Stránka 1 z 1

Prosím kontrolu RSIT logu

Napsal: 16 zář 2016 09:47
od D.Dixon
Zdravím,
prišiel som k rodičom a súrodencom domov a vidím, že mali veľmi pomalý PC. Tak som povymazoval programy, ktoré som považoval za nepotrebné, prečistil PC trocha pomocou CCleaner a spustil antivírak. No bol by som rád ak by bol PC prečistený na profesionálnej úrovni a tú ja nedám :)
Preto vám tu dávam RSIT log a žiadam o jeho prekontrolovanie, dík


Logfile of random's system information tool 1.10 (written by random/random)
Run by Dvorščák at 2016-09-16 10:38:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 327 GB (72%) free of 451 GB
Total RAM: 6039 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:38:47, on 16. 9. 2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18450)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\FreePro Manager\service.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\windows\jmesoft\hotkey.exe
C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.1\Lightshot.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\Dvorščák.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8118
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [jmekey] C:\windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKLM\..\Run: [Fastboot] C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
O4 - HKLM\..\Run: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Lightshot] C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX130"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [service.exe] C:\Program Files (x86)\FreePro Manager\service.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: FastbootService - 1206 Lab - C:\Program Files (x86)\Lenovo\Rapidboot\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12395 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
winlogon.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\windows\System32\igfxtray.exe"
"C:\windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE"
"C:\windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Lenovo\Rapidboot\FBService.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
C:\Windows\jmesoft\Service.exe
"C:\windows\System32\spool\drivers\x64\3\E_IATIHJE.EXE" /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX130"
"C:\Program Files (x86)\FreePro Manager\service.exe"
"C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\windows\jmesoft\hotkey.exe"
"C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe"
"C:\Windows\jmesoft\JME_LOAD.exe"
"C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.1\Lightshot.exe"
C:\windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\windows\SysWOW64\PnkBstrA.exe
C:\windows\SysWOW64\PnkBstrB.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
WLIDSvcM.exe 3380
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\windows\system32\wuauclt.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe18_ Global\UsGthrCtrlFltPipeMssGthrPipe18 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Dvorščák\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player PPAPI Notifier.job - C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_242_pepper.exe -check pepperplugin
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\update-S-1-5-21-2898392049-1419488004-4050302534-1001.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
C:\windows\tasks\update-sys.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-26 553024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-08 901600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-26 214080]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-08 678656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-12-21 170264]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-12-21 398104]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-12-21 440600]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-09-05 12850792]
"UpdatePRCShortCut"=C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [2009-05-14 222504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"EPLTarget\P0000000000000000"=C:\windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE [2015-04-06 283232]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2015-03-31 5585136]
"service.exe"=C:\Program Files (x86)\FreePro Manager\service.exe [2016-07-10 1035776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2015-03-31 5585136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVT]
C:\Program Files\Lenovo\LVT\LJYZ.exe [2011-11-24 886112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-08-17 29538432]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-05-20 284440]
"jmekey"=C:\windows\jmesoft\hotkey.exe [2011-06-08 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-03-16 28672]
"Fastboot"=C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe [2011-12-16 1260128]
"UpdatePRCShortCut"=C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [2009-05-14 222504]
"Lenovo Registration"=C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [2011-07-14 4351712]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-08-30 979328]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2016-08-29 1009632]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-03-23 7139256]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-05-20 595992]
"Lightshot"=C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [2016-07-11 225944]

C:\Users\Dvorščák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-12-15 430080]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\windows\NOTEPAD.EXE %1

======List of files/folders created in the last 1 month======

2016-09-16 10:38:14 ----D---- C:\rsit
2016-09-16 10:38:14 ----D---- C:\Program Files\trend micro
2016-09-14 22:11:15 ----A---- C:\windows\system32\drivers\srv2.sys
2016-09-14 22:11:15 ----A---- C:\windows\system32\drivers\srv.sys
2016-09-14 22:11:14 ----A---- C:\windows\system32\drivers\srvnet.sys
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\vbscript.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\urlmon.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\occache.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\inseng.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\iernonce.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2016-09-14 22:11:11 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2016-09-14 22:11:11 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2016-09-14 22:11:11 ----A---- C:\windows\system32\inseng.dll
2016-09-14 22:11:11 ----A---- C:\windows\system32\iernonce.dll
2016-09-14 22:11:11 ----A---- C:\windows\system32\ieetwproxystub.dll
2016-09-14 22:11:11 ----A---- C:\windows\system32\ieetwcollector.exe
2016-09-14 22:11:11 ----A---- C:\windows\system32\ie4uinit.exe
2016-09-14 22:11:10 ----A---- C:\windows\SYSWOW64\mshtml.dll
2016-09-14 22:11:09 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2016-09-14 22:11:09 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2016-09-14 22:11:09 ----A---- C:\windows\SYSWOW64\jscript.dll
2016-09-14 22:11:09 ----A---- C:\windows\SYSWOW64\iesetup.dll
2016-09-14 22:11:09 ----A---- C:\windows\SYSWOW64\iertutil.dll
2016-09-14 22:11:09 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2016-09-14 22:11:09 ----A---- C:\windows\system32\urlmon.dll
2016-09-14 22:11:09 ----A---- C:\windows\system32\occache.dll
2016-09-14 22:11:09 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2016-09-14 22:11:09 ----A---- C:\windows\system32\ieetwcollectorres.dll
2016-09-14 22:11:09 ----A---- C:\windows\system32\iedkcs32.dll
2016-09-14 22:11:08 ----A---- C:\windows\SYSWOW64\ieui.dll
2016-09-14 22:11:08 ----A---- C:\windows\SYSWOW64\ieframe.dll
2016-09-14 22:11:08 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2016-09-14 22:11:08 ----A---- C:\windows\system32\msfeeds.dll
2016-09-14 22:11:08 ----A---- C:\windows\system32\iesetup.dll
2016-09-14 22:11:08 ----A---- C:\windows\system32\dxtrans.dll
2016-09-14 22:11:07 ----A---- C:\windows\system32\iertutil.dll
2016-09-14 22:11:07 ----A---- C:\windows\system32\ieapfltr.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\wininet.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\webcheck.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\msrating.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\jscript9.dll
2016-09-14 22:11:06 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2016-09-14 22:11:06 ----A---- C:\windows\system32\vbscript.dll
2016-09-14 22:11:06 ----A---- C:\windows\system32\jsproxy.dll
2016-09-14 22:11:05 ----A---- C:\windows\system32\ieui.dll
2016-09-14 22:11:05 ----A---- C:\windows\system32\ieframe.dll
2016-09-14 22:11:05 ----A---- C:\windows\system32\dxtmsft.dll
2016-09-14 22:11:04 ----A---- C:\windows\system32\webcheck.dll
2016-09-14 22:11:04 ----A---- C:\windows\system32\mshtmlmedia.dll
2016-09-14 22:11:04 ----A---- C:\windows\system32\mshtmled.dll
2016-09-14 22:11:04 ----A---- C:\windows\system32\ieUnatt.exe
2016-09-14 22:11:03 ----A---- C:\windows\system32\wininet.dll
2016-09-14 22:11:03 ----A---- C:\windows\system32\jscript9diag.dll
2016-09-14 22:11:03 ----A---- C:\windows\system32\jscript9.dll
2016-09-14 22:11:03 ----A---- C:\windows\system32\jscript.dll
2016-09-14 22:11:02 ----A---- C:\windows\system32\msrating.dll
2016-09-14 22:11:02 ----A---- C:\windows\system32\MshtmlDac.dll
2016-09-14 22:11:01 ----A---- C:\windows\system32\mshtml.dll
2016-09-14 22:09:03 ----A---- C:\windows\system32\wucltux.dll
2016-09-14 22:09:03 ----A---- C:\windows\system32\wuauclt.exe
2016-09-14 22:09:03 ----A---- C:\windows\system32\wuapp.exe
2016-09-14 22:09:03 ----A---- C:\windows\system32\WinSetupUI.dll
2016-09-14 22:09:02 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2016-09-14 22:09:02 ----A---- C:\windows\SYSWOW64\wudriver.dll
2016-09-14 22:09:02 ----A---- C:\windows\SYSWOW64\wuapp.exe
2016-09-14 22:09:02 ----A---- C:\windows\SYSWOW64\wuapi.dll
2016-09-14 22:09:02 ----A---- C:\windows\system32\wuwebv.dll
2016-09-14 22:09:02 ----A---- C:\windows\system32\wudriver.dll
2016-09-14 22:09:02 ----A---- C:\windows\system32\wuaueng.dll
2016-09-14 22:09:02 ----A---- C:\windows\system32\wuapi.dll
2016-09-14 22:09:02 ----A---- C:\windows\system32\ntoskrnl.exe
2016-09-14 22:09:01 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2016-09-14 22:09:01 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2016-09-14 22:09:01 ----A---- C:\windows\SYSWOW64\ntdll.dll
2016-09-14 22:09:01 ----A---- C:\windows\SYSWOW64\advapi32.dll
2016-09-14 22:09:01 ----A---- C:\windows\system32\ntdll.dll
2016-09-14 22:09:01 ----A---- C:\windows\system32\KernelBase.dll
2016-09-14 22:09:01 ----A---- C:\windows\system32\kernel32.dll
2016-09-14 22:09:01 ----A---- C:\windows\system32\advapi32.dll
2016-09-14 22:09:00 ----A---- C:\windows\SYSWOW64\wups.dll
2016-09-14 22:09:00 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2016-09-14 22:09:00 ----A---- C:\windows\SYSWOW64\kernel32.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\wups2.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\wups.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\wow64win.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\wow64.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\winsrv.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\srcore.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\schannel.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\msi.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\crypt32.dll
2016-09-14 22:09:00 ----A---- C:\windows\system32\appidpolicyconverter.exe
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-09-14 22:08:59 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\wow32.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\wintrust.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\srclient.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\schannel.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\setup16.exe
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\olepro32.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\msiexec.exe
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\msi.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\instnm.exe
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\crypt32.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\certcli.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\asycfilt.dll
2016-09-14 22:08:59 ----A---- C:\windows\SYSWOW64\appidapi.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\wow64cpu.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\wintrust.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\srclient.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\smss.exe
2016-09-14 22:08:59 ----A---- C:\windows\system32\setbcdlocale.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\rstrui.exe
2016-09-14 22:08:59 ----A---- C:\windows\system32\ntvdm64.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\msiexec.exe
2016-09-14 22:08:59 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2016-09-14 22:08:59 ----A---- C:\windows\system32\drivers\ksecdd.sys
2016-09-14 22:08:59 ----A---- C:\windows\system32\drivers\appid.sys
2016-09-14 22:08:59 ----A---- C:\windows\system32\csrsrv.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\cryptsvc.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\cryptnet.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\consent.exe
2016-09-14 22:08:59 ----A---- C:\windows\system32\conhost.exe
2016-09-14 22:08:59 ----A---- C:\windows\system32\certcli.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\asycfilt.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\appidsvc.dll
2016-09-14 22:08:59 ----A---- C:\windows\system32\appidcertstorecheck.exe
2016-09-14 22:08:59 ----A---- C:\windows\system32\appidapi.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-09-14 22:08:58 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\wdigest.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\user.exe
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\sspicli.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\secur32.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\msobjs.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\msimsg.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\msihnd.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\msaudite.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\kerberos.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\credssp.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\authui.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\auditpol.exe
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2016-09-14 22:08:58 ----A---- C:\windows\SYSWOW64\adtschema.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\wdigest.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\TSpkg.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\sspisrv.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\sspicli.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\secur32.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\rpchttp.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\rpcrt4.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\ncrypt.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\msv1_0.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\msobjs.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\msimsg.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\msihnd.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\msaudite.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\lsass.exe
2016-09-14 22:08:58 ----A---- C:\windows\system32\lsasrv.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\kerberos.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2016-09-14 22:08:58 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2016-09-14 22:08:58 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2016-09-14 22:08:58 ----A---- C:\windows\system32\cryptbase.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\credssp.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\authui.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\auditpol.exe
2016-09-14 22:08:58 ----A---- C:\windows\system32\appinfo.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\apisetschema.dll
2016-09-14 22:08:58 ----A---- C:\windows\system32\adtschema.dll
2016-09-14 22:08:02 ----A---- C:\windows\SYSWOW64\user32.dll
2016-09-14 22:08:02 ----A---- C:\windows\system32\win32k.sys
2016-09-14 22:08:02 ----A---- C:\windows\system32\user32.dll
2016-09-14 22:08:01 ----A---- C:\windows\SYSWOW64\inetcomm.dll
2016-09-14 22:08:01 ----A---- C:\windows\system32\inetcomm.dll
2016-09-14 22:08:01 ----A---- C:\windows\system32\drivers\tcpipreg.sys
2016-09-14 22:08:01 ----A---- C:\windows\system32\drivers\tcpip.sys
2016-09-14 22:08:01 ----A---- C:\windows\system32\drivers\netio.sys
2016-09-14 22:08:01 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2016-09-14 22:08:00 ----A---- C:\windows\SYSWOW64\oleaut32.dll
2016-09-14 22:08:00 ----A---- C:\windows\SYSWOW64\INETRES.dll
2016-09-14 22:08:00 ----A---- C:\windows\system32\oleaut32.dll
2016-09-14 22:08:00 ----A---- C:\windows\system32\INETRES.dll
2016-08-26 00:06:08 ----D---- C:\Users\Dvorščák\AppData\Roaming\Mount&Blade Warband
2016-08-25 16:03:34 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-08-18 09:46:26 ----D---- C:\Program Files (x86)\Steam
2016-08-17 09:52:21 ----A---- C:\windows\SYSWOW64\tzres.dll
2016-08-17 09:52:21 ----A---- C:\windows\system32\tzres.dll

======List of files/folders modified in the last 1 month======

2016-09-16 10:38:16 ----D---- C:\windows\Temp
2016-09-16 10:38:14 ----RD---- C:\Program Files
2016-09-16 10:28:01 ----SHD---- C:\windows\Installer
2016-09-16 10:28:01 ----SHD---- C:\Config.Msi
2016-09-16 10:26:42 ----D---- C:\windows\system32\config
2016-09-16 10:25:32 ----RD---- C:\Program Files (x86)
2016-09-16 10:25:20 ----D---- C:\Program Files (x86)\Google
2016-09-16 10:23:26 ----D---- C:\windows\Prefetch
2016-09-16 10:23:18 ----D---- C:\windows\Tasks
2016-09-16 10:23:18 ----D---- C:\windows\system32\Tasks
2016-09-16 10:18:21 ----D---- C:\windows\inf
2016-09-16 10:16:06 ----SHD---- C:\System Volume Information
2016-09-16 10:16:05 ----D---- C:\ProgramData\DivX
2016-09-16 10:16:05 ----D---- C:\Program Files (x86)\DivX
2016-09-16 10:13:46 ----D---- C:\Users\Dvorščák\AppData\Roaming\DivX
2016-09-16 10:13:17 ----D---- C:\windows\SysWOW64
2016-09-16 09:12:34 ----D---- C:\windows\system32\FxsTmp
2016-09-16 08:58:03 ----D---- C:\Users\Dvorščák\AppData\Roaming\uTorrent
2016-09-16 08:58:03 ----D---- C:\Users\Dvorščák\AppData\Roaming\TS3Client
2016-09-16 08:58:03 ----D---- C:\Users\Dvorščák\AppData\Roaming\DAEMON Tools Lite
2016-09-16 08:57:37 ----D---- C:\windows\Minidump
2016-09-16 08:57:37 ----D---- C:\windows\Logs
2016-09-16 08:57:37 ----D---- C:\windows
2016-09-16 08:53:41 ----D---- C:\Games
2016-09-16 08:47:46 ----D---- C:\Users\Dvorščák\AppData\Roaming\The Creative Assembly
2016-09-16 08:47:39 ----D---- C:\totalcmd
2016-09-16 08:47:38 ----D---- C:\Users\Dvorščák\AppData\Roaming\GHISLER
2016-09-16 08:47:13 ----D---- C:\Program Files (x86)\Bradbury
2016-09-16 08:43:14 ----D---- C:\Program Files (x86)\Lavalys
2016-09-16 08:40:47 ----HD---- C:\ProgramData
2016-09-16 08:15:04 ----A---- C:\windows\SYSWOW64\log.txt
2016-09-15 22:25:10 ----D---- C:\Users\Dvorščák\AppData\Roaming\Skype
2016-09-15 20:45:53 ----D---- C:\windows\system32\drivers
2016-09-15 08:36:37 ----D---- C:\windows\winsxs
2016-09-15 08:33:31 ----D---- C:\windows\SYSWOW64\sk-SK
2016-09-15 08:33:31 ----D---- C:\Program Files\Internet Explorer
2016-09-15 08:33:30 ----D---- C:\windows\SYSWOW64\en-US
2016-09-15 08:33:29 ----D---- C:\windows\system32\sk-SK
2016-09-15 08:33:29 ----D---- C:\windows\system32\en-US
2016-09-15 08:33:29 ----AD---- C:\windows\System32
2016-09-15 08:33:28 ----D---- C:\Program Files (x86)\Internet Explorer
2016-09-15 08:33:20 ----D---- C:\windows\AppPatch
2016-09-15 08:33:19 ----D---- C:\windows\system32\Boot
2016-09-15 00:24:18 ----D---- C:\ProgramData\Microsoft Help
2016-09-15 00:21:21 ----D---- C:\Program Files\Microsoft Silverlight
2016-09-15 00:21:21 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-09-14 22:07:54 ----D---- C:\windows\system32\catroot2
2016-09-08 20:22:47 ----RSD---- C:\windows\assembly
2016-09-08 15:17:49 ----D---- C:\Program Files (x86)\Opera
2016-09-02 13:17:41 ----D---- C:\Users\Dvorščák\AppData\Roaming\vlc
2016-08-29 21:30:04 ----RD---- C:\Program Files (x86)\Skype
2016-08-29 21:28:41 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2016-03-08 74544]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2016-08-05 292704]
R0 Fastboot;Fastboot; C:\windows\System32\DRIVERS\Fastboot.sys [2011-12-16 69216]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-05-20 557848]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2016-03-08 37144]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2016-03-08 103064]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2016-03-09 1070904]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2016-03-08 463744]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2016-03-08 37656]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2016-03-09 107792]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2016-03-08 165344]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\windows\system32\DRIVERS\dtlitescsibus.sys [2015-04-17 30352]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-12-15 14646560]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2011-09-06 3074536]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-05 331264]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\HECIx64.sys [2011-11-09 60184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2010-07-20 247400]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
S3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2009-07-13 5020672]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;USB Scanner Driver; C:\windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 wsvd;wsvd; C:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]
S4 RsFx0301;RsFx0301 Driver; C:\windows\system32\DRIVERS\RsFx0301.sys [2016-05-27 249024]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-09-08 82128]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-03-08 237096]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2015-04-06 151648]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\Rapidboot\FBService.exe [2011-12-16 199264]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-05-20 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-09 607456]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2011-12-16 161560]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-03-16 32768]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-12-16 277784]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2016-07-24 66872]
R2 PnkBstrB;PnkBstrB; C:\windows\syswow64\PnkBstrB.exe [2016-07-24 107832]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2016-05-27 134336]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-16 363800]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-03-31 1277680]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-16 153752]
S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2016-05-27 370368]
S2 ReportServer$SQLEXPRESS;SQL Server Reporting Services (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSRS12.SQLEXPRESS\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2016-05-27 2468032]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-12 270016]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2011-12-21 274200]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-16 153752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2016-09-01 114688]
S3 Lenovo EasyPlus Hotspot;Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [2015-07-22 625632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MSSQLFDLauncher$SQLEXPRESS;SQL Full-text Filter Daemon Launcher (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\fdlauncher.exe [2014-02-21 50880]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-23 1465120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2015-04-03 1255736]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2016-05-27 613056]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2014-02-21 270016]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

-----------------EOF-----------------

Re: Prosím kontrolu RSIT logu

Napsal: 16 zář 2016 13:55
od altrok
Krasny den Vam preju :bye:


:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).


:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan (Skenovani), pote na Cleaning (Cisteni)
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Prosím kontrolu RSIT logu

Napsal: 16 zář 2016 14:19
od D.Dixon
Nech sa páči, adw log:

# AdwCleaner v6.020 - *Logfile created 16/09/2016 *at 15:11:39
# *Updated on 14/09/2016 by ToolsLib
# *Database : 2016-09-15.2 [*Server]
# *Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# *Username : Dvorščák - DVORSCAK-PC
# *Running from : C:\Users\Dvorščák\Downloads\adwcleaner_6.020.exe
# *Mode: Clean
# *Support : https://toolslib.net/forum



***** [ *Services ] *****



***** [ *Folders ] *****

[-] *Folder deleted: C:\ProgramData\rWdsManPror
[-] *Folder deleted: C:\Users\Dvorščák\AppData\Local\UpdateAdmin
[-] *Folder deleted: C:\Users\Dvorščák\AppData\Roaming\omniboxes
[-] *Folder deleted: C:\Users\Dvorščák\AppData\Roaming\RHEng
[-] *Folder deleted: C:\Users\Dvorščák\AppData\Roaming\Mozila
[-] *Folder deleted: C:\Users\Dvorščák\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
[-] *Folder deleted: C:\ProgramData\Partner
[#] *Folder deleted on reboot: C:\ProgramData\Application Data\Partner
[-] *Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
[-] *Folder deleted: C:\Program Files (x86)\Amazon\ABB


***** [ *Files ] *****

[-] *File deleted: C:\windows\SysNative\roboot64.exe
[-] *File deleted: C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
[#] *File deleted: C:\ProgramData\Application Data\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


***** [ DLL ] *****



***** [ WMI ] *****



***** [ *Shortcuts ] *****



***** [ *Scheduled Tasks ] *****



***** [ *Registry ] *****

[-] *Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdsManPro
[#] *Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdsManPro
[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] *Key deleted: HKU\.DEFAULT\Software\ByteFence
[-] *Key deleted: HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Alexa Internet
[-] *Key deleted: HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\DownloadAdmin
[-] *Key deleted: HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\PRODUCTSETUP
[-] *Key deleted: HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\csastats
[#] *Key deleted on reboot: HKU\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Alexa Internet
[-] *Key deleted: HKU\S-1-5-80-425977601-1203083412-1631309457-2457533047-3321749933\Software\Alexa Internet
[#] *Key deleted on reboot: HKU\S-1-5-80-997390408-2153310517-3119169589-2253446180-2226563786\Software\Alexa Internet
[#] *Key deleted on reboot: HKU\S-1-5-18\Software\ByteFence
[#] *Key deleted on reboot: HKCU\Software\Alexa Internet
[#] *Key deleted on reboot: HKCU\Software\DownloadAdmin
[#] *Key deleted on reboot: HKCU\Software\PRODUCTSETUP
[#] *Key deleted on reboot: HKCU\Software\csastats
[-] *Key deleted: HKLM\SOFTWARE\omniboxesSoftware
[-] *Key deleted: HKLM\SOFTWARE\WdsManPro
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{81F17B54-5D57-485E-88CC-F6D20D66B5E0}
[#] *Key deleted on reboot: [x64] HKCU\Software\Alexa Internet
[#] *Key deleted on reboot: [x64] HKCU\Software\DownloadAdmin
[#] *Key deleted on reboot: [x64] HKCU\Software\PRODUCTSETUP
[#] *Key deleted on reboot: [x64] HKCU\Software\csastats
[-] *Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\45B71F1875D5E58488CC6F2DD0665B0E
[-] *Key deleted: HKLM\SOFTWARE\Classes\Installer\Products\45B71F1875D5E58488CC6F2DD0665B0E
[-] *Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45B71F1875D5E58488CC6F2DD0665B0E
[#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45B71F1875D5E58488CC6F2DD0665B0E
[#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Features\45B71F1875D5E58488CC6F2DD0665B0E
[#] *Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Products\45B71F1875D5E58488CC6F2DD0665B0E
[-] *Key deleted: HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
[-] *Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
[#] *Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{20B9D1AE-AD1A-38B4-87FE-AF278DA9861D}
[-] *Data restored: HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [Default]


***** [ *Browsers ] *****



*************************

:: *"Tracing" keys deleted
:: *Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [4767 *Bytes] - [16/09/2016 15:11:39]
C:\AdwCleaner\AdwCleaner[S0].txt - [4739 *Bytes] - [16/09/2016 15:11:28]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4915 *Bytes] ##########

Re: Prosím kontrolu RSIT logu

Napsal: 16 zář 2016 14:25
od altrok
:arrow: Dejte logy FRST.txt a Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.

Re: Prosím kontrolu RSIT logu

Napsal: 16 zář 2016 16:19
od D.Dixon
Log FRST a log Addition je v prílohe zabalený do rar archívu:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-09-2016
Ran by Dvorščák (administrator) on DVORSCAK-PC (16-09-2016 17:11:15)
Running from C:\Users\Dvorščák\Desktop
Loaded Profiles: Dvorščák & MSSQL$SQLEXPRESS & ReportServer$SQLEXPRESS & MSSQLFDLauncher$SQLEXPRESS (Available Profiles: Dvorščák & MSSQL$SQLEXPRESS & ReportServer$SQLEXPRESS & MSSQLFDLauncher$SQLEXPRESS)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Intel Corporation) C:\windows\System32\igfxtray.exe
(Intel Corporation) C:\windows\System32\hkcmd.exe
(Intel Corporation) C:\windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(1206 Lab) C:\Program Files (x86)\Lenovo\Rapidboot\FBService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\windows\jmesoft\Service.exe
(SEIKO EPSON CORPORATION) C:\windows\System32\spool\drivers\x64\3\E_IATIHJE.EXE
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
() C:\windows\SysWOW64\PnkBstrA.exe
() C:\windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSRS12.SQLEXPRESS\Reporting Services\ReportServer\bin\ReportingServicesService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\FreePro Manager\service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Lenovo) C:\windows\jmesoft\hotkey.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe
() C:\windows\jmesoft\JME_LOAD.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Microsoft Corporation) C:\windows\System32\dllhost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.1\Lightshot.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\fdhost.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Users\Dvorščák\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12850792 2011-09-05] (Realtek Semiconductor)
HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [jmekey] => C:\windows\jmesoft\hotkey.exe
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe
HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe [1260128 2011-12-16] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-08-30] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [1009632 2016-08-29] (DivX, LLC)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE [283232 2015-04-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5585136 2015-03-31] (Disc Soft Ltd)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [service.exe] => C:\Program Files (x86)\FreePro Manager\service.exe [1035776 2016-07-10] ()
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\MountPoints2: G - G:\SETUP.EXE
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\MountPoints2: {6f96561a-e4be-11e4-a3f2-eca86b6451ba} - E:\autorun.exe
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-08] (AVAST Software)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => No File
Startup: C:\Users\Dvorščák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk [2015-10-19]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-2898392049-1419488004-4050302534-1001] => 127.0.0.1:8118
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{255F9FAC-57F3-4691-91A9-6806D9212252}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKU\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKU\S-1-5-80-425977601-1203083412-1631309457-2457533047-3321749933\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-80-425977601-1203083412-1631309457-2457533047-3321749933\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKU\S-1-5-80-425977601-1203083412-1631309457-2457533047-3321749933\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKU\S-1-5-80-997390408-2153310517-3119169589-2253446180-2226563786\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-80-997390408-2153310517-3119169589-2253446180-2226563786\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
HKU\S-1-5-80-997390408-2153310517-3119169589-2253446180-2226563786\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LEND&bmod=LEND
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2898392049-1419488004-4050302534-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-80-3880006512-4290199581-1648723128-3569869737-3631323133 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-80-425977601-1203083412-1631309457-2457533047-3321749933 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-80-425977601-1203083412-1631309457-2457533047-3321749933 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-80-997390408-2153310517-3119169589-2253446180-2226563786 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-80-997390408-2153310517-3119169589-2253446180-2226563786 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-26] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-08] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24] (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-26] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-08] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24] (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.omniboxes.com/?type=sc&ts=144354032 ... 9311093110

FireFox:
========
FF ProfilePath: C:\Users\Dvorščák\AppData\Roaming\Mozilla\Firefox\Profiles\q7znbqf0.default
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2016-09-06] (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2011-12-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2011-12-01] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2898392049-1419488004-4050302534-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Dvorščák\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-03-28]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird => not found

Chrome:
=======
CHR Profile: C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentácie Google) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-01]
CHR Extension: (Dokumenty Google) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-01]
CHR Extension: (Disk Google) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-01]
CHR Extension: (Adblock Plus) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-24]
CHR Extension: (Google Search) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tabuľky Google) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-01]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (Avast Online Security) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-01]
CHR Extension: (Chrome Media Router) - C:\Users\Dvorščák\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-31]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-08]

Opera:
=======
OPR Extension: (Adblock Plus) - C:\Users\Dvorščák\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-08-26]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-08] (AVAST Software)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1277680 2015-03-31] (Disc Soft Ltd)
R2 FastbootService; C:\Program Files (x86)\Lenovo\Rapidboot\FBService.exe [199264 2011-12-16] (1206 Lab)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-16] () [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625632 2015-07-22] (Lenovo)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [370368 2016-05-27] (Microsoft Corporation)
R3 MSSQLFDLauncher$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\fdlauncher.exe [50880 2014-02-21] (Microsoft Corporation)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [66872 2016-07-24] ()
R2 PnkBstrB; C:\windows\SysWOW64\PnkBstrB.exe [107832 2016-07-24] ()
R2 ReportServer$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSRS12.SQLEXPRESS\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2468032 2016-05-27] (Microsoft Corporation)
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL12.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [613056 2016-05-27] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-08] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-08] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-08] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-08] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-05] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2015-04-17] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [69216 2011-12-16] (Windows (R) Win 7 DDK provider)
S4 RsFx0301; C:\Windows\System32\DRIVERS\RsFx0301.sys [249024 2016-05-27] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-16 17:11 - 2016-09-16 17:12 - 00024767 _____ C:\Users\Dvorščák\Desktop\FRST.txt
2016-09-16 17:10 - 2016-09-16 17:11 - 00000000 ____D C:\FRST
2016-09-16 17:09 - 2016-09-16 17:09 - 00112640 _____ (forum.viry.cz) C:\Users\Dvorščák\Desktop\FRSTLauncher.exe
2016-09-16 17:01 - 2016-09-16 17:01 - 02399232 _____ (Farbar) C:\Users\Dvorščák\Desktop\FRST64.exe
2016-09-16 15:08 - 2016-09-16 15:11 - 00000000 ____D C:\AdwCleaner
2016-09-16 15:06 - 2016-09-16 15:08 - 03861056 _____ C:\Users\Dvorščák\Downloads\adwcleaner_6.020.exe
2016-09-16 15:02 - 2016-09-16 15:02 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-16 15:02 - 2016-09-16 15:02 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-16 15:02 - 2016-09-16 15:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-16 10:38 - 2016-09-16 10:38 - 00000000 ____D C:\rsit
2016-09-16 10:38 - 2016-09-16 10:38 - 00000000 ____D C:\Program Files\trend micro
2016-09-16 10:37 - 2016-09-16 10:37 - 01222144 _____ C:\Users\Dvorščák\Downloads\RSITx64.exe
2016-09-16 10:23 - 2016-09-16 16:54 - 00000936 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-16 10:23 - 2016-09-16 16:28 - 00000940 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-16 10:23 - 2016-09-16 10:23 - 00003936 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-09-16 10:23 - 2016-09-16 10:23 - 00003684 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-09-16 08:46 - 2016-09-16 08:46 - 00000011 ____R C:\windows\amunres.lsl
2016-09-14 22:11 - 2016-09-01 21:26 - 00394440 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-09-14 22:11 - 2016-09-01 20:41 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-09-14 22:11 - 2016-09-01 05:18 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-09-14 22:11 - 2016-09-01 05:08 - 20312064 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-09-14 22:11 - 2016-09-01 04:48 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-09-14 22:11 - 2016-09-01 04:46 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-09-14 22:11 - 2016-09-01 04:46 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-09-14 22:11 - 2016-09-01 04:46 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-09-14 22:11 - 2016-09-01 04:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-09-14 22:11 - 2016-09-01 04:34 - 02286592 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-09-14 22:11 - 2016-09-01 04:31 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-09-14 22:11 - 2016-09-01 04:31 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-09-14 22:11 - 2016-09-01 04:26 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-09-14 22:11 - 2016-09-01 04:24 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-09-14 22:11 - 2016-09-01 04:24 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-09-14 22:11 - 2016-09-01 04:23 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-09-14 22:11 - 2016-09-01 04:08 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-09-14 22:11 - 2016-09-01 03:59 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-09-14 22:11 - 2016-09-01 03:57 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-09-14 22:11 - 2016-09-01 03:53 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-09-14 22:11 - 2016-09-01 03:52 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-09-14 22:11 - 2016-09-01 03:48 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-09-14 22:11 - 2016-09-01 03:45 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-09-14 22:11 - 2016-09-01 03:34 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-09-14 22:11 - 2016-09-01 03:30 - 00692736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-09-14 22:11 - 2016-09-01 03:29 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-09-14 22:11 - 2016-09-01 03:29 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-09-14 22:11 - 2016-09-01 03:27 - 13808128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-09-14 22:11 - 2016-09-01 03:24 - 04607488 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-09-14 22:11 - 2016-09-01 02:45 - 25770496 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-09-14 22:11 - 2016-09-01 02:43 - 02445824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-09-14 22:11 - 2016-09-01 02:42 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-09-14 22:11 - 2016-09-01 02:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-09-14 22:11 - 2016-09-01 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-09-14 22:11 - 2016-09-01 02:38 - 01316352 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-09-14 22:11 - 2016-09-01 02:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-09-14 22:11 - 2016-09-01 02:24 - 02894336 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-09-14 22:11 - 2016-09-01 02:24 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-09-14 22:11 - 2016-09-01 02:24 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-09-14 22:11 - 2016-09-01 02:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-09-14 22:11 - 2016-09-01 02:24 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-09-14 22:11 - 2016-09-01 02:16 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-09-14 22:11 - 2016-09-01 02:15 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-09-14 22:11 - 2016-09-01 02:12 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-09-14 22:11 - 2016-09-01 02:11 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-09-14 22:11 - 2016-09-01 02:11 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-09-14 22:11 - 2016-09-01 02:10 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-09-14 22:11 - 2016-09-01 02:10 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-09-14 22:11 - 2016-09-01 02:06 - 06047232 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-09-14 22:11 - 2016-09-01 02:03 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-09-14 22:11 - 2016-09-01 01:59 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-09-14 22:11 - 2016-09-01 01:51 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-09-14 22:11 - 2016-09-01 01:50 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-09-14 22:11 - 2016-09-01 01:47 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-09-14 22:11 - 2016-09-01 01:46 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-09-14 22:11 - 2016-09-01 01:44 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-09-14 22:11 - 2016-09-01 01:42 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-09-14 22:11 - 2016-09-01 01:31 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-09-14 22:11 - 2016-09-01 01:29 - 00724992 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-09-14 22:11 - 2016-09-01 01:28 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-09-14 22:11 - 2016-09-01 01:27 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-09-14 22:11 - 2016-09-01 01:26 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-09-14 22:11 - 2016-09-01 01:15 - 15411712 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-09-14 22:11 - 2016-09-01 01:10 - 02921472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-09-14 22:11 - 2016-09-01 00:58 - 01550848 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-09-14 22:11 - 2016-09-01 00:47 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-09-14 22:11 - 2016-08-12 18:26 - 00464896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
2016-09-14 22:11 - 2016-08-12 18:26 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2016-09-14 22:11 - 2016-08-12 18:26 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
2016-09-14 22:09 - 2016-09-02 17:40 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2016-09-14 22:09 - 2016-09-02 17:35 - 05548264 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-09-14 22:09 - 2016-09-02 17:35 - 00706280 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2016-09-14 22:09 - 2016-09-02 17:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-09-14 22:09 - 2016-09-02 17:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2016-09-14 22:09 - 2016-09-02 17:31 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2016-09-14 22:09 - 2016-09-02 17:31 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2016-09-14 22:09 - 2016-09-02 17:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2016-09-14 22:09 - 2016-09-02 17:30 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2016-09-14 22:09 - 2016-09-02 17:30 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2016-09-14 22:09 - 2016-09-02 17:30 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-09-14 22:09 - 2016-09-02 17:30 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2016-09-14 22:09 - 2016-09-02 17:21 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2016-09-14 22:09 - 2016-09-02 17:21 - 03944680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2016-09-14 22:09 - 2016-09-02 17:18 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-09-14 22:09 - 2016-09-02 17:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2016-09-14 22:09 - 2016-09-02 17:16 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2016-09-14 22:09 - 2016-09-02 17:16 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-09-14 22:09 - 2016-09-02 17:02 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2016-09-14 22:09 - 2016-06-06 18:50 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2016-09-14 22:09 - 2016-05-14 00:09 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2016-09-14 22:09 - 2016-05-14 00:09 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2016-09-14 22:09 - 2016-05-14 00:09 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2016-09-14 22:09 - 2016-05-14 00:07 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2016-09-14 22:09 - 2016-05-13 23:55 - 02607104 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-09-14 22:09 - 2016-05-13 23:53 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2016-09-14 22:09 - 2016-05-13 23:53 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2016-09-14 22:09 - 2016-05-13 23:52 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2016-09-14 22:09 - 2016-05-13 23:52 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2016-09-14 22:09 - 2016-05-13 23:52 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2016-09-14 22:09 - 2016-05-13 23:52 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2016-09-14 22:09 - 2016-05-13 23:50 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2016-09-14 22:09 - 2016-05-13 23:38 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2016-09-14 22:09 - 2016-05-13 23:38 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2016-09-14 22:09 - 2016-05-13 23:38 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2016-09-14 22:09 - 2016-05-13 23:38 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2016-09-14 22:09 - 2016-05-04 19:17 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2016-09-14 22:08 - 2016-09-02 17:35 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-09-14 22:08 - 2016-09-02 17:35 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2016-09-14 22:08 - 2016-09-02 17:31 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2016-09-14 22:08 - 2016-09-02 17:31 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2016-09-14 22:08 - 2016-09-02 17:31 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2016-09-14 22:08 - 2016-09-02 17:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2016-09-14 22:08 - 2016-09-02 17:31 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2016-09-14 22:08 - 2016-09-02 17:31 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 01464320 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00260608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 17:02 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2016-09-14 22:08 - 2016-09-02 17:02 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2016-09-14 22:08 - 2016-09-02 17:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2016-09-14 22:08 - 2016-09-02 16:58 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2016-09-14 22:08 - 2016-09-02 16:57 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2016-09-14 22:08 - 2016-09-02 16:55 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-09-14 22:08 - 2016-09-02 16:54 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-09-14 22:08 - 2016-09-02 16:54 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2016-09-14 22:08 - 2016-09-02 16:53 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2016-09-14 22:08 - 2016-09-02 16:53 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2016-09-14 22:08 - 2016-09-02 16:53 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2016-09-14 22:08 - 2016-09-02 16:49 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2016-09-14 22:08 - 2016-09-02 16:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2016-09-14 22:08 - 2016-09-02 16:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2016-09-14 22:08 - 2016-09-02 16:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2016-09-14 22:08 - 2016-09-02 16:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2016-09-14 22:08 - 2016-09-02 16:48 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 16:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 16:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-14 22:08 - 2016-09-02 16:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-09-14 22:08 - 2016-08-16 19:36 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
2016-09-14 22:08 - 2016-08-16 04:48 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2016-09-14 22:08 - 2016-08-16 04:35 - 03218432 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-09-14 22:08 - 2016-08-06 17:31 - 00877056 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2016-09-14 22:08 - 2016-08-06 17:15 - 00581632 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2016-09-14 22:08 - 2016-07-07 17:36 - 01896168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2016-09-14 22:08 - 2016-07-07 17:36 - 00377576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2016-09-14 22:08 - 2016-07-07 17:36 - 00287976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2016-09-14 22:08 - 2016-07-07 17:08 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
2016-09-14 22:08 - 2016-07-01 17:31 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2016-09-14 22:08 - 2016-07-01 17:31 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2016-09-14 22:08 - 2016-07-01 17:13 - 00741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2016-09-14 22:08 - 2016-07-01 17:13 - 00084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2016-09-14 22:08 - 2016-06-06 18:50 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2016-09-14 22:08 - 2016-06-06 18:50 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2016-09-14 22:08 - 2016-06-06 18:50 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2016-09-14 22:08 - 2016-06-06 17:23 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2016-09-14 22:08 - 2016-06-06 17:23 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2016-09-14 22:08 - 2016-06-06 17:23 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2016-09-14 22:08 - 2016-06-06 17:23 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2016-09-14 22:08 - 2016-05-12 19:14 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-09-14 22:08 - 2016-05-12 17:18 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2016-09-14 22:08 - 2016-05-12 17:18 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-09-14 22:08 - 2016-05-04 19:21 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2016-09-14 22:08 - 2016-05-04 19:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2016-09-14 22:08 - 2016-05-04 19:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2016-09-14 22:08 - 2016-05-04 19:17 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2016-09-14 22:08 - 2016-05-04 19:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2016-09-14 22:08 - 2016-05-04 19:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2016-09-14 22:08 - 2016-05-04 19:17 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2016-09-14 22:08 - 2016-05-04 19:16 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2016-09-14 22:08 - 2016-05-04 19:16 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2016-09-14 22:08 - 2016-05-04 17:04 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2016-09-14 22:08 - 2016-05-04 16:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2016-09-08 15:17 - 2016-09-08 15:17 - 00003864 _____ C:\windows\System32\Tasks\Opera scheduled Autoupdate 1444832528
2016-09-02 08:43 - 2016-09-02 08:43 - 00365536 _____ (DivX, LLC) C:\windows\SysWOW64\DivXControlPanelApplet.cpl
2016-08-26 00:07 - 2016-08-26 09:34 - 00000000 ____D C:\Users\Dvorščák\Documents\Mount&Blade Warband Savegames
2016-08-26 00:06 - 2016-08-26 00:08 - 00000000 ____D C:\Users\Dvorščák\Documents\Mount&Blade Warband
2016-08-26 00:06 - 2016-08-26 00:07 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\Mount&Blade Warband
2016-08-25 16:03 - 2016-09-16 15:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-20 11:42 - 2016-08-20 11:42 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-19 23:49 - 2016-08-19 23:49 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
2016-08-18 09:46 - 2016-09-16 08:58 - 00000000 ____D C:\Program Files (x86)\Steam
2016-08-18 09:46 - 2016-08-18 09:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-17 09:52 - 2016-07-08 17:32 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2016-08-17 09:52 - 2016-07-08 17:16 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-16 17:04 - 2009-07-14 06:45 - 00020688 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-16 17:04 - 2009-07-14 06:45 - 00020688 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-16 16:56 - 2016-06-03 13:03 - 00000000 ____D C:\Users\MSSQLFDLauncher$SQLEXPRESS
2016-09-16 16:54 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-09-16 15:11 - 2012-08-26 11:41 - 00000000 ____D C:\Program Files (x86)\Amazon
2016-09-16 10:32 - 2016-05-30 17:56 - 00000394 _____ C:\windows\Tasks\update-sys.job
2016-09-16 10:25 - 2012-08-26 11:43 - 00000000 ____D C:\Program Files (x86)\Google
2016-09-16 10:18 - 2009-07-14 05:20 - 00000000 ____D C:\windows\inf
2016-09-16 10:17 - 2015-07-23 18:58 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-09-16 10:16 - 2015-09-18 20:02 - 00000000 ____D C:\Program Files (x86)\DivX
2016-09-16 10:16 - 2015-09-18 20:01 - 00000000 ____D C:\ProgramData\DivX
2016-09-16 10:15 - 2016-04-08 14:53 - 00003640 _____ C:\windows\System32\Tasks\DivXUpdate
2016-09-16 10:15 - 2015-09-18 20:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2016-09-16 10:13 - 2015-09-18 20:07 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\DivX
2016-09-16 09:48 - 2016-05-30 17:56 - 00000394 _____ C:\windows\Tasks\update-S-1-5-21-2898392049-1419488004-4050302534-1001.job
2016-09-16 09:12 - 2009-07-14 07:32 - 00000000 ____D C:\windows\system32\FxsTmp
2016-09-16 08:58 - 2016-05-21 22:18 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\TS3Client
2016-09-16 08:58 - 2015-05-19 10:37 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\uTorrent
2016-09-16 08:58 - 2015-04-17 10:09 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\DAEMON Tools Lite
2016-09-16 08:57 - 2016-07-15 23:19 - 00000000 ____D C:\windows\Minidump
2016-09-16 08:56 - 2015-05-10 16:12 - 00000000 ____D C:\Users\Dvorščák\Documents\MKD
2016-09-16 08:54 - 2015-09-23 20:51 - 00000000 ____D C:\Users\Dvorščák\Documents\My Games
2016-09-16 08:53 - 2015-04-17 10:06 - 00000000 ____D C:\Games
2016-09-16 08:47 - 2016-06-13 17:16 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\GHISLER
2016-09-16 08:47 - 2016-06-13 17:16 - 00000000 ____D C:\totalcmd
2016-09-16 08:47 - 2016-06-06 19:38 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\The Creative Assembly
2016-09-16 08:47 - 2016-04-04 16:20 - 00000000 ____D C:\Program Files (x86)\Bradbury
2016-09-16 08:46 - 2016-03-09 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2016-09-16 08:43 - 2016-02-25 16:40 - 00000000 ____D C:\Program Files (x86)\Lavalys
2016-09-16 08:41 - 2016-06-06 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prehistoryk
2016-09-16 08:41 - 2016-06-06 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Caveman Adventures
2016-09-15 22:25 - 2015-04-03 11:36 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\Skype
2016-09-15 13:01 - 2015-08-07 13:17 - 04066304 ___SH C:\Users\Dvorščák\Desktop\Thumbs.db
2016-09-15 08:35 - 2009-07-14 06:45 - 00446080 _____ C:\windows\system32\FNTCACHE.DAT
2016-09-15 00:22 - 2015-04-03 21:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-09-15 00:21 - 2015-04-03 21:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-09-15 00:21 - 2015-04-03 21:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-09-14 08:29 - 2015-06-24 07:52 - 00004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2016-09-14 08:29 - 2015-04-03 11:31 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-09-12 16:46 - 2015-04-04 11:28 - 00000000 ____D C:\Users\Dvorščák\Documents\Julka
2016-09-11 22:30 - 2015-11-13 20:56 - 00000000 ____D C:\Users\Dvorščák\Documents\FIFA 14
2016-09-08 15:17 - 2015-10-14 16:21 - 00000000 ____D C:\Program Files (x86)\Opera
2016-09-02 13:17 - 2015-07-23 18:58 - 00000000 ____D C:\Users\Dvorščák\AppData\Roaming\vlc
2016-08-29 21:30 - 2015-12-21 10:38 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-08-29 21:28 - 2015-04-03 11:36 - 00000000 ____D C:\ProgramData\Skype
2016-08-26 12:26 - 2009-07-14 07:08 - 00032544 _____ C:\windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2015-10-07 16:49 - 2015-10-07 16:49 - 0000000 _____ () C:\Users\Dvorščák\AppData\Roaming\69DA.tmp
2015-06-21 17:46 - 2015-06-21 17:46 - 0000000 _____ () C:\Users\Dvorščák\AppData\Roaming\9990.tmp
2016-04-04 20:51 - 2016-04-04 20:51 - 0003584 _____ () C:\Users\Dvorščák\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-05-30 17:56 - 2016-05-30 17:56 - 0000003 _____ () C:\Users\Dvorščák\AppData\Local\updater.log
2016-05-30 17:56 - 2016-08-06 13:32 - 0000424 _____ () C:\Users\Dvorščák\AppData\Local\UserProducts.xml
2012-08-26 11:38 - 2012-08-26 11:38 - 1914000 _____ (Adobe Systems Incorporated) C:\ProgramData\flashax10.exe

Files to move or delete:
====================
C:\ProgramData\flashax10.exe
C:\Users\Public\AlexaNSISPlugin.2316.dll


Some files in TEMP:
====================
C:\Users\Dvorščák\AppData\Local\Temp\libeay32.dll
C:\Users\Dvorščák\AppData\Local\Temp\msvcr120.dll
C:\Users\Dvorščák\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-05-08 13:40

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:440.59 GB) (Free:318.62 GB) NTFS

Available physical RAM: 4333.21 MB
Total physical RAM: 6038.82 MB
Percentage of memory in use: 28%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D7BDDC33)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=440.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=25.1 GB) - (Type=12)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_242_pepper.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\update-S-1-5-21-2898392049-1419488004-4050302534-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\ProgramData\Temp:888AFB86 [110]

==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Dvor矠k\Desktop" je 8 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVT
C:\Program Files\Lenovo\LVT\LJYZ.exe 1 [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Prosím kontrolu RSIT logu

Napsal: 17 zář 2016 12:05
od altrok
:arrow: Jedna se o soukrome nebo pracovni PC?


:arrow: Odinstalujte starou a zranitelnou verzi Javy. Pokud Javu potrebujete, pak nainstalujte novou z java.com/verify - pozor na adware pri instalaci. Pote se presvedcte, ze starsi verze jsou odinstalovane. Z hlediska bezpecnosti (zranitelnosti a exploity) je lepsi ji nemit. Aktualni je 8U101. Verze Javy, ktere v PC mate nainstalovane:

  • Java 8 Update 91 (64-bit)




  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CreateRestorePoint:
    CloseProcesses:
    File: C:\Program Files (x86)\FreePro Manager\service.exe
    Folder: C:\Program Files (x86)\FreePro Manager
    HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5585136 2015-03-31] (Disc Soft Ltd)
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [service.exe] => C:\Program Files (x86)\FreePro Manager\service.exe [1035776 2016-07-10] ()
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\MountPoints2: G - G:\SETUP.EXE
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\MountPoints2: {6f96561a-e4be-11e4-a3f2-eca86b6451ba} - E:\autorun.exe
    ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => No File
    ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => No File
    ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => No File
    ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => No File
    GroupPolicy: Restriction - Chrome <======= ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
    HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.omniboxes.com/?type=sc&ts=14 ... 9311093110
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    2016-09-16 10:38 - 2016-09-16 10:38 - 00000000 ____D C:\rsit
    2016-09-16 10:38 - 2016-09-16 10:38 - 00000000 ____D C:\Program Files\trend micro
    2016-09-16 10:37 - 2016-09-16 10:37 - 01222144 _____ C:\Users\Dvorščák\Downloads\RSITx64.exe
    CMD: del %appdata%\*.tmp
    2015-10-07 16:49 - 2015-10-07 16:49 - 0000000 _____ () C:\Users\Dvorščák\AppData\Roaming\69DA.tmp
    2015-06-21 17:46 - 2015-06-21 17:46 - 0000000 _____ () C:\Users\Dvorščák\AppData\Roaming\9990.tmp
    File: C:\ProgramData\flashax10.exe
    File: C:\Users\Public\AlexaNSISPlugin.2316.dll
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\update-S-1-5-21-2898392049-1419488004-4050302534-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    Task: C:\windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
    StartRegedit:
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    EndRegedit:
    Task: {0E85C50A-7395-4DB7-A8B6-8ED2D5FFC372} - System32\Tasks\{054E8C40-2E82-4FA3-BB37-62DE3E94C6AE} => pcalua.exe -a "C:\Games\TES 4\install_cz.exe" -d "C:\Games\TES 4"
    Task: {135B1AA6-EF5B-48FF-9E2F-75670F1AED32} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
    Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
    Task: {3FDCDB05-87C1-4A9E-8113-14CC2C21E6B7} - System32\Tasks\{E85C9354-92B7-488B-B669-F115E1248090} => pcalua.exe -a F:\Installer.exe -d F:\
    Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
    Task: {CAF28C92-024A-47EE-A94C-6B8FBAB6E2C8} - System32\Tasks\{528EE450-0439-4DB2-910A-73C04377099E} => C:\Users\Dvorščák\Downloads\NHL.09-RELOADED\CRACK\nhl2009.exe
    Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
    File: C:\Windows\system32\OFFICEICON.vbs
    Task: {F34872C9-B1D2-484F-B82E-6157D8E9B163} - System32\Tasks\{C9431845-31E9-4D31-B98E-CB2FCE21C54B} => pcalua.exe -a C:\Users\Dvorščák\Downloads\Oblivion_CZ_standard_105\InstallOblivionCZ.exe -d C:\Users\Dvorščák\Downloads\Oblivion_CZ_standard_105
    Task: {F9870102-8A45-494C-B5D9-B7BD6622D024} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
    Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
    Folder: C:\Users\Dvorščák\AppData\Roaming\Mozila
    AlternateDataStreams: C:\ProgramData\Temp:888AFB86 [110]
    CMD: dir "C:\PROGRA~1"
    CMD: dir "C:\PROGRA~2"
    CMD: dir "C:\PROGRA~3"
    CMD: dir "%localappdata%"
    CMD: dir "%appdata%"
    Hosts:
    EmptyTemp:
    End

Re: Prosím kontrolu RSIT logu

Napsal: 18 zář 2016 13:33
od D.Dixon
PC je skôr súkromný, hoci ho brat a sestra používajú do školy.
Javu som preinštaloval a adware mi ani neukazovalo ako doplnok pri inštalácii.
Tu je fixlog:


Fix result of Farbar Recovery Scan Tool (x64) Version: 17-09-2016
Ran by Dvorščák (18-09-2016 14:22:38) Run:1
Running from C:\Users\Dvorščák\Desktop
Loaded Profiles: Dvorščák & MSSQL$SQLEXPRESS & ReportServer$SQLEXPRESS & MSSQLFDLauncher$SQLEXPRESS (Available Profiles: Dvorščák & MSSQL$SQLEXPRESS & ReportServer$SQLEXPRESS & MSSQLFDLauncher$SQLEXPRESS)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
File: C:\Program Files (x86)\FreePro Manager\service.exe
Folder: C:\Program Files (x86)\FreePro Manager
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5585136 2015-03-31] (Disc Soft Ltd)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [service.exe] => C:\Program Files (x86)\FreePro Manager\service.exe [1035776 2016-07-10] ()
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\MountPoints2: G - G:\SETUP.EXE
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\MountPoints2: {6f96561a-e4be-11e4-a3f2-eca86b6451ba} - E:\autorun.exe
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.omniboxes.com/?type=sc&ts=14 ... 9311093110
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
2016-09-16 10:38 - 2016-09-16 10:38 - 00000000 ____D C:\rsit
2016-09-16 10:38 - 2016-09-16 10:38 - 00000000 ____D C:\Program Files\trend micro
2016-09-16 10:37 - 2016-09-16 10:37 - 01222144 _____ C:\Users\Dvorščák\Downloads\RSITx64.exe
CMD: del %appdata%\*.tmp
2015-10-07 16:49 - 2015-10-07 16:49 - 0000000 _____ () C:\Users\Dvorščák\AppData\Roaming\69DA.tmp
2015-06-21 17:46 - 2015-06-21 17:46 - 0000000 _____ () C:\Users\Dvorščák\AppData\Roaming\9990.tmp
File: C:\ProgramData\flashax10.exe
File: C:\Users\Public\AlexaNSISPlugin.2316.dll
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\update-S-1-5-21-2898392049-1419488004-4050302534-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
StartRegedit:
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
EndRegedit:
Task: {0E85C50A-7395-4DB7-A8B6-8ED2D5FFC372} - System32\Tasks\{054E8C40-2E82-4FA3-BB37-62DE3E94C6AE} => pcalua.exe -a "C:\Games\TES 4\install_cz.exe" -d "C:\Games\TES 4"
Task: {135B1AA6-EF5B-48FF-9E2F-75670F1AED32} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {3FDCDB05-87C1-4A9E-8113-14CC2C21E6B7} - System32\Tasks\{E85C9354-92B7-488B-B669-F115E1248090} => pcalua.exe -a F:\Installer.exe -d F:\
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CAF28C92-024A-47EE-A94C-6B8FBAB6E2C8} - System32\Tasks\{528EE450-0439-4DB2-910A-73C04377099E} => C:\Users\Dvorščák\Downloads\NHL.09-RELOADED\CRACK\nhl2009.exe
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
File: C:\Windows\system32\OFFICEICON.vbs
Task: {F34872C9-B1D2-484F-B82E-6157D8E9B163} - System32\Tasks\{C9431845-31E9-4D31-B98E-CB2FCE21C54B} => pcalua.exe -a C:\Users\Dvorščák\Downloads\Oblivion_CZ_standard_105\InstallOblivionCZ.exe -d C:\Users\Dvorščák\Downloads\Oblivion_CZ_standard_105
Task: {F9870102-8A45-494C-B5D9-B7BD6622D024} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
Folder: C:\Users\Dvorščák\AppData\Roaming\Mozila
AlternateDataStreams: C:\ProgramData\Temp:888AFB86 [110]
CMD: dir "C:\PROGRA~1"
CMD: dir "C:\PROGRA~2"
CMD: dir "C:\PROGRA~3"
CMD: dir "%localappdata%"
CMD: dir "%appdata%"
Hosts:
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.

========================= File: C:\Program Files (x86)\FreePro Manager\service.exe ========================

File not signed
MD5: B019ADCE113E4D87F06B33359C3EA117
Creation and modification date: 2016-07-19 15:37 - 2016-07-10 21:44
Size: 1035776
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:

====== End of File: ======


========================= Folder: C:\Program Files (x86)\FreePro Manager ========================

2016-07-19 15:37 - 2016-05-09 12:25 - 0001883 _____ () C:\Program Files (x86)\FreePro Manager\begin.htm
2016-07-19 15:37 - 2016-07-10 21:44 - 1035776 _____ () C:\Program Files (x86)\FreePro Manager\service.exe
2016-07-19 15:37 - 2013-11-16 01:29 - 0007530 _____ () C:\Program Files (x86)\FreePro Manager\tray.png

====== End of Folder: ======

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Windows\CurrentVersion\Run\\service.exe => value removed successfully
"HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G" => key removed successfully
"HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6f96561a-e4be-11e4-a3f2-eca86b6451ba}" => key removed successfully
HKCR\CLSID\{6f96561a-e4be-11e4-a3f2-eca86b6451ba} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp" => key removed successfully
HKCR\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending" => key removed successfully
HKCR\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot" => key removed successfully
HKCR\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared" => key removed successfully
HKCR\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51} => key not found.
C:\windows\system32\GroupPolicy\Machine => moved successfully
C:\windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
C:\rsit => moved successfully
C:\Program Files\trend micro => moved successfully
C:\Users\Dvorščák\Downloads\RSITx64.exe => moved successfully

========= del %appdata%\*.tmp =========


========= End of CMD: =========

"C:\Users\Dvorščák\AppData\Roaming\69DA.tmp" => not found.
"C:\Users\Dvorščák\AppData\Roaming\9990.tmp" => not found.

========================= File: C:\ProgramData\flashax10.exe ========================

File is digitally signed
MD5: C41B29F0FEE117CED47248CC7FECAD11
Creation and modification date: 2012-08-26 11:38 - 2012-08-26 11:38
Size: 1914000
Attributes: ----A
Company Name: Adobe Systems Incorporated
Internal Name:
Original Name:
Product: Adobe® Flash® Player ActiveX
Description: Adobe® Flash® Player ActiveX Installer
File Version: 1.0.20
Product Version: 10.0.22.87
Copyright: Copyright © 1996-2009 Adobe Systems Incorporated and its licensors. All Rights Reserved.

====== End of File: ======


========================= File: C:\Users\Public\AlexaNSISPlugin.2316.dll ========================

File not signed
MD5: D86CB3256D031F68CE38F909A824D161
Creation and modification date: 2012-08-26 11:41 - 2012-08-26 11:41
Size: 0090624
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:

====== End of File: ======

C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\windows\Tasks\update-S-1-5-21-2898392049-1419488004-4050302534-1001.job => moved successfully
C:\windows\Tasks\update-sys.job => moved successfully

====> Registry
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0E85C50A-7395-4DB7-A8B6-8ED2D5FFC372}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E85C50A-7395-4DB7-A8B6-8ED2D5FFC372}" => key removed successfully
C:\windows\System32\Tasks\{054E8C40-2E82-4FA3-BB37-62DE3E94C6AE} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{054E8C40-2E82-4FA3-BB37-62DE3E94C6AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{135B1AA6-EF5B-48FF-9E2F-75670F1AED32}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{135B1AA6-EF5B-48FF-9E2F-75670F1AED32}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3FDCDB05-87C1-4A9E-8113-14CC2C21E6B7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FDCDB05-87C1-4A9E-8113-14CC2C21E6B7}" => key removed successfully
C:\windows\System32\Tasks\{E85C9354-92B7-488B-B669-F115E1248090} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E85C9354-92B7-488B-B669-F115E1248090}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CAF28C92-024A-47EE-A94C-6B8FBAB6E2C8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAF28C92-024A-47EE-A94C-6B8FBAB6E2C8}" => key removed successfully
C:\windows\System32\Tasks\{528EE450-0439-4DB2-910A-73C04377099E} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{528EE450-0439-4DB2-910A-73C04377099E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector" => key removed successfully

========================= File: C:\Windows\system32\OFFICEICON.vbs ========================

"C:\Windows\system32\OFFICEICON.vbs" => not found.
====== End of File: ======

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F34872C9-B1D2-484F-B82E-6157D8E9B163}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F34872C9-B1D2-484F-B82E-6157D8E9B163}" => key removed successfully
C:\windows\System32\Tasks\{C9431845-31E9-4D31-B98E-CB2FCE21C54B} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C9431845-31E9-4D31-B98E-CB2FCE21C54B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F9870102-8A45-494C-B5D9-B7BD6622D024}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9870102-8A45-494C-B5D9-B7BD6622D024}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector" => key removed successfully

========================= Folder: C:\Users\Dvorščák\AppData\Roaming\Mozila ========================

not found.

====== End of Folder: ======

C:\ProgramData\Temp => ":888AFB86" ADS removed successfully.

========= dir "C:\PROGRA~1" =========

Volume in drive C has no label.
Volume Serial Number is 7A2D-73A9

Directory of C:\PROGRA~1

18. 09. 2016 14:22 <DIR> .
18. 09. 2016 14:22 <DIR> ..
08. 03. 2016 08:35 <DIR> AVAST Software
02. 04. 2015 20:14 <DIR> CCleaner
16. 05. 2016 10:03 <DIR> Common Files
17. 04. 2015 10:09 <DIR> DAEMON Tools Lite
18. 09. 2015 20:07 <DIR> DivX
30. 03. 2015 22:39 <DIR> DVD Maker
03. 04. 2015 08:51 <DIR> Epson Software
03. 04. 2015 08:04 <DIR> Google
26. 08. 2012 09:36 <DIR> Intel
15. 09. 2016 08:33 <DIR> Internet Explorer
26. 08. 2012 11:38 <DIR> Lenovo
03. 06. 2016 12:55 <DIR> Microsoft Analysis Services
15. 02. 2011 12:41 <DIR> Microsoft Games
03. 06. 2016 12:48 <DIR> Microsoft Help Viewer
19. 10. 2015 20:08 <DIR> Microsoft Office
15. 09. 2016 00:21 <DIR> Microsoft Silverlight
28. 07. 2016 22:41 <DIR> Microsoft SQL Server
03. 06. 2016 12:48 <DIR> Microsoft Visual Studio 10.0
03. 06. 2016 12:53 <DIR> Microsoft.NET
14. 07. 2009 07:32 <DIR> MSBuild
26. 08. 2012 09:39 <DIR> Realtek
14. 07. 2009 07:32 <DIR> Reference Assemblies
04. 04. 2015 09:15 <DIR> Windows Defender
26. 08. 2012 11:52 <DIR> Windows Live
30. 03. 2015 22:40 <DIR> Windows Mail
10. 03. 2016 16:21 <DIR> Windows Media Player
14. 07. 2009 07:32 <DIR> Windows NT
30. 03. 2015 22:40 <DIR> Windows Photo Viewer
21. 11. 2010 05:31 <DIR> Windows Portable Devices
30. 03. 2015 22:40 <DIR> Windows Sidebar
18. 04. 2015 13:38 <DIR> WinRAR
0 File(s) 0 bytes
33 Dir(s) 340˙759˙605˙248 bytes free

========= End of CMD: =========


========= dir "C:\PROGRA~2" =========

Volume in drive C has no label.
Volume Serial Number is 7A2D-73A9

Directory of C:\PROGRA~2

17. 09. 2016 20:38 <DIR> .
17. 09. 2016 20:38 <DIR> ..
06. 04. 2015 19:45 <DIR> ABBYY FineReader 9.0 Sprint
03. 04. 2015 11:31 <DIR> Adobe
29. 06. 2015 13:09 <DIR> AGEIA Technologies
16. 09. 2016 15:11 <DIR> Amazon
16. 09. 2016 08:47 <DIR> Bradbury
24. 06. 2015 14:58 <DIR> BRS
30. 08. 2012 15:11 27˙624 changes.txt
21. 06. 2016 16:48 <DIR> Cheat Engine 6.5.1
19. 06. 2016 18:52 <DIR> Cisco Packet Tracer 6.3
17. 09. 2016 20:39 <DIR> Common Files
16. 09. 2016 10:16 <DIR> DivX
03. 04. 2015 08:48 <DIR> epson
03. 04. 2015 08:51 <DIR> Epson Software
30. 08. 2012 15:20 2˙550˙968 fraps.exe
30. 08. 2012 15:20 234˙168 fraps32.dll
30. 08. 2012 15:20 68˙792 fraps64.dat
30. 08. 2012 15:20 186˙552 fraps64.dll
30. 08. 2012 15:17 140˙288 frapslcd.dll
19. 07. 2016 15:37 <DIR> FreePro Manager
16. 09. 2016 10:25 <DIR> Google
17. 09. 2016 06:16 <DIR> HELP
16. 05. 2016 10:03 <DIR> Intel
15. 09. 2016 08:33 <DIR> Internet Explorer
10. 10. 2015 18:48 <DIR> Inçtalaźky
17. 09. 2016 20:38 <DIR> Java
16. 09. 2016 08:43 <DIR> Lavalys
18. 09. 2015 20:08 <DIR> Lenovo
26. 08. 2012 11:39 <DIR> Lenovo Registration
03. 06. 2016 12:55 <DIR> Microsoft Analysis Services
17. 06. 2015 18:39 <DIR> Microsoft Games for Windows - LIVE
03. 06. 2016 12:56 <DIR> Microsoft Office
03. 06. 2016 12:48 <DIR> Microsoft SDKs
15. 09. 2016 00:21 <DIR> Microsoft Silverlight
28. 07. 2016 22:41 <DIR> Microsoft SQL Server
19. 10. 2015 19:59 <DIR> Microsoft SQL Server Compact Edition
19. 10. 2015 20:10 <DIR> Microsoft Visual Studio
03. 06. 2016 12:50 <DIR> Microsoft Visual Studio 10.0
19. 10. 2015 20:08 <DIR> Microsoft Visual Studio 8
19. 10. 2015 22:20 <DIR> Microsoft Works
03. 06. 2016 12:53 <DIR> Microsoft.NET
16. 09. 2016 15:02 <DIR> Mozilla Firefox
16. 09. 2016 15:02 <DIR> Mozilla Maintenance Service
16. 05. 2016 10:03 <DIR> MSBuild
23. 09. 2015 20:50 <DIR> MSXML 4.0
29. 06. 2015 13:09 <DIR> NVIDIA Corporation
17. 06. 2015 18:38 <DIR> OpenAL
08. 09. 2016 15:17 <DIR> Opera
28. 05. 2016 10:53 <DIR> PSPad editor
30. 08. 2012 15:09 1˙892 README.HTM
26. 08. 2012 09:39 <DIR> Realtek
17. 09. 2016 06:31 <DIR> Red Giant
17. 09. 2016 06:32 <DIR> Red Giant Link
14. 07. 2009 07:32 <DIR> Reference Assemblies
30. 05. 2016 17:56 <DIR> Skillbrains
29. 08. 2016 21:30 <DIR> Skype
23. 10. 2015 21:21 <DIR> Sony Setup
18. 09. 2016 14:12 <DIR> Steam
21. 12. 2015 09:41 <DIR> SugarSync
22. 07. 2016 20:18 <DIR> TeamSpeak 3 Client
17. 09. 2016 06:16 40˙445 uninstall.exe
23. 07. 2015 18:58 <DIR> VideoLAN
04. 04. 2015 09:15 <DIR> Windows Defender
26. 08. 2012 11:53 <DIR> Windows Live
30. 03. 2015 22:40 <DIR> Windows Mail
10. 03. 2016 16:21 <DIR> Windows Media Player
14. 07. 2009 07:32 <DIR> Windows NT
30. 03. 2015 22:40 <DIR> Windows Photo Viewer
21. 11. 2010 05:31 <DIR> Windows Portable Devices
30. 03. 2015 22:40 <DIR> Windows Sidebar
01. 11. 2015 19:15 <DIR> Youtube Movie Maker
8 File(s) 3˙250˙729 bytes
64 Dir(s) 340˙759˙605˙248 bytes free

========= End of CMD: =========


========= dir "C:\PROGRA~3" =========

Volume in drive C has no label.
Volume Serial Number is 7A2D-73A9

Directory of C:\PROGRA~3

03. 04. 2015 08:54 <DIR> ABBYY
03. 04. 2015 18:39 <DIR> Adobe
23. 09. 2015 20:51 <DIR> Age of Empires 3
08. 03. 2016 08:36 <DIR> AVAST Software
03. 04. 2015 08:04 <DIR> AVG2015
22. 07. 2015 19:54 <DIR> Codemasters
17. 04. 2015 10:09 <DIR> DAEMON Tools Lite
03. 04. 2015 20:44 <DIR> DAEMON Tools Pro
16. 09. 2016 10:16 <DIR> DivX
13. 06. 2015 21:29 <DIR> EA Core
13. 11. 2015 20:56 <DIR> Electronic Arts
06. 04. 2015 19:47 <DIR> EPSON
26. 08. 2012 11:38 1˙914˙000 flashax10.exe
26. 08. 2012 11:31 <DIR> Intel
17. 04. 2015 10:24 <DIR> Logs
03. 04. 2015 11:32 <DIR> McAfee
03. 04. 2015 08:04 <DIR> MFAData
15. 09. 2016 00:24 <DIR> Microsoft Help
17. 09. 2016 20:39 <DIR> Oracle
27. 04. 2016 18:56 <DIR> Origin
08. 04. 2016 14:52 <DIR> Package Cache
17. 09. 2016 06:32 <DIR> Red Giant
29. 08. 2016 21:28 <DIR> Skype
17. 04. 2015 10:30 <DIR> Solidshield
18. 04. 2015 13:47 <DIR> Steam
23. 10. 2015 22:09 <DIR> Temp
11. 12. 2015 21:57 <DIR> Ubisoft
03. 04. 2015 08:52 <DIR> UDL
1 File(s) 1˙914˙000 bytes
27 Dir(s) 340˙759˙601˙152 bytes free

========= End of CMD: =========


========= dir "%localappdata%" =========

Volume in drive C has no label.
Volume Serial Number is 7A2D-73A9

Directory of C:\Users\Dvorçź k\AppData\Local

18. 09. 2016 14:21 <DIR> .
18. 09. 2016 14:21 <DIR> ..
29. 06. 2015 12:39 <DIR> 2K Games
03. 04. 2015 08:54 <DIR> ABBYY
12. 08. 2016 09:07 <DIR> Adobe
01. 10. 2015 21:23 <DIR> Apps
09. 03. 2016 18:45 <DIR> Black_Tree_Gaming
09. 05. 2016 12:44 <DIR> CEF
04. 04. 2016 20:51 3˙584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
01. 10. 2015 21:23 <DIR> Deployment
08. 03. 2016 09:14 <DIR> Diagnostics
01. 11. 2015 19:13 <DIR> Downloaded Installations
16. 05. 2015 10:19 <DIR> EA Core
27. 02. 2016 17:15 <DIR> Eclipse
05. 05. 2015 10:14 <DIR> ElevatedDiagnostics
10. 10. 2015 18:24 <DIR> ESET
20. 10. 2015 12:00 116˙696 GDIPFONTCACHEV1.DAT
01. 10. 2015 21:25 <DIR> Google
01. 06. 2015 08:37 <DIR> GWX
18. 09. 2015 20:09 <DIR> Lenovo
02. 04. 2015 19:36 <DIR> MFAData
27. 07. 2016 17:19 <DIR> Microsoft
27. 03. 2016 13:28 <DIR> Microsoft Games
11. 11. 2015 00:26 <DIR> Microsoft Help
03. 06. 2016 13:06 <DIR> Microsoft_Corporation
04. 10. 2015 08:44 <DIR> Mozilla
18. 09. 2016 14:21 29˙696 MSGBOX.EXE
27. 07. 2016 17:52 <DIR> My Games
26. 09. 2015 11:16 <DIR> Oblivion
14. 10. 2015 16:22 <DIR> Opera Software
07. 06. 2016 22:34 <DIR> Overwolf
10. 10. 2015 18:12 <DIR> PlutoTV
17. 04. 2015 10:23 <DIR> Programs
29. 06. 2015 13:21 <DIR> SKIDROW
21. 12. 2015 10:38 <DIR> Skype
09. 03. 2016 18:21 <DIR> Skyrim
23. 10. 2015 21:24 <DIR> Sony
09. 05. 2016 12:44 <DIR> Steam
18. 09. 2016 14:22 <DIR> Temp
04. 04. 2015 17:18 <DIR> Unity
30. 05. 2016 17:56 3 updater.log
06. 08. 2016 13:32 424 UserProducts.xml
11. 12. 2015 22:07 <DIR> VirtualStore
30. 05. 2016 17:59 <DIR> Windows Live
22. 04. 2015 22:57 <DIR> {002D2A6E-F026-450C-B9C4-1705948B95C7}
24. 04. 2015 15:24 <DIR> {1C367D2D-B760-4A9E-9A10-32115BC5F2B0}
03. 05. 2016 22:03 <DIR> {2190282B-46A9-403A-8894-DBE5891D7B9F}
12. 08. 2015 18:27 <DIR> {27369B1E-68E4-4A57-A63C-C94E66D9E422}
12. 04. 2015 22:17 <DIR> {2BB7D452-5499-454E-BDD4-02D9FCE49CFC}
12. 03. 2016 14:52 <DIR> {2CACBEB6-6E01-4F9A-BF64-57D0C4A12E03}
20. 09. 2015 21:40 <DIR> {31655310-0723-4445-AB10-D9081D6283B4}
04. 06. 2015 22:23 <DIR> {32BADDE1-B44E-440E-9CF2-267DD3E8DE36}
30. 05. 2016 09:10 <DIR> {482F4540-CE2D-4E10-880A-9AF5197A6CAC}
05. 11. 2015 20:37 <DIR> {4BB373D0-267B-4A63-A9B8-FA1F0D72FAB8}
19. 09. 2015 12:03 <DIR> {4BD2B4E9-4C1C-49C4-938C-DAEC63CC670F}
17. 01. 2016 15:23 <DIR> {5132B782-77F7-40B6-9C22-7857A96A9CFA}
25. 04. 2016 20:01 <DIR> {56AB3A07-A7DA-4B7E-A8EE-48158C672030}
28. 10. 2015 17:58 <DIR> {629658DA-A711-42DA-89D8-903E5934D110}
04. 07. 2016 20:23 <DIR> {6382DED5-39C0-44E2-8737-B02FA849C4B1}
03. 04. 2016 15:52 <DIR> {641CD405-E19F-45DC-91A2-08F2C1EDC05E}
27. 09. 2015 16:50 <DIR> {68305D01-1B9C-4785-A198-43D8B3464061}
12. 03. 2016 14:51 <DIR> {69D6AEE5-341C-46AD-A86C-F5DBD6522CA1}
27. 03. 2016 13:06 <DIR> {6F77021B-3B62-419B-83E3-D56C4CD44394}
15. 12. 2015 22:16 <DIR> {7C6010F8-6185-405B-94E6-10E2D383588F}
09. 04. 2016 12:23 <DIR> {86388A80-C7A0-4699-A7BD-FAADB9809058}
23. 10. 2015 21:33 <DIR> {8C61355B-9FDB-4EFA-9100-C6E207320DC2}
12. 08. 2015 18:29 <DIR> {9690894C-549F-4150-BF27-F7FFAF6D0A18}
08. 09. 2015 12:58 <DIR> {A7277E5A-4B72-4CEC-9631-F5A7B5A8E953}
12. 04. 2015 22:18 <DIR> {CC44CD83-7421-48A5-8E04-1FAC314727B2}
04. 04. 2016 20:50 <DIR> {D98A6A35-0439-4E46-B237-66F3884AC745}
13. 06. 2016 21:21 <DIR> {E1CC6947-DDA9-4B94-A1D7-45F60D2ED93B}
5 File(s) 150˙403 bytes
66 Dir(s) 340˙759˙592˙960 bytes free

========= End of CMD: =========


========= dir "%appdata%" =========

Volume in drive C has no label.
Volume Serial Number is 7A2D-73A9

Directory of C:\Users\Dvorçź k\AppData\Roaming

18. 09. 2016 14:22 <DIR> .
18. 09. 2016 14:22 <DIR> ..
12. 04. 2015 19:13 <DIR> Adobe
13. 11. 2015 12:25 <DIR> AVAST Software
21. 09. 2015 19:16 <DIR> CadSoft
16. 09. 2016 08:58 <DIR> DAEMON Tools Lite
16. 09. 2016 10:13 <DIR> DivX
26. 04. 2015 20:06 <DIR> Epson
19. 07. 2016 15:40 <DIR> FreePro Manager
16. 09. 2016 08:47 <DIR> GHISLER
28. 03. 2015 15:30 <DIR> Identities
03. 04. 2015 08:50 <DIR> InstallShield
28. 03. 2015 15:30 <DIR> Intel Corporation
28. 03. 2015 15:30 <DIR> Leadertech
28. 03. 2015 15:31 <DIR> Macromedia
15. 02. 2011 12:41 <DIR> Media Center Programs
26. 08. 2016 00:07 <DIR> Mount&Blade Warband
01. 10. 2015 21:39 <DIR> Mozilla
23. 10. 2015 22:25 <DIR> Nero
14. 10. 2015 16:22 <DIR> Opera Software
21. 02. 2016 01:31 <DIR> PowerISO
13. 06. 2016 21:06 <DIR> PSpad
23. 10. 2015 21:24 <DIR> Publish Providers
17. 09. 2016 06:32 <DIR> Red Giant
15. 09. 2016 22:25 <DIR> Skype
23. 10. 2015 21:24 <DIR> Sony
17. 01. 2016 22:16 <DIR> Sun
16. 09. 2016 08:47 <DIR> The Creative Assembly
18. 09. 2016 11:58 <DIR> TS3Client
02. 04. 2015 19:43 <DIR> TuneUp Software
06. 04. 2015 12:00 <DIR> Unity
16. 09. 2016 08:58 <DIR> uTorrent
02. 09. 2016 13:17 <DIR> vlc
18. 04. 2015 13:38 <DIR> WinRAR
0 File(s) 0 bytes
34 Dir(s) 340˙759˙592˙960 bytes free

========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 12582912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 22457715 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 33269045 B
Edge => 0 B
Chrome => 130504871 B
Firefox => 373994018 B
Opera => 371835140 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58858277 B
systemprofile32 => 92130 B
LocalService => 0 B
NetworkService => 168552 B
Dvorščák => 64146706 B
MSSQL$SQLEXPRESS => 0 B
ReportServer$SQLEXPRESS => 0 B
MSSQLFDLauncher$SQLEXPRESS => 0 B

RecycleBin => 254316089 B
EmptyTemp: => 1.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 14:23:34 ====

Re: Prosím kontrolu RSIT logu

Napsal: 18 zář 2016 14:38
od altrok
Vyborne, pocitaci se ted hodne odlehcilo. Jake problemy na PC pozorujete ted?

Re: Prosím kontrolu RSIT logu

Napsal: 18 zář 2016 15:33
od D.Dixon
Problémy nejaké extra veľké nie sú, ale tak 2 také malé :)

Veľmi pomaly sa zapína a trvá to minimálne 3-4 minúty, kým sa dá niečo spustiť. Ale to je podľa mňa aj tým, že to nie je práve najvýkonnejší PC.

A potom ešte, keď sme na FB cez google chrome, tak tam ako sú rôzne príspevky, tak ani v jednom neukazuje obrázky a videá. No na opere alebo mozille, to ide všetko v pohode.
Názorná ukážka:
http://prntscr.com/cjficf

Re: Prosím kontrolu RSIT logu

Napsal: 19 zář 2016 09:20
od altrok
Na prvnim problemu se nepochybne podili i bloatware i Lenova. Pri startu pocitace se vam spousti na muj vkus zbytecne moc aplikaci a sluzeb.

Kód: Vybrat vše

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12850792 2011-09-05] (Realtek Semiconductor)
HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [jmekey] => C:\windows\jmesoft\hotkey.exe
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe
HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\Rapidboot\FBConsole.exe [1260128 2011-12-16] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\Lenovo Rescue System\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.)
HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-08-30] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [1009632 2016-08-29] (DivX, LLC)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-2898392049-1419488004-4050302534-1001\...\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE [283232 2015-04-06] (SEIKO EPSON CORPORATION)
Cast jich muzete zakazat nasledovne:
Win+R -> msconfig -> zalozka Po spusteni.



Resenim problemu s facebookem by mohlo byt preinstalovani Chromu. Zazalohujte zalozky a hesla napr. pomoci http://www.stahuj.centrum.cz/internet_a ... me-backup/ pak Chrome odinstalujte vcetne profilu a provedte cistou instalaci.