Re: Poprpsím o preventívku
Napsal: 28 dub 2018 20:00
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018
Ran by Peter (28-04-2018 20:59:28)
Running from C:\Users\Peter\Desktop
Windows 7 Professional Service Pack 1 (X64) (2016-11-26 15:09:47)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1762337417-2231521048-3039012980-500 - Administrator - Disabled)
Guest (S-1-5-21-1762337417-2231521048-3039012980-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1762337417-2231521048-3039012980-1002 - Limited - Enabled)
Peter (S-1-5-21-1762337417-2231521048-3039012980-1000 - Administrator - Enabled) => C:\Users\Peter
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\uTorrent) (Version: 3.5.3.44358 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Aktualizácie NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.71.1081 - AB Team, d.o.o.)
bwin Poker (HKLM-x32\...\bwincomPoker) (Version: - bwincom)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
CountDown ShutDown PC (HKLM-x32\...\CountDown ShutDown PC_is1) (Version: - Velkej Chytrák)
Creative Audio Control Panel (HKLM-x32\...\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Ultra (HKLM\...\DAEMON Tools Ultra) (Version: 5.0.0.0540 - Disc Soft Ltd)
EAX Unified (HKLM-x32\...\EAX Unified) (Version: - )
EZ CD Audio Converter (HKLM-x32\...\EZ CD Audio Converter) (Version: 7.0 - Poikosoft)
Charles 4.1.3 (HKLM\...\{81045AC5-B1C4-4B5D-8719-9BEB41167F17}) (Version: 4.1.3.5 - XK72 Ltd)
Cheat Engine 6.6 (HKLM-x32\...\Cheat Engine 6.6_is1) (Version: - Cheat Engine)
Cheat Engine 6.7 (HKLM-x32\...\Cheat Engine 6.7_is1) (Version: - Cheat Engine)
InstaTrader (HKLM-x32\...\InstaTrader) (Version: 6.00 - MetaQuotes Software Corp.)
Malwarebytes verzia 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office 2016 Professional Plus - sk-sk (HKLM\...\ProplusRetail - sk-sk) (Version: 16.0.9126.2152 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{9085041B-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 59.0.2.6656 - Mozilla)
NVIDIA Softvér systému s podporou technológie PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.9001.2171 - Microsoft Corporation) Hidden
OkayFreedom (HKLM-x32\...\{3F3FB10C-7175-4D38-9335-3488B89C12AF}) (Version: 1.8.3 - Steganos Software GmbH)
OpenOffice 4.1.5 (HKLM-x32\...\{E177AC33-EC9C-4537-8996-37ED331D9227}) (Version: 4.15.9789 - Apache Software Foundation)
Ovládací panel NVIDIA 342.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 342.01 - NVIDIA Corporation) Hidden
Scorpions WinCheater (HKLM-x32\...\Scorpions WinCheater 2.07 (s finální databází 178)_is1) (Version: - )
SDÍLEJ.CZ Manager (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\69f070f18ade444c) (Version: 0.0.1.42 - SDÍLEJ.CZ)
SharewareOnSale Notifier (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\SharewareOnSale Notifier) (Version: 20 - SharewareOnSale)
SiSoftware Sandra Lite 2015.SP1a (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 21.32.2015.3 - SiSoftware)
Spotify (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\Spotify) (Version: 1.0.66.478.g1296534d - Spotify AB)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.71503 - TeamViewer)
TomTom HOME (HKLM-x32\...\{F55189F0-F34D-49E4-9ABF-31D28DCA328E}) (Version: 2.11.1 - Meno vašej spoločnosti)
TomTom MyDrive Connect 4.2.0.3437 (HKLM-x32\...\MyDriveConnect) (Version: 4.2.0.3437 - TomTom)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0 - Ghisler Software GmbH)
Total Commander verze 9.12 (HKLM-x32\...\{B12BC641-C553-4138-A829-31B1A642333B}_is1) (Version: 9.12 - ©Ghisler Software GmbH)
Total Uninstall 6.21.1 (HKLM\...\Total Uninstall 6_is1) (Version: 6.21.1 - Gavrila Martau)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - BigNox Corporation (VBoxUSB) USB (01/20/2017 4.3.12) (HKLM\...\5704FF66AFA4D394842933DCC54279C2E177D380) (Version: 01/20/2017 4.3.12 - BigNox Corporation)
Windows Driver Package - BigNox Corporation VBoxUSBMon System (01/20/2017 4.3.12) (HKLM\...\35C6212A24F5D9B7942ECD18B0255759779999C2) (Version: 01/20/2017 4.3.12 - BigNox Corporation)
Windows Movie Maker 2016 (HKLM-x32\...\{3CC29C1A-B5FE-457B-8F22-32A2videowin}}_is1) (Version: - videowinsoft.com)
WinZip 22.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24119}) (Version: 22.0.12706 - Corel Corporation)
XChat 2 (remove only) (HKLM-x32\...\xchat) (Version: - )
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_SK_is1) (Version: 19.1802.2.51 - ZONER software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll ()
ContextMenuHandlers1: [EzCd] -> {E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => C:\Program Files\EZ CD Audio Converter\ezcd64.dll [2016-01-01] (Poikosoft)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers4: [EzCd] -> {E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => C:\Program Files\EZ CD Audio Converter\ezcd64.dll [2016-01-01] (Poikosoft)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-11-14] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {13BD8189-A171-49FE-9027-8C33F59C029F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {2526F98E-7DEA-4119-8FC1-7E8272BC7DA1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-10] (Adobe Systems Incorporated)
Task: {2FCA3065-1A28-42D1-AB38-031F12963200} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-04-06] (Microsoft Corporation)
Task: {51866950-7186-4069-BA8F-A63C3279F21D} - System32\Tasks\{E30CA91D-AAF5-480F-A381-9FC5B3911889} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Nox\bin\Nox_unload.exe" -d "C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Nox"
Task: {95DB87D3-3FAD-45B7-B2F3-002C8DE0E96C} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-12-11] (WinZip)
Task: {E0F94AAF-0B95-444C-A0BC-54A6A4F0404B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {E182B577-489C-40B4-8627-246BAD945241} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-10] (Adobe Systems Incorporated)
Task: {F0657953-640D-4E04-872C-94156750C463} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-04-06] (Microsoft Corporation)
Task: {F5C6E9EE-90CE-48E2-A0DE-099EB67E52CF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-11-26 17:36 - 2016-11-14 13:15 - 000135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-01-22 11:03 - 2018-01-22 11:03 - 000061920 _____ () C:\Program Files\CCleaner\branding.dll
2016-12-13 14:54 - 2018-03-12 15:09 - 002300192 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-01-10 19:53 - 2017-11-24 10:12 - 000158288 _____ () C:\Program Files (x86)\Total Commander\wcmzip64.dll
2017-02-15 01:06 - 2016-05-03 23:50 - 000913161 _____ () C:\Users\Peter\Downloads\IRC\libcairo-2.dll
2017-02-15 01:06 - 2016-05-04 13:43 - 000941543 _____ () C:\Users\Peter\Downloads\IRC\libgcc_s_seh-1.dll
2017-02-15 01:06 - 2016-05-03 18:43 - 000503368 _____ () C:\Users\Peter\Downloads\IRC\libpixman-1-0.dll
2017-02-15 01:06 - 2016-02-06 21:12 - 000221854 _____ () C:\Users\Peter\Downloads\IRC\libpng16-16.dll
2017-02-15 01:06 - 2015-06-18 00:58 - 000091289 _____ () C:\Users\Peter\Downloads\IRC\zlib1.dll
2017-02-15 01:06 - 2016-02-04 14:23 - 000037680 _____ () C:\Users\Peter\Downloads\IRC\iconv.dll
2017-02-15 01:06 - 2016-02-06 20:58 - 000301854 _____ () C:\Users\Peter\Downloads\IRC\libpcre-1.dll
2017-02-15 01:06 - 2015-06-18 00:37 - 000033679 _____ () C:\Users\Peter\Downloads\IRC\libffi-6.dll
2017-02-15 01:06 - 2016-05-16 00:42 - 000074031 _____ () C:\Users\Peter\Downloads\IRC\lib\gtk-2.0\2.10.0\engines\libwimp.dll
2017-02-15 01:06 - 2016-05-15 02:47 - 000293888 _____ () C:\Users\Peter\Downloads\IRC\lib\enchant\libenchant_myspell.dll
2017-02-15 01:06 - 2017-02-14 21:49 - 000019456 _____ () C:\Users\Peter\Downloads\IRC\plugins\winampctrl_x64.dll
2017-02-15 01:06 - 2012-06-17 10:03 - 000015360 _____ () C:\Users\Peter\Downloads\IRC\plugins\xcfishlim.dll
2017-02-15 01:06 - 2012-06-17 10:03 - 000028672 _____ () C:\Users\Peter\Downloads\IRC\plugins\xclua.dll
2017-02-15 01:06 - 2010-10-29 17:06 - 000161280 _____ () C:\Users\Peter\Downloads\IRC\lua51.dll
2017-02-15 01:06 - 2015-08-21 05:16 - 000010240 _____ () C:\Users\Peter\Downloads\IRC\plugins\xcwinamp.dll
2017-02-15 01:06 - 2016-10-11 21:50 - 000024576 _____ () C:\Users\Peter\Downloads\IRC\plugins\xcxsys.dll
2018-01-25 15:28 - 2018-01-25 15:28 - 001160704 _____ () C:\Program Files (x86)\OkayFreedom\vpn.dll
2017-06-28 06:11 - 2017-06-28 06:11 - 000013312 _____ () C:\Program Files (x86)\MyDrive Connect\libEGL.DLL
2017-06-28 06:11 - 2017-06-28 06:11 - 001949696 _____ () C:\Program Files (x86)\MyDrive Connect\libGLESv2.dll
2014-09-11 17:14 - 2014-09-11 17:14 - 000218112 _____ () C:\Program Files (x86)\MyDrive Connect\Plugins\imageformats\qmng.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2018-04-21 13:04 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^Users^Peter^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Gameroom.lnk => C:\Windows\pss\Facebook Gameroom.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Ultra Agent => "C:\Users\Peter\DAEMON Tools Ultra\DTAgent.exe" -autorun
MSCONFIG\startupreg: OKAYFREEDOM Notifier => "C:\Program Files (x86)\OkayFreedom\Notifier.exe"
MSCONFIG\startupreg: OKAYFREEDOM_Agent => "C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe" -agent
MSCONFIG\startupreg: Spotify => "C:\Users\Peter\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Peter\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
MSCONFIG\startupreg: uTorrent => "C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{21AF00BC-69E4-46D0-9E2C-7BDCA808AB87}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1a\RpcAgentSrv.exe
FirewallRules: [{49A999C8-E8ED-493A-8569-474C1C02AA67}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5F3E2D9C-ADDF-4688-BA9C-7498CB62CE88}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BF242538-1915-4CB0-9CCA-0BE42684B226}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{C2B13292-FE11-4D92-8BE6-FC58126E6FE3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{91562D1F-4BB8-4DE3-9061-83293C19044B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{65A90583-4A75-4A42-B53E-574948CA365F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{C9F0D391-BBD5-4832-819B-8FED00D6A67B}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{62EF1DAB-D355-4394-8692-6C9DE01C8F57}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [{C536916A-B3E5-478E-9A3B-99FBC19BE9BF}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1a\WNt600x64\RpcSandraSrv.exe
FirewallRules: [TCP Query User{E99ACC46-EB4B-4690-AF11-A6D761CE11CB}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [UDP Query User{5F003441-B584-43ED-9AC2-F4CFC62463F4}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [{7C805329-BE04-4FE2-ADBA-FE123F381327}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{FD895352-A201-4520-99D3-041E934E9621}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{22D57A7F-28F1-433B-B1B8-20C30E90BED8}] => (Block) LPort=445
FirewallRules: [{287B29C8-F3BB-40DB-A7F1-CE083767A946}] => (Block) LPort=445
FirewallRules: [TCP Query User{9E74E1B7-D2A6-485D-939B-C6BDF5A46CAF}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [UDP Query User{8C4309E6-FF2E-47F3-BF23-EB0C4B101B69}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [TCP Query User{A283D731-EAFB-411F-BEFC-AD2A2B510395}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{A48889D6-B34D-4693-B1B3-3CCC50F648E5}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [{334F2B70-9981-4709-A053-2CBE9A891BED}] => (Allow) \Nox\bin\Nox.exe
FirewallRules: [{C8EFF610-85D7-48FF-9174-DEF031BEE7EB}] => (Allow) \Bignox\BigNoxVM\RT\NoxVMHandle.exe
FirewallRules: [{BFF57A19-B280-410D-B975-C97037BCA189}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B21132F8-8F3E-4BC4-ADEC-9A7249804BA8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BC3F5B27-B14C-4FF5-8AC0-C7D159430180}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BC7FAFBE-7EB6-4B94-8D7B-3BFB5255A88E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F6E760AF-CE67-405E-BBC9-46110337E7D1}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{50855B08-1183-4AED-951E-018DD6B1D6F1}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F8B9BB92-C8D0-4DED-81B5-7C3ADA1DDE27}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6E6E9127-557D-4739-B1DC-FE44AC816735}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5C42852C-D506-4AD0-B1AE-42F3DD1E6C9B}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DB88DE23-4E74-4DD7-A823-3D35DDF6F429}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{0F46680C-39B8-40E8-9D78-437FB59383E9}] => (Allow) C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\xchat\xchat.exe] => Enabled:XChat IRC Client
==================== Restore Points =========================
21-04-2018 13:03:30 Restore Point Created by FRST
28-04-2018 11:01:18 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/28/2018 11:11:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0x2084
Čas spustenia chybnej aplikácie: 0x01d3ded0e4f10bd6
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: 23978733-4ac4-11e8-b387-001e8c60ef64
Error: (04/28/2018 11:11:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0xf3c
Čas spustenia chybnej aplikácie: 0x01d3ded0dcf1ec6b
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: 2397ae43-4ac4-11e8-b387-001e8c60ef64
Error: (04/28/2018 03:10:36 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8736
Error: (04/28/2018 03:10:36 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8736
Error: (04/28/2018 03:10:36 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (04/27/2018 10:21:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0x2074
Čas spustenia chybnej aplikácie: 0x01d3de00bd459757
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: fbba3cdf-49f3-11e8-b387-001e8c60ef64
Error: (04/27/2018 10:21:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0x207c
Čas spustenia chybnej aplikácie: 0x01d3de00bd517e39
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: fbba15cf-49f3-11e8-b387-001e8c60ef64
Error: (04/26/2018 10:04:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0xa80
Čas spustenia chybnej aplikácie: 0x01d3dd35381ca5b5
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: 76b4ffe1-4928-11e8-b387-001e8c60ef64
System errors:
=============
Error: (04/28/2018 05:41:46 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/28/2018 05:41:42 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/24/2018 10:16:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby ShellHWDetection bol dosiahnutý časový limit (120000 ms).
Error: (04/24/2018 10:16:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby lmhosts bol dosiahnutý časový limit (120000 ms).
Error: (04/23/2018 04:26:21 AM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (04/21/2018 07:24:59 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby ShellHWDetection bol dosiahnutý časový limit (120000 ms).
Error: (04/21/2018 03:56:59 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (04/21/2018 01:46:23 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Windows Defender:
===================================
Date: 2018-03-29 17:53:58.309
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{126F799B-869C-440B-9062-942759E2D4AA}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan
CodeIntegrity:
===================================
Date: 2017-06-02 05:57:47.906
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-06-02 05:57:47.906
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-06-02 05:57:47.906
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-27 14:23:26.429
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-27 14:23:26.427
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-27 14:23:26.415
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-20 08:33:09.048
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-20 08:33:09.031
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
Percentage of memory in use: 52%
Total physical RAM: 4095.12 MB
Available physical RAM: 1932.24 MB
Total Virtual: 8188.4 MB
Available Virtual: 4888.63 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:195.31 GB) (Free:32.67 GB) NTFS ==>[drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 08CB08CB)
Partition 1: (Active) - (Size=195.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Ran by Peter (28-04-2018 20:59:28)
Running from C:\Users\Peter\Desktop
Windows 7 Professional Service Pack 1 (X64) (2016-11-26 15:09:47)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1762337417-2231521048-3039012980-500 - Administrator - Disabled)
Guest (S-1-5-21-1762337417-2231521048-3039012980-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1762337417-2231521048-3039012980-1002 - Limited - Enabled)
Peter (S-1-5-21-1762337417-2231521048-3039012980-1000 - Administrator - Enabled) => C:\Users\Peter
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\uTorrent) (Version: 3.5.3.44358 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Aktualizácie NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.71.1081 - AB Team, d.o.o.)
bwin Poker (HKLM-x32\...\bwincomPoker) (Version: - bwincom)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
CountDown ShutDown PC (HKLM-x32\...\CountDown ShutDown PC_is1) (Version: - Velkej Chytrák)
Creative Audio Control Panel (HKLM-x32\...\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Ultra (HKLM\...\DAEMON Tools Ultra) (Version: 5.0.0.0540 - Disc Soft Ltd)
EAX Unified (HKLM-x32\...\EAX Unified) (Version: - )
EZ CD Audio Converter (HKLM-x32\...\EZ CD Audio Converter) (Version: 7.0 - Poikosoft)
Charles 4.1.3 (HKLM\...\{81045AC5-B1C4-4B5D-8719-9BEB41167F17}) (Version: 4.1.3.5 - XK72 Ltd)
Cheat Engine 6.6 (HKLM-x32\...\Cheat Engine 6.6_is1) (Version: - Cheat Engine)
Cheat Engine 6.7 (HKLM-x32\...\Cheat Engine 6.7_is1) (Version: - Cheat Engine)
InstaTrader (HKLM-x32\...\InstaTrader) (Version: 6.00 - MetaQuotes Software Corp.)
Malwarebytes verzia 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office 2016 Professional Plus - sk-sk (HKLM\...\ProplusRetail - sk-sk) (Version: 16.0.9126.2152 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{9085041B-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 59.0.2.6656 - Mozilla)
NVIDIA Softvér systému s podporou technológie PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.9001.2171 - Microsoft Corporation) Hidden
OkayFreedom (HKLM-x32\...\{3F3FB10C-7175-4D38-9335-3488B89C12AF}) (Version: 1.8.3 - Steganos Software GmbH)
OpenOffice 4.1.5 (HKLM-x32\...\{E177AC33-EC9C-4537-8996-37ED331D9227}) (Version: 4.15.9789 - Apache Software Foundation)
Ovládací panel NVIDIA 342.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 342.01 - NVIDIA Corporation) Hidden
Scorpions WinCheater (HKLM-x32\...\Scorpions WinCheater 2.07 (s finální databází 178)_is1) (Version: - )
SDÍLEJ.CZ Manager (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\69f070f18ade444c) (Version: 0.0.1.42 - SDÍLEJ.CZ)
SharewareOnSale Notifier (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\SharewareOnSale Notifier) (Version: 20 - SharewareOnSale)
SiSoftware Sandra Lite 2015.SP1a (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 21.32.2015.3 - SiSoftware)
Spotify (HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\...\Spotify) (Version: 1.0.66.478.g1296534d - Spotify AB)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.71503 - TeamViewer)
TomTom HOME (HKLM-x32\...\{F55189F0-F34D-49E4-9ABF-31D28DCA328E}) (Version: 2.11.1 - Meno vašej spoločnosti)
TomTom MyDrive Connect 4.2.0.3437 (HKLM-x32\...\MyDriveConnect) (Version: 4.2.0.3437 - TomTom)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0 - Ghisler Software GmbH)
Total Commander verze 9.12 (HKLM-x32\...\{B12BC641-C553-4138-A829-31B1A642333B}_is1) (Version: 9.12 - ©Ghisler Software GmbH)
Total Uninstall 6.21.1 (HKLM\...\Total Uninstall 6_is1) (Version: 6.21.1 - Gavrila Martau)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.0 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - BigNox Corporation (VBoxUSB) USB (01/20/2017 4.3.12) (HKLM\...\5704FF66AFA4D394842933DCC54279C2E177D380) (Version: 01/20/2017 4.3.12 - BigNox Corporation)
Windows Driver Package - BigNox Corporation VBoxUSBMon System (01/20/2017 4.3.12) (HKLM\...\35C6212A24F5D9B7942ECD18B0255759779999C2) (Version: 01/20/2017 4.3.12 - BigNox Corporation)
Windows Movie Maker 2016 (HKLM-x32\...\{3CC29C1A-B5FE-457B-8F22-32A2videowin}}_is1) (Version: - videowinsoft.com)
WinZip 22.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24119}) (Version: 22.0.12706 - Corel Corporation)
XChat 2 (remove only) (HKLM-x32\...\xchat) (Version: - )
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_SK_is1) (Version: 19.1802.2.51 - ZONER software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1762337417-2231521048-3039012980-1000_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll ()
ContextMenuHandlers1: [EzCd] -> {E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => C:\Program Files\EZ CD Audio Converter\ezcd64.dll [2016-01-01] (Poikosoft)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers4: [EzCd] -> {E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => C:\Program Files\EZ CD Audio Converter\ezcd64.dll [2016-01-01] (Poikosoft)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-11-14] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {13BD8189-A171-49FE-9027-8C33F59C029F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {2526F98E-7DEA-4119-8FC1-7E8272BC7DA1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-10] (Adobe Systems Incorporated)
Task: {2FCA3065-1A28-42D1-AB38-031F12963200} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-04-06] (Microsoft Corporation)
Task: {51866950-7186-4069-BA8F-A63C3279F21D} - System32\Tasks\{E30CA91D-AAF5-480F-A381-9FC5B3911889} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Nox\bin\Nox_unload.exe" -d "C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Nox"
Task: {95DB87D3-3FAD-45B7-B2F3-002C8DE0E96C} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-12-11] (WinZip)
Task: {E0F94AAF-0B95-444C-A0BC-54A6A4F0404B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {E182B577-489C-40B4-8627-246BAD945241} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-10] (Adobe Systems Incorporated)
Task: {F0657953-640D-4E04-872C-94156750C463} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-04-06] (Microsoft Corporation)
Task: {F5C6E9EE-90CE-48E2-A0DE-099EB67E52CF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-11-26 17:36 - 2016-11-14 13:15 - 000135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-01-22 11:03 - 2018-01-22 11:03 - 000061920 _____ () C:\Program Files\CCleaner\branding.dll
2016-12-13 14:54 - 2018-03-12 15:09 - 002300192 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-01-10 19:53 - 2017-11-24 10:12 - 000158288 _____ () C:\Program Files (x86)\Total Commander\wcmzip64.dll
2017-02-15 01:06 - 2016-05-03 23:50 - 000913161 _____ () C:\Users\Peter\Downloads\IRC\libcairo-2.dll
2017-02-15 01:06 - 2016-05-04 13:43 - 000941543 _____ () C:\Users\Peter\Downloads\IRC\libgcc_s_seh-1.dll
2017-02-15 01:06 - 2016-05-03 18:43 - 000503368 _____ () C:\Users\Peter\Downloads\IRC\libpixman-1-0.dll
2017-02-15 01:06 - 2016-02-06 21:12 - 000221854 _____ () C:\Users\Peter\Downloads\IRC\libpng16-16.dll
2017-02-15 01:06 - 2015-06-18 00:58 - 000091289 _____ () C:\Users\Peter\Downloads\IRC\zlib1.dll
2017-02-15 01:06 - 2016-02-04 14:23 - 000037680 _____ () C:\Users\Peter\Downloads\IRC\iconv.dll
2017-02-15 01:06 - 2016-02-06 20:58 - 000301854 _____ () C:\Users\Peter\Downloads\IRC\libpcre-1.dll
2017-02-15 01:06 - 2015-06-18 00:37 - 000033679 _____ () C:\Users\Peter\Downloads\IRC\libffi-6.dll
2017-02-15 01:06 - 2016-05-16 00:42 - 000074031 _____ () C:\Users\Peter\Downloads\IRC\lib\gtk-2.0\2.10.0\engines\libwimp.dll
2017-02-15 01:06 - 2016-05-15 02:47 - 000293888 _____ () C:\Users\Peter\Downloads\IRC\lib\enchant\libenchant_myspell.dll
2017-02-15 01:06 - 2017-02-14 21:49 - 000019456 _____ () C:\Users\Peter\Downloads\IRC\plugins\winampctrl_x64.dll
2017-02-15 01:06 - 2012-06-17 10:03 - 000015360 _____ () C:\Users\Peter\Downloads\IRC\plugins\xcfishlim.dll
2017-02-15 01:06 - 2012-06-17 10:03 - 000028672 _____ () C:\Users\Peter\Downloads\IRC\plugins\xclua.dll
2017-02-15 01:06 - 2010-10-29 17:06 - 000161280 _____ () C:\Users\Peter\Downloads\IRC\lua51.dll
2017-02-15 01:06 - 2015-08-21 05:16 - 000010240 _____ () C:\Users\Peter\Downloads\IRC\plugins\xcwinamp.dll
2017-02-15 01:06 - 2016-10-11 21:50 - 000024576 _____ () C:\Users\Peter\Downloads\IRC\plugins\xcxsys.dll
2018-01-25 15:28 - 2018-01-25 15:28 - 001160704 _____ () C:\Program Files (x86)\OkayFreedom\vpn.dll
2017-06-28 06:11 - 2017-06-28 06:11 - 000013312 _____ () C:\Program Files (x86)\MyDrive Connect\libEGL.DLL
2017-06-28 06:11 - 2017-06-28 06:11 - 001949696 _____ () C:\Program Files (x86)\MyDrive Connect\libGLESv2.dll
2014-09-11 17:14 - 2014-09-11 17:14 - 000218112 _____ () C:\Program Files (x86)\MyDrive Connect\Plugins\imageformats\qmng.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2018-04-21 13:04 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1762337417-2231521048-3039012980-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^Users^Peter^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Gameroom.lnk => C:\Windows\pss\Facebook Gameroom.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Ultra Agent => "C:\Users\Peter\DAEMON Tools Ultra\DTAgent.exe" -autorun
MSCONFIG\startupreg: OKAYFREEDOM Notifier => "C:\Program Files (x86)\OkayFreedom\Notifier.exe"
MSCONFIG\startupreg: OKAYFREEDOM_Agent => "C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe" -agent
MSCONFIG\startupreg: Spotify => "C:\Users\Peter\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Peter\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
MSCONFIG\startupreg: uTorrent => "C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{21AF00BC-69E4-46D0-9E2C-7BDCA808AB87}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1a\RpcAgentSrv.exe
FirewallRules: [{49A999C8-E8ED-493A-8569-474C1C02AA67}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5F3E2D9C-ADDF-4688-BA9C-7498CB62CE88}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BF242538-1915-4CB0-9CCA-0BE42684B226}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{C2B13292-FE11-4D92-8BE6-FC58126E6FE3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{91562D1F-4BB8-4DE3-9061-83293C19044B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{65A90583-4A75-4A42-B53E-574948CA365F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{C9F0D391-BBD5-4832-819B-8FED00D6A67B}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{62EF1DAB-D355-4394-8692-6C9DE01C8F57}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [{C536916A-B3E5-478E-9A3B-99FBC19BE9BF}] => (Allow) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2015.SP1a\WNt600x64\RpcSandraSrv.exe
FirewallRules: [TCP Query User{E99ACC46-EB4B-4690-AF11-A6D761CE11CB}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [UDP Query User{5F003441-B584-43ED-9AC2-F4CFC62463F4}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [{7C805329-BE04-4FE2-ADBA-FE123F381327}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{FD895352-A201-4520-99D3-041E934E9621}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{22D57A7F-28F1-433B-B1B8-20C30E90BED8}] => (Block) LPort=445
FirewallRules: [{287B29C8-F3BB-40DB-A7F1-CE083767A946}] => (Block) LPort=445
FirewallRules: [TCP Query User{9E74E1B7-D2A6-485D-939B-C6BDF5A46CAF}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [UDP Query User{8C4309E6-FF2E-47F3-BF23-EB0C4B101B69}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe
FirewallRules: [TCP Query User{A283D731-EAFB-411F-BEFC-AD2A2B510395}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{A48889D6-B34D-4693-B1B3-3CCC50F648E5}C:\users\peter\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\peter\appdata\roaming\spotify\spotify.exe
FirewallRules: [{334F2B70-9981-4709-A053-2CBE9A891BED}] => (Allow) \Nox\bin\Nox.exe
FirewallRules: [{C8EFF610-85D7-48FF-9174-DEF031BEE7EB}] => (Allow) \Bignox\BigNoxVM\RT\NoxVMHandle.exe
FirewallRules: [{BFF57A19-B280-410D-B975-C97037BCA189}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B21132F8-8F3E-4BC4-ADEC-9A7249804BA8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BC3F5B27-B14C-4FF5-8AC0-C7D159430180}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BC7FAFBE-7EB6-4B94-8D7B-3BFB5255A88E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F6E760AF-CE67-405E-BBC9-46110337E7D1}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{50855B08-1183-4AED-951E-018DD6B1D6F1}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F8B9BB92-C8D0-4DED-81B5-7C3ADA1DDE27}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6E6E9127-557D-4739-B1DC-FE44AC816735}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5C42852C-D506-4AD0-B1AE-42F3DD1E6C9B}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DB88DE23-4E74-4DD7-A823-3D35DDF6F429}] => (Allow) C:\Users\Peter\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{0F46680C-39B8-40E8-9D78-437FB59383E9}] => (Allow) C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\xchat\xchat.exe] => Enabled:XChat IRC Client
==================== Restore Points =========================
21-04-2018 13:03:30 Restore Point Created by FRST
28-04-2018 11:01:18 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/28/2018 11:11:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0x2084
Čas spustenia chybnej aplikácie: 0x01d3ded0e4f10bd6
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: 23978733-4ac4-11e8-b387-001e8c60ef64
Error: (04/28/2018 11:11:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0xf3c
Čas spustenia chybnej aplikácie: 0x01d3ded0dcf1ec6b
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: 2397ae43-4ac4-11e8-b387-001e8c60ef64
Error: (04/28/2018 03:10:36 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8736
Error: (04/28/2018 03:10:36 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8736
Error: (04/28/2018 03:10:36 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (04/27/2018 10:21:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0x2074
Čas spustenia chybnej aplikácie: 0x01d3de00bd459757
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: fbba3cdf-49f3-11e8-b387-001e8c60ef64
Error: (04/27/2018 10:21:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0x207c
Čas spustenia chybnej aplikácie: 0x01d3de00bd517e39
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: fbba15cf-49f3-11e8-b387-001e8c60ef64
Error: (04/26/2018 10:04:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybovej aplikácie: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Názov chybového modulu: OneDriveSetup.exe, verzia: 18.25.204.9, časová značka: 0x5a9798dc
Kód výnimky: 0x40000015
Odstup chyby: 0x00086722
Identifikácia chybného procesu: 0xa80
Čas spustenia chybnej aplikácie: 0x01d3dd35381ca5b5
Cesta chybnej aplikácie: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Cesta chybného modulu: C:\Users\Peter\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
Identifikácia hlásenia: 76b4ffe1-4928-11e8-b387-001e8c60ef64
System errors:
=============
Error: (04/28/2018 05:41:46 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/28/2018 05:41:42 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (04/24/2018 10:16:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby ShellHWDetection bol dosiahnutý časový limit (120000 ms).
Error: (04/24/2018 10:16:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby lmhosts bol dosiahnutý časový limit (120000 ms).
Error: (04/23/2018 04:26:21 AM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (04/21/2018 07:24:59 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby ShellHWDetection bol dosiahnutý časový limit (120000 ms).
Error: (04/21/2018 03:56:59 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (04/21/2018 01:46:23 PM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Windows Defender:
===================================
Date: 2018-03-29 17:53:58.309
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{126F799B-869C-440B-9062-942759E2D4AA}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan
CodeIntegrity:
===================================
Date: 2017-06-02 05:57:47.906
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-06-02 05:57:47.906
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-06-02 05:57:47.906
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-27 14:23:26.429
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-27 14:23:26.427
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-27 14:23:26.415
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-20 08:33:09.048
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-05-20 08:33:09.031
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\ESET\ESET NOD32 Antivirus\Drivers\eelam\eelam.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
Percentage of memory in use: 52%
Total physical RAM: 4095.12 MB
Available physical RAM: 1932.24 MB
Total Virtual: 8188.4 MB
Available Virtual: 4888.63 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:195.31 GB) (Free:32.67 GB) NTFS ==>[drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 08CB08CB)
Partition 1: (Active) - (Size=195.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================