Problém - reimageplus.com
Napsal: 16 bře 2017 18:13
Dobrý den, potřeboval bych pomoc s odstraněním reimageplus.com, který mi otevírá okna. Antivir jej nedetekuje.
Předem děkuji JD
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Lukáš (administrator) on ASUS-K50IN (16-03-2017 18:02:25)
Running from C:\Users\Lukáš\Desktop
Loaded Profiles: Lukáš (Available Profiles: Lukáš)
Platform: Windows 10 Pro Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Wacom Technology, Corp.) C:\Windows\System32\Wacom_Tablet.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(forum.viry.cz) C:\Users\Lukáš\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2016-12-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-12-09] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2000-01-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1407201582-3230588637-309285028-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1407201582-3230588637-309285028-1001\...\MountPoints2: {5b641cc8-cc36-11e6-9bda-90e6ba2b2201} - "F:\Setup.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2017-01-15]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 195.250.128.34 212.20.96.34
Tcpip\..\Interfaces\{8669b414-8228-4a70-915d-a3033176af77}: [DhcpNameServer] 195.250.128.34 212.20.96.34
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-10-11] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-10-18] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2009-09-25] (Wacom, Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-10-18] (Microsoft Corporation)
Chrome:
=======
CHR HomePage: Default -> hxxp://google.com/
CHR NewTab: Default -> Not-active:"chrome-extension://oilnfikhhkljogdookibmpkbmdiklgfp/newtab/newtab.html", Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/stubby.html"
CHR Profile: C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default [2017-03-16]
CHR Extension: (Tabulky Google) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-08]
CHR Extension: (Data generator) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\legklhfpihknmgmlhiadachbaihccpho [2017-02-01]
CHR Extension: (FromDocToPDF) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2017-02-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Muzik Fury) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilnfikhhkljogdookibmpkbmdiklgfp [2017-02-01]
CHR Extension: (Gmail) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-08]
CHR Extension: (Chrome Media Router) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-06]
CHR HKU\S-1-5-21-1407201582-3230588637-309285028-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2016-12-08] (ELAN Microelectronics Corp.)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2016-11-17] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1165368 2016-11-17] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [307456 2000-01-01] (Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-12-09] (Microsoft Corporation)
R2 TabletServiceWacom; C:\WINDOWS\system32\Wacom_Tablet.exe [6245744 2010-03-09] (Wacom Technology, Corp.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ATK64AMD.sys [13680 2016-12-08] ()
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2016-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47672 2016-11-17] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [888064 2000-01-01] (Realtek )
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-16 18:02 - 2017-03-16 18:03 - 00011764 _____ C:\Users\Lukáš\Desktop\FRST.txt
2017-03-16 18:02 - 2017-03-16 18:02 - 00000000 ____D C:\FRST
2017-03-16 18:00 - 2017-03-16 18:02 - 02424832 _____ (Farbar) C:\Users\Lukáš\Desktop\FRST64.exe
2017-03-16 17:58 - 2017-03-16 18:01 - 00112640 _____ (forum.viry.cz) C:\Users\Lukáš\Desktop\FRSTLauncher.exe
2017-03-15 16:53 - 2017-03-15 16:53 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Lukáš\Downloads\esetonlinescanner_enu (2).exe
2017-03-15 16:53 - 2017-03-15 16:53 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Lukáš\Downloads\esetonlinescanner_enu (1).exe
2017-03-14 21:56 - 2017-03-14 21:56 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Lukáš\Downloads\esetonlinescanner_enu.exe
2017-03-14 21:56 - 2017-03-14 21:56 - 00000000 ____D C:\Users\Lukáš\AppData\Local\ESET
2017-03-14 21:50 - 2017-03-14 21:51 - 09607112 _____ (TeamViewer) C:\Users\Lukáš\Downloads\TeamViewerQS_cs.exe
2017-03-10 16:43 - 2017-03-10 16:43 - 01146138 _____ C:\Users\Lukáš\Desktop\Princip ochrany novostaveb.jpeg
2017-03-10 16:42 - 2017-03-10 16:41 - 01134058 _____ C:\Users\Lukáš\Desktop\Stanovenà radonového indexu pozemku.jpeg
2017-03-10 16:40 - 2017-03-10 16:39 - 01039410 _____ C:\Users\Lukáš\Desktop\VĂ˝sledky měřenĂ.jpeg
2017-03-10 16:39 - 2017-03-10 16:38 - 00864960 _____ C:\Users\Lukáš\Desktop\Metodika průzkumu.jpeg
2017-03-10 16:37 - 2017-03-10 16:36 - 01063203 _____ C:\Users\Lukáš\Desktop\Odborný posudek.jpeg
2017-03-09 20:14 - 2017-03-09 20:14 - 00783166 _____ C:\Users\Lukáš\Desktop\8_2013160OST_5_Priloha_3_8_2013160OST_5_1_Metodika_1238485.pdf
2017-03-09 19:20 - 2017-03-09 19:20 - 00222130 _____ C:\Users\Lukáš\Downloads\Stanovisko_správnĂ_delikt_provozovatele_vozidla.pdf
2017-03-09 19:06 - 2017-03-09 19:06 - 00237324 _____ C:\Users\Lukáš\Desktop\30A_43_2014_40_20141016133803_prevedeno.pdf
2017-03-06 20:10 - 2017-03-06 20:11 - 33357112 _____ C:\Users\Lukáš\Desktop\manual Husqvarna_2006-610sm-service-m.pdf
2017-03-06 20:10 - 2017-03-06 20:10 - 08499090 _____ C:\Users\Lukáš\Desktop\TE-SM_610_2006.pdf
2017-03-06 19:47 - 2017-03-06 19:47 - 08499090 _____ C:\Users\Lukáš\Downloads\TE-SM_610_2006.pdf
2017-03-06 18:02 - 2017-03-06 18:02 - 33333029 _____ C:\Users\Lukáš\Downloads\5526_2006-610sm-service-m.pdf
2017-03-03 23:09 - 2017-03-03 23:09 - 01819930 _____ C:\Users\Lukáš\Downloads\commonly_used_ornate_border_vector_531356.zip
2017-03-03 23:08 - 2017-03-03 23:08 - 04573804 _____ C:\Users\Lukáš\Downloads\common_border_frame_vector_531518 (1).zip
2017-03-03 23:07 - 2017-03-03 23:08 - 04573804 _____ C:\Users\Lukáš\Downloads\common_border_frame_vector_531518.zip
2017-03-03 23:07 - 2017-03-03 23:07 - 09113031 _____ C:\Users\Lukáš\Downloads\black8_white_vintage_frames_mix_vector_520336 (1).zip
2017-03-03 23:01 - 2017-03-03 23:01 - 00553307 _____ C:\Users\Lukáš\Downloads\gold_decoration_border_vector_536547.zip
2017-03-03 22:56 - 2017-03-03 22:56 - 00580275 _____ C:\Users\Lukáš\Downloads\shiny_gold_framed_labels_ornament_vector_586650.zip
2017-03-03 22:55 - 2017-03-03 22:55 - 05907346 _____ C:\Users\Lukáš\Downloads\set_of_decorative_vintage_frame_vector_graphics_551505.zip
2017-03-03 22:52 - 2017-03-03 22:52 - 00493784 _____ C:\Users\Lukáš\Downloads\gold_lace_frame_vector_set_524535.zip
2017-03-03 22:51 - 2017-03-03 22:51 - 09113031 _____ C:\Users\Lukáš\Downloads\black8_white_vintage_frames_mix_vector_520336.zip
2017-03-03 22:23 - 2017-03-06 14:00 - 00000000 ____D C:\Users\Lukáš\Desktop\Kronika
2017-03-03 22:14 - 2017-03-03 22:14 - 00000000 ____D C:\Users\Lukáš\Downloads\set_of_decorative_vintage_frame_vector_graphics_551504
2017-03-03 22:01 - 2017-03-03 22:01 - 01785233 _____ C:\Users\Lukáš\Downloads\vintage_frames_ornaments_vector_set_587580 (2).zip
2017-03-03 22:00 - 2017-03-03 22:01 - 05640817 _____ C:\Users\Lukáš\Downloads\set_of_decorative_vintage_frame_vector_graphics_551504.zip
2017-03-03 22:00 - 2017-03-03 22:00 - 07618934 _____ C:\Users\Lukáš\Downloads\vintage_frames_vector_147952 (1).zip
2017-03-03 21:59 - 2017-03-03 21:59 - 07618934 _____ C:\Users\Lukáš\Downloads\vintage_frames_vector_147952.zip
2017-03-03 21:58 - 2017-03-03 21:58 - 01785233 _____ C:\Users\Lukáš\Downloads\vintage_frames_ornaments_vector_set_587580 (1).zip
2017-03-03 21:57 - 2017-03-03 21:57 - 01785233 _____ C:\Users\Lukáš\Downloads\vintage_frames_ornaments_vector_set_587580.zip
2017-03-02 10:55 - 2017-03-02 10:56 - 00835925 _____ C:\Users\Lukáš\Downloads\85-Free-Vintage-Vector-ornaments-vectorjunky.zip
2017-03-01 23:43 - 2017-03-01 23:43 - 00057618 _____ C:\Users\Lukáš\Downloads\yaquote_script.zip
2017-03-01 23:42 - 2017-03-01 23:42 - 00058823 _____ C:\Users\Lukáš\Downloads\odstemplik.zip
2017-03-01 23:40 - 2017-03-01 23:40 - 00061246 _____ C:\Users\Lukáš\Downloads\italianno.zip
2017-03-01 23:36 - 2017-03-01 23:36 - 00048019 _____ C:\Users\Lukáš\Downloads\respective.zip
2017-03-01 23:31 - 2017-03-01 23:31 - 00088299 _____ C:\Users\Lukáš\Downloads\kovanovicpisn_d.zip
2017-03-01 23:31 - 2017-03-01 23:31 - 00067412 _____ C:\Users\Lukáš\Downloads\porcelain.zip
2017-03-01 23:29 - 2017-03-01 23:29 - 00035231 _____ C:\Users\Lukáš\Downloads\be_safe.zip
2017-03-01 23:27 - 2017-03-01 23:27 - 00043459 _____ C:\Users\Lukáš\Downloads\beautiful_es.zip
2017-03-01 23:26 - 2017-03-01 23:26 - 00021159 _____ C:\Users\Lukáš\Downloads\lainiedaysh.zip
2017-03-01 23:21 - 2017-03-01 23:21 - 00156618 _____ C:\Users\Lukáš\Downloads\promocyja.zip
2017-03-01 23:19 - 2017-03-01 23:19 - 00169320 _____ C:\Users\Lukáš\Downloads\kawoszeh.zip
2017-03-01 23:11 - 2017-03-01 23:21 - 175227723 _____ C:\Users\Lukáš\Downloads\ceske-fonty-lianna-layoutgraphic-blog.cz.zip
2017-03-01 22:43 - 2017-03-01 22:43 - 00194524 _____ C:\Users\Lukáš\Downloads\a_glitch_in_time.zip
2017-03-01 22:42 - 2017-03-01 22:42 - 00026733 _____ C:\Users\Lukáš\Downloads\calligraphy.zip
2017-03-01 22:29 - 2017-03-01 22:29 - 00040504 _____ C:\Users\Lukáš\Downloads\indie_flower.zip
2017-03-01 22:27 - 2017-03-01 22:27 - 00099780 _____ C:\Users\Lukáš\Downloads\__dominique_font_by_ohwebelongtomusic-d422sio.ttf
2017-03-01 21:16 - 2017-03-01 21:16 - 31094400 _____ C:\Users\Lukáš\Downloads\DD_Vintage_Texture_45309.zip
2017-03-01 21:14 - 2017-03-01 21:14 - 01083697 _____ C:\Users\Lukáš\Downloads\japanese_borders_ai.zip
2017-02-28 22:00 - 2017-02-28 22:00 - 00040840 _____ C:\Users\Lukáš\Downloads\CEPHYLIS.TTF
2017-02-28 22:00 - 2017-02-28 22:00 - 00040840 _____ C:\Users\Lukáš\Downloads\CEPHYLIS (1).TTF
2017-02-28 21:53 - 2017-02-28 21:53 - 00052874 _____ C:\Users\Lukáš\Downloads\Piranesi_Italic_BT.ttf
2017-02-27 15:09 - 2017-02-27 15:09 - 00026151 _____ C:\Users\Lukáš\Downloads\etapa I. -A-2017_tĹ™Ădy_pro uÄŤitele.xlsx
2017-02-26 21:52 - 2017-02-26 21:53 - 178415392 _____ C:\Users\Lukáš\Desktop\Kniva rodiny.pdf
2017-02-26 17:48 - 2017-02-26 17:48 - 00695356 _____ C:\Users\Lukáš\Desktop\ÄŚestnĂ© prohlášenĂ.jpeg
2017-02-26 17:30 - 2017-02-26 17:31 - 00839695 _____ C:\Users\Lukáš\Desktop\Předávacà protokol.jpeg
2017-02-24 15:08 - 2017-02-24 15:08 - 06785492 _____ C:\Users\Lukáš\Downloads\11.tif
2017-02-24 15:08 - 2017-02-24 15:08 - 06785492 _____ C:\Users\Lukáš\Downloads\11 (1).tif
2017-02-23 08:18 - 2017-02-23 08:18 - 00504968 _____ C:\Users\Lukáš\Downloads\361_2003_Sb.pdf
2017-02-22 22:02 - 2017-02-22 22:02 - 08161756 _____ C:\Users\Lukáš\Downloads\2 (1).tif
2017-02-22 20:02 - 2017-02-22 20:02 - 06785296 _____ C:\Users\Lukáš\Downloads\10.tif
2017-02-22 19:48 - 2017-02-22 19:48 - 00063061 _____ C:\Users\Lukáš\Downloads\ÄŚĂm kanalizace.jpeg
2017-02-22 18:41 - 2017-02-22 18:41 - 84169528 _____ C:\Users\Lukáš\Desktop\ÄŚĂm kanalizace.tif
2017-02-22 18:37 - 2017-02-22 18:37 - 47803764 _____ C:\Users\Lukáš\Desktop\DSCN2957.tif
2017-02-22 18:28 - 2017-02-22 18:28 - 01063460 _____ C:\Users\Lukáš\Desktop\ÄŚĂm kanalizace.jpeg
2017-02-22 17:25 - 2017-02-22 17:25 - 08161756 _____ C:\Users\Lukáš\Downloads\2.tif
2017-02-22 17:15 - 2017-02-22 17:15 - 07039856 _____ C:\Users\Lukáš\Downloads\1.tif
2017-02-21 20:45 - 2017-02-21 20:45 - 04150003 _____ C:\Users\Lukáš\Downloads\04_Dopravnà služba.pdf
2017-02-21 18:28 - 2017-02-21 18:29 - 10496204 _____ C:\Users\Lukáš\Desktop\RozhodnutĂ o zvláštnĂm uĹľĂvánĂ komunikace 1.tif
2017-02-21 17:51 - 2017-02-21 17:50 - 09568042 _____ C:\Users\Lukáš\Desktop\RozhodnutĂ o zvláštnĂm uĹľĂvánĂ komunikace 1.tiff
2017-02-21 17:48 - 2017-02-21 17:47 - 00169794 _____ C:\Users\Lukáš\Desktop\ZvláštnĂ uĹľĂvánĂ.tiff
2017-02-21 17:32 - 2017-02-21 17:32 - 00065069 _____ C:\Users\Lukáš\Desktop\000232e1_medium.jpeg
2017-02-17 12:44 - 2017-02-17 12:43 - 00254450 _____ C:\Users\Lukáš\Desktop\306_2015_Sb dálničnà kupony.pdf
2017-02-17 11:14 - 2017-02-17 11:14 - 00254450 _____ C:\Users\Lukáš\Downloads\306_2015_Sb.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-16 17:43 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-16 17:43 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-16 17:42 - 2016-12-08 19:57 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-16 17:37 - 2016-12-09 00:40 - 00003808 _____ C:\WINDOWS\System32\Tasks\AutoKMS
2017-03-16 17:33 - 2016-12-09 00:24 - 00000000 ____D C:\Users\Lukáš
2017-03-16 17:33 - 2016-12-09 00:19 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-16 17:32 - 2016-12-09 00:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-16 17:32 - 2016-12-09 00:16 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-16 09:18 - 2016-12-09 00:15 - 02891856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-03-15 22:20 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-11 14:51 - 2016-12-13 10:17 - 00000000 ____D C:\Users\Lukáš\Desktop\Na prodej
2017-03-11 14:30 - 2016-12-13 14:04 - 00000000 ____D C:\Users\Lukáš\Desktop\Rothbauer
2017-03-10 16:43 - 2017-01-15 20:40 - 00000000 ___RD C:\Users\Lukáš\Documents\Scanned Documents
2017-03-10 10:46 - 2016-12-08 19:49 - 00000000 ____D C:\Users\Lukáš\AppData\Local\Packages
2017-03-10 06:17 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-10 06:17 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-09 17:50 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-09 09:50 - 2017-02-01 08:19 - 00000000 ____D C:\Users\Lukáš\Desktop\Škola
2017-03-06 20:12 - 2017-01-27 08:36 - 00003280 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-03-06 20:12 - 2016-12-08 19:53 - 00002387 _____ C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-03-06 20:12 - 2016-12-08 19:53 - 00000000 ___RD C:\Users\Lukáš\OneDrive
2017-03-06 11:12 - 2016-12-28 13:48 - 00000000 ____D C:\Users\Lukáš\Desktop\Stavba
2017-03-03 21:26 - 2016-12-08 22:21 - 00001219 _____ C:\Users\Lukáš\Desktop\Adobe Photoshop CS4 (64 Bit).lnk
2017-03-02 20:25 - 2017-01-11 07:26 - 00000000 ____D C:\Users\Lukáš\Desktop\Moje
2017-03-01 19:29 - 2017-01-24 12:32 - 00000000 ____D C:\Users\Lukáš\AppData\Local\ElevatedDiagnostics
2017-02-24 17:19 - 2016-12-08 21:29 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-24 17:17 - 2016-12-08 21:29 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 11:59 - 2017-02-05 20:28 - 00000000 ____D C:\Users\Lukáš\Desktop\Těhotná
2017-02-22 17:14 - 2016-12-08 20:37 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-21 20:20 - 2016-12-11 13:06 - 00000000 ____D C:\Users\Lukáš\AppData\Roaming\vlc
2017-02-14 17:15 - 2016-12-08 20:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
==================== Files in the root of some directories =======
2017-01-15 21:06 - 2017-01-15 21:36 - 0000836 _____ () C:\ProgramData\hpzinstall.log
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Luk ç\Desktop" je 15387 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================
Předem děkuji JD
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Lukáš (administrator) on ASUS-K50IN (16-03-2017 18:02:25)
Running from C:\Users\Lukáš\Desktop
Loaded Profiles: Lukáš (Available Profiles: Lukáš)
Platform: Windows 10 Pro Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Wacom Technology, Corp.) C:\Windows\System32\Wacom_Tablet.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(forum.viry.cz) C:\Users\Lukáš\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2016-12-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-12-09] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2000-01-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1407201582-3230588637-309285028-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1407201582-3230588637-309285028-1001\...\MountPoints2: {5b641cc8-cc36-11e6-9bda-90e6ba2b2201} - "F:\Setup.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2017-01-15]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 195.250.128.34 212.20.96.34
Tcpip\..\Interfaces\{8669b414-8228-4a70-915d-a3033176af77}: [DhcpNameServer] 195.250.128.34 212.20.96.34
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-10-11] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-10-18] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2009-09-25] (Wacom, Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-10-18] (Microsoft Corporation)
Chrome:
=======
CHR HomePage: Default -> hxxp://google.com/
CHR NewTab: Default -> Not-active:"chrome-extension://oilnfikhhkljogdookibmpkbmdiklgfp/newtab/newtab.html", Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/stubby.html"
CHR Profile: C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default [2017-03-16]
CHR Extension: (Tabulky Google) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-08]
CHR Extension: (Data generator) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\legklhfpihknmgmlhiadachbaihccpho [2017-02-01]
CHR Extension: (FromDocToPDF) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2017-02-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Muzik Fury) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilnfikhhkljogdookibmpkbmdiklgfp [2017-02-01]
CHR Extension: (Gmail) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-08]
CHR Extension: (Chrome Media Router) - C:\Users\Lukáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-06]
CHR HKU\S-1-5-21-1407201582-3230588637-309285028-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2016-12-08] (ELAN Microelectronics Corp.)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2016-11-17] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1165368 2016-11-17] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [307456 2000-01-01] (Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-12-09] (Microsoft Corporation)
R2 TabletServiceWacom; C:\WINDOWS\system32\Wacom_Tablet.exe [6245744 2010-03-09] (Wacom Technology, Corp.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ATK64AMD.sys [13680 2016-12-08] ()
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2016-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47672 2016-11-17] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [888064 2000-01-01] (Realtek )
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-16 18:02 - 2017-03-16 18:03 - 00011764 _____ C:\Users\Lukáš\Desktop\FRST.txt
2017-03-16 18:02 - 2017-03-16 18:02 - 00000000 ____D C:\FRST
2017-03-16 18:00 - 2017-03-16 18:02 - 02424832 _____ (Farbar) C:\Users\Lukáš\Desktop\FRST64.exe
2017-03-16 17:58 - 2017-03-16 18:01 - 00112640 _____ (forum.viry.cz) C:\Users\Lukáš\Desktop\FRSTLauncher.exe
2017-03-15 16:53 - 2017-03-15 16:53 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Lukáš\Downloads\esetonlinescanner_enu (2).exe
2017-03-15 16:53 - 2017-03-15 16:53 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Lukáš\Downloads\esetonlinescanner_enu (1).exe
2017-03-14 21:56 - 2017-03-14 21:56 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Lukáš\Downloads\esetonlinescanner_enu.exe
2017-03-14 21:56 - 2017-03-14 21:56 - 00000000 ____D C:\Users\Lukáš\AppData\Local\ESET
2017-03-14 21:50 - 2017-03-14 21:51 - 09607112 _____ (TeamViewer) C:\Users\Lukáš\Downloads\TeamViewerQS_cs.exe
2017-03-10 16:43 - 2017-03-10 16:43 - 01146138 _____ C:\Users\Lukáš\Desktop\Princip ochrany novostaveb.jpeg
2017-03-10 16:42 - 2017-03-10 16:41 - 01134058 _____ C:\Users\Lukáš\Desktop\Stanovenà radonového indexu pozemku.jpeg
2017-03-10 16:40 - 2017-03-10 16:39 - 01039410 _____ C:\Users\Lukáš\Desktop\VĂ˝sledky měřenĂ.jpeg
2017-03-10 16:39 - 2017-03-10 16:38 - 00864960 _____ C:\Users\Lukáš\Desktop\Metodika průzkumu.jpeg
2017-03-10 16:37 - 2017-03-10 16:36 - 01063203 _____ C:\Users\Lukáš\Desktop\Odborný posudek.jpeg
2017-03-09 20:14 - 2017-03-09 20:14 - 00783166 _____ C:\Users\Lukáš\Desktop\8_2013160OST_5_Priloha_3_8_2013160OST_5_1_Metodika_1238485.pdf
2017-03-09 19:20 - 2017-03-09 19:20 - 00222130 _____ C:\Users\Lukáš\Downloads\Stanovisko_správnĂ_delikt_provozovatele_vozidla.pdf
2017-03-09 19:06 - 2017-03-09 19:06 - 00237324 _____ C:\Users\Lukáš\Desktop\30A_43_2014_40_20141016133803_prevedeno.pdf
2017-03-06 20:10 - 2017-03-06 20:11 - 33357112 _____ C:\Users\Lukáš\Desktop\manual Husqvarna_2006-610sm-service-m.pdf
2017-03-06 20:10 - 2017-03-06 20:10 - 08499090 _____ C:\Users\Lukáš\Desktop\TE-SM_610_2006.pdf
2017-03-06 19:47 - 2017-03-06 19:47 - 08499090 _____ C:\Users\Lukáš\Downloads\TE-SM_610_2006.pdf
2017-03-06 18:02 - 2017-03-06 18:02 - 33333029 _____ C:\Users\Lukáš\Downloads\5526_2006-610sm-service-m.pdf
2017-03-03 23:09 - 2017-03-03 23:09 - 01819930 _____ C:\Users\Lukáš\Downloads\commonly_used_ornate_border_vector_531356.zip
2017-03-03 23:08 - 2017-03-03 23:08 - 04573804 _____ C:\Users\Lukáš\Downloads\common_border_frame_vector_531518 (1).zip
2017-03-03 23:07 - 2017-03-03 23:08 - 04573804 _____ C:\Users\Lukáš\Downloads\common_border_frame_vector_531518.zip
2017-03-03 23:07 - 2017-03-03 23:07 - 09113031 _____ C:\Users\Lukáš\Downloads\black8_white_vintage_frames_mix_vector_520336 (1).zip
2017-03-03 23:01 - 2017-03-03 23:01 - 00553307 _____ C:\Users\Lukáš\Downloads\gold_decoration_border_vector_536547.zip
2017-03-03 22:56 - 2017-03-03 22:56 - 00580275 _____ C:\Users\Lukáš\Downloads\shiny_gold_framed_labels_ornament_vector_586650.zip
2017-03-03 22:55 - 2017-03-03 22:55 - 05907346 _____ C:\Users\Lukáš\Downloads\set_of_decorative_vintage_frame_vector_graphics_551505.zip
2017-03-03 22:52 - 2017-03-03 22:52 - 00493784 _____ C:\Users\Lukáš\Downloads\gold_lace_frame_vector_set_524535.zip
2017-03-03 22:51 - 2017-03-03 22:51 - 09113031 _____ C:\Users\Lukáš\Downloads\black8_white_vintage_frames_mix_vector_520336.zip
2017-03-03 22:23 - 2017-03-06 14:00 - 00000000 ____D C:\Users\Lukáš\Desktop\Kronika
2017-03-03 22:14 - 2017-03-03 22:14 - 00000000 ____D C:\Users\Lukáš\Downloads\set_of_decorative_vintage_frame_vector_graphics_551504
2017-03-03 22:01 - 2017-03-03 22:01 - 01785233 _____ C:\Users\Lukáš\Downloads\vintage_frames_ornaments_vector_set_587580 (2).zip
2017-03-03 22:00 - 2017-03-03 22:01 - 05640817 _____ C:\Users\Lukáš\Downloads\set_of_decorative_vintage_frame_vector_graphics_551504.zip
2017-03-03 22:00 - 2017-03-03 22:00 - 07618934 _____ C:\Users\Lukáš\Downloads\vintage_frames_vector_147952 (1).zip
2017-03-03 21:59 - 2017-03-03 21:59 - 07618934 _____ C:\Users\Lukáš\Downloads\vintage_frames_vector_147952.zip
2017-03-03 21:58 - 2017-03-03 21:58 - 01785233 _____ C:\Users\Lukáš\Downloads\vintage_frames_ornaments_vector_set_587580 (1).zip
2017-03-03 21:57 - 2017-03-03 21:57 - 01785233 _____ C:\Users\Lukáš\Downloads\vintage_frames_ornaments_vector_set_587580.zip
2017-03-02 10:55 - 2017-03-02 10:56 - 00835925 _____ C:\Users\Lukáš\Downloads\85-Free-Vintage-Vector-ornaments-vectorjunky.zip
2017-03-01 23:43 - 2017-03-01 23:43 - 00057618 _____ C:\Users\Lukáš\Downloads\yaquote_script.zip
2017-03-01 23:42 - 2017-03-01 23:42 - 00058823 _____ C:\Users\Lukáš\Downloads\odstemplik.zip
2017-03-01 23:40 - 2017-03-01 23:40 - 00061246 _____ C:\Users\Lukáš\Downloads\italianno.zip
2017-03-01 23:36 - 2017-03-01 23:36 - 00048019 _____ C:\Users\Lukáš\Downloads\respective.zip
2017-03-01 23:31 - 2017-03-01 23:31 - 00088299 _____ C:\Users\Lukáš\Downloads\kovanovicpisn_d.zip
2017-03-01 23:31 - 2017-03-01 23:31 - 00067412 _____ C:\Users\Lukáš\Downloads\porcelain.zip
2017-03-01 23:29 - 2017-03-01 23:29 - 00035231 _____ C:\Users\Lukáš\Downloads\be_safe.zip
2017-03-01 23:27 - 2017-03-01 23:27 - 00043459 _____ C:\Users\Lukáš\Downloads\beautiful_es.zip
2017-03-01 23:26 - 2017-03-01 23:26 - 00021159 _____ C:\Users\Lukáš\Downloads\lainiedaysh.zip
2017-03-01 23:21 - 2017-03-01 23:21 - 00156618 _____ C:\Users\Lukáš\Downloads\promocyja.zip
2017-03-01 23:19 - 2017-03-01 23:19 - 00169320 _____ C:\Users\Lukáš\Downloads\kawoszeh.zip
2017-03-01 23:11 - 2017-03-01 23:21 - 175227723 _____ C:\Users\Lukáš\Downloads\ceske-fonty-lianna-layoutgraphic-blog.cz.zip
2017-03-01 22:43 - 2017-03-01 22:43 - 00194524 _____ C:\Users\Lukáš\Downloads\a_glitch_in_time.zip
2017-03-01 22:42 - 2017-03-01 22:42 - 00026733 _____ C:\Users\Lukáš\Downloads\calligraphy.zip
2017-03-01 22:29 - 2017-03-01 22:29 - 00040504 _____ C:\Users\Lukáš\Downloads\indie_flower.zip
2017-03-01 22:27 - 2017-03-01 22:27 - 00099780 _____ C:\Users\Lukáš\Downloads\__dominique_font_by_ohwebelongtomusic-d422sio.ttf
2017-03-01 21:16 - 2017-03-01 21:16 - 31094400 _____ C:\Users\Lukáš\Downloads\DD_Vintage_Texture_45309.zip
2017-03-01 21:14 - 2017-03-01 21:14 - 01083697 _____ C:\Users\Lukáš\Downloads\japanese_borders_ai.zip
2017-02-28 22:00 - 2017-02-28 22:00 - 00040840 _____ C:\Users\Lukáš\Downloads\CEPHYLIS.TTF
2017-02-28 22:00 - 2017-02-28 22:00 - 00040840 _____ C:\Users\Lukáš\Downloads\CEPHYLIS (1).TTF
2017-02-28 21:53 - 2017-02-28 21:53 - 00052874 _____ C:\Users\Lukáš\Downloads\Piranesi_Italic_BT.ttf
2017-02-27 15:09 - 2017-02-27 15:09 - 00026151 _____ C:\Users\Lukáš\Downloads\etapa I. -A-2017_tĹ™Ădy_pro uÄŤitele.xlsx
2017-02-26 21:52 - 2017-02-26 21:53 - 178415392 _____ C:\Users\Lukáš\Desktop\Kniva rodiny.pdf
2017-02-26 17:48 - 2017-02-26 17:48 - 00695356 _____ C:\Users\Lukáš\Desktop\ÄŚestnĂ© prohlášenĂ.jpeg
2017-02-26 17:30 - 2017-02-26 17:31 - 00839695 _____ C:\Users\Lukáš\Desktop\Předávacà protokol.jpeg
2017-02-24 15:08 - 2017-02-24 15:08 - 06785492 _____ C:\Users\Lukáš\Downloads\11.tif
2017-02-24 15:08 - 2017-02-24 15:08 - 06785492 _____ C:\Users\Lukáš\Downloads\11 (1).tif
2017-02-23 08:18 - 2017-02-23 08:18 - 00504968 _____ C:\Users\Lukáš\Downloads\361_2003_Sb.pdf
2017-02-22 22:02 - 2017-02-22 22:02 - 08161756 _____ C:\Users\Lukáš\Downloads\2 (1).tif
2017-02-22 20:02 - 2017-02-22 20:02 - 06785296 _____ C:\Users\Lukáš\Downloads\10.tif
2017-02-22 19:48 - 2017-02-22 19:48 - 00063061 _____ C:\Users\Lukáš\Downloads\ÄŚĂm kanalizace.jpeg
2017-02-22 18:41 - 2017-02-22 18:41 - 84169528 _____ C:\Users\Lukáš\Desktop\ÄŚĂm kanalizace.tif
2017-02-22 18:37 - 2017-02-22 18:37 - 47803764 _____ C:\Users\Lukáš\Desktop\DSCN2957.tif
2017-02-22 18:28 - 2017-02-22 18:28 - 01063460 _____ C:\Users\Lukáš\Desktop\ÄŚĂm kanalizace.jpeg
2017-02-22 17:25 - 2017-02-22 17:25 - 08161756 _____ C:\Users\Lukáš\Downloads\2.tif
2017-02-22 17:15 - 2017-02-22 17:15 - 07039856 _____ C:\Users\Lukáš\Downloads\1.tif
2017-02-21 20:45 - 2017-02-21 20:45 - 04150003 _____ C:\Users\Lukáš\Downloads\04_Dopravnà služba.pdf
2017-02-21 18:28 - 2017-02-21 18:29 - 10496204 _____ C:\Users\Lukáš\Desktop\RozhodnutĂ o zvláštnĂm uĹľĂvánĂ komunikace 1.tif
2017-02-21 17:51 - 2017-02-21 17:50 - 09568042 _____ C:\Users\Lukáš\Desktop\RozhodnutĂ o zvláštnĂm uĹľĂvánĂ komunikace 1.tiff
2017-02-21 17:48 - 2017-02-21 17:47 - 00169794 _____ C:\Users\Lukáš\Desktop\ZvláštnĂ uĹľĂvánĂ.tiff
2017-02-21 17:32 - 2017-02-21 17:32 - 00065069 _____ C:\Users\Lukáš\Desktop\000232e1_medium.jpeg
2017-02-17 12:44 - 2017-02-17 12:43 - 00254450 _____ C:\Users\Lukáš\Desktop\306_2015_Sb dálničnà kupony.pdf
2017-02-17 11:14 - 2017-02-17 11:14 - 00254450 _____ C:\Users\Lukáš\Downloads\306_2015_Sb.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-16 17:43 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-16 17:43 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-16 17:42 - 2016-12-08 19:57 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-16 17:37 - 2016-12-09 00:40 - 00003808 _____ C:\WINDOWS\System32\Tasks\AutoKMS
2017-03-16 17:33 - 2016-12-09 00:24 - 00000000 ____D C:\Users\Lukáš
2017-03-16 17:33 - 2016-12-09 00:19 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-16 17:32 - 2016-12-09 00:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-16 17:32 - 2016-12-09 00:16 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-16 09:18 - 2016-12-09 00:15 - 02891856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-03-15 22:20 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-11 14:51 - 2016-12-13 10:17 - 00000000 ____D C:\Users\Lukáš\Desktop\Na prodej
2017-03-11 14:30 - 2016-12-13 14:04 - 00000000 ____D C:\Users\Lukáš\Desktop\Rothbauer
2017-03-10 16:43 - 2017-01-15 20:40 - 00000000 ___RD C:\Users\Lukáš\Documents\Scanned Documents
2017-03-10 10:46 - 2016-12-08 19:49 - 00000000 ____D C:\Users\Lukáš\AppData\Local\Packages
2017-03-10 06:17 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-10 06:17 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-09 17:50 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-09 09:50 - 2017-02-01 08:19 - 00000000 ____D C:\Users\Lukáš\Desktop\Škola
2017-03-06 20:12 - 2017-01-27 08:36 - 00003280 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-03-06 20:12 - 2016-12-08 19:53 - 00002387 _____ C:\Users\Lukáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-03-06 20:12 - 2016-12-08 19:53 - 00000000 ___RD C:\Users\Lukáš\OneDrive
2017-03-06 11:12 - 2016-12-28 13:48 - 00000000 ____D C:\Users\Lukáš\Desktop\Stavba
2017-03-03 21:26 - 2016-12-08 22:21 - 00001219 _____ C:\Users\Lukáš\Desktop\Adobe Photoshop CS4 (64 Bit).lnk
2017-03-02 20:25 - 2017-01-11 07:26 - 00000000 ____D C:\Users\Lukáš\Desktop\Moje
2017-03-01 19:29 - 2017-01-24 12:32 - 00000000 ____D C:\Users\Lukáš\AppData\Local\ElevatedDiagnostics
2017-02-24 17:19 - 2016-12-08 21:29 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-24 17:17 - 2016-12-08 21:29 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 11:59 - 2017-02-05 20:28 - 00000000 ____D C:\Users\Lukáš\Desktop\Těhotná
2017-02-22 17:14 - 2016-12-08 20:37 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-21 20:20 - 2016-12-11 13:06 - 00000000 ____D C:\Users\Lukáš\AppData\Roaming\vlc
2017-02-14 17:15 - 2016-12-08 20:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
==================== Files in the root of some directories =======
2017-01-15 21:06 - 2017-01-15 21:36 - 0000836 _____ () C:\ProgramData\hpzinstall.log
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Luk ç\Desktop" je 15387 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================