Kontrola logu - PC se neustále zasekává v prohlížeči
Napsal: 13 led 2017 14:08
Prosím o kontrolu logu PC se neustále zasekává v prohlížeči - vždy to napíše čeká na mezipamět a pak se to sekne úplně - nutný tvrdy restart předem díky
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-01-2017
Ran by Nark (administrator) on DESKTOP-FCT7QP6 (13-01-2017 13:37:57)
Running from C:\Users\Nark\Downloads
Loaded Profiles: Nark (Available Profiles: Nark)
Platform: Windows 10 Pro Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(CANON INC.) C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(ASUS) C:\Program Files (x86)\ASUS\PCE-AC68 WLAN Card Utilities\WlanMgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [486552 2012-09-27] (CANON INC.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [7536520 2016-09-07] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26287016 2017-01-06] (Dropbox, Inc.)
HKLM-x32\...\Run: [ABNotify] => C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe -auto
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{209a9738-8236-4e89-86a5-8c8ab5cca3ca}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{51b5cd53-3cd9-408a-b9ba-48e4a9f70edc}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2801192629-3347599642-1102522820-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default [2017-01-13]
CHR Extension: (Prezentace Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-11-16]
CHR Extension: (Dokumenty Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-16]
CHR Extension: (Disk Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-01]
CHR Extension: (YouTube) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-01]
CHR Extension: (GeoGebra Math Apps) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2016-08-02]
CHR Extension: (Adobe Acrobat) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-11]
CHR Extension: (Tabulky Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-16]
CHR Extension: (AudioSauna) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2016-08-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-01]
CHR Extension: (Outlook.com) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2016-08-02]
CHR Extension: (Gmail) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-01]
CHR Extension: (Chrome Media Router) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-19]
CHR HKU\S-1-5-21-2801192629-3347599642-1102522820-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hegneaniplmfjcmohoclabblbahcbjoe] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hegneaniplmfjcmohoclabblbahcbjoe] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
S3 cplspcon; C:\WINDOWS\system32\IntelCpHDCPSvc.exe [449112 2016-07-28] (Intel Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-15] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-15] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51504 2017-01-06] (Dropbox, Inc.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [374360 2016-07-28] (Intel Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmdag.sys [26559504 2016-10-01] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmpag.sys [527264 2016-10-01] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-07-24] (Advanced Micro Devices)
R3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [8510640 2014-02-06] (Broadcom Corporation)
S3 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [22568 2014-08-12] (IVT Corporation.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 IvtAudioBusSrv; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.)
S3 IvtPanBusSrv; C:\WINDOWS\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 PcaSp60; C:\Windows\SysWOW64\DRIVERS\PcaSp60.sys [38912 2010-09-07] (Printing Communications Assoc., Inc. (PCAUSA))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 BlueletAudio; \SystemRoot\system32\DRIVERS\blueletaudio.sys [X]
S3 BT; \SystemRoot\System32\drivers\btnetdrv.sys [X]
S3 BTCOM; \SystemRoot\system32\DRIVERS\btcomport.sys [X]
S3 Btcsrusb; \SystemRoot\System32\Drivers\btcusb.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 IvtComBusSrv; \SystemRoot\System32\Drivers\btcombus.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-13 13:37 - 2017-01-13 13:38 - 00016511 _____ C:\Users\Nark\Downloads\FRST.txt
2017-01-13 13:37 - 2017-01-13 13:37 - 00000000 ____D C:\FRST
2017-01-13 13:33 - 2017-01-13 13:33 - 02419200 _____ (Farbar) C:\Users\Nark\Downloads\FRST64.exe
2017-01-12 07:37 - 2017-01-12 07:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-01-12 07:36 - 2017-01-12 07:36 - 00000000 ___HD C:\OneDriveTemp
2017-01-09 17:57 - 2017-01-09 18:41 - 00001456 _____ C:\Users\Nark\AppData\Local\Adobe Save for Web 12.0 Prefs
2017-01-09 17:50 - 2017-01-09 17:50 - 00001440 _____ C:\Users\Nark\Desktop\Photoshop – zástupce.lnk
2017-01-09 12:03 - 2017-01-09 12:03 - 00001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2017-01-09 12:03 - 2017-01-09 12:03 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2017-01-09 12:03 - 2017-01-09 12:03 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2017-01-09 11:04 - 2017-01-09 11:04 - 00009616 _____ C:\Users\Nark\Downloads\JakubKade ábek.pdf
2017-01-09 11:03 - 2017-01-09 11:06 - 00000000 ____D C:\Users\Nark\Downloads\CreativeMarket - Resume Set Template
2017-01-07 23:02 - 2017-01-07 23:02 - 00414860 _____ C:\WINDOWS\Minidump\010717-6843-01.dmp
2017-01-07 23:02 - 2017-01-07 23:02 - 00000000 ____D C:\WINDOWS\Minidump
2017-01-07 16:05 - 2017-01-07 16:05 - 01919588 _____ C:\Users\Nark\Downloads\[CzT]James_Bond_Edice_k_50_vyroci_1080pHD_.torrent
2017-01-07 16:03 - 2017-01-07 16:03 - 00296695 _____ C:\Users\Nark\Downloads\[CzT]Casino_Royale_Casino_Royale_2006_1080p_.torrent
2017-01-07 16:00 - 2017-01-07 16:10 - 135240048 _____ C:\Users\Nark\Downloads\serviio-1.8-win-setup.exe
2017-01-07 15:48 - 2017-01-07 15:48 - 00039855 _____ C:\Users\Nark\Downloads\[CzT]Spectre_2015_CZ_720pHD_.torrent
2017-01-07 15:46 - 2017-01-07 15:46 - 00089720 _____ C:\Users\Nark\Downloads\[CzT]Osm_hroznych_The_Hateful_Eight_2015_CZ_EN_1080pHD_.torrent
2017-01-07 15:46 - 2017-01-07 15:46 - 00082573 _____ C:\Users\Nark\Downloads\[CzT]Martan_The_Martian_2015_CZ_EN_1080pHD_.torrent
2017-01-07 15:44 - 2017-01-07 15:44 - 00088054 _____ C:\Users\Nark\Downloads\[CzT]REVENANT_Zmrtvychvstani_The_Revenant_2015_CZ_EN_1080pHD_.torrent
2017-01-07 15:43 - 2017-01-07 15:43 - 00104325 _____ C:\Users\Nark\Downloads\[CzT]Star_Wars_Sila_se_probouzi_Star_Wars_The_Force_Awakens_2015_CZ_SK_EN_1080pHD_.torrent
2017-01-07 15:43 - 2017-01-07 15:43 - 00088403 _____ C:\Users\Nark\Downloads\[CzT]Sedm_statecnych_The_Magnificent_Seven_2016_CZ_EN_1080pHD_.torrent
2017-01-07 15:41 - 2017-01-07 15:41 - 00062802 _____ C:\Users\Nark\Downloads\[CzT]Teorie_velkeho_tresku_The_Big_Bang_Theory_9_serie_CZ_WebRip_720p_.torrent
2017-01-06 01:04 - 2017-01-06 01:04 - 00051504 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-01-05 17:03 - 2017-01-05 17:03 - 01711096 _____ C:\Users\Nark\Downloads\Chata Nebovidy - Kaderabek (1).pdf
2017-01-04 10:31 - 2017-01-04 10:31 - 00987197 _____ C:\Users\Nark\Desktop\uver_splaceni_cs.pdf
2017-01-02 12:02 - 2017-01-02 12:02 - 01711096 _____ C:\Users\Nark\Downloads\Chata Nebovidy - Kaderabek.pdf
2017-01-02 11:54 - 2017-01-02 11:54 - 00042401 _____ C:\Users\Nark\Downloads\a_RB_seznam_HYPO_mist_150629.xlsx
2017-01-02 11:52 - 2017-01-02 11:52 - 01395586 _____ C:\Users\Nark\Desktop\Nabídka HU_Kadeřábek.pdf
2016-12-28 13:53 - 2016-12-28 13:53 - 00703669 _____ C:\Users\Nark\Downloads\SPP_FLEXI_12_2016.pdf
2016-12-28 13:53 - 2016-12-28 13:53 - 00150033 _____ C:\Users\Nark\Downloads\VPP_OSOZIV14_12_2016.pdf
2016-12-28 13:45 - 2016-12-28 13:45 - 07964511 _____ C:\Users\Nark\Downloads\PP_garde_4_0.pdf
2016-12-23 19:56 - 2016-12-23 19:56 - 00382340 _____ C:\Users\Nark\Desktop\5884387-cocaine_extraction.pdf
2016-12-23 19:02 - 2016-12-23 19:02 - 00047610 _____ C:\Users\Nark\Downloads\dontyo1.mid
2016-12-23 10:54 - 2016-12-23 10:54 - 00068052 _____ C:\Users\Nark\Downloads\426843225_0_00712193_dad_0216_1604765349.pdf
2016-12-23 10:48 - 2016-12-23 10:48 - 00132415 _____ C:\Users\Nark\Downloads\zadost_hypo_ČS.doc
2016-12-23 10:41 - 2016-12-23 10:41 - 00322753 _____ C:\Users\Nark\Downloads\potvrzeni_prijmu_2015.pdf
2016-12-23 10:41 - 2016-12-23 10:41 - 00200192 _____ C:\Users\Nark\Downloads\prilohy podklady.xls
2016-12-23 10:41 - 2016-12-23 10:41 - 00056410 _____ C:\Users\Nark\Downloads\Zadost_HU_Unicredit.xls
2016-12-23 10:40 - 2016-12-23 10:40 - 00547070 _____ C:\Users\Nark\Desktop\939-zadost-o-hypo-hlavni-zadatel-01122016_Equa.pdf
2016-12-21 17:07 - 2016-12-21 17:07 - 00033792 _____ C:\Users\Nark\Downloads\Neco malo o nasi Materske skole Nebovidy (1).doc
2016-12-21 12:14 - 2016-12-21 12:14 - 00280299 _____ C:\Users\Nark\Downloads\17082008_003.jpg
2016-12-21 12:13 - 2016-12-21 12:13 - 00311353 _____ C:\Users\Nark\Downloads\Obraz011.jpg
2016-12-21 12:02 - 2016-12-21 13:50 - 00000000 ____D C:\Users\Nark\Desktop\Nebovidy_typovka
2016-12-20 12:13 - 2016-12-20 12:13 - 00000165 ____H C:\Users\Nark\Desktop\~$H4P-Jihava_1_12_2016.xlsx
2016-12-20 12:11 - 2016-12-23 10:06 - 00011041 _____ C:\Users\Nark\Desktop\H4P-Jihava_1_12_2016.xlsx
2016-12-19 17:57 - 2016-12-19 17:57 - 01018377 _____ C:\Users\Nark\Desktop\Podání kopie.pdf
2016-12-19 15:37 - 2016-12-19 15:37 - 00026718 _____ C:\Users\Nark\Downloads\426006957_0_oznameni_neucinnosti.pdf
2016-12-19 15:37 - 2016-12-19 15:37 - 00026718 _____ C:\Users\Nark\Downloads\426006957_0_oznameni_neucinnosti (1).pdf
2016-12-19 09:39 - 2016-12-19 09:39 - 00945695 _____ C:\Users\Nark\Downloads\objednávka leady scan.pdf
2016-12-16 18:39 - 2016-12-16 18:39 - 00000000 ____D C:\WINDOWS\LastGood
2016-12-14 16:58 - 2016-12-14 16:58 - 02849792 _____ C:\Users\Nark\Downloads\animation_luka.avi
2016-12-14 12:55 - 2016-12-14 12:56 - 00012934 _____ C:\Users\Nark\Downloads\Bendová.docx
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-13 13:37 - 2016-07-16 23:25 - 02145718 _____ C:\WINDOWS\system32\perfh005.dat
2017-01-13 13:37 - 2016-07-16 23:25 - 00608080 _____ C:\WINDOWS\system32\perfc005.dat
2017-01-13 13:37 - 2016-07-14 20:10 - 01014882 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-01-13 13:32 - 2016-07-14 20:08 - 00000000 ___RD C:\Users\Nark\OneDrive
2017-01-13 13:31 - 2016-08-09 18:00 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-13 13:31 - 2016-08-09 17:57 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-13 13:31 - 2016-08-09 17:57 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-01-13 10:41 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-12 14:32 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-12 14:31 - 2016-08-19 08:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-01-12 14:31 - 2016-08-09 17:58 - 00000000 ____D C:\Users\Nark
2017-01-12 08:05 - 2016-07-17 09:03 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-12 08:04 - 2016-07-17 09:03 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-01-12 07:40 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-12 07:37 - 2016-07-15 08:35 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-01-12 07:36 - 2016-07-17 09:52 - 00000000 ____D C:\Users\Nark\AppData\Local\Adobe
2017-01-11 22:16 - 2016-07-22 12:13 - 00000000 ____D C:\Users\Nark\AppData\Roaming\uTorrent
2017-01-11 21:45 - 2016-07-17 09:53 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 21:44 - 2016-08-09 18:00 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-01-09 21:40 - 2016-07-14 20:07 - 00000000 ____D C:\Users\Nark\AppData\Local\Packages
2017-01-09 17:57 - 2016-07-14 20:07 - 00000000 ____D C:\Users\Nark\AppData\Roaming\Adobe
2017-01-09 12:03 - 2016-07-17 09:53 - 00000000 ____D C:\ProgramData\Adobe
2017-01-09 12:03 - 2016-07-17 09:53 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-01-07 23:02 - 2016-07-15 23:26 - 1066999816 _____ C:\WINDOWS\MEMORY.DMP
2017-01-07 15:53 - 2016-07-31 17:33 - 00000000 ____D C:\Users\Nark\AppData\Local\SmartView2
2016-12-31 20:03 - 2016-07-22 11:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2016-12-31 20:03 - 2016-07-16 07:04 - 83361792 _____ C:\WINDOWS\system32\config\SOFTWARE
2016-12-31 20:03 - 2016-07-16 07:04 - 19660800 _____ C:\WINDOWS\system32\config\SYSTEM
2016-12-31 20:03 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\DEFAULT
2016-12-31 20:03 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-12-31 20:03 - 2016-07-16 07:04 - 00049152 _____ C:\WINDOWS\system32\config\SECURITY
2016-12-31 20:03 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\CatRoot
2016-12-19 18:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\catroot2
2016-12-19 16:23 - 2016-12-08 13:57 - 00000000 ____D C:\Users\Nark\Desktop\ZUZA
2016-12-19 09:16 - 2016-08-01 08:00 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-19 09:16 - 2016-08-01 08:00 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-19 09:10 - 2016-08-09 18:00 - 00003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-19 09:10 - 2016-08-09 18:00 - 00003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-19 09:10 - 2016-07-16 07:04 - 00000000 ___RD C:\Program Files (x86)
2016-12-19 09:10 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Tasks
2016-12-16 18:39 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2016-12-16 18:39 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\DriverStore
==================== Files in the root of some directories =======
2016-11-10 19:56 - 2016-11-10 19:56 - 0000600 _____ () C:\Users\Nark\AppData\Roaming\winscp.rnd
2017-01-09 17:57 - 2017-01-09 18:41 - 0001456 _____ () C:\Users\Nark\AppData\Local\Adobe Save for Web 12.0 Prefs
Some files in TEMP:
====================
C:\Users\Nark\AppData\Local\Temp\AcDeltree.exe
C:\Users\Nark\AppData\Local\Temp\AuConv.dll
C:\Users\Nark\AppData\Local\Temp\AuConvEx.dll
C:\Users\Nark\AppData\Local\Temp\bcdedit.exe
C:\Users\Nark\AppData\Local\Temp\Boot.dll
C:\Users\Nark\AppData\Local\Temp\BootDriver.dll
C:\Users\Nark\AppData\Local\Temp\bootsect.exe
C:\Users\Nark\AppData\Local\Temp\Burn.dll
C:\Users\Nark\AppData\Local\Temp\DataMana.dll
C:\Users\Nark\AppData\Local\Temp\DevCtrl.dll
C:\Users\Nark\AppData\Local\Temp\FatLib.dll
C:\Users\Nark\AppData\Local\Temp\GetDriverInfo.dll
C:\Users\Nark\AppData\Local\Temp\grubinst.exe
C:\Users\Nark\AppData\Local\Temp\ISOExportHome.exe
C:\Users\Nark\AppData\Local\Temp\MSVCP60.DLL
C:\Users\Nark\AppData\Local\Temp\RecLib.dll
C:\Users\Nark\AppData\Local\Temp\syslinux.exe
C:\Users\Nark\AppData\Local\Temp\tem1.exe
C:\Users\Nark\AppData\Local\Temp\UserRes.dll
C:\Users\Nark\AppData\Local\Temp\UserResEx.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-09 19:07
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-01-2017
Ran by Nark (administrator) on DESKTOP-FCT7QP6 (13-01-2017 13:37:57)
Running from C:\Users\Nark\Downloads
Loaded Profiles: Nark (Available Profiles: Nark)
Platform: Windows 10 Pro Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(CANON INC.) C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(ASUS) C:\Program Files (x86)\ASUS\PCE-AC68 WLAN Card Utilities\WlanMgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [486552 2012-09-27] (CANON INC.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-07] (Microsoft Corporation)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [7536520 2016-09-07] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26287016 2017-01-06] (Dropbox, Inc.)
HKLM-x32\...\Run: [ABNotify] => C:\Program Files (x86)\AOMEI Backupper\ABNotify.exe -auto
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-06] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{209a9738-8236-4e89-86a5-8c8ab5cca3ca}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{51b5cd53-3cd9-408a-b9ba-48e4a9f70edc}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2801192629-3347599642-1102522820-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default [2017-01-13]
CHR Extension: (Prezentace Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-11-16]
CHR Extension: (Dokumenty Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-16]
CHR Extension: (Disk Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-01]
CHR Extension: (YouTube) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-01]
CHR Extension: (GeoGebra Math Apps) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2016-08-02]
CHR Extension: (Adobe Acrobat) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-11]
CHR Extension: (Tabulky Google) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-16]
CHR Extension: (AudioSauna) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2016-08-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-01]
CHR Extension: (Outlook.com) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2016-08-02]
CHR Extension: (Gmail) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-01]
CHR Extension: (Chrome Media Router) - C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-19]
CHR HKU\S-1-5-21-2801192629-3347599642-1102522820-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hegneaniplmfjcmohoclabblbahcbjoe] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hegneaniplmfjcmohoclabblbahcbjoe] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
S3 cplspcon; C:\WINDOWS\system32\IntelCpHDCPSvc.exe [449112 2016-07-28] (Intel Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-15] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-15] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51504 2017-01-06] (Dropbox, Inc.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [374360 2016-07-28] (Intel Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmdag.sys [26559504 2016-10-01] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmpag.sys [527264 2016-10-01] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-07-24] (Advanced Micro Devices)
R3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [8510640 2014-02-06] (Broadcom Corporation)
S3 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [22568 2014-08-12] (IVT Corporation.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 IvtAudioBusSrv; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.)
S3 IvtPanBusSrv; C:\WINDOWS\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 PcaSp60; C:\Windows\SysWOW64\DRIVERS\PcaSp60.sys [38912 2010-09-07] (Printing Communications Assoc., Inc. (PCAUSA))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 BlueletAudio; \SystemRoot\system32\DRIVERS\blueletaudio.sys [X]
S3 BT; \SystemRoot\System32\drivers\btnetdrv.sys [X]
S3 BTCOM; \SystemRoot\system32\DRIVERS\btcomport.sys [X]
S3 Btcsrusb; \SystemRoot\System32\Drivers\btcusb.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 IvtComBusSrv; \SystemRoot\System32\Drivers\btcombus.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-13 13:37 - 2017-01-13 13:38 - 00016511 _____ C:\Users\Nark\Downloads\FRST.txt
2017-01-13 13:37 - 2017-01-13 13:37 - 00000000 ____D C:\FRST
2017-01-13 13:33 - 2017-01-13 13:33 - 02419200 _____ (Farbar) C:\Users\Nark\Downloads\FRST64.exe
2017-01-12 07:37 - 2017-01-12 07:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-01-12 07:36 - 2017-01-12 07:36 - 00000000 ___HD C:\OneDriveTemp
2017-01-09 17:57 - 2017-01-09 18:41 - 00001456 _____ C:\Users\Nark\AppData\Local\Adobe Save for Web 12.0 Prefs
2017-01-09 17:50 - 2017-01-09 17:50 - 00001440 _____ C:\Users\Nark\Desktop\Photoshop – zástupce.lnk
2017-01-09 12:03 - 2017-01-09 12:03 - 00001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2017-01-09 12:03 - 2017-01-09 12:03 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2017-01-09 12:03 - 2017-01-09 12:03 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2017-01-09 11:04 - 2017-01-09 11:04 - 00009616 _____ C:\Users\Nark\Downloads\JakubKade ábek.pdf
2017-01-09 11:03 - 2017-01-09 11:06 - 00000000 ____D C:\Users\Nark\Downloads\CreativeMarket - Resume Set Template
2017-01-07 23:02 - 2017-01-07 23:02 - 00414860 _____ C:\WINDOWS\Minidump\010717-6843-01.dmp
2017-01-07 23:02 - 2017-01-07 23:02 - 00000000 ____D C:\WINDOWS\Minidump
2017-01-07 16:05 - 2017-01-07 16:05 - 01919588 _____ C:\Users\Nark\Downloads\[CzT]James_Bond_Edice_k_50_vyroci_1080pHD_.torrent
2017-01-07 16:03 - 2017-01-07 16:03 - 00296695 _____ C:\Users\Nark\Downloads\[CzT]Casino_Royale_Casino_Royale_2006_1080p_.torrent
2017-01-07 16:00 - 2017-01-07 16:10 - 135240048 _____ C:\Users\Nark\Downloads\serviio-1.8-win-setup.exe
2017-01-07 15:48 - 2017-01-07 15:48 - 00039855 _____ C:\Users\Nark\Downloads\[CzT]Spectre_2015_CZ_720pHD_.torrent
2017-01-07 15:46 - 2017-01-07 15:46 - 00089720 _____ C:\Users\Nark\Downloads\[CzT]Osm_hroznych_The_Hateful_Eight_2015_CZ_EN_1080pHD_.torrent
2017-01-07 15:46 - 2017-01-07 15:46 - 00082573 _____ C:\Users\Nark\Downloads\[CzT]Martan_The_Martian_2015_CZ_EN_1080pHD_.torrent
2017-01-07 15:44 - 2017-01-07 15:44 - 00088054 _____ C:\Users\Nark\Downloads\[CzT]REVENANT_Zmrtvychvstani_The_Revenant_2015_CZ_EN_1080pHD_.torrent
2017-01-07 15:43 - 2017-01-07 15:43 - 00104325 _____ C:\Users\Nark\Downloads\[CzT]Star_Wars_Sila_se_probouzi_Star_Wars_The_Force_Awakens_2015_CZ_SK_EN_1080pHD_.torrent
2017-01-07 15:43 - 2017-01-07 15:43 - 00088403 _____ C:\Users\Nark\Downloads\[CzT]Sedm_statecnych_The_Magnificent_Seven_2016_CZ_EN_1080pHD_.torrent
2017-01-07 15:41 - 2017-01-07 15:41 - 00062802 _____ C:\Users\Nark\Downloads\[CzT]Teorie_velkeho_tresku_The_Big_Bang_Theory_9_serie_CZ_WebRip_720p_.torrent
2017-01-06 01:04 - 2017-01-06 01:04 - 00051504 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-01-06 00:48 - 2017-01-06 00:48 - 00075888 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-01-05 17:03 - 2017-01-05 17:03 - 01711096 _____ C:\Users\Nark\Downloads\Chata Nebovidy - Kaderabek (1).pdf
2017-01-04 10:31 - 2017-01-04 10:31 - 00987197 _____ C:\Users\Nark\Desktop\uver_splaceni_cs.pdf
2017-01-02 12:02 - 2017-01-02 12:02 - 01711096 _____ C:\Users\Nark\Downloads\Chata Nebovidy - Kaderabek.pdf
2017-01-02 11:54 - 2017-01-02 11:54 - 00042401 _____ C:\Users\Nark\Downloads\a_RB_seznam_HYPO_mist_150629.xlsx
2017-01-02 11:52 - 2017-01-02 11:52 - 01395586 _____ C:\Users\Nark\Desktop\Nabídka HU_Kadeřábek.pdf
2016-12-28 13:53 - 2016-12-28 13:53 - 00703669 _____ C:\Users\Nark\Downloads\SPP_FLEXI_12_2016.pdf
2016-12-28 13:53 - 2016-12-28 13:53 - 00150033 _____ C:\Users\Nark\Downloads\VPP_OSOZIV14_12_2016.pdf
2016-12-28 13:45 - 2016-12-28 13:45 - 07964511 _____ C:\Users\Nark\Downloads\PP_garde_4_0.pdf
2016-12-23 19:56 - 2016-12-23 19:56 - 00382340 _____ C:\Users\Nark\Desktop\5884387-cocaine_extraction.pdf
2016-12-23 19:02 - 2016-12-23 19:02 - 00047610 _____ C:\Users\Nark\Downloads\dontyo1.mid
2016-12-23 10:54 - 2016-12-23 10:54 - 00068052 _____ C:\Users\Nark\Downloads\426843225_0_00712193_dad_0216_1604765349.pdf
2016-12-23 10:48 - 2016-12-23 10:48 - 00132415 _____ C:\Users\Nark\Downloads\zadost_hypo_ČS.doc
2016-12-23 10:41 - 2016-12-23 10:41 - 00322753 _____ C:\Users\Nark\Downloads\potvrzeni_prijmu_2015.pdf
2016-12-23 10:41 - 2016-12-23 10:41 - 00200192 _____ C:\Users\Nark\Downloads\prilohy podklady.xls
2016-12-23 10:41 - 2016-12-23 10:41 - 00056410 _____ C:\Users\Nark\Downloads\Zadost_HU_Unicredit.xls
2016-12-23 10:40 - 2016-12-23 10:40 - 00547070 _____ C:\Users\Nark\Desktop\939-zadost-o-hypo-hlavni-zadatel-01122016_Equa.pdf
2016-12-21 17:07 - 2016-12-21 17:07 - 00033792 _____ C:\Users\Nark\Downloads\Neco malo o nasi Materske skole Nebovidy (1).doc
2016-12-21 12:14 - 2016-12-21 12:14 - 00280299 _____ C:\Users\Nark\Downloads\17082008_003.jpg
2016-12-21 12:13 - 2016-12-21 12:13 - 00311353 _____ C:\Users\Nark\Downloads\Obraz011.jpg
2016-12-21 12:02 - 2016-12-21 13:50 - 00000000 ____D C:\Users\Nark\Desktop\Nebovidy_typovka
2016-12-20 12:13 - 2016-12-20 12:13 - 00000165 ____H C:\Users\Nark\Desktop\~$H4P-Jihava_1_12_2016.xlsx
2016-12-20 12:11 - 2016-12-23 10:06 - 00011041 _____ C:\Users\Nark\Desktop\H4P-Jihava_1_12_2016.xlsx
2016-12-19 17:57 - 2016-12-19 17:57 - 01018377 _____ C:\Users\Nark\Desktop\Podání kopie.pdf
2016-12-19 15:37 - 2016-12-19 15:37 - 00026718 _____ C:\Users\Nark\Downloads\426006957_0_oznameni_neucinnosti.pdf
2016-12-19 15:37 - 2016-12-19 15:37 - 00026718 _____ C:\Users\Nark\Downloads\426006957_0_oznameni_neucinnosti (1).pdf
2016-12-19 09:39 - 2016-12-19 09:39 - 00945695 _____ C:\Users\Nark\Downloads\objednávka leady scan.pdf
2016-12-16 18:39 - 2016-12-16 18:39 - 00000000 ____D C:\WINDOWS\LastGood
2016-12-14 16:58 - 2016-12-14 16:58 - 02849792 _____ C:\Users\Nark\Downloads\animation_luka.avi
2016-12-14 12:55 - 2016-12-14 12:56 - 00012934 _____ C:\Users\Nark\Downloads\Bendová.docx
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-13 13:37 - 2016-07-16 23:25 - 02145718 _____ C:\WINDOWS\system32\perfh005.dat
2017-01-13 13:37 - 2016-07-16 23:25 - 00608080 _____ C:\WINDOWS\system32\perfc005.dat
2017-01-13 13:37 - 2016-07-14 20:10 - 01014882 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-01-13 13:32 - 2016-07-14 20:08 - 00000000 ___RD C:\Users\Nark\OneDrive
2017-01-13 13:31 - 2016-08-09 18:00 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-01-13 13:31 - 2016-08-09 17:57 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-01-13 13:31 - 2016-08-09 17:57 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-01-13 10:41 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-01-12 14:32 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-12 14:31 - 2016-08-19 08:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-01-12 14:31 - 2016-08-09 17:58 - 00000000 ____D C:\Users\Nark
2017-01-12 08:05 - 2016-07-17 09:03 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-01-12 08:04 - 2016-07-17 09:03 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-01-12 07:40 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-01-12 07:37 - 2016-07-15 08:35 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-01-12 07:36 - 2016-07-17 09:52 - 00000000 ____D C:\Users\Nark\AppData\Local\Adobe
2017-01-11 22:16 - 2016-07-22 12:13 - 00000000 ____D C:\Users\Nark\AppData\Roaming\uTorrent
2017-01-11 21:45 - 2016-07-17 09:53 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-11 21:44 - 2016-08-09 18:00 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-01-09 21:40 - 2016-07-14 20:07 - 00000000 ____D C:\Users\Nark\AppData\Local\Packages
2017-01-09 17:57 - 2016-07-14 20:07 - 00000000 ____D C:\Users\Nark\AppData\Roaming\Adobe
2017-01-09 12:03 - 2016-07-17 09:53 - 00000000 ____D C:\ProgramData\Adobe
2017-01-09 12:03 - 2016-07-17 09:53 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-01-07 23:02 - 2016-07-15 23:26 - 1066999816 _____ C:\WINDOWS\MEMORY.DMP
2017-01-07 15:53 - 2016-07-31 17:33 - 00000000 ____D C:\Users\Nark\AppData\Local\SmartView2
2016-12-31 20:03 - 2016-07-22 11:20 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2016-12-31 20:03 - 2016-07-16 07:04 - 83361792 _____ C:\WINDOWS\system32\config\SOFTWARE
2016-12-31 20:03 - 2016-07-16 07:04 - 19660800 _____ C:\WINDOWS\system32\config\SYSTEM
2016-12-31 20:03 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\DEFAULT
2016-12-31 20:03 - 2016-07-16 07:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-12-31 20:03 - 2016-07-16 07:04 - 00049152 _____ C:\WINDOWS\system32\config\SECURITY
2016-12-31 20:03 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\CatRoot
2016-12-19 18:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\catroot2
2016-12-19 16:23 - 2016-12-08 13:57 - 00000000 ____D C:\Users\Nark\Desktop\ZUZA
2016-12-19 09:16 - 2016-08-01 08:00 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-19 09:16 - 2016-08-01 08:00 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-19 09:10 - 2016-08-09 18:00 - 00003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-19 09:10 - 2016-08-09 18:00 - 00003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-19 09:10 - 2016-07-16 07:04 - 00000000 ___RD C:\Program Files (x86)
2016-12-19 09:10 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Tasks
2016-12-16 18:39 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2016-12-16 18:39 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\DriverStore
==================== Files in the root of some directories =======
2016-11-10 19:56 - 2016-11-10 19:56 - 0000600 _____ () C:\Users\Nark\AppData\Roaming\winscp.rnd
2017-01-09 17:57 - 2017-01-09 18:41 - 0001456 _____ () C:\Users\Nark\AppData\Local\Adobe Save for Web 12.0 Prefs
Some files in TEMP:
====================
C:\Users\Nark\AppData\Local\Temp\AcDeltree.exe
C:\Users\Nark\AppData\Local\Temp\AuConv.dll
C:\Users\Nark\AppData\Local\Temp\AuConvEx.dll
C:\Users\Nark\AppData\Local\Temp\bcdedit.exe
C:\Users\Nark\AppData\Local\Temp\Boot.dll
C:\Users\Nark\AppData\Local\Temp\BootDriver.dll
C:\Users\Nark\AppData\Local\Temp\bootsect.exe
C:\Users\Nark\AppData\Local\Temp\Burn.dll
C:\Users\Nark\AppData\Local\Temp\DataMana.dll
C:\Users\Nark\AppData\Local\Temp\DevCtrl.dll
C:\Users\Nark\AppData\Local\Temp\FatLib.dll
C:\Users\Nark\AppData\Local\Temp\GetDriverInfo.dll
C:\Users\Nark\AppData\Local\Temp\grubinst.exe
C:\Users\Nark\AppData\Local\Temp\ISOExportHome.exe
C:\Users\Nark\AppData\Local\Temp\MSVCP60.DLL
C:\Users\Nark\AppData\Local\Temp\RecLib.dll
C:\Users\Nark\AppData\Local\Temp\syslinux.exe
C:\Users\Nark\AppData\Local\Temp\tem1.exe
C:\Users\Nark\AppData\Local\Temp\UserRes.dll
C:\Users\Nark\AppData\Local\Temp\UserResEx.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-09 19:07
==================== End of FRST.txt ============================