Nakažený NTB (odpojení od banky)
Napsal: 11 črc 2015 23:18
Dobrý den.
Dovoluji si Vás kontaktovat. Mám na ntb nejspíše nějakou havěť - dlouhodobě se mi choval podivně (dlouhé nabíhání jak po přihlášení, tak i při spuštění např. IE). No a vrcholem bylo vyrozumění z Komerční banky, že zablokovali můj certifikát a tedy i přístup do "mojebanka" z důvodu ohrožení na mém ntb.
- provedl jsem odstranění všech nedůležitých a často nechtěných aplikaci a programů
- vyčistil všechny možné pluginy, a další otravnosti.
- provedl čištění ccleanerem
- provedl jsem instalaci nového "placeného" Eset Endpoint Security a provedl hloubkový test (41 infekcí)
- no po několikátém testu už ESET hlásí OK, ale přeci jenom bych rád měl jistotu
proto prosím o Vaši pomoc a zhlédnutí - přikládám log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:11-07-2015
Ran by Clarrien (administrator) on CLARRIEN-PC on 12-07-2015 00:03:52
Running from C:\Users\Clarrien\Desktop
Loaded Profiles: Clarrien (Available Profiles: Clarrien & Pájinka & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Security\egui.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
() C:\Users\Clarrien\AppData\Local\Viber\Viber.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(forum.viry.cz) C:\Users\Clarrien\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6561384 2010-12-14] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [608112 2011-03-29] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Security\egui.exe [4124360 2014-09-24] (ESET)
HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2320752 2009-11-05] (Microsoft Corporation)
HKLM\...\Run: [itype] => C:\Program Files\Microsoft IntelliType Pro\itype.exe [2345848 2009-11-05] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487562 2010-08-20] (Creative Technology Ltd)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Print2PDF Print Monitor] => C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [220992 2011-10-04] (Software602)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\Run: [Viber] => C:\Users\Clarrien\AppData\Local\Viber\Viber.exe [80035536 2015-06-10] ()
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: E - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {1acec923-6ecb-11e1-bc86-bc77376b217c} - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {a994792b-6c41-11e3-b4b7-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {c8725bfa-4495-11e3-9091-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {c8725c0e-4495-11e3-9091-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {d2b16c33-cb5f-11e1-be1d-bc77376b217c} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {d2b16ce7-cb5f-11e1-be1d-bc77376b217c} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {e6ad675e-a297-11e0-ad89-bc77376b217c} - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {e6ad676b-a297-11e0-ad89-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {e6ad677c-a297-11e0-ad89-bc77376b217c} - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {f7a57293-fa3b-11e3-8320-bc77376b217c} - F:\Autorun.exe
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176904 2015-06-17] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155280 2015-06-17] (NVIDIA Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor technologie Intel(R) Turbo Boost 2.0.lnk [2012-02-20]
ShortcutTarget: Monitor technologie Intel(R) Turbo Boost 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type ... earchTerms}
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts= ... XX5WS0SJRV
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type ... earchTerms}
URLSearchHook: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {5AC01746-3F0D-41DE-BD67-39973EB94A32} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {239C5695-98CB-4979-9A31-6880330AB1A2} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 77376B217C}
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {239C5695-98CB-4979-9A31-6880330AB1A2} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {5AC01746-3F0D-41DE-BD67-39973EB94A32} URL =
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-11] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-11] (Oracle Corporation)
BHO-x32: qualitink -> {73ad5d47-66e5-4127-80ca-c0eedabafbcc} -> No File
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
Toolbar: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.)
Toolbar: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.10.111
Tcpip\..\Interfaces\{356E1E27-04B6-457F-93E3-0CC75551617B}: [DhcpNameServer] 192.168.10.111
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_191.dll [2015-07-11] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-11] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-11] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_191.dll [2015-07-11] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-17] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-17] (NVIDIA Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2011-11-24] (Software602 a.s.)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt [2011-05-21]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-02-26]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird
FF Extension: ESET Endpoint Security Extension - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird [2015-07-10]
FF HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-17]
CHR Extension: (Google Search) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-17]
CHR Extension: (Google Wallet) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-18]
CHR Extension: (Gmail) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-17]
CHR HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [bicnnkjibmphdeigoodpjlcklcnaobdj] - C:\Program Files (x86)\TornTV.com\torntv10.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [hfimjncgpflkpkhbnnblhblobjjjhjhd] - C:\Program Files (x86)\qualitink\hfimjncgpflkpkhbnnblhblobjjjhjhd.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - No Path Or update_url value
CHR HKLM-x32\...\Chrome\Extension: [ljkcijnbckdflhifmbnfnkjacokloacf] - C:\Program Files (x86)\qualitink\ljkcijnbckdflhifmbnfnkjacokloacf.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [mdipponmnbnnclmkmnnddnbecckhbjdj] - C:\Program Files (x86)\qualitink\mdipponmnbnnclmkmnnddnbecckhbjdj.crx [Not Found]
Opera:
=======
OPR Extension: (GoHD) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\bokijhalndhhhikpnaniimagniglonke [2014-09-19]
OPR Extension: (ejpepffjfmamnambagiibghpglaidiec) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\ejpepffjfmamnambagiibghpglaidiec [2015-04-02]
OPR Extension: (gomekmidlodglbbmalcneegieacbdmki) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-28]
OPR Extension: (new game) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\jlinpflaifheoeohbdffhfnnpghdnlel [2015-04-02]
OPR Extension: (Games for you and me) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\monpennifgclhopkmgdbcnaagkgdemch [2015-05-28]
OPR Extension: (nbkekaeindpfpcoldfckljplboolgkfm) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\nbkekaeindpfpcoldfckljplboolgkfm [2015-04-07]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [901184 2010-12-14] (Intel Corporation) [File not signed]
R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-12-14] (Intel Corporation) [File not signed]
R2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [974912 2010-12-14] (Intel Corporation) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-05-20] (Creative Technology Ltd) [File not signed]
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2557136 2015-02-26] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [201936 2015-02-26] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [232152 2015-05-20] (Dell Inc.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe [41672 2014-09-24] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe [1029704 2014-09-24] (ESET)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe [190152 2014-09-24] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-17] (NVIDIA Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-17] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [23312 2015-02-26] (Dell Computer Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [219696 2014-08-19] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [155896 2014-08-19] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [198096 2014-08-19] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [59064 2014-09-10] (ESET)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [299664 2015-06-17] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46768 2015-06-17] (NVIDIA Corporation)
S3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.)
S3 cpuz134; \??\C:\Users\Clarrien\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-11 23:41 - 2015-07-11 23:41 - 00000000 ____D C:\rsit
2015-07-11 23:41 - 2015-07-11 23:41 - 00000000 ____D C:\Program Files\trend micro
2015-07-11 23:39 - 2015-07-11 23:41 - 01222144 _____ C:\Users\Clarrien\Downloads\RSITx64.exe
2015-07-11 23:38 - 2015-07-12 00:04 - 00027830 _____ C:\Users\Clarrien\Desktop\FRST.txt
2015-07-11 23:38 - 2015-07-11 23:38 - 00000000 ____D C:\Users\Clarrien\AppData\Local\NVIDIA Corporation
2015-07-11 23:37 - 2015-07-12 00:03 - 00000000 ____D C:\FRST
2015-07-11 23:37 - 2015-07-11 23:37 - 00000000 ____D C:\Users\Clarrien\AppData\Local\NVIDIA
2015-07-11 23:34 - 2015-06-17 11:10 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-07-11 23:34 - 2015-06-17 11:10 - 01571696 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-07-11 23:34 - 2015-06-17 11:10 - 01320304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-07-11 23:34 - 2015-06-17 11:10 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-07-11 23:33 - 2015-07-11 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-07-11 23:32 - 2015-07-11 23:32 - 00000000 ____D C:\Windows\SysWOW64\NV
2015-07-11 23:32 - 2015-07-11 23:32 - 00000000 ____D C:\Windows\system32\NV
2015-07-11 23:32 - 2015-06-17 08:03 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-07-11 23:31 - 2015-07-11 23:31 - 00000000 ____D C:\Windows\LastGood
2015-07-11 23:29 - 2015-07-11 23:29 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-11 23:29 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 22947144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 17724600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 15866992 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 15224784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 13263056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 11831856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-07-11 23:29 - 2015-06-17 11:10 - 02997544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 02599752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00975176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00299664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvkflt.sys
2015-07-11 23:29 - 2015-06-17 11:10 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00061616 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00057520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00046768 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-07-11 23:29 - 2015-06-17 11:10 - 00031376 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2015-07-11 23:27 - 2015-07-11 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Clarrien\Desktop\FRSTLauncher.exe
2015-07-11 23:27 - 2015-07-11 23:27 - 00000000 ____D C:\NVIDIA
2015-07-11 23:26 - 2015-07-11 23:27 - 02130944 _____ (Farbar) C:\Users\Clarrien\Desktop\FRST64.exe
2015-07-11 23:16 - 2015-07-11 23:27 - 292264080 _____ (NVIDIA Corporation) C:\Users\Clarrien\Downloads\353.30-notebook-win8-win7-64bit-international-whql.exe
2015-07-11 16:52 - 2015-07-11 16:52 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Oracle
2015-07-11 16:51 - 2015-07-11 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-07-11 16:51 - 2015-07-11 16:50 - 00110688 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-07-11 16:50 - 2015-07-11 16:50 - 00000000 ____D C:\Program Files\Java
2015-07-11 16:47 - 2015-07-11 16:50 - 43189344 _____ (Oracle Corporation) C:\Users\Clarrien\Downloads\jre-8u45-windows-x64.exe
2015-07-11 16:40 - 2015-07-11 16:41 - 38624400 _____ (Adobe Systems Incorporated) C:\Users\Clarrien\Downloads\AdbeRdr11000_cs_CZ.exe
2015-07-11 14:09 - 2015-07-11 14:09 - 00000000 ____D C:\ProgramData\PCDr
2015-07-10 23:02 - 2015-07-10 23:02 - 00002731 _____ C:\Users\Public\Desktop\Skype.lnk
2015-07-10 23:02 - 2015-07-10 23:02 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-10 23:02 - 2015-07-10 23:02 - 00000000 ____D C:\Users\Clarrien\AppData\Local\Skype
2015-07-10 23:02 - 2015-07-10 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-07-10 23:01 - 2015-07-10 23:02 - 00000000 ____D C:\ProgramData\Skype
2015-07-10 22:59 - 2014-09-05 04:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-10 22:59 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-10 22:58 - 2014-12-11 19:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-07-10 22:40 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-07-10 22:40 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-07-10 22:40 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-07-10 22:40 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-07-10 22:40 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-07-10 22:40 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-10 22:40 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-07-10 22:40 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-10 22:40 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-07-10 22:40 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-07-10 22:40 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-10 22:40 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-10 22:40 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-07-10 22:40 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-10 22:40 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-07-10 22:31 - 2015-06-29 20:01 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-10 22:31 - 2015-06-29 19:59 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-10 22:31 - 2015-06-29 19:50 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-10 22:31 - 2015-06-27 00:06 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-10 22:31 - 2015-06-27 00:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-10 22:31 - 2015-06-27 00:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-10 22:31 - 2015-06-26 19:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-10 22:31 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-07-10 22:31 - 2015-04-27 21:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-07-10 22:31 - 2015-04-27 21:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-07-10 22:31 - 2015-04-27 21:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-07-10 22:31 - 2015-04-27 21:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-10 22:31 - 2015-03-14 05:21 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-07-10 22:31 - 2015-03-14 05:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-07-10 22:31 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-07-10 22:31 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-07-10 18:25 - 2015-07-10 18:25 - 00000000 ____D C:\ProgramData\WinZip
2015-07-10 17:42 - 2015-07-10 17:42 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\ESET
2015-07-10 17:42 - 2015-07-10 17:42 - 00000000 ____D C:\Users\Clarrien\AppData\Local\ESET
2015-07-10 17:40 - 2015-07-10 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-07-10 17:40 - 2015-07-10 17:40 - 00000000 ____D C:\ProgramData\ESET
2015-07-10 17:40 - 2015-07-10 17:40 - 00000000 ____D C:\Program Files\ESET
2015-07-10 16:42 - 2015-07-10 16:42 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-10 16:40 - 2015-07-11 23:34 - 00000887 _____ C:\Windows\setupact.log
2015-07-10 16:40 - 2015-07-10 16:40 - 00000000 ____D C:\ProgramData\Validity
2015-07-10 16:40 - 2015-07-10 16:40 - 00000000 _____ C:\Windows\setuperr.log
2015-07-10 16:25 - 2015-07-11 12:41 - 00000000 ____D C:\ProgramData\GoluKfid
2015-07-02 20:28 - 2015-07-02 20:28 - 00001168 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2015-07-02 20:26 - 2015-07-02 20:26 - 00093896 _____ C:\Users\Clarrien\Documents\cc_20150702_202621.reg
2015-07-02 19:47 - 2015-07-11 13:50 - 00000000 ____D C:\Windows\pss
2015-07-02 19:41 - 2015-07-02 19:44 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Clarrien\Downloads\avira_en_av_559575ec52e1e__ws1.exe
2015-07-02 19:30 - 2015-07-02 19:30 - 00464026 _____ C:\Users\Clarrien\Documents\cc_20150702_193024.reg
2015-07-02 19:26 - 2015-07-02 19:26 - 00002802 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-07-02 19:26 - 2015-07-02 19:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-02 19:26 - 2015-07-02 19:26 - 00000000 ____D C:\Program Files\CCleaner
2015-07-02 18:12 - 2015-07-02 18:12 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Roxio Log Files
2015-06-28 16:39 - 2015-06-28 16:39 - 00001789 _____ C:\Users\Clarrien\Desktop\googleearth – zástupce.lnk
2015-06-28 14:20 - 2015-07-11 14:09 - 00003484 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2015-06-28 14:20 - 2015-06-28 14:20 - 00004040 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2015-06-28 14:20 - 2015-06-28 14:20 - 00003230 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2015-06-28 14:19 - 2015-06-28 14:19 - 00000000 ____D C:\Program Files\Dell Support Center
2015-06-27 15:57 - 2015-06-27 15:57 - 00009448 _____ C:\Users\Clarrien\Desktop\KASA.xlsx
2015-06-27 14:41 - 2015-06-27 14:41 - 00000928 _____ C:\Users\Clarrien\Desktop\Stažené soubory – zástupce.lnk
2015-06-27 14:30 - 2015-06-27 14:43 - 712729020 _____ C:\Users\Clarrien\Downloads\nepĹ™Ătel pĹ™ed branami.avi
2015-06-26 10:40 - 2015-06-26 10:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Poruchy
2015-06-26 10:39 - 2015-06-26 10:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Smlouvy
2015-06-26 10:36 - 2015-06-26 10:37 - 00000000 ____D C:\Users\Clarrien\Desktop\Nabídky 2015
2015-06-26 10:35 - 2015-06-26 10:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Povrchy
2015-06-25 14:21 - 2010-04-08 00:38 - 00000693 _____ C:\Users\Clarrien\Downloads\gadget.xml
2015-06-25 14:09 - 2015-06-25 14:09 - 00001267 _____ C:\Users\Pájinka\Desktop\Display Stix 2.1.1.lnk
2015-06-25 14:09 - 2015-06-25 14:09 - 00001267 _____ C:\Users\Administrator\Desktop\Display Stix 2.1.1.lnk
2015-06-25 14:01 - 2015-07-11 16:32 - 18174128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-06-25 12:58 - 2015-06-25 13:06 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\7 Sticky Notes
2015-06-25 12:41 - 2012-10-13 22:20 - 00805376 ____N C:\Windows\SysWOW64\EditCtlsU.ocx
2015-06-25 12:41 - 2011-08-13 21:06 - 01031168 ____N C:\Windows\SysWOW64\ExLVwU.ocx
2015-06-25 12:41 - 2011-05-21 00:02 - 00604672 ____N C:\Windows\SysWOW64\ExTVwU.ocx
2015-06-25 12:41 - 2008-01-19 11:34 - 00554008 ____N (Microsoft Corporation) C:\Windows\SysWOW64\dao360.dll
2015-06-25 12:41 - 2004-03-09 14:45 - 00212240 ____N (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2015-06-25 12:41 - 1998-06-24 01:00 - 00198456 ____N (Microsoft Corporation) C:\Windows\SysWOW64\MCI32.OCX
2015-06-25 10:07 - 2006-08-16 12:22 - 00331438 _____ C:\Users\Clarrien\Downloads\Help.chm
2015-06-25 10:07 - 2006-08-16 12:22 - 00000157 _____ C:\Users\Clarrien\Downloads\index.url
2015-06-25 10:03 - 2015-06-25 14:38 - 00000233 _____ C:\Users\Clarrien\Desktop\MARUSHKA.url
2015-06-25 09:30 - 2015-06-25 10:10 - 00000282 _____ C:\Users\Clarrien\Desktop\Bus Nbk-Pdy.url
2015-06-24 15:08 - 2015-06-27 17:48 - 00000000 ____D C:\Users\Clarrien\Desktop\Potvrzenky - KAMAT
2015-06-24 15:08 - 2015-06-25 09:51 - 00000000 ____D C:\Users\Clarrien\Desktop\Potvrzenky - AZ
2015-06-24 12:54 - 2015-06-24 12:54 - 00001001 _____ C:\Users\Clarrien\Desktop\CELEX – zástupce.lnk
2015-06-23 17:08 - 2014-12-17 18:39 - 00000000 ____D C:\Users\Clarrien\Desktop\pdf2image
2015-06-23 17:02 - 2015-06-23 17:02 - 00001890 _____ C:\Users\Clarrien\Desktop\burningstudio – zástupce.lnk
2015-06-23 10:34 - 2015-06-23 10:34 - 02602496 _____ C:\Users\Clarrien\Desktop\cenik-elco-nymburk-5-2015-115.xls
2015-06-22 19:41 - 2015-06-26 11:00 - 00000000 ___RD C:\Users\Clarrien\Desktop\Práce
2015-06-22 19:08 - 2015-06-25 10:19 - 00001384 _____ C:\Users\Clarrien\Desktop\WRRT50 – zástupce.lnk
2015-06-22 17:45 - 2015-06-22 19:52 - 00000000 ____D C:\Users\Clarrien\Desktop\sešity
2015-06-22 17:44 - 2015-06-22 18:19 - 00170636 _____ C:\Users\Clarrien\Desktop\Objednávkový košík AZ (v150309).xlsm
2015-06-22 17:43 - 2015-07-01 07:16 - 00000000 ____D C:\Users\Clarrien\Desktop\Faktury, smlouvy, DL
2015-06-22 17:42 - 2015-07-02 18:23 - 00000000 ____D C:\Users\Clarrien\Desktop\Objednávky opravy
2015-06-22 17:42 - 2015-07-02 18:23 - 00000000 ____D C:\Users\Clarrien\Desktop\Objednávky materiálu
2015-06-22 17:42 - 2015-06-22 17:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Předávací protokoly 2015
2015-06-22 17:40 - 2015-06-23 16:42 - 00000000 ____D C:\Users\Clarrien\Desktop\ARCHIV STAVEB
2015-06-22 14:32 - 2015-06-22 14:32 - 04924246 _____ C:\Users\Clarrien\Desktop\sch. zn..bmp
2015-06-20 16:32 - 2015-07-02 14:13 - 00000000 ____D C:\Users\Clarrien\Documents\Soubory aplikace Outlook
2015-06-20 15:04 - 2015-06-13 12:08 - 933451776 _____ C:\Users\Clarrien\Desktop\Návrat blbýho a blbějšího.avi
2015-06-16 10:19 - 2015-07-01 06:56 - 00028265 _____ C:\Windows\system32\ScanResults.xml
2015-06-16 10:06 - 2015-07-01 06:48 - 00000464 _____ C:\Windows\system32\ScannerSettings
2015-06-14 09:21 - 2015-06-29 14:19 - 00000165 _____ C:\Windows\Reimage.ini
2015-06-12 16:20 - 2015-06-12 16:20 - 00000000 ____D C:\Program Files (x86)\Dell Update
2015-06-12 09:22 - 2015-07-02 17:37 - 00000000 ____D C:\Users\Clarrien\AppData\Everything
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-11 23:43 - 2014-09-19 15:43 - 00003442 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-6.job
2015-07-11 23:42 - 2011-06-21 19:34 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-11 23:38 - 2011-05-21 04:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-07-11 23:34 - 2011-05-21 04:02 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-11 23:34 - 2011-05-21 04:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-07-11 23:34 - 2011-05-21 04:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-07-11 23:33 - 2012-07-11 16:09 - 00000000 ____D C:\Temp
2015-07-11 23:32 - 2012-04-02 17:32 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-11 23:15 - 2015-04-02 16:15 - 00001308 _____ C:\Windows\Tasks\new_game_notification_service.job
2015-07-11 21:44 - 2014-09-19 15:44 - 00002762 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5_user.job
2015-07-11 21:44 - 2014-09-19 15:44 - 00002762 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00004468 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-11.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00003442 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-7.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00003442 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-4.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00002724 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-1.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00002082 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-2.job
2015-07-11 17:03 - 2009-07-14 06:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-11 17:03 - 2009-07-14 06:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-11 16:55 - 2014-08-31 16:57 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\ViberPC
2015-07-11 16:54 - 2012-04-02 17:32 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-11 16:54 - 2011-06-21 19:34 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-11 16:53 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-11 16:52 - 2009-07-14 07:10 - 01735506 _____ C:\Windows\WindowsUpdate.log
2015-07-11 16:32 - 2012-04-02 17:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-11 16:32 - 2011-06-23 20:29 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-11 16:30 - 2011-06-24 18:39 - 00000000 ____D C:\Users\Clarrien\AppData\Local\Adobe
2015-07-11 14:11 - 2011-07-03 16:04 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\PCDr
2015-07-11 14:03 - 2009-07-14 17:18 - 00681226 _____ C:\Windows\system32\perfh005.dat
2015-07-11 14:03 - 2009-07-14 17:18 - 00148048 _____ C:\Windows\system32\perfc005.dat
2015-07-11 14:03 - 2009-07-14 07:13 - 01621092 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-11 12:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-07-10 23:03 - 2011-06-21 18:56 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Skype
2015-07-10 22:46 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-10 22:43 - 2014-12-11 16:39 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-10 22:43 - 2014-05-07 03:00 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-10 22:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-07-10 22:38 - 2011-06-23 19:47 - 01596742 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-07-10 17:17 - 2011-07-13 14:19 - 00000000 ____D C:\Users\Pájinka\AppData\Local\CrashDumps
2015-07-10 17:14 - 2011-06-28 20:46 - 00110352 _____ C:\Users\Pájinka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-10 17:05 - 2013-01-12 15:12 - 00002261 _____ C:\Users\Pájinka\Desktop\Google Chrome.lnk
2015-07-10 16:30 - 2011-06-24 18:24 - 00000000 ____D C:\ProgramData\VirtualizedApplications
2015-07-10 16:30 - 2011-05-21 11:35 - 00000000 ____D C:\ProgramData\Temp
2015-07-03 11:22 - 2011-06-21 18:04 - 00001399 _____ C:\Users\Clarrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-03 11:04 - 2011-06-21 19:34 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-02 20:28 - 2012-11-04 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-07-02 20:28 - 2012-11-04 16:50 - 00000000 ____D C:\Program Files (x86)\Avira
2015-07-02 20:00 - 2011-11-16 18:25 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\ObviousIdea
2015-07-02 19:29 - 2012-06-13 17:15 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\TeamViewer
2015-07-02 19:29 - 2011-08-28 18:22 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\DAEMON Tools Lite
2015-07-02 19:28 - 2011-07-09 14:05 - 00000000 ____D C:\Users\Clarrien\AppData\Local\CrashDumps
2015-07-02 19:28 - 2011-05-21 13:28 - 00000000 ____D C:\Windows\Panther
2015-07-02 19:05 - 2011-05-21 11:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-07-02 19:01 - 2009-07-14 06:45 - 00410880 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-02 18:56 - 2011-05-21 13:13 - 00000000 ____D C:\dell
2015-07-02 18:41 - 2012-02-06 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2015-07-02 18:41 - 2011-05-21 11:37 - 00000000 ____D C:\Program Files (x86)\Creative
2015-07-02 18:40 - 2011-05-21 11:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-07-02 18:35 - 2011-06-21 18:01 - 00110352 _____ C:\Users\Clarrien\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-02 18:24 - 2011-05-21 11:50 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-07-02 18:21 - 2014-02-23 13:09 - 00000000 ____D C:\Windows\SysWOW64\FoxPDF
2015-07-02 18:20 - 2011-09-12 09:52 - 00000000 ____D C:\Program Files\Tracker Software
2015-07-02 18:19 - 2011-05-21 11:25 - 00000000 ____D C:\Program Files\Dell
2015-07-02 18:13 - 2011-06-21 18:04 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Roxio
2015-07-02 18:12 - 2011-05-21 11:41 - 00000000 ____D C:\Program Files (x86)\Roxio
2015-07-02 18:11 - 2014-09-19 15:42 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\systweak
2015-07-02 18:10 - 2013-03-27 17:39 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Seznam.cz
2015-07-02 18:09 - 2013-02-26 15:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-07-02 18:09 - 2011-07-10 14:37 - 00000000 ____D C:\Program Files (x86)\HP
2015-07-02 18:05 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-07-02 17:45 - 2011-05-21 11:18 - 00002437 _____ C:\freefallprotection.log
2015-07-02 14:13 - 2015-01-19 12:43 - 00015531 _____ C:\Users\Clarrien\Desktop\Potvrzenky materiálu.xlsx
2015-06-25 14:08 - 2014-09-19 15:35 - 00720896 _____ (Indigo Rose Corporation) C:\Windows\iun6002.exe
2015-06-25 10:16 - 2011-07-04 09:32 - 00000539 _____ C:\Users\Clarrien\Desktop\Mojebanka.url
2015-06-25 08:11 - 2012-10-21 21:37 - 00058663 _____ C:\Users\Clarrien\Desktop\STAVBY.xlsx
2015-06-24 13:04 - 2011-09-13 14:03 - 00000000 ____D C:\celektro
2015-06-23 13:30 - 2011-06-21 18:14 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-23 10:27 - 2014-05-10 11:04 - 00012898 _____ C:\Users\Clarrien\Desktop\Termíny odstávek.xlsx
2015-06-22 16:44 - 2014-12-24 12:02 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\mystartsearch
2015-06-22 16:43 - 2014-12-24 12:03 - 00000000 ____D C:\Program Files (x86)\SupTab
2015-06-22 12:17 - 2015-04-02 17:15 - 00000004 ____N C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-20 14:59 - 2014-08-31 16:57 - 00001010 _____ C:\Users\Clarrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2015-06-20 14:59 - 2014-08-31 16:57 - 00001002 _____ C:\Users\Clarrien\Desktop\Viber.lnk
2015-06-20 14:59 - 2014-08-31 16:57 - 00000000 ____D C:\Users\Clarrien\AppData\Local\Viber
2015-06-17 11:10 - 2011-05-21 13:33 - 12855416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 03395648 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 01099992 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00938752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00030966 _____ C:\Windows\system32\nvinfo.pb
2015-06-17 08:48 - 2011-02-18 19:19 - 06873232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 03492168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 01059472 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-06-17 08:48 - 2011-02-18 19:19 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 00074896 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2015-06-17 08:48 - 2011-02-18 12:19 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-06-15 09:56 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-14 08:09 - 2015-01-11 15:18 - 00000000 __SHD C:\Users\Pájinka\AppData\Local\EmieBrowserModeList
2015-06-14 08:09 - 2014-04-18 17:59 - 00000000 __SHD C:\Users\Pájinka\AppData\Local\EmieUserList
2015-06-14 08:09 - 2014-04-18 17:59 - 00000000 __SHD C:\Users\Pájinka\AppData\Local\EmieSiteList
2015-06-13 13:58 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-12 12:08 - 2011-05-21 11:25 - 00000000 ____D C:\ProgramData\Dell
2015-06-12 10:11 - 2014-11-15 11:54 - 00000000 __SHD C:\Users\Clarrien\AppData\Local\EmieBrowserModeList
2015-06-12 10:11 - 2014-04-11 08:28 - 00000000 __SHD C:\Users\Clarrien\AppData\Local\EmieUserList
2015-06-12 10:11 - 2014-04-11 08:28 - 00000000 __SHD C:\Users\Clarrien\AppData\Local\EmieSiteList
==================== Files in the root of some directories =======
2013-09-16 10:47 - 2013-09-16 10:47 - 1029383 _____ () C:\Users\Clarrien\AppData\Roaming\2433f433
2014-04-16 15:57 - 2014-08-06 08:33 - 0000066 _____ () C:\Users\Clarrien\AppData\Roaming\WB.CFG
2013-09-16 10:47 - 2013-09-16 10:47 - 1029446 _____ () C:\Users\Clarrien\AppData\Local\2433f433
2011-06-22 21:56 - 2013-06-14 17:02 - 0005120 _____ () C:\Users\Clarrien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-23 11:40 - 2011-10-23 11:40 - 0000096 _____ () C:\Users\Clarrien\AppData\Local\fusioncache.dat
2011-07-02 09:44 - 2011-07-02 09:44 - 0001567 _____ () C:\Users\Clarrien\AppData\Local\PDLSetup.20110702.094404.txt
2011-07-15 17:25 - 2011-07-15 17:25 - 0001544 _____ () C:\Users\Clarrien\AppData\Local\PDLSetup.20110715.172509.txt
2014-05-16 12:12 - 2014-05-16 12:12 - 0002125 _____ () C:\Users\Clarrien\AppData\Local\recently-used.xbel
2012-02-20 21:25 - 2012-02-20 21:25 - 0000017 _____ () C:\Users\Clarrien\AppData\Local\resmon.resmoncfg
2011-10-16 22:08 - 2014-04-13 20:11 - 0013432 _____ () C:\Users\Clarrien\AppData\Local\SRDownloader.err
2011-10-16 18:46 - 2014-04-13 20:11 - 0001120 _____ () C:\Users\Clarrien\AppData\Local\SRDownloader.nast
Some files in TEMP:
====================
C:\Users\Clarrien\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-1.job => C:\Program Files (x86)\GoHD\GoHD-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-11.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-2.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-4.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5_user.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-6.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-7.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\new_game_notification_service.job => C:\Program Files (x86)\new game\new_game_notification_service.exeǤ/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='new game' /appid='73143' /srcid='2913' /bic='0edca9529b3c5561889aeadd10f3b799' /verifier='9934a51cb16c4746fea34eb4c4b9d3e7' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Clarrien\Desktop" je 2630 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelTBRunOnce
wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Prosím o Vaše odborné zhlédnutí.
Děkuji Josef K.
Dovoluji si Vás kontaktovat. Mám na ntb nejspíše nějakou havěť - dlouhodobě se mi choval podivně (dlouhé nabíhání jak po přihlášení, tak i při spuštění např. IE). No a vrcholem bylo vyrozumění z Komerční banky, že zablokovali můj certifikát a tedy i přístup do "mojebanka" z důvodu ohrožení na mém ntb.
- provedl jsem odstranění všech nedůležitých a často nechtěných aplikaci a programů
- vyčistil všechny možné pluginy, a další otravnosti.
- provedl čištění ccleanerem
- provedl jsem instalaci nového "placeného" Eset Endpoint Security a provedl hloubkový test (41 infekcí)
- no po několikátém testu už ESET hlásí OK, ale přeci jenom bych rád měl jistotu
proto prosím o Vaši pomoc a zhlédnutí - přikládám log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:11-07-2015
Ran by Clarrien (administrator) on CLARRIEN-PC on 12-07-2015 00:03:52
Running from C:\Users\Clarrien\Desktop
Loaded Profiles: Clarrien (Available Profiles: Clarrien & Pájinka & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Security\egui.exe
(Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
() C:\Users\Clarrien\AppData\Local\Viber\Viber.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(forum.viry.cz) C:\Users\Clarrien\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6561384 2010-12-14] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [608112 2011-03-29] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Endpoint Security\egui.exe [4124360 2014-09-24] (ESET)
HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation)
HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2320752 2009-11-05] (Microsoft Corporation)
HKLM\...\Run: [itype] => C:\Program Files\Microsoft IntelliType Pro\itype.exe [2345848 2009-11-05] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487562 2010-08-20] (Creative Technology Ltd)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Print2PDF Print Monitor] => C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [220992 2011-10-04] (Software602)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\Run: [Viber] => C:\Users\Clarrien\AppData\Local\Viber\Viber.exe [80035536 2015-06-10] ()
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: E - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {1acec923-6ecb-11e1-bc86-bc77376b217c} - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {a994792b-6c41-11e3-b4b7-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {c8725bfa-4495-11e3-9091-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {c8725c0e-4495-11e3-9091-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {d2b16c33-cb5f-11e1-be1d-bc77376b217c} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {d2b16ce7-cb5f-11e1-be1d-bc77376b217c} - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {e6ad675e-a297-11e0-ad89-bc77376b217c} - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {e6ad676b-a297-11e0-ad89-bc77376b217c} - F:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {e6ad677c-a297-11e0-ad89-bc77376b217c} - E:\Autorun.exe
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\MountPoints2: {f7a57293-fa3b-11e3-8320-bc77376b217c} - F:\Autorun.exe
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176904 2015-06-17] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155280 2015-06-17] (NVIDIA Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor technologie Intel(R) Turbo Boost 2.0.lnk [2012-02-20]
ShortcutTarget: Monitor technologie Intel(R) Turbo Boost 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type ... earchTerms}
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts= ... XX5WS0SJRV
HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type ... earchTerms}
URLSearchHook: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {5AC01746-3F0D-41DE-BD67-39973EB94A32} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {239C5695-98CB-4979-9A31-6880330AB1A2} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 77376B217C}
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {239C5695-98CB-4979-9A31-6880330AB1A2} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {5AC01746-3F0D-41DE-BD67-39973EB94A32} URL =
SearchScopes: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-11] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-11] (Oracle Corporation)
BHO-x32: qualitink -> {73ad5d47-66e5-4127-80ca-c0eedabafbcc} -> No File
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
Toolbar: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.)
Toolbar: HKU\S-1-5-21-3420416177-1627521652-3136778559-1001 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.10.111
Tcpip\..\Interfaces\{356E1E27-04B6-457F-93E3-0CC75551617B}: [DhcpNameServer] 192.168.10.111
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_191.dll [2015-07-11] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-11] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-11] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_191.dll [2015-07-11] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-17] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-17] (NVIDIA Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2011-11-24] (Software602 a.s.)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt [2011-05-21]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-02-26]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird
FF Extension: ESET Endpoint Security Extension - C:\Program Files\ESET\ESET Endpoint Security\Mozilla Thunderbird [2015-07-10]
FF HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-17]
CHR Extension: (Google Search) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-17]
CHR Extension: (Google Wallet) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-18]
CHR Extension: (Gmail) - C:\Users\Clarrien\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-17]
CHR HKU\S-1-5-21-3420416177-1627521652-3136778559-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [bicnnkjibmphdeigoodpjlcklcnaobdj] - C:\Program Files (x86)\TornTV.com\torntv10.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [hfimjncgpflkpkhbnnblhblobjjjhjhd] - C:\Program Files (x86)\qualitink\hfimjncgpflkpkhbnnblhblobjjjhjhd.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - No Path Or update_url value
CHR HKLM-x32\...\Chrome\Extension: [ljkcijnbckdflhifmbnfnkjacokloacf] - C:\Program Files (x86)\qualitink\ljkcijnbckdflhifmbnfnkjacokloacf.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [mdipponmnbnnclmkmnnddnbecckhbjdj] - C:\Program Files (x86)\qualitink\mdipponmnbnnclmkmnnddnbecckhbjdj.crx [Not Found]
Opera:
=======
OPR Extension: (GoHD) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\bokijhalndhhhikpnaniimagniglonke [2014-09-19]
OPR Extension: (ejpepffjfmamnambagiibghpglaidiec) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\ejpepffjfmamnambagiibghpglaidiec [2015-04-02]
OPR Extension: (gomekmidlodglbbmalcneegieacbdmki) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-28]
OPR Extension: (new game) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\jlinpflaifheoeohbdffhfnnpghdnlel [2015-04-02]
OPR Extension: (Games for you and me) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\monpennifgclhopkmgdbcnaagkgdemch [2015-05-28]
OPR Extension: (nbkekaeindpfpcoldfckljplboolgkfm) - C:\Users\Clarrien\AppData\Roaming\Opera Software\Opera Stable\Extensions\nbkekaeindpfpcoldfckljplboolgkfm [2015-04-07]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [901184 2010-12-14] (Intel Corporation) [File not signed]
R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-12-14] (Intel Corporation) [File not signed]
R2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [974912 2010-12-14] (Intel Corporation) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-05-20] (Creative Technology Ltd) [File not signed]
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2557136 2015-02-26] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [201936 2015-02-26] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [232152 2015-05-20] (Dell Inc.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Security\EHttpSrv.exe [41672 2014-09-24] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Security\x86\ekrn.exe [1029704 2014-09-24] (ESET)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Security\EShaSrv.exe [190152 2014-09-24] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-17] (NVIDIA Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-17] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [23312 2015-02-26] (Dell Computer Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [219696 2014-08-19] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [155896 2014-08-19] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [198096 2014-08-19] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [59064 2014-09-10] (ESET)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [299664 2015-06-17] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46768 2015-06-17] (NVIDIA Corporation)
S3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.)
S3 cpuz134; \??\C:\Users\Clarrien\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-11 23:41 - 2015-07-11 23:41 - 00000000 ____D C:\rsit
2015-07-11 23:41 - 2015-07-11 23:41 - 00000000 ____D C:\Program Files\trend micro
2015-07-11 23:39 - 2015-07-11 23:41 - 01222144 _____ C:\Users\Clarrien\Downloads\RSITx64.exe
2015-07-11 23:38 - 2015-07-12 00:04 - 00027830 _____ C:\Users\Clarrien\Desktop\FRST.txt
2015-07-11 23:38 - 2015-07-11 23:38 - 00000000 ____D C:\Users\Clarrien\AppData\Local\NVIDIA Corporation
2015-07-11 23:37 - 2015-07-12 00:03 - 00000000 ____D C:\FRST
2015-07-11 23:37 - 2015-07-11 23:37 - 00000000 ____D C:\Users\Clarrien\AppData\Local\NVIDIA
2015-07-11 23:34 - 2015-06-17 11:10 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-07-11 23:34 - 2015-06-17 11:10 - 01571696 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-07-11 23:34 - 2015-06-17 11:10 - 01320304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-07-11 23:34 - 2015-06-17 11:10 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-07-11 23:33 - 2015-07-11 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-07-11 23:32 - 2015-07-11 23:32 - 00000000 ____D C:\Windows\SysWOW64\NV
2015-07-11 23:32 - 2015-07-11 23:32 - 00000000 ____D C:\Windows\system32\NV
2015-07-11 23:32 - 2015-06-17 08:03 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-07-11 23:31 - 2015-07-11 23:31 - 00000000 ____D C:\Windows\LastGood
2015-07-11 23:29 - 2015-07-11 23:29 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-11 23:29 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 22947144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 17724600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 15866992 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 15224784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 13263056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 11831856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-07-11 23:29 - 2015-06-17 11:10 - 02997544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 02599752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00975176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00299664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvkflt.sys
2015-07-11 23:29 - 2015-06-17 11:10 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00061616 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00057520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-07-11 23:29 - 2015-06-17 11:10 - 00046768 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-07-11 23:29 - 2015-06-17 11:10 - 00031376 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2015-07-11 23:27 - 2015-07-11 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Clarrien\Desktop\FRSTLauncher.exe
2015-07-11 23:27 - 2015-07-11 23:27 - 00000000 ____D C:\NVIDIA
2015-07-11 23:26 - 2015-07-11 23:27 - 02130944 _____ (Farbar) C:\Users\Clarrien\Desktop\FRST64.exe
2015-07-11 23:16 - 2015-07-11 23:27 - 292264080 _____ (NVIDIA Corporation) C:\Users\Clarrien\Downloads\353.30-notebook-win8-win7-64bit-international-whql.exe
2015-07-11 16:52 - 2015-07-11 16:52 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Oracle
2015-07-11 16:51 - 2015-07-11 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-07-11 16:51 - 2015-07-11 16:50 - 00110688 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-07-11 16:50 - 2015-07-11 16:50 - 00000000 ____D C:\Program Files\Java
2015-07-11 16:47 - 2015-07-11 16:50 - 43189344 _____ (Oracle Corporation) C:\Users\Clarrien\Downloads\jre-8u45-windows-x64.exe
2015-07-11 16:40 - 2015-07-11 16:41 - 38624400 _____ (Adobe Systems Incorporated) C:\Users\Clarrien\Downloads\AdbeRdr11000_cs_CZ.exe
2015-07-11 14:09 - 2015-07-11 14:09 - 00000000 ____D C:\ProgramData\PCDr
2015-07-10 23:02 - 2015-07-10 23:02 - 00002731 _____ C:\Users\Public\Desktop\Skype.lnk
2015-07-10 23:02 - 2015-07-10 23:02 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-10 23:02 - 2015-07-10 23:02 - 00000000 ____D C:\Users\Clarrien\AppData\Local\Skype
2015-07-10 23:02 - 2015-07-10 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-07-10 23:01 - 2015-07-10 23:02 - 00000000 ____D C:\ProgramData\Skype
2015-07-10 22:59 - 2014-09-05 04:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-10 22:59 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-10 22:58 - 2014-12-11 19:47 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-07-10 22:40 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-07-10 22:40 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-07-10 22:40 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-07-10 22:40 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-07-10 22:40 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-07-10 22:40 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-10 22:40 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-07-10 22:40 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-10 22:40 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2015-07-10 22:40 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2015-07-10 22:40 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-10 22:40 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-10 22:40 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-07-10 22:40 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-10 22:40 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-07-10 22:31 - 2015-06-29 20:01 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-10 22:31 - 2015-06-29 19:59 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-10 22:31 - 2015-06-29 19:59 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-10 22:31 - 2015-06-29 19:50 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-10 22:31 - 2015-06-27 00:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-10 22:31 - 2015-06-27 00:06 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-10 22:31 - 2015-06-27 00:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-10 22:31 - 2015-06-27 00:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-10 22:31 - 2015-06-26 19:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-10 22:31 - 2015-06-26 19:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-10 22:31 - 2015-05-09 20:26 - 00493504 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-07-10 22:31 - 2015-04-27 21:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-07-10 22:31 - 2015-04-27 21:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-07-10 22:31 - 2015-04-27 21:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-07-10 22:31 - 2015-04-27 21:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-07-10 22:31 - 2015-04-27 21:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-10 22:31 - 2015-03-14 05:21 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-07-10 22:31 - 2015-03-14 05:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-07-10 22:31 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-07-10 22:31 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-07-10 18:25 - 2015-07-10 18:25 - 00000000 ____D C:\ProgramData\WinZip
2015-07-10 17:42 - 2015-07-10 17:42 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\ESET
2015-07-10 17:42 - 2015-07-10 17:42 - 00000000 ____D C:\Users\Clarrien\AppData\Local\ESET
2015-07-10 17:40 - 2015-07-10 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-07-10 17:40 - 2015-07-10 17:40 - 00000000 ____D C:\ProgramData\ESET
2015-07-10 17:40 - 2015-07-10 17:40 - 00000000 ____D C:\Program Files\ESET
2015-07-10 16:42 - 2015-07-10 16:42 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-10 16:40 - 2015-07-11 23:34 - 00000887 _____ C:\Windows\setupact.log
2015-07-10 16:40 - 2015-07-10 16:40 - 00000000 ____D C:\ProgramData\Validity
2015-07-10 16:40 - 2015-07-10 16:40 - 00000000 _____ C:\Windows\setuperr.log
2015-07-10 16:25 - 2015-07-11 12:41 - 00000000 ____D C:\ProgramData\GoluKfid
2015-07-02 20:28 - 2015-07-02 20:28 - 00001168 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2015-07-02 20:26 - 2015-07-02 20:26 - 00093896 _____ C:\Users\Clarrien\Documents\cc_20150702_202621.reg
2015-07-02 19:47 - 2015-07-11 13:50 - 00000000 ____D C:\Windows\pss
2015-07-02 19:41 - 2015-07-02 19:44 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Clarrien\Downloads\avira_en_av_559575ec52e1e__ws1.exe
2015-07-02 19:30 - 2015-07-02 19:30 - 00464026 _____ C:\Users\Clarrien\Documents\cc_20150702_193024.reg
2015-07-02 19:26 - 2015-07-02 19:26 - 00002802 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-07-02 19:26 - 2015-07-02 19:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-02 19:26 - 2015-07-02 19:26 - 00000000 ____D C:\Program Files\CCleaner
2015-07-02 18:12 - 2015-07-02 18:12 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Roxio Log Files
2015-06-28 16:39 - 2015-06-28 16:39 - 00001789 _____ C:\Users\Clarrien\Desktop\googleearth – zástupce.lnk
2015-06-28 14:20 - 2015-07-11 14:09 - 00003484 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2015-06-28 14:20 - 2015-06-28 14:20 - 00004040 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2015-06-28 14:20 - 2015-06-28 14:20 - 00003230 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2015-06-28 14:19 - 2015-06-28 14:19 - 00000000 ____D C:\Program Files\Dell Support Center
2015-06-27 15:57 - 2015-06-27 15:57 - 00009448 _____ C:\Users\Clarrien\Desktop\KASA.xlsx
2015-06-27 14:41 - 2015-06-27 14:41 - 00000928 _____ C:\Users\Clarrien\Desktop\Stažené soubory – zástupce.lnk
2015-06-27 14:30 - 2015-06-27 14:43 - 712729020 _____ C:\Users\Clarrien\Downloads\nepĹ™Ătel pĹ™ed branami.avi
2015-06-26 10:40 - 2015-06-26 10:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Poruchy
2015-06-26 10:39 - 2015-06-26 10:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Smlouvy
2015-06-26 10:36 - 2015-06-26 10:37 - 00000000 ____D C:\Users\Clarrien\Desktop\Nabídky 2015
2015-06-26 10:35 - 2015-06-26 10:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Povrchy
2015-06-25 14:21 - 2010-04-08 00:38 - 00000693 _____ C:\Users\Clarrien\Downloads\gadget.xml
2015-06-25 14:09 - 2015-06-25 14:09 - 00001267 _____ C:\Users\Pájinka\Desktop\Display Stix 2.1.1.lnk
2015-06-25 14:09 - 2015-06-25 14:09 - 00001267 _____ C:\Users\Administrator\Desktop\Display Stix 2.1.1.lnk
2015-06-25 14:01 - 2015-07-11 16:32 - 18174128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-06-25 12:58 - 2015-06-25 13:06 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\7 Sticky Notes
2015-06-25 12:41 - 2012-10-13 22:20 - 00805376 ____N C:\Windows\SysWOW64\EditCtlsU.ocx
2015-06-25 12:41 - 2011-08-13 21:06 - 01031168 ____N C:\Windows\SysWOW64\ExLVwU.ocx
2015-06-25 12:41 - 2011-05-21 00:02 - 00604672 ____N C:\Windows\SysWOW64\ExTVwU.ocx
2015-06-25 12:41 - 2008-01-19 11:34 - 00554008 ____N (Microsoft Corporation) C:\Windows\SysWOW64\dao360.dll
2015-06-25 12:41 - 2004-03-09 14:45 - 00212240 ____N (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2015-06-25 12:41 - 1998-06-24 01:00 - 00198456 ____N (Microsoft Corporation) C:\Windows\SysWOW64\MCI32.OCX
2015-06-25 10:07 - 2006-08-16 12:22 - 00331438 _____ C:\Users\Clarrien\Downloads\Help.chm
2015-06-25 10:07 - 2006-08-16 12:22 - 00000157 _____ C:\Users\Clarrien\Downloads\index.url
2015-06-25 10:03 - 2015-06-25 14:38 - 00000233 _____ C:\Users\Clarrien\Desktop\MARUSHKA.url
2015-06-25 09:30 - 2015-06-25 10:10 - 00000282 _____ C:\Users\Clarrien\Desktop\Bus Nbk-Pdy.url
2015-06-24 15:08 - 2015-06-27 17:48 - 00000000 ____D C:\Users\Clarrien\Desktop\Potvrzenky - KAMAT
2015-06-24 15:08 - 2015-06-25 09:51 - 00000000 ____D C:\Users\Clarrien\Desktop\Potvrzenky - AZ
2015-06-24 12:54 - 2015-06-24 12:54 - 00001001 _____ C:\Users\Clarrien\Desktop\CELEX – zástupce.lnk
2015-06-23 17:08 - 2014-12-17 18:39 - 00000000 ____D C:\Users\Clarrien\Desktop\pdf2image
2015-06-23 17:02 - 2015-06-23 17:02 - 00001890 _____ C:\Users\Clarrien\Desktop\burningstudio – zástupce.lnk
2015-06-23 10:34 - 2015-06-23 10:34 - 02602496 _____ C:\Users\Clarrien\Desktop\cenik-elco-nymburk-5-2015-115.xls
2015-06-22 19:41 - 2015-06-26 11:00 - 00000000 ___RD C:\Users\Clarrien\Desktop\Práce
2015-06-22 19:08 - 2015-06-25 10:19 - 00001384 _____ C:\Users\Clarrien\Desktop\WRRT50 – zástupce.lnk
2015-06-22 17:45 - 2015-06-22 19:52 - 00000000 ____D C:\Users\Clarrien\Desktop\sešity
2015-06-22 17:44 - 2015-06-22 18:19 - 00170636 _____ C:\Users\Clarrien\Desktop\Objednávkový košík AZ (v150309).xlsm
2015-06-22 17:43 - 2015-07-01 07:16 - 00000000 ____D C:\Users\Clarrien\Desktop\Faktury, smlouvy, DL
2015-06-22 17:42 - 2015-07-02 18:23 - 00000000 ____D C:\Users\Clarrien\Desktop\Objednávky opravy
2015-06-22 17:42 - 2015-07-02 18:23 - 00000000 ____D C:\Users\Clarrien\Desktop\Objednávky materiálu
2015-06-22 17:42 - 2015-06-22 17:42 - 00000000 ____D C:\Users\Clarrien\Desktop\Předávací protokoly 2015
2015-06-22 17:40 - 2015-06-23 16:42 - 00000000 ____D C:\Users\Clarrien\Desktop\ARCHIV STAVEB
2015-06-22 14:32 - 2015-06-22 14:32 - 04924246 _____ C:\Users\Clarrien\Desktop\sch. zn..bmp
2015-06-20 16:32 - 2015-07-02 14:13 - 00000000 ____D C:\Users\Clarrien\Documents\Soubory aplikace Outlook
2015-06-20 15:04 - 2015-06-13 12:08 - 933451776 _____ C:\Users\Clarrien\Desktop\Návrat blbýho a blbějšího.avi
2015-06-16 10:19 - 2015-07-01 06:56 - 00028265 _____ C:\Windows\system32\ScanResults.xml
2015-06-16 10:06 - 2015-07-01 06:48 - 00000464 _____ C:\Windows\system32\ScannerSettings
2015-06-14 09:21 - 2015-06-29 14:19 - 00000165 _____ C:\Windows\Reimage.ini
2015-06-12 16:20 - 2015-06-12 16:20 - 00000000 ____D C:\Program Files (x86)\Dell Update
2015-06-12 09:22 - 2015-07-02 17:37 - 00000000 ____D C:\Users\Clarrien\AppData\Everything
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-11 23:43 - 2014-09-19 15:43 - 00003442 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-6.job
2015-07-11 23:42 - 2011-06-21 19:34 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-11 23:38 - 2011-05-21 04:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-07-11 23:34 - 2011-05-21 04:02 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-11 23:34 - 2011-05-21 04:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-07-11 23:34 - 2011-05-21 04:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-07-11 23:33 - 2012-07-11 16:09 - 00000000 ____D C:\Temp
2015-07-11 23:32 - 2012-04-02 17:32 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-11 23:15 - 2015-04-02 16:15 - 00001308 _____ C:\Windows\Tasks\new_game_notification_service.job
2015-07-11 21:44 - 2014-09-19 15:44 - 00002762 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5_user.job
2015-07-11 21:44 - 2014-09-19 15:44 - 00002762 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00004468 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-11.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00003442 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-7.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00003442 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-4.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00002724 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-1.job
2015-07-11 21:43 - 2014-09-19 15:43 - 00002082 _____ C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-2.job
2015-07-11 17:03 - 2009-07-14 06:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-11 17:03 - 2009-07-14 06:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-11 16:55 - 2014-08-31 16:57 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\ViberPC
2015-07-11 16:54 - 2012-04-02 17:32 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-11 16:54 - 2011-06-21 19:34 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-11 16:53 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-11 16:52 - 2009-07-14 07:10 - 01735506 _____ C:\Windows\WindowsUpdate.log
2015-07-11 16:32 - 2012-04-02 17:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-11 16:32 - 2011-06-23 20:29 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-11 16:30 - 2011-06-24 18:39 - 00000000 ____D C:\Users\Clarrien\AppData\Local\Adobe
2015-07-11 14:11 - 2011-07-03 16:04 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\PCDr
2015-07-11 14:03 - 2009-07-14 17:18 - 00681226 _____ C:\Windows\system32\perfh005.dat
2015-07-11 14:03 - 2009-07-14 17:18 - 00148048 _____ C:\Windows\system32\perfc005.dat
2015-07-11 14:03 - 2009-07-14 07:13 - 01621092 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-11 12:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-07-10 23:03 - 2011-06-21 18:56 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Skype
2015-07-10 22:46 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-10 22:43 - 2014-12-11 16:39 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-10 22:43 - 2014-05-07 03:00 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-10 22:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-07-10 22:38 - 2011-06-23 19:47 - 01596742 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-07-10 17:17 - 2011-07-13 14:19 - 00000000 ____D C:\Users\Pájinka\AppData\Local\CrashDumps
2015-07-10 17:14 - 2011-06-28 20:46 - 00110352 _____ C:\Users\Pájinka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-10 17:05 - 2013-01-12 15:12 - 00002261 _____ C:\Users\Pájinka\Desktop\Google Chrome.lnk
2015-07-10 16:30 - 2011-06-24 18:24 - 00000000 ____D C:\ProgramData\VirtualizedApplications
2015-07-10 16:30 - 2011-05-21 11:35 - 00000000 ____D C:\ProgramData\Temp
2015-07-03 11:22 - 2011-06-21 18:04 - 00001399 _____ C:\Users\Clarrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-03 11:04 - 2011-06-21 19:34 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-02 20:28 - 2012-11-04 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-07-02 20:28 - 2012-11-04 16:50 - 00000000 ____D C:\Program Files (x86)\Avira
2015-07-02 20:00 - 2011-11-16 18:25 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\ObviousIdea
2015-07-02 19:29 - 2012-06-13 17:15 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\TeamViewer
2015-07-02 19:29 - 2011-08-28 18:22 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\DAEMON Tools Lite
2015-07-02 19:28 - 2011-07-09 14:05 - 00000000 ____D C:\Users\Clarrien\AppData\Local\CrashDumps
2015-07-02 19:28 - 2011-05-21 13:28 - 00000000 ____D C:\Windows\Panther
2015-07-02 19:05 - 2011-05-21 11:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-07-02 19:01 - 2009-07-14 06:45 - 00410880 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-02 18:56 - 2011-05-21 13:13 - 00000000 ____D C:\dell
2015-07-02 18:41 - 2012-02-06 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2015-07-02 18:41 - 2011-05-21 11:37 - 00000000 ____D C:\Program Files (x86)\Creative
2015-07-02 18:40 - 2011-05-21 11:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-07-02 18:35 - 2011-06-21 18:01 - 00110352 _____ C:\Users\Clarrien\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-02 18:24 - 2011-05-21 11:50 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-07-02 18:21 - 2014-02-23 13:09 - 00000000 ____D C:\Windows\SysWOW64\FoxPDF
2015-07-02 18:20 - 2011-09-12 09:52 - 00000000 ____D C:\Program Files\Tracker Software
2015-07-02 18:19 - 2011-05-21 11:25 - 00000000 ____D C:\Program Files\Dell
2015-07-02 18:13 - 2011-06-21 18:04 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Roxio
2015-07-02 18:12 - 2011-05-21 11:41 - 00000000 ____D C:\Program Files (x86)\Roxio
2015-07-02 18:11 - 2014-09-19 15:42 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\systweak
2015-07-02 18:10 - 2013-03-27 17:39 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\Seznam.cz
2015-07-02 18:09 - 2013-02-26 15:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-07-02 18:09 - 2011-07-10 14:37 - 00000000 ____D C:\Program Files (x86)\HP
2015-07-02 18:05 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-07-02 17:45 - 2011-05-21 11:18 - 00002437 _____ C:\freefallprotection.log
2015-07-02 14:13 - 2015-01-19 12:43 - 00015531 _____ C:\Users\Clarrien\Desktop\Potvrzenky materiálu.xlsx
2015-06-25 14:08 - 2014-09-19 15:35 - 00720896 _____ (Indigo Rose Corporation) C:\Windows\iun6002.exe
2015-06-25 10:16 - 2011-07-04 09:32 - 00000539 _____ C:\Users\Clarrien\Desktop\Mojebanka.url
2015-06-25 08:11 - 2012-10-21 21:37 - 00058663 _____ C:\Users\Clarrien\Desktop\STAVBY.xlsx
2015-06-24 13:04 - 2011-09-13 14:03 - 00000000 ____D C:\celektro
2015-06-23 13:30 - 2011-06-21 18:14 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-23 10:27 - 2014-05-10 11:04 - 00012898 _____ C:\Users\Clarrien\Desktop\Termíny odstávek.xlsx
2015-06-22 16:44 - 2014-12-24 12:02 - 00000000 ____D C:\Users\Clarrien\AppData\Roaming\mystartsearch
2015-06-22 16:43 - 2014-12-24 12:03 - 00000000 ____D C:\Program Files (x86)\SupTab
2015-06-22 12:17 - 2015-04-02 17:15 - 00000004 ____N C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-20 14:59 - 2014-08-31 16:57 - 00001010 _____ C:\Users\Clarrien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2015-06-20 14:59 - 2014-08-31 16:57 - 00001002 _____ C:\Users\Clarrien\Desktop\Viber.lnk
2015-06-20 14:59 - 2014-08-31 16:57 - 00000000 ____D C:\Users\Clarrien\AppData\Local\Viber
2015-06-17 11:10 - 2011-05-21 13:33 - 12855416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 03395648 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 01099992 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00938752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-06-17 11:10 - 2011-05-21 13:33 - 00030966 _____ C:\Windows\system32\nvinfo.pb
2015-06-17 08:48 - 2011-02-18 19:19 - 06873232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 03492168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 01059472 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-06-17 08:48 - 2011-02-18 19:19 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-06-17 08:48 - 2011-02-18 19:19 - 00074896 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2015-06-17 08:48 - 2011-02-18 12:19 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-06-15 09:56 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-14 08:09 - 2015-01-11 15:18 - 00000000 __SHD C:\Users\Pájinka\AppData\Local\EmieBrowserModeList
2015-06-14 08:09 - 2014-04-18 17:59 - 00000000 __SHD C:\Users\Pájinka\AppData\Local\EmieUserList
2015-06-14 08:09 - 2014-04-18 17:59 - 00000000 __SHD C:\Users\Pájinka\AppData\Local\EmieSiteList
2015-06-13 13:58 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-12 12:08 - 2011-05-21 11:25 - 00000000 ____D C:\ProgramData\Dell
2015-06-12 10:11 - 2014-11-15 11:54 - 00000000 __SHD C:\Users\Clarrien\AppData\Local\EmieBrowserModeList
2015-06-12 10:11 - 2014-04-11 08:28 - 00000000 __SHD C:\Users\Clarrien\AppData\Local\EmieUserList
2015-06-12 10:11 - 2014-04-11 08:28 - 00000000 __SHD C:\Users\Clarrien\AppData\Local\EmieSiteList
==================== Files in the root of some directories =======
2013-09-16 10:47 - 2013-09-16 10:47 - 1029383 _____ () C:\Users\Clarrien\AppData\Roaming\2433f433
2014-04-16 15:57 - 2014-08-06 08:33 - 0000066 _____ () C:\Users\Clarrien\AppData\Roaming\WB.CFG
2013-09-16 10:47 - 2013-09-16 10:47 - 1029446 _____ () C:\Users\Clarrien\AppData\Local\2433f433
2011-06-22 21:56 - 2013-06-14 17:02 - 0005120 _____ () C:\Users\Clarrien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-10-23 11:40 - 2011-10-23 11:40 - 0000096 _____ () C:\Users\Clarrien\AppData\Local\fusioncache.dat
2011-07-02 09:44 - 2011-07-02 09:44 - 0001567 _____ () C:\Users\Clarrien\AppData\Local\PDLSetup.20110702.094404.txt
2011-07-15 17:25 - 2011-07-15 17:25 - 0001544 _____ () C:\Users\Clarrien\AppData\Local\PDLSetup.20110715.172509.txt
2014-05-16 12:12 - 2014-05-16 12:12 - 0002125 _____ () C:\Users\Clarrien\AppData\Local\recently-used.xbel
2012-02-20 21:25 - 2012-02-20 21:25 - 0000017 _____ () C:\Users\Clarrien\AppData\Local\resmon.resmoncfg
2011-10-16 22:08 - 2014-04-13 20:11 - 0013432 _____ () C:\Users\Clarrien\AppData\Local\SRDownloader.err
2011-10-16 18:46 - 2014-04-13 20:11 - 0001120 _____ () C:\Users\Clarrien\AppData\Local\SRDownloader.nast
Some files in TEMP:
====================
C:\Users\Clarrien\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-1.job => C:\Program Files (x86)\GoHD\GoHD-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-11.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-2.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-4.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5_user.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-6.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\100545cf-1dd6-406b-bbf5-a8c687ac7eff-7.job => C:\Program Files (x86)\GoHD\100545cf-1dd6-406b-bbf5-a8c687ac7eff-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\new_game_notification_service.job => C:\Program Files (x86)\new game\new_game_notification_service.exeǤ/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='new game' /appid='73143' /srcid='2913' /bic='0edca9529b3c5561889aeadd10f3b799' /verifier='9934a51cb16c4746fea34eb4c4b9d3e7' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Clarrien\Desktop" je 2630 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelTBRunOnce
wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Prosím o Vaše odborné zhlédnutí.
Děkuji Josef K.