Vir po stažení programu na snímaní plochy
Napsal: 15 úno 2017 17:18
Dobrý den,
Po stažení programu a následné instalaci mi automaticky program začal stahovat spoustu souborů (aliexpres...) a podobně. V systému je nainstalováno spousta zbytečností, pravděpodobně různé malwary.
Mohli byste se na to kouknout?
Log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 01
Ran by Marťas (administrator) on DESKTOP-IMU1TCG (15-02-2017 17:14:03)
Running from C:\Users\Marťas\Desktop
Loaded Profiles: Marťas (Available Profiles: defaultuser0 & Marťas)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\ProgramData\NetworkPacketManitor\Nettrans.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.16122.10291.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1701.10102.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-12-17] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16405744 2015-09-10] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3351248 2015-09-10] (ELAN Microelectronics Corp.)
HKLM\...\RunOnce: [*Restore] => C:\WINDOWS\System32\rstrui.exe [268288 2016-07-16] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] wscript C:\WINDOWS\run.vbs,
HKLM-x32\...\Winlogon: [Userinit] wscript C:\WINDOWS\run.vbs,
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [OneDrive] => C:\Users\Marťas\AppData\Local\Microsoft\OneDrive\OneDrive.exe [1517280 2017-01-13] (Microsoft Corporation) <===== ATTENTION
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27226072 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [GoogleChromeAutoLaunch_F2169D7533533C5932816DA6EE4B0D3B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1116504 2017-02-01] (Google Inc.)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [MyComGames] => C:\Users\Marťas\AppData\Local\MyComGames\MyComGames.exe [5013392 2017-02-14] (MY.COM B.V.) <===== ATTENTION
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [produpd] => "C:\Users\Marťas\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe" /20506 <===== ATTENTION
HKLM\...\Providers\qs4j0wbq: C:\Program Files (x86)\Coitoy Manager\local64spl.dll [307200 2017-02-14] ()
AppInit_DLLs: C:\ProgramData\Ronzap\Stockin.dll => C:\ProgramData\Ronzap\Stockin.dll [358912 2017-02-15] ()
AppInit_DLLs-x32: C:\ProgramData\Ronzap\U-Zumstrong.dll => C:\ProgramData\Ronzap\U-Zumstrong.dll [248320 2017-02-15] ()
ShellExecuteHooks: No Name - {8A2A2C62-EEB8-11E6-9AB6-64006A5CFC23} - C:\Users\Marťas\AppData\Roaming\Grjelyckojule\Coosak.dll -> No File
Startup: C:\Users\Marťas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\monhost.lnk [2017-02-15] <===== ATTENTION
ShortcutTarget: monhost.lnk -> C:\Users\Marťas\AppData\Roaming\VDI\Shared\Product Updater\monhost.exe (No File)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{02c273f3-199c-452b-9e83-6cf7b4ac56ca}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{03d29909-5cf5-4c48-9d1c-6d0c9b13c62d}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Internet Explorer:
==================
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXNK-9KXdsNt4TNE5gx242qujwVNkv7VFQPatKgidUULgpokjiR3t_QNSkGSP9oKoVCfMXQBx0uNbS8L36e0FA8kWLIom
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1626131941-1098701557-2232362238-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1626131941-1098701557-2232362238-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
FireFox:
========
FF DefaultProfile: pjvuic15.default
FF ProfilePath: C:\Users\Marťas\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\pjvuic15.default\Profiles\pjvuic15.default [not found]
FF ProfilePath: C:\Users\Marťas\AppData\Roaming\Mozilla\Firefox\Profiles\pjvuic15.default [2017-02-15]
FF NewTab: Mozilla\Firefox\Profiles\pjvuic15.default -> C:\\ProgramData\\Ronzaps\\ff.NT
FF Homepage: Mozilla\Firefox\Profiles\pjvuic15.default -> C:\\ProgramData\\Ronzaps\\ff.HP
FF Extension: (Adblocker for Youtube™) - C:\Program Files (x86)\Mozilla Firefox\browser\features\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} [2017-02-14] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-02-05] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-02-05] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-1626131941-1098701557-2232362238-1001: @my.com/Games -> C:\Users\Marťas\AppData\Local\MyComGames\NPMyComDetector.dll [2017-02-12] (MY.COM B.V.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.trotux.com/?z=0193a36a0277feb42dd07 ... UH&type=hp
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=0193a36a0277feb42dd07 ... UH&type=hp"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}& ... UH&type=sp
CHR DefaultSearchKeyword: ChromeDefaultData -> trotux
CHR Profile: C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-15] <==== ATTENTION
CHR Extension: (Prezentace Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-08]
CHR Extension: (Dokumenty Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-08]
CHR Extension: (Disk Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-08]
CHR Extension: (YouTube) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-08]
CHR Extension: (Steam Inventory Helper) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2017-02-14]
CHR Extension: (Tabulky Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-08]
CHR Extension: (Splinter Search) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fnhfdmnphmbbjbgppnpcddkefmeokfho [2017-02-15]
CHR Extension: (Dokumenty Google offline) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-09]
CHR Extension: (Adblocker pro Youtube™) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-08]
CHR Extension: (Gmail) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-08]
CHR Extension: (Chrome Media Router) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [145624 2015-09-10] (ELAN Microelectronics Corp.)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [328624 2015-10-07] (Intel Corporation)
R2 Nettrans; C:\ProgramData\NetworkPacketManitor\Nettrans.exe [43520 2017-02-15] () [File not signed]
S2 Ronzap; C:\ProgramData\\Ronzap\\Ronzap.exe [983040 2017-02-15] () [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Marťas\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-15] (TODO: <Company name>) [File not signed]
S2 WinSnare; C:\Users\Marťas\AppData\Roaming\WinSnare\WinSnare.dll [779776 2017-02-08] (InterSect Alliance Pty Ltd) [File not signed]
S2 serverss; C:\WINDOWS\Temp\E12D.tmp [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 FreshIO; C:\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys [2410 2004-10-26] () [File not signed]
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [59840 2015-11-16] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [410848 2015-08-13] (Realsil Semiconductor Corporation)
S1 ucdrv; C:\Program Files (x86)\UCBrowser\Security:ucdrv-x64.sys [25444 ] (UC Web Inc.) <==== ATTENTION
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-15 17:14 - 2017-02-15 17:14 - 00014491 _____ C:\Users\Marťas\Desktop\FRST.txt
2017-02-15 17:13 - 2017-02-15 17:14 - 00000000 ____D C:\FRST
2017-02-15 17:13 - 2017-02-15 17:13 - 02422272 _____ (Farbar) C:\Users\Marťas\Desktop\FRST64.exe
2017-02-15 17:13 - 2017-02-15 17:13 - 00112640 _____ (forum.viry.cz) C:\Users\Marťas\Desktop\FRSTLauncher.exe
2017-02-15 14:47 - 2017-02-15 14:47 - 00003744 _____ C:\WINDOWS\System32\Tasks\{FF362657-05F5-418A-B833-872C21AA43F5}
2017-02-15 14:16 - 2017-02-15 14:16 - 00000000 ___HD C:\$AV_ASW
2017-02-15 14:16 - 2017-02-15 14:16 - 00000000 ____D C:\Users\TEMP.DESKTOP-IMU1TCG\AppData\Roaming\AVAST Software
2017-02-15 14:15 - 2017-02-15 14:20 - 00000000 ____D C:\Users\TEMP.DESKTOP-IMU1TCG\AppData\Local\Packages
2017-02-15 14:15 - 2017-02-15 14:20 - 00000000 ____D C:\Users\TEMP.DESKTOP-IMU1TCG
2017-02-15 14:15 - 2017-02-15 14:15 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\AVAST Software
2017-02-15 14:11 - 2017-02-15 14:11 - 00000000 ____D C:\Users\Default\AppData\Local\NetworkTiles
2017-02-15 14:11 - 2017-02-15 14:11 - 00000000 ____D C:\Users\Default User\AppData\Local\NetworkTiles
2017-02-15 14:10 - 2017-02-15 14:15 - 00000000 ____D C:\Users\TEMP
2017-02-15 14:08 - 2017-02-15 14:08 - 00000000 ____D C:\Users\Default\winhttp
2017-02-15 13:34 - 2017-02-15 13:34 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\AVAST Software
2017-02-15 13:33 - 2017-02-15 13:33 - 00000000 ____D C:\Program Files\Common Files\AV
2017-02-15 13:22 - 2017-02-15 13:22 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\SMRecorder
2017-02-15 13:21 - 2017-02-15 13:21 - 00000000 ____D C:\Users\Marťas\Documents\SMRecorder
2017-02-15 13:16 - 2017-02-15 13:38 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-15 13:16 - 2017-02-15 13:38 - 00000000 ____D C:\Program Files\AVAST Software
2017-02-15 13:09 - 2017-02-15 13:09 - 00000000 ____D C:\Program Files (x86)\qs4j0wbq
2017-02-15 12:28 - 2017-02-15 12:28 - 00003334 _____ C:\WINDOWS\System32\Tasks\psv_Dentola
2017-02-15 12:27 - 2017-02-15 14:40 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-02-15 11:38 - 2017-02-15 11:38 - 00003306 _____ C:\WINDOWS\System32\Tasks\psv_S-it
2017-02-15 11:35 - 2017-02-15 12:31 - 00003658 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2017-02-15 11:33 - 2017-02-15 11:33 - 00003314 _____ C:\WINDOWS\System32\Tasks\psv_Zaamtax
2017-02-15 11:28 - 2017-02-15 11:28 - 00003692 _____ C:\WINDOWS\System32\Tasks\WinTOOL
2017-02-15 11:27 - 2017-02-15 14:45 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.0)
2017-02-15 11:27 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\WinSnare
2017-02-15 11:27 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\WinSAPSvc
2017-02-15 11:27 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\wintools
2017-02-15 11:26 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-02-15 11:26 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\MIO
2017-02-15 11:26 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\BikaQRssReader
2017-02-15 11:26 - 2017-02-15 11:26 - 00003668 _____ C:\WINDOWS\System32\Tasks\Milimili
2017-02-15 11:26 - 2017-02-15 11:26 - 00003354 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-15 11:25 - 2017-02-15 13:04 - 00000000 ____D C:\Program Files\qs4j0wbq
2017-02-15 11:25 - 2017-02-15 11:25 - 00034328 _____ (Sysinternals - http://www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-02-15 11:24 - 2017-02-15 11:24 - 00003314 _____ C:\WINDOWS\System32\Tasks\psv_Unilax
2017-02-15 08:15 - 2017-02-15 08:15 - 00003476 _____ C:\WINDOWS\System32\Tasks\UCBrowserSecureUpdater
2017-02-15 08:11 - 2017-02-15 14:24 - 00000000 ____D C:\Users\Marťas\AppData\Local\UCBrowser
2017-02-15 08:11 - 2017-02-15 08:11 - 00000000 ____D C:\Users\Marťas\AppData\Local\NoxInsPackFileder
2017-02-15 08:11 - 2017-02-15 08:11 - 00000000 ____D C:\Users\Marťas\AppData\Local\Nox
2017-02-15 08:02 - 2017-02-15 14:46 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2017-02-15 07:52 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\xxx
2017-02-15 07:51 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\gplyra
2017-02-15 07:49 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Seznam.cz
2017-02-15 07:48 - 2017-02-15 14:23 - 00000000 ____D C:\Program Files (x86)\ContentPush
2017-02-15 07:47 - 2017-02-15 07:47 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\VDI
2017-02-15 07:45 - 2017-02-15 07:45 - 00000000 ____D C:\ProgramData\078aa905-6553-1
2017-02-15 07:45 - 2017-02-15 07:45 - 00000000 ____D C:\ProgramData\078aa905-0147-0
2017-02-15 07:41 - 2017-02-15 08:17 - 00000000 ____D C:\ProgramData\Logic Handler
2017-02-15 07:41 - 2017-02-15 07:41 - 01938536 _____ C:\Users\Marťas\AppData\Roaming\Y-zap.bin
2017-02-15 07:41 - 2017-02-15 07:41 - 00136827 _____ () C:\Users\Marťas\AppData\Roaming\Dongnix.bin
2017-02-15 07:41 - 2017-02-15 07:41 - 00002398 _____ C:\WINDOWS\SysWOW64\findit.xml
2017-02-15 07:41 - 2017-02-15 07:41 - 00000000 ____D C:\ProgramData\Ronzaps
2017-02-15 07:40 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\Ronzap
2017-02-15 07:40 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\NetworkPacketManitor
2017-02-15 07:40 - 2017-02-15 07:40 - 07319040 _____ C:\Users\Marťas\AppData\Roaming\agent.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 01908169 _____ C:\Users\Marťas\AppData\Roaming\Mathbam.tst
2017-02-15 07:40 - 2017-02-15 07:40 - 00278518 _____ C:\Users\Marťas\AppData\Roaming\Inch-Lab.bin
2017-02-15 07:40 - 2017-02-15 07:40 - 00126464 _____ C:\Users\Marťas\AppData\Roaming\noah.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 00070752 _____ C:\Users\Marťas\AppData\Roaming\Config.xml
2017-02-15 07:40 - 2017-02-15 07:40 - 00018432 _____ C:\Users\Marťas\AppData\Roaming\Main.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 00005568 _____ C:\Users\Marťas\AppData\Roaming\md.xml
2017-02-15 07:40 - 2017-02-15 07:39 - 00983040 _____ C:\Users\Marťas\AppData\Roaming\Mathbam.exe
2017-02-15 07:39 - 2017-02-15 07:40 - 00019056 _____ C:\Users\Marťas\AppData\Roaming\InstallationConfiguration.xml
2017-02-15 07:39 - 2017-02-15 07:39 - 00140288 _____ C:\Users\Marťas\AppData\Roaming\Installer.dat
2017-02-15 07:39 - 2017-02-15 07:39 - 00001194 _____ C:\Users\Public\Desktop\SMRecorder.lnk
2017-02-15 07:39 - 2017-02-15 07:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMRecorder
2017-02-15 07:39 - 2017-02-15 07:39 - 00000000 ____D C:\Program Files (x86)\SMRecorder
2017-02-14 22:17 - 2017-02-14 22:18 - 00000270 __RSH C:\Users\Marťas\ntuser.pol
2017-02-14 22:16 - 2017-02-14 22:16 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2017-02-14 22:16 - 2017-02-14 22:16 - 00003396 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2017-02-14 22:16 - 2017-02-14 22:16 - 00003076 _____ C:\WINDOWS\System32\Tasks\Update Service for Youtube AdBlock2
2017-02-14 22:16 - 2017-02-14 22:16 - 00003042 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Marťas)
2017-02-14 22:16 - 2017-02-14 22:16 - 00000368 _____ C:\WINDOWS\Tasks\Update Service for Youtube AdBlock2.job
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\Users\Marťas\AppData\LocalLow\IObit
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\Users\Marťas\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\ProgramData\IObit
2017-02-14 22:15 - 2017-02-14 22:16 - 00000000 ____D C:\Users\Public\Thunder Network
2017-02-14 22:15 - 2017-02-14 22:15 - 00000000 ____D C:\ProgramData\Thunder Network
2017-02-14 22:15 - 2017-02-14 22:15 - 00000000 ____D C:\Program Files (x86)\IObit
2017-02-14 22:14 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\Youtube AdBlock
2017-02-14 22:14 - 2017-02-15 11:32 - 00000000 ____D C:\Program Files (x86)\Buluwardatacack
2017-02-14 22:14 - 2017-02-15 08:14 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Grjelyckojule
2017-02-14 22:14 - 2017-02-14 22:15 - 00000000 ____D C:\Users\Marンas\AppData\Local\Ghezeent
2017-02-14 22:14 - 2017-02-14 22:14 - 00000270 __RSH C:\ProgramData\ntuser.pol
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Users\Marンas
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\IObit
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Users\Marťas\AppData\Local\Ghezeent
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Program Files (x86)\Coitoy Manager
2017-02-14 22:07 - 2017-02-14 22:26 - 00000000 ____D C:\Users\Marťas\AppData\Local\Dxtory Software
2017-02-14 22:07 - 2017-02-14 22:07 - 00001198 _____ C:\Users\Marťas\Desktop\Dxtory.lnk
2017-02-14 22:07 - 2017-02-14 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
2017-02-14 22:07 - 2017-02-14 22:07 - 00000000 ____D C:\Program Files (x86)\ExKode
2017-02-14 22:07 - 2015-08-10 16:00 - 02606144 _____ (ExKode Co. Ltd.) C:\WINDOWS\system32\DxtoryCodec.dll
2017-02-14 22:07 - 2015-08-10 16:00 - 02499648 _____ (ExKode Co. Ltd.) C:\WINDOWS\SysWOW64\DxtoryCodec.dll
2017-02-12 08:16 - 2017-02-12 08:16 - 00002098 _____ C:\Users\Marťas\Desktop\My.com Game Center.lnk
2017-02-12 07:13 - 2017-02-12 07:13 - 00000000 ____D C:\Users\Marťas\AppData\Local\CrashRpt
2017-02-12 06:55 - 2017-02-12 07:12 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com Games
2017-02-12 06:54 - 2017-02-15 15:50 - 00000000 ____D C:\Users\Marťas\AppData\Local\MyComGames
2017-02-11 21:08 - 2017-02-11 21:08 - 00000222 _____ C:\Users\Marťas\Desktop\Warface.url
2017-02-08 17:48 - 2017-02-15 17:14 - 00002556 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-08 17:48 - 2017-02-15 17:14 - 00002544 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-08 17:46 - 2017-02-08 17:55 - 00000000 ____D C:\Users\Marťas\AppData\Local\Google
2017-02-08 17:46 - 2017-02-08 17:47 - 00000000 ____D C:\Program Files (x86)\Google
2017-02-06 16:14 - 2017-02-06 16:14 - 00000000 ____D C:\Users\Marťas\AppData\Local\Macromedia
2017-02-06 13:35 - 2017-02-06 13:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-02-05 00:17 - 2017-02-05 00:19 - 00000000 ____D C:\Users\Marťas\AppData\Local\Adobe
2017-01-25 14:42 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-01-25 14:42 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-01-24 14:35 - 2017-01-24 14:35 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\BANDISOFT
2017-01-24 14:34 - 2017-01-24 14:34 - 00000000 ____D C:\Users\Marťas\Documents\Bandicam
2017-01-24 14:34 - 2017-01-24 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2017-01-24 14:34 - 2017-01-24 14:34 - 00000000 ____D C:\Program Files (x86)\Bandicam
2017-01-23 16:47 - 2017-02-13 08:40 - 00000000 ____D C:\Users\Marťas\Desktop\Plocha
2017-01-18 21:51 - 2017-02-13 08:40 - 00000000 ____D C:\Users\Marťas\Desktop\Lyže
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-15 17:14 - 2016-12-17 16:19 - 00001260 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-15 17:10 - 2016-12-17 16:19 - 00000000 ____D C:\Users\Marťas\AppData\LocalLow\Mozilla
2017-02-15 15:50 - 2016-12-17 16:03 - 00000000 ____D C:\Program Files (x86)\Steam
2017-02-15 14:50 - 2016-12-17 15:55 - 01867170 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-15 14:50 - 2016-07-16 23:25 - 00677242 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-15 14:50 - 2016-07-16 23:25 - 00153510 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-15 14:44 - 2016-12-17 19:46 - 00000000 __SHD C:\Users\Marťas\IntelGraphicsProfiles
2017-02-15 14:44 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-15 14:43 - 2016-12-17 19:50 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2017-02-15 14:43 - 2016-12-17 15:38 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-15 14:40 - 2017-01-09 18:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreshDevices
2017-02-15 14:40 - 2017-01-09 18:21 - 00000000 ____D C:\Program Files (x86)\FreshDevices
2017-02-15 14:40 - 2016-12-17 16:26 - 00000000 ____D C:\Program Files\Intel
2017-02-15 14:40 - 2016-12-17 16:00 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Skype
2017-02-15 14:40 - 2016-12-17 15:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-15 14:40 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-15 14:37 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-15 14:27 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\registration
2017-02-15 14:25 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-15 14:24 - 2016-12-17 15:55 - 00000000 ____D C:\Users\Marťas
2017-02-15 14:24 - 2016-12-17 15:51 - 00000000 ____D C:\Users\defaultuser0
2017-02-15 14:15 - 2016-12-17 15:37 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-15 13:44 - 2016-12-17 15:59 - 00000000 ___RD C:\Users\Marťas\OneDrive
2017-02-15 12:25 - 2016-07-16 07:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI
2017-02-15 12:23 - 2016-12-17 16:28 - 00000436 _____ C:\Users\Marťas\Desktop\Tento počítač.lnk
2017-02-15 07:52 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-14 22:14 - 2016-12-17 15:56 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Adobe
2017-02-14 22:14 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Škola
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Reniny dorty
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Fotečky
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Epic moments
2017-02-12 22:37 - 2016-11-23 13:59 - 00000000 ____D C:\Games
2017-02-09 14:20 - 2016-12-17 15:56 - 00000000 ____D C:\Users\Marťas\AppData\Local\VirtualStore
2017-02-09 12:50 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-06 19:45 - 2016-12-25 09:48 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-06 15:59 - 2016-12-24 22:46 - 00000222 _____ C:\Users\Marťas\Desktop\Rebel Galaxy.url
2017-02-05 00:18 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-31 16:34 - 2016-12-17 16:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-31 16:34 - 2016-12-17 16:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-31 15:38 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
==================== Files in the root of some directories =======
2017-02-15 07:40 - 2017-02-15 07:40 - 7319040 _____ () C:\Users\Marťas\AppData\Roaming\agent.dat
2017-02-15 07:51 - 2017-02-15 07:51 - 0023622 _____ () C:\Users\Marťas\AppData\Roaming\aliexpress.ico
2017-02-15 07:50 - 2017-02-15 07:51 - 0099678 _____ () C:\Users\Marťas\AppData\Roaming\booking.ico
2017-02-15 07:40 - 2017-02-15 07:40 - 0070752 _____ () C:\Users\Marťas\AppData\Roaming\Config.xml
2017-02-15 07:41 - 2017-02-15 07:41 - 0136827 _____ () C:\Users\Marťas\AppData\Roaming\Dongnix.bin
2017-02-15 07:40 - 2017-02-15 07:40 - 0278518 _____ () C:\Users\Marťas\AppData\Roaming\Inch-Lab.bin
2017-02-15 07:39 - 2017-02-15 07:40 - 0019056 _____ () C:\Users\Marťas\AppData\Roaming\InstallationConfiguration.xml
2017-02-15 07:39 - 2017-02-15 07:39 - 0140288 _____ () C:\Users\Marťas\AppData\Roaming\Installer.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 0018432 _____ () C:\Users\Marťas\AppData\Roaming\Main.dat
2017-02-15 07:40 - 2017-02-15 07:39 - 0983040 _____ () C:\Users\Marťas\AppData\Roaming\Mathbam.exe
2017-02-15 07:40 - 2017-02-15 07:40 - 1908169 _____ () C:\Users\Marťas\AppData\Roaming\Mathbam.tst
2017-02-15 07:40 - 2017-02-15 07:40 - 0005568 _____ () C:\Users\Marťas\AppData\Roaming\md.xml
2017-02-15 07:40 - 2017-02-15 07:40 - 0126464 _____ () C:\Users\Marťas\AppData\Roaming\noah.dat
2017-02-15 07:42 - 2017-02-15 07:42 - 0001150 _____ () C:\Users\Marťas\AppData\Roaming\uninstall_temp.ico
2017-02-15 07:41 - 2017-02-15 07:41 - 1938536 _____ () C:\Users\Marťas\AppData\Roaming\Y-zap.bin
2016-12-17 16:01 - 2016-12-17 16:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\Marťas\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Users\Marťas\AppData\Local\MyComGames\MyComGames.exe
Some files in TEMP:
====================
2017-02-14 22:14 - 2017-02-14 22:14 - 17628560 _____ (IObit ) C:\Users\Marťas\AppData\Local\Temp\5CCE.tmp.exe
2017-02-15 07:50 - 2017-02-15 07:50 - 1171283 _____ ( ) C:\Users\Marťas\AppData\Local\Temp\8766.tmp.exe
2017-02-14 22:14 - 2017-02-14 22:14 - 2315388 _____ ( ) C:\Users\Marťas\AppData\Local\Temp\AutoTime51495.exe
2013-08-05 07:15 - 2013-08-05 07:15 - 4292136 _____ (http://www.Bandisoft.com) C:\Users\Marťas\AppData\Local\Temp\bdfilters.dll
2017-02-15 07:58 - 2017-02-15 08:00 - 51198352 _____ (UCWeb Inc.) C:\Users\Marťas\AppData\Local\Temp\Browser_V6.0.1121.13_r_4727_(Build1612191708).exe
2017-02-15 08:11 - 2017-02-15 08:11 - 1171283 _____ ( ) C:\Users\Marťas\AppData\Local\Temp\C713.tmp.exe
2017-02-15 07:48 - 2017-02-15 07:48 - 0237624 _____ () C:\Users\Marťas\AppData\Local\Temp\ContentPushSetup.exe
2017-02-15 07:39 - 2017-02-15 07:39 - 0550404 _____ () C:\Users\Marťas\AppData\Local\Temp\DBUpdater.exe
2017-02-14 22:14 - 2017-02-14 22:14 - 0075264 _____ () C:\Users\Marťas\AppData\Local\Temp\DriverBoosterSetup.exe
2017-02-14 22:19 - 2003-02-25 13:44 - 0021019 _____ () C:\Users\Marťas\AppData\Local\Temp\guninst.exe
2017-02-15 11:27 - 2017-02-15 11:27 - 26964688 _____ () C:\Users\Marťas\AppData\Local\Temp\inst12.exe
2017-02-15 07:39 - 2017-02-15 07:39 - 0983040 _____ () C:\Users\Marťas\AppData\Local\Temp\linker.exe
2017-02-15 07:49 - 2017-02-15 07:49 - 8585520 _____ () C:\Users\Marťas\AppData\Local\Temp\listicka-partner-16194-1.1.8-offline.exe
2017-02-15 08:11 - 2017-02-15 08:11 - 1575048 _____ (Duodian Technology Co. Ltd.) C:\Users\Marťas\AppData\Local\Temp\nox_setup_v3.8.0.0_dl_intl.exe
2016-11-06 09:21 - 2016-11-06 09:21 - 0109568 _____ () C:\Users\Marťas\AppData\Local\Temp\nsu2EFD.exe
2017-02-15 07:39 - 2017-02-15 07:39 - 0351232 _____ () C:\Users\Marťas\AppData\Local\Temp\prepreinstaller_win.exe
2007-11-07 15:15 - 2007-11-07 15:15 - 1821192 _____ (Microsoft Corporation) C:\Users\Marťas\AppData\Local\Temp\smd_runtime.exe
2017-02-14 22:13 - 2017-02-14 22:14 - 2984392 _____ () C:\Users\Marťas\AppData\Local\Temp\sys32.exe
2017-02-15 07:42 - 2017-02-15 07:44 - 4446120 _____ () C:\Users\Marťas\AppData\Local\Temp\SystemHealer.exe
2017-02-15 07:48 - 2017-02-15 07:49 - 1821696 _____ () C:\Users\Marťas\AppData\Local\Temp\WindowsUpdateKB12695__7428_il1.exe
2017-02-14 22:13 - 2017-02-14 22:13 - 2560943 _____ () C:\Users\Marťas\AppData\Local\Temp\yt.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-02-14 22:33
==================== End of FRST.txt ============================
Po stažení programu a následné instalaci mi automaticky program začal stahovat spoustu souborů (aliexpres...) a podobně. V systému je nainstalováno spousta zbytečností, pravděpodobně různé malwary.
Mohli byste se na to kouknout?
Log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 01
Ran by Marťas (administrator) on DESKTOP-IMU1TCG (15-02-2017 17:14:03)
Running from C:\Users\Marťas\Desktop
Loaded Profiles: Marťas (Available Profiles: defaultuser0 & Marťas)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\ProgramData\NetworkPacketManitor\Nettrans.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.16122.10291.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1701.10102.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-12-17] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16405744 2015-09-10] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3351248 2015-09-10] (ELAN Microelectronics Corp.)
HKLM\...\RunOnce: [*Restore] => C:\WINDOWS\System32\rstrui.exe [268288 2016-07-16] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] wscript C:\WINDOWS\run.vbs,
HKLM-x32\...\Winlogon: [Userinit] wscript C:\WINDOWS\run.vbs,
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [OneDrive] => C:\Users\Marťas\AppData\Local\Microsoft\OneDrive\OneDrive.exe [1517280 2017-01-13] (Microsoft Corporation) <===== ATTENTION
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27226072 2016-11-15] (Skype Technologies S.A.)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [GoogleChromeAutoLaunch_F2169D7533533C5932816DA6EE4B0D3B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1116504 2017-02-01] (Google Inc.)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [MyComGames] => C:\Users\Marťas\AppData\Local\MyComGames\MyComGames.exe [5013392 2017-02-14] (MY.COM B.V.) <===== ATTENTION
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [Dxtory Update Checker 2.0] => C:\Program Files (x86)\ExKode\Dxtory2.0\UpdateChecker.exe [93696 2010-10-17] (Dxtory Software)
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\...\Run: [produpd] => "C:\Users\Marťas\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe" /20506 <===== ATTENTION
HKLM\...\Providers\qs4j0wbq: C:\Program Files (x86)\Coitoy Manager\local64spl.dll [307200 2017-02-14] ()
AppInit_DLLs: C:\ProgramData\Ronzap\Stockin.dll => C:\ProgramData\Ronzap\Stockin.dll [358912 2017-02-15] ()
AppInit_DLLs-x32: C:\ProgramData\Ronzap\U-Zumstrong.dll => C:\ProgramData\Ronzap\U-Zumstrong.dll [248320 2017-02-15] ()
ShellExecuteHooks: No Name - {8A2A2C62-EEB8-11E6-9AB6-64006A5CFC23} - C:\Users\Marťas\AppData\Roaming\Grjelyckojule\Coosak.dll -> No File
Startup: C:\Users\Marťas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\monhost.lnk [2017-02-15] <===== ATTENTION
ShortcutTarget: monhost.lnk -> C:\Users\Marťas\AppData\Roaming\VDI\Shared\Product Updater\monhost.exe (No File)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{02c273f3-199c-452b-9e83-6cf7b4ac56ca}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{03d29909-5cf5-4c48-9d1c-6d0c9b13c62d}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Internet Explorer:
==================
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
HKU\S-1-5-21-1626131941-1098701557-2232362238-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXNK-9KXdsNt4TNE5gx242qujwVNkv7VFQPatKgidUULgpokjiR3t_QNSkGSP9oKoVCfMXQBx0uNbS8L36e0FA8kWLIom
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1626131941-1098701557-2232362238-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1626131941-1098701557-2232362238-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2IWFP54W9OijJ_IQ1WqfBrLNdF4ChiGQISBE4zK4ob06DMOLaW1-CfbQjUZHr7oXN4MEBW77F2Ugl1z3UZCMgBCEU8cegflI9J2ph4-6lx77xh9b13Cx9zjSzaujmqg3qN89znXixBXCRYlNoNaPJzhF3kt&q={searchTerms}
FireFox:
========
FF DefaultProfile: pjvuic15.default
FF ProfilePath: C:\Users\Marťas\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\pjvuic15.default\Profiles\pjvuic15.default [not found]
FF ProfilePath: C:\Users\Marťas\AppData\Roaming\Mozilla\Firefox\Profiles\pjvuic15.default [2017-02-15]
FF NewTab: Mozilla\Firefox\Profiles\pjvuic15.default -> C:\\ProgramData\\Ronzaps\\ff.NT
FF Homepage: Mozilla\Firefox\Profiles\pjvuic15.default -> C:\\ProgramData\\Ronzaps\\ff.HP
FF Extension: (Adblocker for Youtube™) - C:\Program Files (x86)\Mozilla Firefox\browser\features\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} [2017-02-14] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-02-05] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-02-05] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-1626131941-1098701557-2232362238-1001: @my.com/Games -> C:\Users\Marťas\AppData\Local\MyComGames\NPMyComDetector.dll [2017-02-12] (MY.COM B.V.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.trotux.com/?z=0193a36a0277feb42dd07 ... UH&type=hp
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=0193a36a0277feb42dd07 ... UH&type=hp"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}& ... UH&type=sp
CHR DefaultSearchKeyword: ChromeDefaultData -> trotux
CHR Profile: C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-15] <==== ATTENTION
CHR Extension: (Prezentace Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-08]
CHR Extension: (Dokumenty Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-08]
CHR Extension: (Disk Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-08]
CHR Extension: (YouTube) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-08]
CHR Extension: (Steam Inventory Helper) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cmeakgjggjdlcpncigglobpjbkabhmjl [2017-02-14]
CHR Extension: (Tabulky Google) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-08]
CHR Extension: (Splinter Search) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fnhfdmnphmbbjbgppnpcddkefmeokfho [2017-02-15]
CHR Extension: (Dokumenty Google offline) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-09]
CHR Extension: (Adblocker pro Youtube™) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-08]
CHR Extension: (Gmail) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-08]
CHR Extension: (Chrome Media Router) - C:\Users\Marťas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [145624 2015-09-10] (ELAN Microelectronics Corp.)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [328624 2015-10-07] (Intel Corporation)
R2 Nettrans; C:\ProgramData\NetworkPacketManitor\Nettrans.exe [43520 2017-02-15] () [File not signed]
S2 Ronzap; C:\ProgramData\\Ronzap\\Ronzap.exe [983040 2017-02-15] () [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Marťas\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-15] (TODO: <Company name>) [File not signed]
S2 WinSnare; C:\Users\Marťas\AppData\Roaming\WinSnare\WinSnare.dll [779776 2017-02-08] (InterSect Alliance Pty Ltd) [File not signed]
S2 serverss; C:\WINDOWS\Temp\E12D.tmp [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 FreshIO; C:\Program Files (x86)\FreshDevices\FreshDiagnose\FreshIO.sys [2410 2004-10-26] () [File not signed]
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [59840 2015-11-16] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [410848 2015-08-13] (Realsil Semiconductor Corporation)
S1 ucdrv; C:\Program Files (x86)\UCBrowser\Security:ucdrv-x64.sys [25444 ] (UC Web Inc.) <==== ATTENTION
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-15 17:14 - 2017-02-15 17:14 - 00014491 _____ C:\Users\Marťas\Desktop\FRST.txt
2017-02-15 17:13 - 2017-02-15 17:14 - 00000000 ____D C:\FRST
2017-02-15 17:13 - 2017-02-15 17:13 - 02422272 _____ (Farbar) C:\Users\Marťas\Desktop\FRST64.exe
2017-02-15 17:13 - 2017-02-15 17:13 - 00112640 _____ (forum.viry.cz) C:\Users\Marťas\Desktop\FRSTLauncher.exe
2017-02-15 14:47 - 2017-02-15 14:47 - 00003744 _____ C:\WINDOWS\System32\Tasks\{FF362657-05F5-418A-B833-872C21AA43F5}
2017-02-15 14:16 - 2017-02-15 14:16 - 00000000 ___HD C:\$AV_ASW
2017-02-15 14:16 - 2017-02-15 14:16 - 00000000 ____D C:\Users\TEMP.DESKTOP-IMU1TCG\AppData\Roaming\AVAST Software
2017-02-15 14:15 - 2017-02-15 14:20 - 00000000 ____D C:\Users\TEMP.DESKTOP-IMU1TCG\AppData\Local\Packages
2017-02-15 14:15 - 2017-02-15 14:20 - 00000000 ____D C:\Users\TEMP.DESKTOP-IMU1TCG
2017-02-15 14:15 - 2017-02-15 14:15 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\AVAST Software
2017-02-15 14:11 - 2017-02-15 14:11 - 00000000 ____D C:\Users\Default\AppData\Local\NetworkTiles
2017-02-15 14:11 - 2017-02-15 14:11 - 00000000 ____D C:\Users\Default User\AppData\Local\NetworkTiles
2017-02-15 14:10 - 2017-02-15 14:15 - 00000000 ____D C:\Users\TEMP
2017-02-15 14:08 - 2017-02-15 14:08 - 00000000 ____D C:\Users\Default\winhttp
2017-02-15 13:34 - 2017-02-15 13:34 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\AVAST Software
2017-02-15 13:33 - 2017-02-15 13:33 - 00000000 ____D C:\Program Files\Common Files\AV
2017-02-15 13:22 - 2017-02-15 13:22 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\SMRecorder
2017-02-15 13:21 - 2017-02-15 13:21 - 00000000 ____D C:\Users\Marťas\Documents\SMRecorder
2017-02-15 13:16 - 2017-02-15 13:38 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-15 13:16 - 2017-02-15 13:38 - 00000000 ____D C:\Program Files\AVAST Software
2017-02-15 13:09 - 2017-02-15 13:09 - 00000000 ____D C:\Program Files (x86)\qs4j0wbq
2017-02-15 12:28 - 2017-02-15 12:28 - 00003334 _____ C:\WINDOWS\System32\Tasks\psv_Dentola
2017-02-15 12:27 - 2017-02-15 14:40 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-02-15 11:38 - 2017-02-15 11:38 - 00003306 _____ C:\WINDOWS\System32\Tasks\psv_S-it
2017-02-15 11:35 - 2017-02-15 12:31 - 00003658 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2017-02-15 11:33 - 2017-02-15 11:33 - 00003314 _____ C:\WINDOWS\System32\Tasks\psv_Zaamtax
2017-02-15 11:28 - 2017-02-15 11:28 - 00003692 _____ C:\WINDOWS\System32\Tasks\WinTOOL
2017-02-15 11:27 - 2017-02-15 14:45 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.0)
2017-02-15 11:27 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\WinSnare
2017-02-15 11:27 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\WinSAPSvc
2017-02-15 11:27 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\wintools
2017-02-15 11:26 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-02-15 11:26 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\MIO
2017-02-15 11:26 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\BikaQRssReader
2017-02-15 11:26 - 2017-02-15 11:26 - 00003668 _____ C:\WINDOWS\System32\Tasks\Milimili
2017-02-15 11:26 - 2017-02-15 11:26 - 00003354 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-15 11:25 - 2017-02-15 13:04 - 00000000 ____D C:\Program Files\qs4j0wbq
2017-02-15 11:25 - 2017-02-15 11:25 - 00034328 _____ (Sysinternals - http://www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-02-15 11:24 - 2017-02-15 11:24 - 00003314 _____ C:\WINDOWS\System32\Tasks\psv_Unilax
2017-02-15 08:15 - 2017-02-15 08:15 - 00003476 _____ C:\WINDOWS\System32\Tasks\UCBrowserSecureUpdater
2017-02-15 08:11 - 2017-02-15 14:24 - 00000000 ____D C:\Users\Marťas\AppData\Local\UCBrowser
2017-02-15 08:11 - 2017-02-15 08:11 - 00000000 ____D C:\Users\Marťas\AppData\Local\NoxInsPackFileder
2017-02-15 08:11 - 2017-02-15 08:11 - 00000000 ____D C:\Users\Marťas\AppData\Local\Nox
2017-02-15 08:02 - 2017-02-15 14:46 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2017-02-15 07:52 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\xxx
2017-02-15 07:51 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\gplyra
2017-02-15 07:49 - 2017-02-15 14:40 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Seznam.cz
2017-02-15 07:48 - 2017-02-15 14:23 - 00000000 ____D C:\Program Files (x86)\ContentPush
2017-02-15 07:47 - 2017-02-15 07:47 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\VDI
2017-02-15 07:45 - 2017-02-15 07:45 - 00000000 ____D C:\ProgramData\078aa905-6553-1
2017-02-15 07:45 - 2017-02-15 07:45 - 00000000 ____D C:\ProgramData\078aa905-0147-0
2017-02-15 07:41 - 2017-02-15 08:17 - 00000000 ____D C:\ProgramData\Logic Handler
2017-02-15 07:41 - 2017-02-15 07:41 - 01938536 _____ C:\Users\Marťas\AppData\Roaming\Y-zap.bin
2017-02-15 07:41 - 2017-02-15 07:41 - 00136827 _____ () C:\Users\Marťas\AppData\Roaming\Dongnix.bin
2017-02-15 07:41 - 2017-02-15 07:41 - 00002398 _____ C:\WINDOWS\SysWOW64\findit.xml
2017-02-15 07:41 - 2017-02-15 07:41 - 00000000 ____D C:\ProgramData\Ronzaps
2017-02-15 07:40 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\Ronzap
2017-02-15 07:40 - 2017-02-15 14:40 - 00000000 ____D C:\ProgramData\NetworkPacketManitor
2017-02-15 07:40 - 2017-02-15 07:40 - 07319040 _____ C:\Users\Marťas\AppData\Roaming\agent.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 01908169 _____ C:\Users\Marťas\AppData\Roaming\Mathbam.tst
2017-02-15 07:40 - 2017-02-15 07:40 - 00278518 _____ C:\Users\Marťas\AppData\Roaming\Inch-Lab.bin
2017-02-15 07:40 - 2017-02-15 07:40 - 00126464 _____ C:\Users\Marťas\AppData\Roaming\noah.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 00070752 _____ C:\Users\Marťas\AppData\Roaming\Config.xml
2017-02-15 07:40 - 2017-02-15 07:40 - 00018432 _____ C:\Users\Marťas\AppData\Roaming\Main.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 00005568 _____ C:\Users\Marťas\AppData\Roaming\md.xml
2017-02-15 07:40 - 2017-02-15 07:39 - 00983040 _____ C:\Users\Marťas\AppData\Roaming\Mathbam.exe
2017-02-15 07:39 - 2017-02-15 07:40 - 00019056 _____ C:\Users\Marťas\AppData\Roaming\InstallationConfiguration.xml
2017-02-15 07:39 - 2017-02-15 07:39 - 00140288 _____ C:\Users\Marťas\AppData\Roaming\Installer.dat
2017-02-15 07:39 - 2017-02-15 07:39 - 00001194 _____ C:\Users\Public\Desktop\SMRecorder.lnk
2017-02-15 07:39 - 2017-02-15 07:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMRecorder
2017-02-15 07:39 - 2017-02-15 07:39 - 00000000 ____D C:\Program Files (x86)\SMRecorder
2017-02-14 22:17 - 2017-02-14 22:18 - 00000270 __RSH C:\Users\Marťas\ntuser.pol
2017-02-14 22:16 - 2017-02-14 22:16 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2017-02-14 22:16 - 2017-02-14 22:16 - 00003396 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2017-02-14 22:16 - 2017-02-14 22:16 - 00003076 _____ C:\WINDOWS\System32\Tasks\Update Service for Youtube AdBlock2
2017-02-14 22:16 - 2017-02-14 22:16 - 00003042 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Marťas)
2017-02-14 22:16 - 2017-02-14 22:16 - 00000368 _____ C:\WINDOWS\Tasks\Update Service for Youtube AdBlock2.job
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\Users\Marťas\AppData\LocalLow\IObit
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\Users\Marťas\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4
2017-02-14 22:16 - 2017-02-14 22:16 - 00000000 ____D C:\ProgramData\IObit
2017-02-14 22:15 - 2017-02-14 22:16 - 00000000 ____D C:\Users\Public\Thunder Network
2017-02-14 22:15 - 2017-02-14 22:15 - 00000000 ____D C:\ProgramData\Thunder Network
2017-02-14 22:15 - 2017-02-14 22:15 - 00000000 ____D C:\Program Files (x86)\IObit
2017-02-14 22:14 - 2017-02-15 14:40 - 00000000 ____D C:\Program Files (x86)\Youtube AdBlock
2017-02-14 22:14 - 2017-02-15 11:32 - 00000000 ____D C:\Program Files (x86)\Buluwardatacack
2017-02-14 22:14 - 2017-02-15 08:14 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Grjelyckojule
2017-02-14 22:14 - 2017-02-14 22:15 - 00000000 ____D C:\Users\Marンas\AppData\Local\Ghezeent
2017-02-14 22:14 - 2017-02-14 22:14 - 00000270 __RSH C:\ProgramData\ntuser.pol
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Users\Marンas
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\IObit
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Users\Marťas\AppData\Local\Ghezeent
2017-02-14 22:14 - 2017-02-14 22:14 - 00000000 ____D C:\Program Files (x86)\Coitoy Manager
2017-02-14 22:07 - 2017-02-14 22:26 - 00000000 ____D C:\Users\Marťas\AppData\Local\Dxtory Software
2017-02-14 22:07 - 2017-02-14 22:07 - 00001198 _____ C:\Users\Marťas\Desktop\Dxtory.lnk
2017-02-14 22:07 - 2017-02-14 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
2017-02-14 22:07 - 2017-02-14 22:07 - 00000000 ____D C:\Program Files (x86)\ExKode
2017-02-14 22:07 - 2015-08-10 16:00 - 02606144 _____ (ExKode Co. Ltd.) C:\WINDOWS\system32\DxtoryCodec.dll
2017-02-14 22:07 - 2015-08-10 16:00 - 02499648 _____ (ExKode Co. Ltd.) C:\WINDOWS\SysWOW64\DxtoryCodec.dll
2017-02-12 08:16 - 2017-02-12 08:16 - 00002098 _____ C:\Users\Marťas\Desktop\My.com Game Center.lnk
2017-02-12 07:13 - 2017-02-12 07:13 - 00000000 ____D C:\Users\Marťas\AppData\Local\CrashRpt
2017-02-12 06:55 - 2017-02-12 07:12 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com Games
2017-02-12 06:54 - 2017-02-15 15:50 - 00000000 ____D C:\Users\Marťas\AppData\Local\MyComGames
2017-02-11 21:08 - 2017-02-11 21:08 - 00000222 _____ C:\Users\Marťas\Desktop\Warface.url
2017-02-08 17:48 - 2017-02-15 17:14 - 00002556 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-08 17:48 - 2017-02-15 17:14 - 00002544 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-08 17:46 - 2017-02-08 17:55 - 00000000 ____D C:\Users\Marťas\AppData\Local\Google
2017-02-08 17:46 - 2017-02-08 17:47 - 00000000 ____D C:\Program Files (x86)\Google
2017-02-06 16:14 - 2017-02-06 16:14 - 00000000 ____D C:\Users\Marťas\AppData\Local\Macromedia
2017-02-06 13:35 - 2017-02-06 13:35 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-02-05 00:17 - 2017-02-05 00:19 - 00000000 ____D C:\Users\Marťas\AppData\Local\Adobe
2017-01-25 14:42 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-01-25 14:42 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-01-24 14:35 - 2017-01-24 14:35 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\BANDISOFT
2017-01-24 14:34 - 2017-01-24 14:34 - 00000000 ____D C:\Users\Marťas\Documents\Bandicam
2017-01-24 14:34 - 2017-01-24 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2017-01-24 14:34 - 2017-01-24 14:34 - 00000000 ____D C:\Program Files (x86)\Bandicam
2017-01-23 16:47 - 2017-02-13 08:40 - 00000000 ____D C:\Users\Marťas\Desktop\Plocha
2017-01-18 21:51 - 2017-02-13 08:40 - 00000000 ____D C:\Users\Marťas\Desktop\Lyže
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-15 17:14 - 2016-12-17 16:19 - 00001260 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-15 17:10 - 2016-12-17 16:19 - 00000000 ____D C:\Users\Marťas\AppData\LocalLow\Mozilla
2017-02-15 15:50 - 2016-12-17 16:03 - 00000000 ____D C:\Program Files (x86)\Steam
2017-02-15 14:50 - 2016-12-17 15:55 - 01867170 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-15 14:50 - 2016-07-16 23:25 - 00677242 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-15 14:50 - 2016-07-16 23:25 - 00153510 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-15 14:44 - 2016-12-17 19:46 - 00000000 __SHD C:\Users\Marťas\IntelGraphicsProfiles
2017-02-15 14:44 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-15 14:43 - 2016-12-17 19:50 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2017-02-15 14:43 - 2016-12-17 15:38 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-15 14:40 - 2017-01-09 18:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreshDevices
2017-02-15 14:40 - 2017-01-09 18:21 - 00000000 ____D C:\Program Files (x86)\FreshDevices
2017-02-15 14:40 - 2016-12-17 16:26 - 00000000 ____D C:\Program Files\Intel
2017-02-15 14:40 - 2016-12-17 16:00 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Skype
2017-02-15 14:40 - 2016-12-17 15:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-15 14:40 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-15 14:37 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-15 14:27 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\registration
2017-02-15 14:25 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-15 14:24 - 2016-12-17 15:55 - 00000000 ____D C:\Users\Marťas
2017-02-15 14:24 - 2016-12-17 15:51 - 00000000 ____D C:\Users\defaultuser0
2017-02-15 14:15 - 2016-12-17 15:37 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-15 13:44 - 2016-12-17 15:59 - 00000000 ___RD C:\Users\Marťas\OneDrive
2017-02-15 12:25 - 2016-07-16 07:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI
2017-02-15 12:23 - 2016-12-17 16:28 - 00000436 _____ C:\Users\Marťas\Desktop\Tento počítač.lnk
2017-02-15 07:52 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-14 22:14 - 2016-12-17 15:56 - 00000000 ____D C:\Users\Marťas\AppData\Roaming\Adobe
2017-02-14 22:14 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Škola
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Reniny dorty
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Fotečky
2017-02-13 08:40 - 2016-12-17 16:57 - 00000000 ____D C:\Users\Marťas\Desktop\Epic moments
2017-02-12 22:37 - 2016-11-23 13:59 - 00000000 ____D C:\Games
2017-02-09 14:20 - 2016-12-17 15:56 - 00000000 ____D C:\Users\Marťas\AppData\Local\VirtualStore
2017-02-09 12:50 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-06 19:45 - 2016-12-25 09:48 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-06 15:59 - 2016-12-24 22:46 - 00000222 _____ C:\Users\Marťas\Desktop\Rebel Galaxy.url
2017-02-05 00:18 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-01-31 16:34 - 2016-12-17 16:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-31 16:34 - 2016-12-17 16:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-31 15:38 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
==================== Files in the root of some directories =======
2017-02-15 07:40 - 2017-02-15 07:40 - 7319040 _____ () C:\Users\Marťas\AppData\Roaming\agent.dat
2017-02-15 07:51 - 2017-02-15 07:51 - 0023622 _____ () C:\Users\Marťas\AppData\Roaming\aliexpress.ico
2017-02-15 07:50 - 2017-02-15 07:51 - 0099678 _____ () C:\Users\Marťas\AppData\Roaming\booking.ico
2017-02-15 07:40 - 2017-02-15 07:40 - 0070752 _____ () C:\Users\Marťas\AppData\Roaming\Config.xml
2017-02-15 07:41 - 2017-02-15 07:41 - 0136827 _____ () C:\Users\Marťas\AppData\Roaming\Dongnix.bin
2017-02-15 07:40 - 2017-02-15 07:40 - 0278518 _____ () C:\Users\Marťas\AppData\Roaming\Inch-Lab.bin
2017-02-15 07:39 - 2017-02-15 07:40 - 0019056 _____ () C:\Users\Marťas\AppData\Roaming\InstallationConfiguration.xml
2017-02-15 07:39 - 2017-02-15 07:39 - 0140288 _____ () C:\Users\Marťas\AppData\Roaming\Installer.dat
2017-02-15 07:40 - 2017-02-15 07:40 - 0018432 _____ () C:\Users\Marťas\AppData\Roaming\Main.dat
2017-02-15 07:40 - 2017-02-15 07:39 - 0983040 _____ () C:\Users\Marťas\AppData\Roaming\Mathbam.exe
2017-02-15 07:40 - 2017-02-15 07:40 - 1908169 _____ () C:\Users\Marťas\AppData\Roaming\Mathbam.tst
2017-02-15 07:40 - 2017-02-15 07:40 - 0005568 _____ () C:\Users\Marťas\AppData\Roaming\md.xml
2017-02-15 07:40 - 2017-02-15 07:40 - 0126464 _____ () C:\Users\Marťas\AppData\Roaming\noah.dat
2017-02-15 07:42 - 2017-02-15 07:42 - 0001150 _____ () C:\Users\Marťas\AppData\Roaming\uninstall_temp.ico
2017-02-15 07:41 - 2017-02-15 07:41 - 1938536 _____ () C:\Users\Marťas\AppData\Roaming\Y-zap.bin
2016-12-17 16:01 - 2016-12-17 16:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\Marťas\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Users\Marťas\AppData\Local\MyComGames\MyComGames.exe
Some files in TEMP:
====================
2017-02-14 22:14 - 2017-02-14 22:14 - 17628560 _____ (IObit ) C:\Users\Marťas\AppData\Local\Temp\5CCE.tmp.exe
2017-02-15 07:50 - 2017-02-15 07:50 - 1171283 _____ ( ) C:\Users\Marťas\AppData\Local\Temp\8766.tmp.exe
2017-02-14 22:14 - 2017-02-14 22:14 - 2315388 _____ ( ) C:\Users\Marťas\AppData\Local\Temp\AutoTime51495.exe
2013-08-05 07:15 - 2013-08-05 07:15 - 4292136 _____ (http://www.Bandisoft.com) C:\Users\Marťas\AppData\Local\Temp\bdfilters.dll
2017-02-15 07:58 - 2017-02-15 08:00 - 51198352 _____ (UCWeb Inc.) C:\Users\Marťas\AppData\Local\Temp\Browser_V6.0.1121.13_r_4727_(Build1612191708).exe
2017-02-15 08:11 - 2017-02-15 08:11 - 1171283 _____ ( ) C:\Users\Marťas\AppData\Local\Temp\C713.tmp.exe
2017-02-15 07:48 - 2017-02-15 07:48 - 0237624 _____ () C:\Users\Marťas\AppData\Local\Temp\ContentPushSetup.exe
2017-02-15 07:39 - 2017-02-15 07:39 - 0550404 _____ () C:\Users\Marťas\AppData\Local\Temp\DBUpdater.exe
2017-02-14 22:14 - 2017-02-14 22:14 - 0075264 _____ () C:\Users\Marťas\AppData\Local\Temp\DriverBoosterSetup.exe
2017-02-14 22:19 - 2003-02-25 13:44 - 0021019 _____ () C:\Users\Marťas\AppData\Local\Temp\guninst.exe
2017-02-15 11:27 - 2017-02-15 11:27 - 26964688 _____ () C:\Users\Marťas\AppData\Local\Temp\inst12.exe
2017-02-15 07:39 - 2017-02-15 07:39 - 0983040 _____ () C:\Users\Marťas\AppData\Local\Temp\linker.exe
2017-02-15 07:49 - 2017-02-15 07:49 - 8585520 _____ () C:\Users\Marťas\AppData\Local\Temp\listicka-partner-16194-1.1.8-offline.exe
2017-02-15 08:11 - 2017-02-15 08:11 - 1575048 _____ (Duodian Technology Co. Ltd.) C:\Users\Marťas\AppData\Local\Temp\nox_setup_v3.8.0.0_dl_intl.exe
2016-11-06 09:21 - 2016-11-06 09:21 - 0109568 _____ () C:\Users\Marťas\AppData\Local\Temp\nsu2EFD.exe
2017-02-15 07:39 - 2017-02-15 07:39 - 0351232 _____ () C:\Users\Marťas\AppData\Local\Temp\prepreinstaller_win.exe
2007-11-07 15:15 - 2007-11-07 15:15 - 1821192 _____ (Microsoft Corporation) C:\Users\Marťas\AppData\Local\Temp\smd_runtime.exe
2017-02-14 22:13 - 2017-02-14 22:14 - 2984392 _____ () C:\Users\Marťas\AppData\Local\Temp\sys32.exe
2017-02-15 07:42 - 2017-02-15 07:44 - 4446120 _____ () C:\Users\Marťas\AppData\Local\Temp\SystemHealer.exe
2017-02-15 07:48 - 2017-02-15 07:49 - 1821696 _____ () C:\Users\Marťas\AppData\Local\Temp\WindowsUpdateKB12695__7428_il1.exe
2017-02-14 22:13 - 2017-02-14 22:13 - 2560943 _____ () C:\Users\Marťas\AppData\Local\Temp\yt.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-02-14 22:33
==================== End of FRST.txt ============================