frst log na viac časti
čast 1...
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016
Ran by Michal (administrator) on MICHAL-PC (23-12-2016 13:19:16)
Running from C:\Users\Michal\Desktop
Loaded Profiles: Michal (Available Profiles: Michal)
Platform: Windows 7 Professional N Service Pack 1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-01-31] (Intel Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2876816 2013-03-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [899680 2013-02-04] (Conexant Systems, Inc.)
HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-09-17] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2016-10-07] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2016-10-07] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-04-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-12] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27230168 2016-11-15] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-06-10] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{830EE113-6E8D-40FA-8F66-2B1E9AE588DC}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 2lsd24he.default
FF ProfilePath: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\2lsd24he.default [2016-12-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-13] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-12] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-13] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @Sibelius.com/Scorch Plugin,version=6.2.0.88 -> C:\Program Files (x86)\Sibelius Software\Scorch\npsibelius.dll [2013-03-11] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-12] (Adobe Systems)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-12-23] <==== ATTENTION
CHR Extension: (Dokumenty Google) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-08]
CHR Extension: (Adblocker na Youtube™) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\eojeoeddgeaeahpmfabdfpfialkoplcb [2016-12-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-08]
CHR Extension: (Chrome Media Router) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-17]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-24] (Qualcomm Atheros Commnucations) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-04-18] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-11-18] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-01-24] (Atheros) [File not signed]
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3388144 2013-04-18] (Intel® Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.)
R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-01-24] (Qualcomm Atheros)
S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [132920 2013-03-25] (Motorola Solutions, Inc.)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-01-31] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [128200 2013-04-03] (Qualcomm Atheros Co., Ltd.)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8243144 2013-04-24] (Realtek Semiconductor Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2016-10-07] () [File not signed]
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [121248 2016-09-12] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [195936 2016-09-12] (Oracle Corporation)
U3 ar6f5qv5; C:\Windows\System32\Drivers\ar6f5qv5.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-23 13:19 - 2016-12-23 13:19 - 00015743 _____ C:\Users\Michal\Desktop\FRST.txt
2016-12-23 13:14 - 2016-12-23 13:14 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Mozilla
2016-12-23 13:14 - 2016-12-23 13:14 - 00000000 ____D C:\Users\Michal\AppData\Local\Mozilla
2016-12-23 13:13 - 2016-12-23 13:13 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-12-23 13:13 - 2016-12-23 13:13 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-12-23 13:13 - 2016-12-23 13:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-23 13:13 - 2016-12-23 13:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-23 13:00 - 2016-12-23 13:03 - 45137072 _____ C:\Users\Michal\Downloads\Firefox Setup 50.1.0.exe
2016-12-21 18:05 - 2016-12-21 18:05 - 01426772 _____ C:\Users\Michal\Downloads\MisoDoPiceNeserTigraBosouNohou.rar
2016-12-20 16:29 - 2016-12-20 16:29 - 00001115 _____ C:\Users\Michal\Downloads\skuska.rar
2016-12-19 17:07 - 2016-12-19 17:08 - 15309238 _____ C:\Users\Michal\Downloads\Nový-priečinok.rar
2016-12-19 14:52 - 2016-12-19 14:53 - 21340803 _____ C:\Users\Michal\Downloads\ea1.rar
2016-12-19 14:19 - 2016-12-19 14:19 - 00248257 _____ C:\Users\Michal\Downloads\2012_1001_sj-verejne.pdf
2016-12-19 11:14 - 2016-12-19 11:14 - 00008607 _____ C:\Users\Michal\Desktop\Fixlog.txt
2016-12-17 16:40 - 2016-12-17 16:45 - 80593615 _____ C:\Users\Michal\Downloads\eaaaa.rar
2016-12-17 16:10 - 2016-12-17 16:09 - 00000943 _____ C:\Users\Michal\Documents\indexfile.txt
2016-12-17 16:09 - 2016-12-17 16:09 - 23446111 _____ C:\Users\Michal\Documents\Firefox 50.0.2 (x86 sk) - 2016-12-17.pcv
2016-12-17 16:08 - 2016-12-17 16:08 - 01035926 _____ C:\Users\Michal\Downloads\MozBackup-1.5.1-EN.exe
2016-12-17 16:08 - 2016-12-17 16:08 - 00001031 _____ C:\Users\Public\Desktop\MozBackup.lnk
2016-12-17 16:08 - 2016-12-17 16:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup
2016-12-17 16:08 - 2016-12-17 16:08 - 00000000 ____D C:\Program Files (x86)\MozBackup
2016-12-17 10:51 - 2016-12-17 10:51 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-12-16 17:17 - 2016-12-16 17:17 - 00026756 _____ C:\Users\Michal\Desktop\v_pondelok_doma_nebudem_husle.pdf
2016-12-16 12:55 - 2016-12-16 13:42 - 824817956 _____ C:\Users\Michal\Downloads\3-dny-na-zabití-2014_CZ-dab.avi
2016-12-16 10:25 - 2016-12-16 10:25 - 00882405 _____ C:\Users\Michal\Downloads\newsletter 02-07.pdf
2016-12-14 20:40 - 2016-12-14 20:40 - 00033326 _____ C:\ComboFix.txt
2016-12-14 20:22 - 2016-12-17 08:40 - 00000000 ____D C:\Windows\erdnt
2016-12-14 20:18 - 2016-12-14 20:19 - 00002772 _____ C:\Users\Michal\Desktop\Rkill.txt
2016-12-14 20:18 - 2016-12-14 20:18 - 00000000 ____D C:\Users\Michal\Desktop\rkill
2016-12-14 15:28 - 2016-12-14 15:38 - 00000000 ____D C:\Users\Michal\Desktop\ea zap
2016-12-14 15:18 - 2016-12-14 15:18 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Michal\Desktop\rkill.exe
2016-12-13 13:09 - 2016-12-13 13:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigneb139762080477ae
2016-12-13 13:09 - 2016-12-13 13:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigne52d9fbe0f737919
2016-12-13 13:09 - 2016-12-13 13:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignaa0a89b2b72d676c
2016-12-13 13:09 - 2016-12-13 13:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign8924fc58313f079a
2016-12-13 13:08 - 2016-12-13 13:08 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignb9d28553828958ec
2016-12-13 13:08 - 2016-12-13 13:08 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign8b1b574b55534ede
2016-12-12 16:32 - 2016-12-23 13:19 - 00000000 ____D C:\FRST
2016-12-12 16:32 - 2016-12-12 16:32 - 02420224 _____ (Farbar) C:\Users\Michal\Desktop\FRST64.exe
2016-12-12 13:47 - 2016-12-12 13:47 - 00189833 _____ C:\Users\Michal\Downloads\9.3.2.12 Configuring Extended ACLs Scenario 3.pka
2016-12-12 13:38 - 2016-12-12 13:44 - 00515337 _____ C:\Users\Michal\Downloads\9.3.2.10 Configuring Extended ACLs Scenario 1.pka
2016-12-12 13:05 - 2016-12-12 14:37 - 1329831828 _____ C:\Users\Michal\Downloads\Fantastická zvířata a kde je najít (kino) cz.dabing.avi
2016-12-12 12:59 - 2016-12-20 17:10 - 00000000 ____D C:\Users\Michal\Desktop\v
2016-12-12 10:55 - 2016-12-12 16:33 - 00133173 _____ C:\Users\Michal\Desktop\router.pkt
2016-12-11 10:13 - 2016-12-11 16:22 - 00000000 _____ C:\Users\Michal\Downloads\9.2.1.10 Packet Tracer Configuring Standard ACLs.pka
2016-12-11 10:13 - 2016-12-11 10:13 - 00364660 _____ C:\Users\Michal\Downloads\9.2.1.10 Packet Tracer Configuring Standard ACLs.pka~
2016-12-10 20:10 - 2016-12-10 20:10 - 00000000 ____D C:\Windows\system32\%LOCALAPPDATA%
2016-12-10 18:02 - 2016-12-10 18:06 - 00001373 _____ C:\Users\Michal\Desktop\iptv.cfg
2016-12-10 15:05 - 2016-12-13 15:36 - 00000000 ____D C:\Users\Michal\Desktop\audio
2016-12-10 14:27 - 2016-12-10 14:27 - 00000000 ____D C:\Users\Michal\AppData\LocalLow\uTorrent
2016-12-10 13:17 - 2016-12-10 17:52 - 00000000 ____D C:\Users\Michal\AppData\Roaming\MuseScore
2016-12-10 13:16 - 2016-12-10 14:12 - 00000000 ____D C:\Users\Michal\AppData\Local\AnthemScore
2016-12-10 13:16 - 2016-12-10 13:16 - 00000000 ____D C:\Users\Michal\Documents\MuseScore2
2016-12-10 13:16 - 2016-12-10 13:16 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MuseScore 2
2016-12-10 13:16 - 2016-12-10 13:16 - 00000000 ____D C:\Users\Michal\AppData\Local\MuseScore
2016-12-10 13:15 - 2016-12-10 13:16 - 00000000 ____D C:\Program Files (x86)\MuseScore 2
2016-12-10 13:10 - 2016-12-10 13:10 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnthemScore
2016-12-10 13:06 - 2016-12-10 13:16 - 00000000 ____D C:\Program Files (x86)\AnthemScore
2016-12-10 11:50 - 2016-12-10 11:50 - 00000000 ____D C:\Users\Public\Documents\Notation_3
2016-12-10 11:46 - 2016-12-10 14:55 - 00000000 ____D C:\Users\Michal\AppData\Roaming\ScoreCloud
2016-12-10 11:39 - 2016-12-10 11:39 - 00001096 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScoreCloud Studio.lnk
2016-12-10 11:39 - 2016-12-10 11:39 - 00000000 ____D C:\Program Files (x86)\ScoreCloud Studio
2016-12-10 11:16 - 2016-12-10 11:16 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignff25e483c072c8cf
2016-12-10 11:16 - 2016-12-10 11:16 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignca5c412747d76b3f
2016-12-10 11:16 - 2016-12-10 11:16 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign6280dd11afb9dba7
2016-12-10 09:41 - 2016-12-10 09:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neuratron
2016-12-10 09:40 - 2016-12-10 09:41 - 00000000 ____D C:\Program Files (x86)\Neuratron AudioScore Ultimate Demo
2016-12-10 09:19 - 2016-12-10 09:32 - 00000000 ____D C:\Windows\system32\log
2016-12-10 08:56 - 2016-12-17 10:51 - 00000008 __RSH C:\Users\Michal\ntuser.pol
2016-12-09 16:40 - 2016-12-09 16:40 - 00000000 ____D C:\Users\Michal\Documents\AudioScore Documents
2016-12-09 16:40 - 2016-12-09 16:40 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Neuratron
2016-12-09 16:39 - 2016-12-09 17:50 - 00000000 ____D C:\Program Files (x86)\Neuratron
2016-12-09 16:00 - 2016-12-11 13:06 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Audacity
2016-12-09 16:00 - 2016-12-09 17:50 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-12-09 16:00 - 2016-12-09 16:00 - 00001023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-12-09 15:32 - 2016-12-09 15:32 - 00000000 ____D C:\Users\Michal\Documents\Mixcraft Projects
2016-12-09 15:32 - 2016-12-09 15:32 - 00000000 ____D C:\Users\Michal\AppData\Roaming\SynthMaker
2016-12-09 15:31 - 2016-12-09 15:31 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Acoustica
2016-12-09 15:31 - 2016-12-09 15:31 - 00000000 ____D C:\ProgramData\Acoustica
2016-12-09 15:28 - 2016-12-09 17:50 - 00000000 ____D C:\Program Files (x86)\RightMark
2016-12-08 14:39 - 2016-12-08 14:39 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign5f5d0463584beaab
2016-12-08 14:36 - 2016-12-08 14:36 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigne1ced321dfdfb9a4
2016-12-08 14:34 - 2016-12-08 14:34 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignf1f638c1177a31b0
2016-12-08 14:33 - 2016-12-08 14:33 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignfc3eb4accfdb44f1
2016-12-08 14:33 - 2016-12-08 14:33 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigne006d29ead18caf3
2016-12-08 14:26 - 2016-12-08 14:26 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignee60114fb4b1736e
2016-12-08 14:26 - 2016-12-08 14:26 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignbbb6b284072599f2
2016-12-08 14:26 - 2016-12-08 14:26 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign1a4957ae9e010c42
2016-12-08 09:13 - 2016-12-08 09:13 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign63449d47d21786f7
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignbee8659ec374bfd9
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign75c2f24933b279cf
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign6630ea7a2aaaea6f
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign617167e66810f387
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign5fa04cddc00c2968
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign5caf336a714ad62c
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign3431ccb9f2be5af8
2016-12-08 09:09 - 2016-12-08 09:09 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign2368e15f51aa66f0
2016-12-07 19:32 - 2016-12-07 19:32 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigncee4ec77b8cd039b
2016-12-07 19:31 - 2016-12-07 19:31 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignc98638ed7eea07cb
2016-12-07 19:31 - 2016-12-07 19:31 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign84b58b53f9301053
2016-12-07 19:19 - 2016-12-07 19:19 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigna64625fb825af44a
2016-12-07 19:18 - 2016-12-07 19:18 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign26187949b09a3374
2016-12-07 19:18 - 2016-12-07 19:18 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign08708443e994ca5f
2016-12-07 19:10 - 2016-12-07 19:10 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign4049943a7c9bee0e
2016-12-07 19:03 - 2016-12-07 19:03 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigncf9de7cb9f6227d4
2016-12-07 19:03 - 2016-12-07 19:03 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign6f2861bb349627f7
2016-12-07 18:47 - 2016-12-07 18:47 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignd67b7683074df9c9
2016-12-07 18:41 - 2016-12-07 18:41 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigna4112098cba3b545
2016-12-07 18:38 - 2016-12-07 18:38 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign6dcc49399f8c408e
2016-12-07 18:38 - 2016-12-07 18:38 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign58387ca720608c0e
2016-12-05 21:37 - 2016-12-05 21:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2016-12-04 15:27 - 2016-12-04 15:27 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignd1bf3c4c02a0b68b
2016-12-04 15:26 - 2016-12-04 15:26 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign4a446d41aab2d9ce
2016-12-04 15:23 - 2016-12-04 15:23 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignee9598d774c5a0ab
2016-12-04 15:23 - 2016-12-04 15:23 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignc45ea8219c449654
2016-12-04 15:23 - 2016-12-04 15:23 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignbbb9965e4c421aac
2016-12-04 15:22 - 2016-12-04 15:22 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigne825740709a62977
2016-12-04 15:22 - 2016-12-04 15:22 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign76352d9288f330e9
2016-12-03 17:20 - 2016-12-03 17:20 - 03968464 _____ C:\Users\Michal\Desktop\adwcleaner_6.040.exe
2016-12-03 12:36 - 2016-12-03 12:36 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignd5da385de6fd2890
2016-12-03 12:36 - 2016-12-03 12:36 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignb9a0456209b0fb90
2016-12-03 12:36 - 2016-12-03 12:36 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign637f95dfd3deab22
2016-12-02 08:55 - 2016-12-02 08:55 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignedd1f5a77ec3e170
2016-12-02 08:36 - 2016-12-02 08:36 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign8a48116b133eec3d
2016-12-02 08:36 - 2016-12-02 08:36 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign4dfed01b68589eff
2016-12-02 08:35 - 2016-12-02 08:35 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignde71e76c18358e83
2016-12-02 08:35 - 2016-12-02 08:35 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignca2078198d882286
2016-12-02 08:35 - 2016-12-02 08:35 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign089f88d9de54e320
2016-12-01 14:47 - 2016-12-01 14:47 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign0c6c77f61ea482b9
2016-12-01 14:46 - 2016-12-01 14:46 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignf5b96ce0dbd76646
2016-12-01 14:46 - 2016-12-01 14:46 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignafa4cfdfa387e7f7
2016-12-01 14:33 - 2016-12-01 14:33 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignef86ed7a47234b5f
2016-12-01 14:33 - 2016-12-01 14:33 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign836b3f85dac8e120
2016-12-01 14:33 - 2016-12-01 14:33 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign2030b3848e1630f2
2016-12-01 14:28 - 2016-12-01 14:28 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign093bb2eebf52505b
2016-12-01 14:21 - 2016-12-01 14:21 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign8f2c1411af27bf28
2016-12-01 14:21 - 2016-12-01 14:21 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign83da037ce220920b
2016-12-01 14:05 - 2016-12-01 14:05 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignc416a405298374d2
2016-12-01 14:05 - 2016-12-01 14:05 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign981669be21ccd874
2016-12-01 14:05 - 2016-12-01 14:05 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign0f35eaf1cde8fff5
2016-12-01 09:50 - 2016-12-01 09:50 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigncde8aac452b4324e
2016-12-01 09:50 - 2016-12-01 09:50 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign90b3543d86bb94b7
2016-12-01 09:50 - 2016-12-01 09:50 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign3f0c97113d683f5b
2016-12-01 09:38 - 2016-12-01 09:38 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign726672b45aceab45
2016-12-01 09:12 - 2016-12-01 09:12 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignc9a5cc778c404459
2016-12-01 09:12 - 2016-12-01 09:12 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign712e33010fec095c
2016-12-01 08:43 - 2016-12-01 08:43 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignce36f1c8dc468bf1
2016-12-01 08:43 - 2016-12-01 08:43 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign8f0f885cd9fcb2c8
2016-12-01 08:43 - 2016-12-01 08:43 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign7dd9662d1863cfba
2016-11-30 21:56 - 2016-11-30 21:56 - 02331607 ____R C:\Users\Michal\Desktop\vianocna.wma
2016-11-30 18:31 - 2016-11-30 18:31 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign2ae16539ec40858b
2016-11-30 18:23 - 2016-11-30 18:23 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign54ffb038181ccd4d
2016-11-30 18:23 - 2016-11-30 18:23 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign0e2689382ab7988b
2016-11-30 18:22 - 2016-12-09 17:50 - 00000000 ____D C:\Program Files (x86)\Brackets
2016-11-30 18:22 - 2016-11-30 18:22 - 00000776 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brackets.lnk
2016-11-29 15:59 - 2016-11-29 15:59 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignf2f5363d549be76a
2016-11-29 15:58 - 2016-11-29 15:58 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignad766ffe9529aa1c
2016-11-29 15:42 - 2016-11-29 15:42 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign38237170c6290eb9
2016-11-29 14:34 - 2016-11-29 14:34 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign760eae1ed084535c
2016-11-29 14:18 - 2016-11-29 14:18 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign8d8256ce50bbc819
2016-11-29 14:17 - 2016-11-29 14:17 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignd65fbc1f5a9677ef
2016-11-29 14:17 - 2016-11-29 14:17 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign7ba0c41e17cff74f
2016-11-29 12:41 - 2016-11-29 12:41 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign0869e5917f164ad8
2016-11-29 12:39 - 2016-11-29 12:39 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignebb2588b068b8ce7
2016-11-29 12:39 - 2016-11-29 12:39 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsigne0d742a69f007cec
2016-11-29 12:39 - 2016-11-29 12:39 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignc95b42e29036466e
2016-11-26 18:37 - 2016-11-26 18:37 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignfdc10a1f9615cd11
2016-11-26 18:37 - 2016-11-26 18:37 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignf638436609388d93
2016-11-26 18:37 - 2016-11-26 18:37 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignea81d48a8b65529b
2016-11-26 18:37 - 2016-11-26 18:37 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignd7cb58767b595773
2016-11-26 18:30 - 2016-11-26 18:30 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign44f91b5941852f0a
2016-11-26 18:30 - 2016-11-26 18:30 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign315e73162b4dc7e7
2016-11-26 17:14 - 2016-11-26 17:14 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign2e2e77420baffa19
2016-11-26 17:12 - 2016-11-26 17:12 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign911d90bba4c005a5
2016-11-26 17:11 - 2016-11-26 17:11 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign9c1abd5d31566242
2016-11-26 17:11 - 2016-11-26 17:11 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign2c2cd75c0b565547
2016-11-25 16:51 - 2016-11-25 16:51 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsignbffc69d2e5d60b32
2016-11-25 16:51 - 2016-11-25 16:51 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign9aca18065b137984
2016-11-25 16:51 - 2016-11-25 16:51 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign7c50c242c36dec9a
2016-11-25 16:50 - 2016-11-25 16:50 - 00000000 ____D C:\Users\Michal\AppData\Local\Tempzxpsign76cb548188a4d357