Tak včera jsem přeinstaloval Windows a vypadá to že pomohlo. Projížděl jsem totiž log a není tam nic co by bylo skutečně vir ale jsou tam soubory které jsou tak na hraně a proto bych se chtěl zeptat vás jestli je to OK.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2017
Ran by cunik.cz (administrator) on DESKTOP-4T1NASI (03-11-2017 17:27:51)
Running from C:\Users\cunik.cz\Desktop
Loaded Profiles: cunik.cz (Available Profiles: cunik.cz)
Platform: Windows 10 Home N Version 1703 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
() C:\Users\cunik.cz\Desktop\RogueKillerX64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8911872 2016-10-15] (Realtek Semiconductor)
HKLM\...\RunOnce: [SRS_APO_Install] => rundll32.exe C:\Windows\system32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\slInit64.dll,SRS_InitializeEndpoints_Rundll32
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{ba9ec0cb-3572-4dea-87b5-006c25dacc12}: [DhcpNameServer] 213.46.172.37 213.46.172.36
Internet Explorer:
==================
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2286848 2015-10-01] (Broadcom Corporation.)
R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1394360 2015-08-12] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373720 2017-01-13] (Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [326656 2016-10-15] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-08-18] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [177440 2016-01-27] (Broadcom Corporation.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [11774712 2017-11-03] (Broadcom Corp)
R3 BCMWL63A; C:\Windows\system32\DRIVERS\bcmwl63a.sys [11774712 2017-11-03] (Broadcom Corp)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [53752 2015-08-12] (Intel Corporation)
R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [50696 2015-08-12] (Intel Corporation)
R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [261624 2015-08-12] (Intel Corporation)
R1 MpKsl4b07f5a6; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A9BB2DE8-8D49-4265-AC1A-13B4CDF7365F}\MpKsl4b07f5a6.sys [58120 2017-11-03] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [55384 2017-08-18] (Synaptics Incorporated)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-11-03] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\Windows\system32\DRIVERS\WirelessButtonDriver64.sys [31656 2016-04-13] (HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-03 17:27 - 2017-11-03 17:27 - 000000000 ____D C:\Users\cunik.cz\Desktop\FRST-OlderVersion
2017-11-03 17:21 - 2017-11-03 17:21 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\AvgSetupLog
2017-11-03 17:21 - 2017-11-03 17:21 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\Avg
2017-11-03 17:21 - 2017-11-03 17:21 - 000000000 ____D C:\ProgramData\Avg
2017-11-03 17:14 - 2017-11-03 17:14 - 000544424 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-11-03 17:10 - 2017-11-03 17:10 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\Comms
2017-11-03 17:04 - 2017-11-03 17:04 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-11-03 17:04 - 2017-11-03 17:04 - 000000000 ____D C:\ProgramData\RogueKiller
2017-11-03 16:47 - 2017-11-03 16:47 - 000000000 ____D C:\Users\cunik.cz\Downloads\backups
2017-11-03 16:34 - 2017-11-03 16:34 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_esif_umdf2_02_00_00.Wdf
2017-11-03 16:34 - 2017-11-03 16:34 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_esif_lf_01011.Wdf
2017-11-03 16:34 - 2017-11-03 16:34 - 000000000 ____D C:\Program Files (x86)\HP
2017-11-03 16:33 - 2017-11-03 16:33 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2017-11-03 16:33 - 2017-11-03 16:33 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2017-11-03 16:33 - 2017-11-03 16:33 - 000000000 ____D C:\Program Files\Synaptics
2017-11-03 16:33 - 2017-08-18 02:23 - 000055384 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys
2017-11-03 16:32 - 2017-11-03 16:32 - 000013167 _____ C:\Windows\system32\Drivers\rtkhdasetting.zip
2017-11-03 16:32 - 2017-11-03 16:32 - 000001844 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DTS Audio Control.lnk
2017-11-03 16:32 - 2017-11-03 16:32 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2017-11-03 16:32 - 2017-11-03 16:32 - 000000000 ____D C:\Windows\system32\SRSLabs
2017-11-03 16:32 - 2017-11-03 16:32 - 000000000 ____D C:\ProgramData\SRS Labs
2017-11-03 16:32 - 2017-11-03 16:32 - 000000000 ____D C:\Program Files\Realtek
2017-11-03 16:29 - 2017-11-03 16:34 - 000000000 ____D C:\Program Files (x86)\Intel
2017-11-03 16:29 - 2017-11-03 16:29 - 000000200 _____ C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2017-11-03 16:29 - 2017-11-03 16:29 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-11-03 16:29 - 2017-11-03 16:29 - 000000000 __SHD C:\Users\cunik.cz\IntelGraphicsProfiles
2017-11-03 16:29 - 2017-11-03 16:29 - 000000000 ____D C:\Program Files\Intel
2017-11-03 16:29 - 2017-11-03 16:29 - 000000000 ____D C:\Intel
2017-11-03 16:29 - 2017-11-03 16:29 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2017-11-03 16:29 - 2017-01-13 19:38 - 000103936 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL
2017-11-03 16:29 - 2017-01-13 19:38 - 000099840 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL
2017-11-03 16:25 - 2017-11-03 16:25 - 000388608 _____ (Trend Micro Inc.) C:\Users\cunik.cz\Downloads\HijackThis.exe
2017-11-03 16:24 - 2017-11-03 16:24 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\MicrosoftEdge
2017-11-03 16:23 - 2017-11-03 16:34 - 000000000 ____D C:\Windows\LastGood
2017-11-03 16:23 - 2017-11-03 16:23 - 011774712 _____ (Broadcom Corp) C:\Windows\system32\Drivers\bcmwl63a.sys
2017-11-03 16:23 - 2017-11-03 16:23 - 004132384 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2017-11-03 16:23 - 2017-11-03 16:23 - 003787296 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2017-11-03 16:23 - 2017-11-03 16:23 - 000000000 ____D C:\SWSetup
2017-11-03 16:23 - 2017-11-03 16:23 - 000000000 ____D C:\ProgramData\Package Cache
2017-11-03 16:23 - 2017-11-03 16:23 - 000000000 ____D C:\Program Files\Broadcom
2017-11-03 16:13 - 2017-11-03 16:13 - 000000000 ____D C:\_OTM
2017-11-03 16:12 - 2017-10-31 20:18 - 000522240 _____ (OldTimer Tools) C:\Users\cunik.cz\Desktop\OTM.exe
2017-11-03 15:49 - 2017-11-03 15:49 - 000000000 ____D C:\ProgramData\USOShared
2017-11-03 15:45 - 2017-11-03 15:45 - 000013629 _____ C:\Users\cunik.cz\Desktop\Addition.txt
2017-11-03 15:43 - 2017-11-03 17:28 - 000006403 _____ C:\Users\cunik.cz\Desktop\FRST.txt
2017-11-03 15:43 - 2017-11-03 17:27 - 002403328 _____ (Farbar) C:\Users\cunik.cz\Desktop\FRST64.exe
2017-11-03 15:43 - 2017-11-03 17:27 - 000000000 ____D C:\FRST
2017-11-03 15:43 - 2017-10-19 20:03 - 016563352 _____ (Malwarebytes Corp.) C:\Users\cunik.cz\Desktop\mbar-1.09.3.1001.exe
2017-11-03 15:43 - 2017-10-16 14:56 - 047459488 _____ (Hewlett-Packard Company ) C:\Users\cunik.cz\Desktop\sp75249.exe
2017-11-03 15:43 - 2017-10-12 16:00 - 026775624 _____ C:\Users\cunik.cz\Desktop\RogueKillerX64.exe
2017-11-02 17:12 - 2017-11-02 17:12 - 000003296 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-11-02 17:12 - 2017-11-02 17:12 - 000002396 _____ C:\Users\cunik.cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-11-02 17:12 - 2017-11-02 17:12 - 000000000 ___RD C:\Users\cunik.cz\OneDrive
2017-11-02 17:11 - 2017-11-02 17:11 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-11-02 17:10 - 2017-11-03 17:00 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\Packages
2017-11-02 17:10 - 2017-11-03 16:25 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\VirtualStore
2017-11-02 17:10 - 2017-11-02 17:10 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-11-02 17:10 - 2017-11-02 17:10 - 000000000 ____D C:\Users\cunik.cz\AppData\Roaming\Adobe
2017-11-02 17:10 - 2017-11-02 17:10 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\TileDataLayer
2017-11-02 17:10 - 2017-11-02 17:10 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\Publishers
2017-11-02 17:10 - 2017-11-02 17:10 - 000000000 ____D C:\Users\cunik.cz\AppData\Local\ConnectedDevicesPlatform
2017-11-02 17:09 - 2017-11-03 16:29 - 000000000 ____D C:\Users\cunik.cz
2017-11-02 17:09 - 2017-11-02 17:09 - 000000020 ___SH C:\Users\cunik.cz\ntuser.ini
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Šablony
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Soubory cookie
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Poslední
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Okolní tiskárny
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Okolní síť
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Nabídka Start
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Dokumenty
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Documents\Obrázky
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Documents\Hudba
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Documents\Filmy
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\Data aplikací
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-11-02 17:09 - 2017-11-02 17:09 - 000000000 _SHDL C:\Users\cunik.cz\AppData\Local\Data aplikací
2017-11-02 17:08 - 2017-11-03 16:35 - 001788062 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-02 17:06 - 2017-03-18 21:55 - 002233344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Public\Documents\Obrázky
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Public\Documents\Hudba
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Public\Documents\Filmy
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Šablony
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Soubory cookie
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Poslední
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Okolní tiskárny
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Okolní síť
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Nabídka Start
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Dokumenty
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Documents\Obrázky
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Documents\Hudba
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Documents\Filmy
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\Data aplikací
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default User\Documents\Obrázky
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default User\Documents\Hudba
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default User\Documents\Filmy
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\ProgramData\Šablony
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\ProgramData\Plocha
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\ProgramData\Nabídka Start
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\ProgramData\Dokumenty
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\ProgramData\Data aplikací
2017-11-02 17:04 - 2017-11-02 17:04 - 000000000 _SHDL C:\Documents and Settings
2017-11-02 16:59 - 2017-11-02 17:04 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-02 16:58 - 2017-11-02 17:02 - 000000000 ____D C:\Windows\Panther
2017-11-02 16:58 - 2017-11-02 16:59 - 000217296 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-02 16:58 - 2017-11-02 16:59 - 000000000 ____D C:\Windows\system32\SleepStudy
2017-11-02 16:58 - 2017-11-02 16:59 - 000000000 ____D C:\Windows\ServiceProfiles
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-03 17:20 - 2017-03-18 22:02 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-03 17:20 - 2017-03-18 22:02 - 000000000 ____D C:\Windows\AppReadiness
2017-11-03 17:10 - 2017-03-18 22:00 - 000000000 ____D C:\Windows\INF
2017-11-03 16:35 - 2017-03-20 05:41 - 000769760 _____ C:\Windows\system32\perfh005.dat
2017-11-03 16:35 - 2017-03-20 05:41 - 000158448 _____ C:\Windows\system32\perfc005.dat
2017-11-03 15:55 - 2017-03-18 22:02 - 000000000 ____D C:\Windows\system32\NDF
2017-11-03 15:49 - 2017-03-18 22:02 - 000000000 ____D C:\ProgramData\USOPrivate
2017-11-02 17:06 - 2017-03-18 22:02 - 000000000 ____D C:\Windows\system32\spool
2017-11-02 17:06 - 2017-03-18 22:02 - 000000000 ____D C:\Windows\system32\FxsTmp
2017-11-02 17:06 - 2017-03-18 22:02 - 000000000 ____D C:\Windows\rescache
2017-11-02 17:05 - 2017-03-18 22:02 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-11-02 17:04 - 2017-03-18 22:02 - 000000000 ____D C:\Program Files\Windows NT
2017-11-02 17:03 - 2017-03-18 12:40 - 000131072 _____ C:\Windows\system32\config\BBI
2017-11-02 17:02 - 2017-03-18 12:40 - 000000000 ____D C:\Windows\system32\Sysprep
2017-11-02 17:00 - 2017-03-18 22:02 - 000000000 ___RD C:\Windows\PrintDialog
2017-11-02 17:00 - 2017-03-18 22:02 - 000000000 ___RD C:\Windows\MiracastView
2017-11-02 17:00 - 2017-03-18 22:02 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2017-11-02 17:00 - 2017-03-18 12:40 - 000032768 _____ C:\Windows\system32\config\ELAM
2017-11-02 16:58 - 2017-03-18 22:02 - 000028672 _____ C:\Windows\system32\config\BCD-Template
Some files in TEMP:
====================
2017-11-03 17:04 - 2017-03-18 21:56 - 001930320 _____ (Microsoft Corporation) C:\Users\cunik.cz\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-11-02 16:58
==================== End of FRST.txt ============================