Potvrďte Enterem.

Co jste před restartem prováděl ?

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#13 Příspěvek od 3rw0sh »

Z ničeho nic ztratil wifina signál od routeru, ale od hotspotu z mobilu ho měla, tak jsem zrestartoval pc a modem a pak když se zapnul tak po přihlášení naskočil rovnou dočasný profil. Nevím co to mohlo způsobit. Ten log má 62tis řádků a 12mb, chcete ho někam upnout? Napsalo to, že některé soubory špatné, ale není schopný je opravit.

sorcer
Přítel fóra
Přítel fóra
Příspěvky: 527
Registrován: 26 čer 2006 01:29

Re: Preventivka - děkuji

#14 Příspěvek od sorcer »

27.1.2017 jsme vytvořili bod obnovy. Zkuste se k němu vrátit.

Pěkný návod zde: http://www.servispckupka.cz/jak_opravit ... ystemu.php

3rw0sh
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 26 čer 2012 16:53

Re: Preventivka - děkuji

#15 Příspěvek od 3rw0sh »

Tak bod obnovení co vytvořil FRST je údajně požkozený, tak jsem použil z 12.1. co vytvořila aktualizace systému, ale systém pořádně nefunguje (nejde Word, antivir nejde spustit, některé programy padají) asi bude lepší to celé přeinstalovat, i když teda představa stahování všech her (legálních) je s internetem co mám docela hrůzostrašná představa.

Zamčeno