Počítač se chová divně :-)
Napsal: 01 bře 2017 14:49
Dobrý den, prosím o kontrolu logu. Počítač se chová divně. Včera nefungoval skoro vůbec, pomohlo až obnovení bodu systému, který byl vytvořen někdy před 14 dny.
Děkuji
Helena
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-03-2017
Ran by Helenka (administrator) on DOMA (01-03-2017 14:42:10)
Running from C:\Users\Helenka\Desktop\ÚDRŽBA
Loaded Profiles: Helenka (Available Profiles: Helenka)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
() C:\Windows\SysWOW64\spdsvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Informer Technologies, Inc.) C:\Program Files\Software Informer\softinfo.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-11-20] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe [64640 2013-01-28] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-24] (Conexant Systems, Inc.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2017-01-21] (AVAST Software)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-01-28] (Qualcomm Atheros Commnucations)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {0c4bd6aa-b710-11e6-bea7-089e01400cec} - "E:\autorun.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {4651e03c-df23-11e6-bead-806e6f6e6963} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {59627320-ca0a-11e6-beab-089e01400cec} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {ba04a953-ed21-11e5-be69-806e6f6e6963} - "D:\Setup.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {cb6f8045-dfe3-11e6-beb1-089e01400cec} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {eff2e197-8fbc-11e6-be92-089e01400cec} - "F:\Setup.exe"
HKLM\...\Providers\Internet Print Provider: inetpp.dll
HKLM\...\Providers\LanMan Print Services: win32spl.dll
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-01-21] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk [2017-03-01]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Network PC Fax.lnk [2017-03-01]
Startup: C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk [2017-03-01]
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 185.97.254.158 api.facepunch.com
Tcpip\Parameters: [DhcpNameServer] 82.144.128.1 82.144.129.1
Tcpip\..\Interfaces\{6E729190-5055-4A76-BB8B-3DEFC60ADD76}: [DhcpNameServer] 82.144.128.1 82.144.129.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.cz/
SearchScopes: HKU\S-1-5-21-2520944081-2684202109-2728405321-1001 -> DefaultScope {4B7AB1A7-9E69-4413-BBB0-50F38FBC11F0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2520944081-2684202109-2728405321-1001 -> {4B7AB1A7-9E69-4413-BBB0-50F38FBC11F0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2520944081-2684202109-2728405321-1001 -> {BD63004A-89AC-488F-8A5A-D4311713A735} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-01] (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll [2013-01-28] (Qualcomm Atheros Commnucations)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-01] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: taoywzw4.default
FF ProfilePath: C:\Users\Helenka\AppData\Roaming\Mozilla\Firefox\Profiles\taoywzw4.default [2017-02-28]
FF Extension: (MEGA) - C:\Users\Helenka\AppData\Roaming\Mozilla\Firefox\Profiles\taoywzw4.default\Extensions\firefox@mega.co.nz.xpi [2017-01-21]
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-01] (Oracle Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-09-01] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2520944081-2684202109-2728405321-1001: @nsroblox.roblox.com/launcher -> C:\Users\Helenka\AppData\Local\Roblox\Versions\version-ca61db0aa1b8462c\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2520944081-2684202109-2728405321-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Helenka\AppData\Local\Roblox\Versions\version-ca61db0aa1b8462c\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-01] <==== ATTENTION
CHR Extension: (Dokumenty Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-16]
CHR Extension: (Chrome Media Router) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-16]
CHR Profile: C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default [2017-02-16]
CHR Extension: (Prezentace Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-28]
CHR Extension: (Dokumenty Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-28]
CHR Extension: (Disk Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-28]
CHR Extension: (YouTube) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-28]
CHR Extension: (Adblock Plus) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-01-21]
CHR Extension: (Kalendář Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-01-07]
CHR Extension: (Tabulky Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Gmail) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-28]
CHR Extension: (Chrome Media Router) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-03]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2017-01-21] (AVAST Software)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2449552 2012-10-25] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [227104 2016-07-21] (EasyAntiCheat Ltd)
S3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658064 2012-10-23] (Acer Incorporated)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-15] (Nero AG) [File not signed]
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2007-03-12] (Nero AG)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-11-03] (NTI Corporation)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2016-03-18] (Dritek System INC.)
R2 Samsung Network Fax Server; C:\WINDOWS\system32\spool\drivers\x64\3\NetFaxServer64.exe [801472 2015-03-10] (Samsung Electronics Co., Ltd.)
R2 Samsung Printer Dianostics Service; C:\WINDOWS\SysWOW64\\spdsvc.exe [499000 2016-07-17] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2016-03-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2016-03-22] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
S2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [37656 2017-01-21] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [108816 2017-01-21] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [103064 2017-01-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2017-01-21] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [969184 2017-01-21] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [513632 2017-01-21] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [163416 2017-01-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2017-01-21] (AVAST Software)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [311968 2016-04-07] ()
S3 BTATH_LWFLT; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros)
R1 ccSet_NARA; C:\WINDOWS\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2016-10-15] (DT Soft Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18816 2016-11-25] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-10-16] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-11-25] (Huawei Technologies Co., Ltd.)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [43168 2016-04-07] ()
R3 Ps2Kb2Hid; C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys [26736 2016-03-18] (Dritek System Inc.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44560 2016-03-22] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [270168 2016-03-22] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [114520 2016-03-22] (Microsoft Corporation)
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-01 14:40 - 2017-03-01 14:40 - 01201152 _____ C:\Users\Helenka\Downloads\RSIT.exe
2017-03-01 14:40 - 2017-03-01 14:40 - 00000000 ____D C:\Program Files (x86)\trend micro
2017-03-01 14:39 - 2017-03-01 14:41 - 00000000 ____D C:\Program Files\trend micro
2017-03-01 14:39 - 2017-03-01 14:39 - 01324032 _____ C:\Users\Helenka\Downloads\RSITx64.exe
2017-03-01 14:39 - 2017-03-01 14:39 - 00000000 ____D C:\rsit
2017-03-01 14:36 - 2017-03-01 14:42 - 00000000 ____D C:\FRST
2017-03-01 14:32 - 2017-03-01 14:32 - 00001342 _____ C:\Users\Helenka\Desktop\Steam – zástupce.lnk
2017-02-28 21:20 - 2017-02-28 21:20 - 04015056 _____ C:\Users\Helenka\Downloads\adwcleaner_6.043.exe
2017-02-28 19:56 - 2017-01-21 17:38 - 00391496 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-02-28 19:50 - 2017-02-28 19:50 - 00000000 ____D C:\Program Files\d6xr5dra
2017-02-28 19:07 - 2017-02-28 19:07 - 00000000 ____D C:\Program Files (x86)\Roblox
2017-02-28 15:12 - 2017-02-28 15:12 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignc09dc6f9b54e61be
2017-02-28 15:12 - 2017-02-28 15:12 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign52d941e8a60fe453
2017-02-28 15:12 - 2017-02-28 15:12 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign217c8aa3415ed6db
2017-02-28 15:11 - 2017-02-28 15:11 - 00162250 _____ C:\Users\Helenka\Downloads\Logo 4_5.psd
2017-02-28 15:07 - 2017-02-28 15:07 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignc916e49dff10a768
2017-02-28 15:06 - 2017-02-28 15:06 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign78991dca011c406e
2017-02-28 15:04 - 2017-02-28 15:04 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign35543eccefd88b80
2017-02-28 15:03 - 2017-02-28 15:03 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigndeadfe53c82375c5
2017-02-28 15:02 - 2017-02-28 15:02 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignba2f8e3179cf541d
2017-02-28 15:02 - 2017-02-28 15:02 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign9fac53ad27915299
2017-02-21 08:58 - 2017-02-23 16:41 - 00002368 _____ C:\Program Files (x86)\metadata
2017-02-20 19:37 - 2017-02-20 19:37 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Firefox
2017-02-20 19:37 - 2017-02-20 19:37 - 00000000 ____D C:\Users\Helenka\AppData\Local\Firefox
2017-02-18 13:02 - 2017-02-18 13:02 - 00000000 ____D C:\Users\Helenka\AppData\LocalLow\Smartly Dressed Games
2017-02-17 15:16 - 2017-02-17 15:16 - 11427754 _____ C:\Users\Helenka\Downloads\SA_Euro_1.01_COLD (1).zip
2017-02-17 15:11 - 2017-02-17 15:12 - 11427754 _____ C:\Users\Helenka\Downloads\SA_Euro_1.01_COLD.zip
2017-02-17 15:10 - 2017-02-17 15:10 - 00000000 ____D C:\Users\Helenka\Downloads\SA_Euro_1[1].01_COLD
2017-02-17 15:07 - 2017-02-17 15:07 - 11429090 _____ C:\Users\Helenka\Downloads\SA_Euro_1[1].01_COLD.zip
2017-02-17 15:06 - 2017-02-28 19:45 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\GetRightToGo
2017-02-17 12:50 - 2017-02-28 20:54 - 00000000 ____D C:\Program Files (x86)\d6xr5dra
2017-02-16 19:03 - 2017-02-16 19:03 - 01191753 _____ C:\Users\Helenka\Downloads\gtasa120cz.zip
2017-02-16 19:03 - 2017-02-16 19:03 - 01191753 _____ C:\Users\Helenka\Downloads\gtasa120cz (1).zip
2017-02-16 18:13 - 2017-02-17 14:34 - 00000000 ____D C:\Users\Helenka\Documents\GTA San Andreas User Files
2017-02-16 17:42 - 2017-02-16 17:42 - 00000000 ____D C:\Users\Helenka\Documents\GTA Vice City User Files
2017-02-16 17:37 - 2017-02-16 17:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2017-02-16 16:01 - 2017-02-16 16:29 - 501886548 _____ C:\Users\Helenka\Downloads\Nepotvrzeno 213209.crdownload
2017-02-16 16:01 - 2017-02-16 16:01 - 00997949 _____ C:\Users\Helenka\Downloads\Odin3-v3.11.1.zip
2017-02-16 15:21 - 2017-02-16 15:21 - 00000000 ____D C:\Users\Helenka\Downloads\This-War-of-Mine-(OBB)_1.4.0-Android-1.com
2017-02-16 15:19 - 2017-02-16 15:21 - 479843375 _____ C:\Users\Helenka\Downloads\This-War-of-Mine-(OBB)_1.4.0-Android-1.com.zip
2017-02-16 15:18 - 2017-02-16 15:19 - 08639390 _____ C:\Users\Helenka\Downloads\This-War-of-Mine-(MOD)_1.4.0-Android-1.com.apk
2017-02-16 15:01 - 2017-02-16 15:03 - 426279395 _____ C:\Users\Helenka\Downloads\main.153.com.elevenbitstudios.twommobile.obb
2017-02-16 15:01 - 2017-02-16 15:01 - 12457066 _____ C:\Users\Helenka\Downloads\This_War_of_Mine_v1.1.0.apk
2017-02-16 14:54 - 2017-02-16 14:59 - 00000000 ____D C:\Users\Helenka\AppData\Local\Fagertain
2017-02-16 14:54 - 2017-02-16 14:54 - 02400960 _____ (BitTorrent Inc.) C:\Users\Helenka\Downloads\Reimage Pc Repair 2017 Crack License Key Full Do
2017-02-16 14:52 - 2017-02-16 14:52 - 01769472 _____ C:\Users\Helenka\Downloads\Reimage_Pc_Repair_2017_Crack_License_Key_Full_Do.iso
2017-02-16 14:44 - 2017-02-16 14:44 - 00000000 ____D C:\Program Files\Common Files\Atheros
2017-02-16 14:41 - 2017-02-16 14:42 - 62008080 _____ (Microsoft Corporation) C:\Users\Helenka\Downloads\NDP462-KB3151800-x86-x64-AllOS-ENU.exe
2017-02-16 14:40 - 2015-01-06 04:01 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2017-02-16 14:40 - 2015-01-06 03:59 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2017-02-16 14:40 - 2015-01-06 02:12 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll
2017-02-16 14:40 - 2015-01-06 02:02 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdgeoqw.dll
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZST.DLL
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZEL.DLL
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZE.DLL
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbdgeoqw.dll
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZST.DLL
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZEL.DLL
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZE.DLL
2017-02-16 14:39 - 2015-06-09 23:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2017-02-16 14:39 - 2015-06-09 23:39 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2017-02-16 14:39 - 2015-06-09 23:38 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-02-16 14:17 - 2017-02-16 14:17 - 00000000 ____D C:\Users\Helenka\Downloads\THIS WAR OF MINE MULTI11-TINYISO
2017-02-16 14:16 - 2017-02-16 14:16 - 1047527424 _____ C:\Users\Helenka\Downloads\THIS WAR OF MINE MULTI11-TINYISO.part1.rar
2017-02-16 14:14 - 2017-02-16 14:14 - 445594172 _____ C:\Users\Helenka\Downloads\THIS WAR OF MINE MULTI11-TINYISO.part2.rar
2017-02-16 13:51 - 2017-02-16 13:55 - 00000000 ____D C:\Users\Helenka\Downloads\This.War.of.Mine.2.2.0.6-GOG
2017-02-14 18:33 - 2017-02-14 18:33 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign2296590078b5e7ae
2017-02-14 18:32 - 2017-02-14 18:32 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignedd47d57ec5bd248
2017-02-14 18:32 - 2017-02-14 18:32 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign888540c9561f0931
2017-02-14 18:32 - 2017-02-14 18:32 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign5667d3375895e8e3
2017-02-14 18:30 - 2017-02-14 18:30 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign301175d1a80dcbea
2017-02-14 18:27 - 2017-02-14 18:27 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign427b32ca5a614424
2017-02-14 18:25 - 2017-02-14 18:25 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign9c0f021eb6fbaa61
2017-02-14 18:24 - 2017-02-14 18:24 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignf614c0408a71828c
2017-02-14 18:24 - 2017-02-14 18:24 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign0b27521e5b84870d
2017-02-14 18:22 - 2017-02-14 18:22 - 00000000 ____D C:\Users\Helenka\Documents\Moje palety
2017-02-14 18:18 - 2017-02-14 18:38 - 00000000 ____D C:\Users\Helenka\Documents\Corel
2017-02-14 18:16 - 2017-02-14 18:18 - 00000000 ____D C:\ProgramData\Protexis64
2017-02-14 18:16 - 2017-02-14 18:17 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Corel
2017-02-14 18:13 - 2017-02-14 18:13 - 00000000 ____D C:\Program Files\Common Files\Protexis
2017-02-14 18:13 - 2017-02-14 18:13 - 00000000 ____D C:\Program Files\Common Files\Corel
2017-02-14 18:12 - 2017-02-14 18:12 - 00000000 ____D C:\Users\Public\Documents\Corel
2017-02-14 18:11 - 2017-02-14 18:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
2017-02-14 18:10 - 2017-02-14 18:22 - 00000000 ____D C:\ProgramData\Corel
2017-02-14 18:10 - 2017-02-14 18:10 - 00000000 ____D C:\Program Files\Corel
2017-02-14 18:09 - 2017-02-14 18:16 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2017-02-13 19:11 - 2017-02-13 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-02-09 15:38 - 2017-02-09 15:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign159db5a12a1b4458
2017-02-09 15:34 - 2017-02-09 15:34 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign2e0d1f449035f999
2017-02-09 15:33 - 2017-02-09 15:33 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigne4353cd72dab39c1
2017-02-09 15:33 - 2017-02-09 15:33 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign416b0962cd957a3c
2017-02-09 15:17 - 2017-02-09 15:17 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign45af800af66706ec
2017-02-09 15:10 - 2017-02-09 15:10 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignb6843e5215a60fce
2017-02-09 15:10 - 2017-02-09 15:10 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigna0f9ada621f7a0da
2017-02-09 15:10 - 2017-02-09 15:10 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign1b69d86ae2371a9d
2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignf5d201c99aadad2b
2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign861a54750adccc38
2017-02-09 14:25 - 2017-02-09 14:25 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign3d1fee0e62ac8541
2017-02-09 14:25 - 2017-02-09 14:25 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign284b588a449ceb0d
2017-02-05 11:08 - 2017-02-05 11:08 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\.mono
2017-02-05 11:08 - 2017-02-05 11:08 - 00000000 ____D C:\Users\Helenka\AppData\Local\Colossal Order
2017-02-05 11:08 - 2017-02-05 11:08 - 00000000 ____D C:\ProgramData\.mono
2017-02-05 11:05 - 2017-02-05 11:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cities Skylines
2017-02-05 10:42 - 2017-02-05 11:09 - 00000000 ____D C:\Program Files (x86)\Cities Skylines
2017-02-05 10:37 - 2017-02-05 10:37 - 00000000 ____D C:\Users\Helenka\Downloads\Cities Skylines (CZ.MULTi8) [Repack] by 'Teag
2017-02-05 10:36 - 2017-02-05 10:36 - 00020273 _____ C:\Users\Helenka\Downloads\[CzT]Cities_Skylines_2015_CZ_.torrent
2017-02-04 11:49 - 2017-02-05 10:49 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\VMware
2017-02-04 11:48 - 2017-02-04 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
2017-02-04 11:44 - 2016-11-11 23:16 - 00052288 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\vmkbd.sys
2017-02-04 11:43 - 2017-02-04 11:43 - 01772950 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-02-04 11:34 - 2017-02-05 10:55 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Andy
2017-02-04 11:34 - 2017-02-04 11:34 - 00000000 ____D C:\Users\Helenka\Andy
2017-02-04 11:34 - 2017-02-04 11:34 - 00000000 ____D C:\Users\Helenk\Andy
2017-02-04 11:34 - 2017-02-04 11:34 - 00000000 ____D C:\Users\Helenk
2017-02-04 11:28 - 2017-02-04 11:28 - 00000000 ____D C:\Users\Helenka\Downloads\turbo_dismount
2017-02-04 11:27 - 2017-02-04 11:27 - 23590896 _____ C:\Users\Helenka\Downloads\turbo_dismount.zip
2017-02-04 11:24 - 2017-02-04 11:24 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign37a12e80b9d0a5ba
2017-02-04 11:18 - 2017-02-04 11:18 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigna10886a37f4fe292
2017-02-04 11:18 - 2017-02-04 11:18 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign8e548af1ed29e347
2017-02-04 11:17 - 2017-02-04 11:17 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignf9a924637a0b91c6
2017-02-04 11:11 - 2017-02-04 11:11 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign53157a1cb68ca8ed
2017-02-04 11:10 - 2017-02-04 11:10 - 00020043 _____ C:\Users\Helenka\Downloads\badaboom_bb.zip
2017-02-04 11:06 - 2017-02-04 11:06 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigneaf45255bdf0fc16
2017-02-04 11:05 - 2017-02-04 11:05 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign9416758e973fe8f0
2017-02-04 11:05 - 2017-02-04 11:05 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign7ab85f2896d733c4
2017-02-03 13:34 - 2017-02-03 14:13 - 122252416 _____ C:\Users\Helenka\Downloads\Gardenscapes_v1.2.6_Mod__6883_Revdl.com.apk
2017-02-03 12:39 - 2017-02-03 12:39 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign99857d28011ee141
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignfc43a01f914379ab
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignb19a9667328a68e7
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign5a94667f9465603c
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign2eb10529867085d2
2017-02-01 18:13 - 2017-02-01 18:13 - 00000000 ____D C:\Users\Helenka\Documents\ROBLOX
2017-02-01 16:53 - 2017-02-01 16:54 - 00000000 ____D C:\Program Files\Android
2017-02-01 16:53 - 2017-02-01 16:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Android SDK Tools
2017-02-01 16:53 - 2017-02-01 16:52 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-02-01 16:51 - 2017-02-01 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2017-02-01 16:50 - 2017-02-01 16:52 - 00000000 ____D C:\Program Files\Java
2017-01-31 17:32 - 2017-02-16 15:25 - 00000000 ____D C:\Users\Helenka\.android
2017-01-31 17:30 - 2017-01-31 17:30 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\ADBDriverInstaller
2017-01-31 17:29 - 2017-01-31 17:29 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Android SDK Tools
2017-01-31 17:28 - 2017-01-31 17:33 - 00000000 ____D C:\Android
2017-01-31 17:15 - 2017-01-31 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Android Studio
2017-01-31 17:07 - 2017-01-31 17:22 - 00000000 ____D C:\Users\Helenka\AppData\Local\Android
2017-01-31 16:57 - 2017-01-31 16:57 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2017-01-31 16:51 - 2017-01-31 16:51 - 00000000 ____D C:\Program Files\SAMSUNG
2017-01-31 16:50 - 2017-01-31 16:50 - 00000185 _____ C:\Users\Helenka\AppData\Local\uts.ini
2017-01-31 16:50 - 2017-01-31 16:50 - 00000000 ____D C:\Users\Helenka\AppData\Local\uts
2017-01-31 16:49 - 2017-02-16 17:37 - 00000000 ____D C:\Program Files (x86)\Kingo ROOT
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-01 14:38 - 2017-01-21 10:46 - 00000000 ____D C:\Program Files (x86)\Steam
2017-03-01 14:36 - 2016-04-01 13:58 - 00000000 ____D C:\Users\Helenka\Desktop\ÚDRŽBA
2017-03-01 14:32 - 2016-03-23 14:20 - 00003962 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2913751E-8255-4176-B63F-A7232F23BCFB}
2017-03-01 14:29 - 2016-10-18 16:03 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2520944081-2684202109-2728405321-1001
2017-03-01 14:28 - 2017-01-14 17:22 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2017-03-01 14:22 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-01 14:21 - 2016-03-19 14:53 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-01 14:17 - 2016-03-19 14:53 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-01 14:13 - 2017-01-21 17:49 - 00001139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-03-01 14:13 - 2016-12-17 15:36 - 00001104 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-03-01 14:13 - 2016-11-29 18:34 - 00001501 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frontier Launchpad.lnk
2017-03-01 14:13 - 2016-10-28 10:05 - 00002179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-01 14:13 - 2016-04-15 11:00 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-03-01 14:13 - 2016-03-23 14:07 - 00001430 _____ C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-01 14:13 - 2016-03-22 23:19 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-03-01 14:13 - 2016-03-22 23:13 - 00000469 _____ C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2017-03-01 14:13 - 2016-03-22 23:13 - 00000467 _____ C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2017-03-01 14:13 - 2016-03-19 12:38 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2017-03-01 14:13 - 2016-03-18 17:53 - 00002133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Norton Online Backup.lnk
2017-03-01 14:13 - 2016-03-18 17:50 - 00001984 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk
2017-03-01 14:13 - 2013-03-12 17:30 - 00002636 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - acer.lnk
2017-02-28 21:24 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2017-02-28 21:23 - 2016-12-13 16:44 - 00000000 ____D C:\AdwCleaner
2017-02-28 21:19 - 2016-03-24 09:44 - 00000000 ____D C:\Users\Helenka\Documents\UCE
2017-02-28 21:18 - 2016-03-24 09:41 - 00000000 ____D C:\Users\Helenka\AppData\Local\Deployment
2017-02-28 21:12 - 2016-12-25 15:29 - 00000000 ____D C:\Users\Helenka\Desktop\HRY
2017-02-28 21:12 - 2016-10-29 09:01 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2017-02-28 21:05 - 2016-11-02 15:02 - 00000000 ____D C:\Program Files (x86)\Prison Architect
2017-02-28 19:58 - 2017-01-21 17:39 - 00003922 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2017-02-28 19:57 - 2016-10-26 17:46 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-28 19:50 - 2016-03-22 23:13 - 00000000 ____D C:\Users\Helenka
2017-02-28 19:48 - 2013-08-22 15:44 - 05119360 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-28 19:46 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2017-02-28 19:45 - 2017-01-21 17:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-02-28 19:45 - 2017-01-21 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid
2017-02-28 19:45 - 2017-01-21 10:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-02-28 19:45 - 2016-09-05 07:18 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller
2017-02-28 19:45 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-28 19:45 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-02-28 19:45 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2017-02-28 19:42 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-28 19:34 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\registration
2017-02-28 19:32 - 2017-01-14 17:22 - 00000000 ____D C:\Users\Helenka\AppData\Local\Roblox
2017-02-28 19:14 - 2017-01-21 14:42 - 00000000 ____D C:\Users\Helenka\AppData\Local\CrashDumps
2017-02-27 13:26 - 2016-03-19 17:25 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\.minecraft
2017-02-22 11:40 - 2012-07-26 08:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-21 09:57 - 2017-01-21 17:50 - 00000000 ____D C:\Users\Helenka\AppData\LocalLow\Mozilla
2017-02-16 17:37 - 2013-03-12 18:01 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-02-16 17:36 - 2016-10-30 10:39 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2017-02-16 14:48 - 2014-11-21 05:53 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-16 14:48 - 2014-11-21 05:10 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-16 14:48 - 2014-11-21 05:10 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-16 14:25 - 2016-10-29 09:01 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\uTorrent
2017-02-16 14:17 - 2016-10-15 16:19 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\DAEMON Tools Pro
2017-02-14 18:15 - 2016-03-23 14:12 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-14 18:15 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-01 16:52 - 2016-10-27 15:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-01-31 16:51 - 2016-09-05 07:18 - 00000000 ____D C:\ProgramData\Samsung
2017-01-31 15:09 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
==================== Files in the root of some directories =======
2017-02-21 08:58 - 2017-02-23 16:41 - 0002368 _____ () C:\Program Files (x86)\metadata
2016-11-14 20:23 - 2016-11-14 20:23 - 0000014 _____ () C:\Users\Helenka\AppData\Roaming\dmcusername.file
2016-03-29 19:55 - 2016-03-29 19:55 - 0050304 _____ () C:\Users\Helenka\AppData\Roaming\gtk20.mo.id_c05a2ddbccba96cf_email_zeta@dr.com.scl
2016-11-14 20:17 - 2016-11-14 20:17 - 0000000 _____ () C:\Users\Helenka\AppData\Roaming\pof.exact
2016-03-27 21:25 - 2016-03-27 21:25 - 0001960 _____ () C:\Users\Helenka\AppData\Roaming\SeleniumCisternaFronton
2014-10-07 05:39 - 2014-10-07 05:39 - 0011264 _____ () C:\Users\Helenka\AppData\Roaming\System.dll
2016-05-04 16:12 - 2016-05-04 16:12 - 0000003 _____ () C:\Users\Helenka\AppData\Local\updater.log
2016-05-04 16:12 - 2016-08-06 20:36 - 0000424 _____ () C:\Users\Helenka\AppData\Local\UserProducts.xml
2017-01-31 16:50 - 2017-01-31 16:50 - 0000185 _____ () C:\Users\Helenka\AppData\Local\uts.ini
2016-03-18 17:18 - 2016-03-18 17:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2017-01-21 12:21 - 2017-01-21 12:21 - 0321024 _____ () C:\Users\Helenka\AppData\Local\Temp\2ce83b48-6995-4a17-8074-68fc477a651e_x86.exe
2017-01-21 12:10 - 2017-01-21 12:10 - 0739904 _____ (Oracle Corporation) C:\Users\Helenka\AppData\Local\Temp\jre-8u121-windows-au.exe
2016-10-19 16:11 - 2016-10-19 16:11 - 2458672 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Helenka\AppData\Local\Temp\libeay32.dll
2016-10-19 16:11 - 2016-10-19 16:11 - 0970912 _____ (Microsoft Corporation) C:\Users\Helenka\AppData\Local\Temp\msvcr120.dll
2017-02-05 10:49 - 2017-02-02 16:56 - 1342792 _____ (Andy OS, inc.) C:\Users\Helenka\AppData\Local\Temp\RemoveTemp.exe
2017-02-04 11:37 - 2017-02-04 11:37 - 1214528 _____ (Andy OS, inc.) C:\Users\Helenka\AppData\Local\Temp\SetAPK.exe
2016-10-19 16:11 - 2016-10-19 16:11 - 0772672 _____ () C:\Users\Helenka\AppData\Local\Temp\sqlite3.dll
2017-01-21 12:13 - 2017-01-21 14:35 - 0663658 _____ () C:\Users\Helenka\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD.
LastRegBack: 2017-02-25 17:25
==================== End of FRST.txt ============================
Děkuji
Helena
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-03-2017
Ran by Helenka (administrator) on DOMA (01-03-2017 14:42:10)
Running from C:\Users\Helenka\Desktop\ÚDRŽBA
Loaded Profiles: Helenka (Available Profiles: Helenka)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
() C:\Windows\SysWOW64\spdsvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Informer Technologies, Inc.) C:\Program Files\Software Informer\softinfo.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-11-20] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe [64640 2013-01-28] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-24] (Conexant Systems, Inc.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2017-01-21] (AVAST Software)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-01-28] (Qualcomm Atheros Commnucations)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {0c4bd6aa-b710-11e6-bea7-089e01400cec} - "E:\autorun.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {4651e03c-df23-11e6-bead-806e6f6e6963} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {59627320-ca0a-11e6-beab-089e01400cec} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {ba04a953-ed21-11e5-be69-806e6f6e6963} - "D:\Setup.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {cb6f8045-dfe3-11e6-beb1-089e01400cec} - "E:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\...\MountPoints2: {eff2e197-8fbc-11e6-be92-089e01400cec} - "F:\Setup.exe"
HKLM\...\Providers\Internet Print Provider: inetpp.dll
HKLM\...\Providers\LanMan Print Services: win32spl.dll
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-01-21] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk [2017-03-01]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Network PC Fax.lnk [2017-03-01]
Startup: C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk [2017-03-01]
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 185.97.254.158 api.facepunch.com
Tcpip\Parameters: [DhcpNameServer] 82.144.128.1 82.144.129.1
Tcpip\..\Interfaces\{6E729190-5055-4A76-BB8B-3DEFC60ADD76}: [DhcpNameServer] 82.144.128.1 82.144.129.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-2520944081-2684202109-2728405321-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.cz/
SearchScopes: HKU\S-1-5-21-2520944081-2684202109-2728405321-1001 -> DefaultScope {4B7AB1A7-9E69-4413-BBB0-50F38FBC11F0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2520944081-2684202109-2728405321-1001 -> {4B7AB1A7-9E69-4413-BBB0-50F38FBC11F0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2520944081-2684202109-2728405321-1001 -> {BD63004A-89AC-488F-8A5A-D4311713A735} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-02-01] (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll [2013-01-28] (Qualcomm Atheros Commnucations)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-01] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: taoywzw4.default
FF ProfilePath: C:\Users\Helenka\AppData\Roaming\Mozilla\Firefox\Profiles\taoywzw4.default [2017-02-28]
FF Extension: (MEGA) - C:\Users\Helenka\AppData\Roaming\Mozilla\Firefox\Profiles\taoywzw4.default\Extensions\firefox@mega.co.nz.xpi [2017-01-21]
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-01] (Oracle Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-21] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2016-09-01] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2520944081-2684202109-2728405321-1001: @nsroblox.roblox.com/launcher -> C:\Users\Helenka\AppData\Local\Roblox\Versions\version-ca61db0aa1b8462c\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2520944081-2684202109-2728405321-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Helenka\AppData\Local\Roblox\Versions\version-ca61db0aa1b8462c\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-01] <==== ATTENTION
CHR Extension: (Dokumenty Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-16]
CHR Extension: (Chrome Media Router) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-16]
CHR Profile: C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default [2017-02-16]
CHR Extension: (Prezentace Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-28]
CHR Extension: (Dokumenty Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-28]
CHR Extension: (Disk Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-28]
CHR Extension: (YouTube) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-28]
CHR Extension: (Adblock Plus) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-01-21]
CHR Extension: (Kalendář Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-01-07]
CHR Extension: (Tabulky Google) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Gmail) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-28]
CHR Extension: (Chrome Media Router) - C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-03]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2017-01-21] (AVAST Software)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2449552 2012-10-25] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [227104 2016-07-21] (EasyAntiCheat Ltd)
S3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658064 2012-10-23] (Acer Incorporated)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-15] (Nero AG) [File not signed]
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2007-03-12] (Nero AG)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-11-03] (NTI Corporation)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2013-09-13] (arvato digital services llc)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2016-03-18] (Dritek System INC.)
R2 Samsung Network Fax Server; C:\WINDOWS\system32\spool\drivers\x64\3\NetFaxServer64.exe [801472 2015-03-10] (Samsung Electronics Co., Ltd.)
R2 Samsung Printer Dianostics Service; C:\WINDOWS\SysWOW64\\spdsvc.exe [499000 2016-07-17] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2016-03-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2016-03-22] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
S2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [37656 2017-01-21] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [108816 2017-01-21] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [103064 2017-01-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2017-01-21] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [969184 2017-01-21] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [513632 2017-01-21] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [163416 2017-01-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2017-01-21] (AVAST Software)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [311968 2016-04-07] ()
S3 BTATH_LWFLT; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros)
R1 ccSet_NARA; C:\WINDOWS\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [283200 2016-10-15] (DT Soft Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18816 2016-11-25] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-10-16] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-11-25] (Huawei Technologies Co., Ltd.)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [43168 2016-04-07] ()
R3 Ps2Kb2Hid; C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys [26736 2016-03-18] (Dritek System Inc.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44560 2016-03-22] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [270168 2016-03-22] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [114520 2016-03-22] (Microsoft Corporation)
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-01 14:40 - 2017-03-01 14:40 - 01201152 _____ C:\Users\Helenka\Downloads\RSIT.exe
2017-03-01 14:40 - 2017-03-01 14:40 - 00000000 ____D C:\Program Files (x86)\trend micro
2017-03-01 14:39 - 2017-03-01 14:41 - 00000000 ____D C:\Program Files\trend micro
2017-03-01 14:39 - 2017-03-01 14:39 - 01324032 _____ C:\Users\Helenka\Downloads\RSITx64.exe
2017-03-01 14:39 - 2017-03-01 14:39 - 00000000 ____D C:\rsit
2017-03-01 14:36 - 2017-03-01 14:42 - 00000000 ____D C:\FRST
2017-03-01 14:32 - 2017-03-01 14:32 - 00001342 _____ C:\Users\Helenka\Desktop\Steam – zástupce.lnk
2017-02-28 21:20 - 2017-02-28 21:20 - 04015056 _____ C:\Users\Helenka\Downloads\adwcleaner_6.043.exe
2017-02-28 19:56 - 2017-01-21 17:38 - 00391496 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-02-28 19:50 - 2017-02-28 19:50 - 00000000 ____D C:\Program Files\d6xr5dra
2017-02-28 19:07 - 2017-02-28 19:07 - 00000000 ____D C:\Program Files (x86)\Roblox
2017-02-28 15:12 - 2017-02-28 15:12 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignc09dc6f9b54e61be
2017-02-28 15:12 - 2017-02-28 15:12 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign52d941e8a60fe453
2017-02-28 15:12 - 2017-02-28 15:12 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign217c8aa3415ed6db
2017-02-28 15:11 - 2017-02-28 15:11 - 00162250 _____ C:\Users\Helenka\Downloads\Logo 4_5.psd
2017-02-28 15:07 - 2017-02-28 15:07 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignc916e49dff10a768
2017-02-28 15:06 - 2017-02-28 15:06 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign78991dca011c406e
2017-02-28 15:04 - 2017-02-28 15:04 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign35543eccefd88b80
2017-02-28 15:03 - 2017-02-28 15:03 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigndeadfe53c82375c5
2017-02-28 15:02 - 2017-02-28 15:02 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignba2f8e3179cf541d
2017-02-28 15:02 - 2017-02-28 15:02 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign9fac53ad27915299
2017-02-21 08:58 - 2017-02-23 16:41 - 00002368 _____ C:\Program Files (x86)\metadata
2017-02-20 19:37 - 2017-02-20 19:37 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Firefox
2017-02-20 19:37 - 2017-02-20 19:37 - 00000000 ____D C:\Users\Helenka\AppData\Local\Firefox
2017-02-18 13:02 - 2017-02-18 13:02 - 00000000 ____D C:\Users\Helenka\AppData\LocalLow\Smartly Dressed Games
2017-02-17 15:16 - 2017-02-17 15:16 - 11427754 _____ C:\Users\Helenka\Downloads\SA_Euro_1.01_COLD (1).zip
2017-02-17 15:11 - 2017-02-17 15:12 - 11427754 _____ C:\Users\Helenka\Downloads\SA_Euro_1.01_COLD.zip
2017-02-17 15:10 - 2017-02-17 15:10 - 00000000 ____D C:\Users\Helenka\Downloads\SA_Euro_1[1].01_COLD
2017-02-17 15:07 - 2017-02-17 15:07 - 11429090 _____ C:\Users\Helenka\Downloads\SA_Euro_1[1].01_COLD.zip
2017-02-17 15:06 - 2017-02-28 19:45 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\GetRightToGo
2017-02-17 12:50 - 2017-02-28 20:54 - 00000000 ____D C:\Program Files (x86)\d6xr5dra
2017-02-16 19:03 - 2017-02-16 19:03 - 01191753 _____ C:\Users\Helenka\Downloads\gtasa120cz.zip
2017-02-16 19:03 - 2017-02-16 19:03 - 01191753 _____ C:\Users\Helenka\Downloads\gtasa120cz (1).zip
2017-02-16 18:13 - 2017-02-17 14:34 - 00000000 ____D C:\Users\Helenka\Documents\GTA San Andreas User Files
2017-02-16 17:42 - 2017-02-16 17:42 - 00000000 ____D C:\Users\Helenka\Documents\GTA Vice City User Files
2017-02-16 17:37 - 2017-02-16 17:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2017-02-16 16:01 - 2017-02-16 16:29 - 501886548 _____ C:\Users\Helenka\Downloads\Nepotvrzeno 213209.crdownload
2017-02-16 16:01 - 2017-02-16 16:01 - 00997949 _____ C:\Users\Helenka\Downloads\Odin3-v3.11.1.zip
2017-02-16 15:21 - 2017-02-16 15:21 - 00000000 ____D C:\Users\Helenka\Downloads\This-War-of-Mine-(OBB)_1.4.0-Android-1.com
2017-02-16 15:19 - 2017-02-16 15:21 - 479843375 _____ C:\Users\Helenka\Downloads\This-War-of-Mine-(OBB)_1.4.0-Android-1.com.zip
2017-02-16 15:18 - 2017-02-16 15:19 - 08639390 _____ C:\Users\Helenka\Downloads\This-War-of-Mine-(MOD)_1.4.0-Android-1.com.apk
2017-02-16 15:01 - 2017-02-16 15:03 - 426279395 _____ C:\Users\Helenka\Downloads\main.153.com.elevenbitstudios.twommobile.obb
2017-02-16 15:01 - 2017-02-16 15:01 - 12457066 _____ C:\Users\Helenka\Downloads\This_War_of_Mine_v1.1.0.apk
2017-02-16 14:54 - 2017-02-16 14:59 - 00000000 ____D C:\Users\Helenka\AppData\Local\Fagertain
2017-02-16 14:54 - 2017-02-16 14:54 - 02400960 _____ (BitTorrent Inc.) C:\Users\Helenka\Downloads\Reimage Pc Repair 2017 Crack License Key Full Do
2017-02-16 14:52 - 2017-02-16 14:52 - 01769472 _____ C:\Users\Helenka\Downloads\Reimage_Pc_Repair_2017_Crack_License_Key_Full_Do.iso
2017-02-16 14:44 - 2017-02-16 14:44 - 00000000 ____D C:\Program Files\Common Files\Atheros
2017-02-16 14:41 - 2017-02-16 14:42 - 62008080 _____ (Microsoft Corporation) C:\Users\Helenka\Downloads\NDP462-KB3151800-x86-x64-AllOS-ENU.exe
2017-02-16 14:40 - 2015-01-06 04:01 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2017-02-16 14:40 - 2015-01-06 03:59 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2017-02-16 14:40 - 2015-01-06 02:12 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll
2017-02-16 14:40 - 2015-01-06 02:02 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdgeoqw.dll
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZST.DLL
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZEL.DLL
2017-02-16 14:39 - 2015-10-22 18:43 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZE.DLL
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbdgeoqw.dll
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZST.DLL
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZEL.DLL
2017-02-16 14:39 - 2015-10-22 17:59 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZE.DLL
2017-02-16 14:39 - 2015-06-09 23:39 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2017-02-16 14:39 - 2015-06-09 23:39 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2017-02-16 14:39 - 2015-06-09 23:38 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-02-16 14:17 - 2017-02-16 14:17 - 00000000 ____D C:\Users\Helenka\Downloads\THIS WAR OF MINE MULTI11-TINYISO
2017-02-16 14:16 - 2017-02-16 14:16 - 1047527424 _____ C:\Users\Helenka\Downloads\THIS WAR OF MINE MULTI11-TINYISO.part1.rar
2017-02-16 14:14 - 2017-02-16 14:14 - 445594172 _____ C:\Users\Helenka\Downloads\THIS WAR OF MINE MULTI11-TINYISO.part2.rar
2017-02-16 13:51 - 2017-02-16 13:55 - 00000000 ____D C:\Users\Helenka\Downloads\This.War.of.Mine.2.2.0.6-GOG
2017-02-14 18:33 - 2017-02-14 18:33 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign2296590078b5e7ae
2017-02-14 18:32 - 2017-02-14 18:32 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignedd47d57ec5bd248
2017-02-14 18:32 - 2017-02-14 18:32 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign888540c9561f0931
2017-02-14 18:32 - 2017-02-14 18:32 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign5667d3375895e8e3
2017-02-14 18:30 - 2017-02-14 18:30 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign301175d1a80dcbea
2017-02-14 18:27 - 2017-02-14 18:27 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign427b32ca5a614424
2017-02-14 18:25 - 2017-02-14 18:25 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign9c0f021eb6fbaa61
2017-02-14 18:24 - 2017-02-14 18:24 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignf614c0408a71828c
2017-02-14 18:24 - 2017-02-14 18:24 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign0b27521e5b84870d
2017-02-14 18:22 - 2017-02-14 18:22 - 00000000 ____D C:\Users\Helenka\Documents\Moje palety
2017-02-14 18:18 - 2017-02-14 18:38 - 00000000 ____D C:\Users\Helenka\Documents\Corel
2017-02-14 18:16 - 2017-02-14 18:18 - 00000000 ____D C:\ProgramData\Protexis64
2017-02-14 18:16 - 2017-02-14 18:17 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Corel
2017-02-14 18:13 - 2017-02-14 18:13 - 00000000 ____D C:\Program Files\Common Files\Protexis
2017-02-14 18:13 - 2017-02-14 18:13 - 00000000 ____D C:\Program Files\Common Files\Corel
2017-02-14 18:12 - 2017-02-14 18:12 - 00000000 ____D C:\Users\Public\Documents\Corel
2017-02-14 18:11 - 2017-02-14 18:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X7 (64-bit)
2017-02-14 18:10 - 2017-02-14 18:22 - 00000000 ____D C:\ProgramData\Corel
2017-02-14 18:10 - 2017-02-14 18:10 - 00000000 ____D C:\Program Files\Corel
2017-02-14 18:09 - 2017-02-14 18:16 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2017-02-13 19:11 - 2017-02-13 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-02-09 15:38 - 2017-02-09 15:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign159db5a12a1b4458
2017-02-09 15:34 - 2017-02-09 15:34 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign2e0d1f449035f999
2017-02-09 15:33 - 2017-02-09 15:33 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigne4353cd72dab39c1
2017-02-09 15:33 - 2017-02-09 15:33 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign416b0962cd957a3c
2017-02-09 15:17 - 2017-02-09 15:17 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign45af800af66706ec
2017-02-09 15:10 - 2017-02-09 15:10 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignb6843e5215a60fce
2017-02-09 15:10 - 2017-02-09 15:10 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigna0f9ada621f7a0da
2017-02-09 15:10 - 2017-02-09 15:10 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign1b69d86ae2371a9d
2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignf5d201c99aadad2b
2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign861a54750adccc38
2017-02-09 14:25 - 2017-02-09 14:25 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign3d1fee0e62ac8541
2017-02-09 14:25 - 2017-02-09 14:25 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign284b588a449ceb0d
2017-02-05 11:08 - 2017-02-05 11:08 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\.mono
2017-02-05 11:08 - 2017-02-05 11:08 - 00000000 ____D C:\Users\Helenka\AppData\Local\Colossal Order
2017-02-05 11:08 - 2017-02-05 11:08 - 00000000 ____D C:\ProgramData\.mono
2017-02-05 11:05 - 2017-02-05 11:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cities Skylines
2017-02-05 10:42 - 2017-02-05 11:09 - 00000000 ____D C:\Program Files (x86)\Cities Skylines
2017-02-05 10:37 - 2017-02-05 10:37 - 00000000 ____D C:\Users\Helenka\Downloads\Cities Skylines (CZ.MULTi8) [Repack] by 'Teag
2017-02-05 10:36 - 2017-02-05 10:36 - 00020273 _____ C:\Users\Helenka\Downloads\[CzT]Cities_Skylines_2015_CZ_.torrent
2017-02-04 11:49 - 2017-02-05 10:49 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\VMware
2017-02-04 11:48 - 2017-02-04 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
2017-02-04 11:44 - 2016-11-11 23:16 - 00052288 _____ (VMware, Inc.) C:\WINDOWS\system32\Drivers\vmkbd.sys
2017-02-04 11:43 - 2017-02-04 11:43 - 01772950 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-02-04 11:34 - 2017-02-05 10:55 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Andy
2017-02-04 11:34 - 2017-02-04 11:34 - 00000000 ____D C:\Users\Helenka\Andy
2017-02-04 11:34 - 2017-02-04 11:34 - 00000000 ____D C:\Users\Helenk\Andy
2017-02-04 11:34 - 2017-02-04 11:34 - 00000000 ____D C:\Users\Helenk
2017-02-04 11:28 - 2017-02-04 11:28 - 00000000 ____D C:\Users\Helenka\Downloads\turbo_dismount
2017-02-04 11:27 - 2017-02-04 11:27 - 23590896 _____ C:\Users\Helenka\Downloads\turbo_dismount.zip
2017-02-04 11:24 - 2017-02-04 11:24 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign37a12e80b9d0a5ba
2017-02-04 11:18 - 2017-02-04 11:18 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigna10886a37f4fe292
2017-02-04 11:18 - 2017-02-04 11:18 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign8e548af1ed29e347
2017-02-04 11:17 - 2017-02-04 11:17 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignf9a924637a0b91c6
2017-02-04 11:11 - 2017-02-04 11:11 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign53157a1cb68ca8ed
2017-02-04 11:10 - 2017-02-04 11:10 - 00020043 _____ C:\Users\Helenka\Downloads\badaboom_bb.zip
2017-02-04 11:06 - 2017-02-04 11:06 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsigneaf45255bdf0fc16
2017-02-04 11:05 - 2017-02-04 11:05 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign9416758e973fe8f0
2017-02-04 11:05 - 2017-02-04 11:05 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign7ab85f2896d733c4
2017-02-03 13:34 - 2017-02-03 14:13 - 122252416 _____ C:\Users\Helenka\Downloads\Gardenscapes_v1.2.6_Mod__6883_Revdl.com.apk
2017-02-03 12:39 - 2017-02-03 12:39 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign99857d28011ee141
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignfc43a01f914379ab
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsignb19a9667328a68e7
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign5a94667f9465603c
2017-02-03 12:38 - 2017-02-03 12:38 - 00000000 ____D C:\Users\Helenka\AppData\Local\Tempzxpsign2eb10529867085d2
2017-02-01 18:13 - 2017-02-01 18:13 - 00000000 ____D C:\Users\Helenka\Documents\ROBLOX
2017-02-01 16:53 - 2017-02-01 16:54 - 00000000 ____D C:\Program Files\Android
2017-02-01 16:53 - 2017-02-01 16:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Android SDK Tools
2017-02-01 16:53 - 2017-02-01 16:52 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-02-01 16:51 - 2017-02-01 16:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2017-02-01 16:50 - 2017-02-01 16:52 - 00000000 ____D C:\Program Files\Java
2017-01-31 17:32 - 2017-02-16 15:25 - 00000000 ____D C:\Users\Helenka\.android
2017-01-31 17:30 - 2017-01-31 17:30 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\ADBDriverInstaller
2017-01-31 17:29 - 2017-01-31 17:29 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Android SDK Tools
2017-01-31 17:28 - 2017-01-31 17:33 - 00000000 ____D C:\Android
2017-01-31 17:15 - 2017-01-31 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Android Studio
2017-01-31 17:07 - 2017-01-31 17:22 - 00000000 ____D C:\Users\Helenka\AppData\Local\Android
2017-01-31 16:57 - 2017-01-31 16:57 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2017-01-31 16:51 - 2017-01-31 16:51 - 00000000 ____D C:\Program Files\SAMSUNG
2017-01-31 16:50 - 2017-01-31 16:50 - 00000185 _____ C:\Users\Helenka\AppData\Local\uts.ini
2017-01-31 16:50 - 2017-01-31 16:50 - 00000000 ____D C:\Users\Helenka\AppData\Local\uts
2017-01-31 16:49 - 2017-02-16 17:37 - 00000000 ____D C:\Program Files (x86)\Kingo ROOT
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-01 14:38 - 2017-01-21 10:46 - 00000000 ____D C:\Program Files (x86)\Steam
2017-03-01 14:36 - 2016-04-01 13:58 - 00000000 ____D C:\Users\Helenka\Desktop\ÚDRŽBA
2017-03-01 14:32 - 2016-03-23 14:20 - 00003962 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2913751E-8255-4176-B63F-A7232F23BCFB}
2017-03-01 14:29 - 2016-10-18 16:03 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2520944081-2684202109-2728405321-1001
2017-03-01 14:28 - 2017-01-14 17:22 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2017-03-01 14:22 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-01 14:21 - 2016-03-19 14:53 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-01 14:17 - 2016-03-19 14:53 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-01 14:13 - 2017-01-21 17:49 - 00001139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-03-01 14:13 - 2016-12-17 15:36 - 00001104 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-03-01 14:13 - 2016-11-29 18:34 - 00001501 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frontier Launchpad.lnk
2017-03-01 14:13 - 2016-10-28 10:05 - 00002179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-01 14:13 - 2016-04-15 11:00 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-03-01 14:13 - 2016-03-23 14:07 - 00001430 _____ C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-01 14:13 - 2016-03-22 23:19 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-03-01 14:13 - 2016-03-22 23:13 - 00000469 _____ C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2017-03-01 14:13 - 2016-03-22 23:13 - 00000467 _____ C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2017-03-01 14:13 - 2016-03-19 12:38 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2017-03-01 14:13 - 2016-03-18 17:53 - 00002133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Norton Online Backup.lnk
2017-03-01 14:13 - 2016-03-18 17:50 - 00001984 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk
2017-03-01 14:13 - 2013-03-12 17:30 - 00002636 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - acer.lnk
2017-02-28 21:24 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2017-02-28 21:23 - 2016-12-13 16:44 - 00000000 ____D C:\AdwCleaner
2017-02-28 21:19 - 2016-03-24 09:44 - 00000000 ____D C:\Users\Helenka\Documents\UCE
2017-02-28 21:18 - 2016-03-24 09:41 - 00000000 ____D C:\Users\Helenka\AppData\Local\Deployment
2017-02-28 21:12 - 2016-12-25 15:29 - 00000000 ____D C:\Users\Helenka\Desktop\HRY
2017-02-28 21:12 - 2016-10-29 09:01 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2017-02-28 21:05 - 2016-11-02 15:02 - 00000000 ____D C:\Program Files (x86)\Prison Architect
2017-02-28 19:58 - 2017-01-21 17:39 - 00003922 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2017-02-28 19:57 - 2016-10-26 17:46 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-28 19:50 - 2016-03-22 23:13 - 00000000 ____D C:\Users\Helenka
2017-02-28 19:48 - 2013-08-22 15:44 - 05119360 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-28 19:46 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2017-02-28 19:45 - 2017-01-21 17:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-02-28 19:45 - 2017-01-21 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirDroid
2017-02-28 19:45 - 2017-01-21 10:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-02-28 19:45 - 2016-09-05 07:18 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller
2017-02-28 19:45 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-28 19:45 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-02-28 19:45 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2017-02-28 19:42 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-28 19:34 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\registration
2017-02-28 19:32 - 2017-01-14 17:22 - 00000000 ____D C:\Users\Helenka\AppData\Local\Roblox
2017-02-28 19:14 - 2017-01-21 14:42 - 00000000 ____D C:\Users\Helenka\AppData\Local\CrashDumps
2017-02-27 13:26 - 2016-03-19 17:25 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\.minecraft
2017-02-22 11:40 - 2012-07-26 08:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-21 09:57 - 2017-01-21 17:50 - 00000000 ____D C:\Users\Helenka\AppData\LocalLow\Mozilla
2017-02-16 17:37 - 2013-03-12 18:01 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-02-16 17:36 - 2016-10-30 10:39 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2017-02-16 14:48 - 2014-11-21 05:53 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-16 14:48 - 2014-11-21 05:10 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-16 14:48 - 2014-11-21 05:10 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-16 14:25 - 2016-10-29 09:01 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\uTorrent
2017-02-16 14:17 - 2016-10-15 16:19 - 00000000 ____D C:\Users\Helenka\AppData\Roaming\DAEMON Tools Pro
2017-02-14 18:15 - 2016-03-23 14:12 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-14 18:15 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-01 16:52 - 2016-10-27 15:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-01-31 16:51 - 2016-09-05 07:18 - 00000000 ____D C:\ProgramData\Samsung
2017-01-31 15:09 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
==================== Files in the root of some directories =======
2017-02-21 08:58 - 2017-02-23 16:41 - 0002368 _____ () C:\Program Files (x86)\metadata
2016-11-14 20:23 - 2016-11-14 20:23 - 0000014 _____ () C:\Users\Helenka\AppData\Roaming\dmcusername.file
2016-03-29 19:55 - 2016-03-29 19:55 - 0050304 _____ () C:\Users\Helenka\AppData\Roaming\gtk20.mo.id_c05a2ddbccba96cf_email_zeta@dr.com.scl
2016-11-14 20:17 - 2016-11-14 20:17 - 0000000 _____ () C:\Users\Helenka\AppData\Roaming\pof.exact
2016-03-27 21:25 - 2016-03-27 21:25 - 0001960 _____ () C:\Users\Helenka\AppData\Roaming\SeleniumCisternaFronton
2014-10-07 05:39 - 2014-10-07 05:39 - 0011264 _____ () C:\Users\Helenka\AppData\Roaming\System.dll
2016-05-04 16:12 - 2016-05-04 16:12 - 0000003 _____ () C:\Users\Helenka\AppData\Local\updater.log
2016-05-04 16:12 - 2016-08-06 20:36 - 0000424 _____ () C:\Users\Helenka\AppData\Local\UserProducts.xml
2017-01-31 16:50 - 2017-01-31 16:50 - 0000185 _____ () C:\Users\Helenka\AppData\Local\uts.ini
2016-03-18 17:18 - 2016-03-18 17:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2017-01-21 12:21 - 2017-01-21 12:21 - 0321024 _____ () C:\Users\Helenka\AppData\Local\Temp\2ce83b48-6995-4a17-8074-68fc477a651e_x86.exe
2017-01-21 12:10 - 2017-01-21 12:10 - 0739904 _____ (Oracle Corporation) C:\Users\Helenka\AppData\Local\Temp\jre-8u121-windows-au.exe
2016-10-19 16:11 - 2016-10-19 16:11 - 2458672 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Helenka\AppData\Local\Temp\libeay32.dll
2016-10-19 16:11 - 2016-10-19 16:11 - 0970912 _____ (Microsoft Corporation) C:\Users\Helenka\AppData\Local\Temp\msvcr120.dll
2017-02-05 10:49 - 2017-02-02 16:56 - 1342792 _____ (Andy OS, inc.) C:\Users\Helenka\AppData\Local\Temp\RemoveTemp.exe
2017-02-04 11:37 - 2017-02-04 11:37 - 1214528 _____ (Andy OS, inc.) C:\Users\Helenka\AppData\Local\Temp\SetAPK.exe
2016-10-19 16:11 - 2016-10-19 16:11 - 0772672 _____ () C:\Users\Helenka\AppData\Local\Temp\sqlite3.dll
2017-01-21 12:13 - 2017-01-21 14:35 - 0663658 _____ () C:\Users\Helenka\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD.
LastRegBack: 2017-02-25 17:25
==================== End of FRST.txt ============================