Děkuji za upozornění a posílám log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2017
Ran by Pavel (administrator) on PAVEL-PC (23-05-2017 19:48:01)
Running from C:\Users\Pavel\Desktop
Loaded Profiles: Pavel (Available Profiles: Pavel)
Platform: Windows 10 Home Version 1703 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(深圳市猫哈网络科技发展有限公司) C:\Program Files (x86)\Maoha\JiSuZip\JszipSvc.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(Malwarebytes Corporation) C:\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes Corporation) C:\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Windows\Temp\gC67A.tmp.exe
(Malwarebytes Corporation) C:\Malwarebytes Anti-Malware\mbam.exe
() C:\Windows\Temp\g877B.tmp.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTray.exe
(Facebook) C:\Users\Pavel\AppData\Local\Facebook\Games\FacebookGameroom.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(The CefSharp Authors) C:\Users\Pavel\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [gplyra] => C:\Users\Pavel\AppData\Roaming\gplyra\gplyra.exe <===== ATTENTION
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3048312 2017-05-20] (Electronic Arts)
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [4952128 2017-05-19] (GOG.com)
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29642368 2016-09-12] (Skype Technologies S.A.)
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [833240 2014-12-23] (ZONER software)
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\TomTom MyDrive Connect.exe [1918696 2017-05-08] (TomTom)
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [isMiner V 1.9] => "C:\Users\Pavel\AppData\Roaming\isMiner\isMiner.exe" -checkforupdates <===== ATTENTION
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [msiql] => C:\Users\Pavel\AppData\Local\Temp\is-9OMOF.tmp\PopWnd.exe /RUNNING <===== ATTENTION
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [-36evSZXiV.exe] => C:\Program Files\Bandizip\TH9DJ\-36evSZXiV.exe -r1_5 -r2_1
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [YeaDesktop] => C:\Program Files (x86)\YeaDesktop\YeaDesktop.exe /autostart <===== ATTENTION
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [JzShlobj] -> {9A0700D2-920A-4E52-8697-9B5230C92612} => C:\Program Files (x86)\Maoha\JiSuZip\JZipExt.dll -> No File
Startup: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2017-05-22]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Pavel\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{45a4bc62-200a-4446-862e-ec0b9dbcd902}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKU\S-1-5-21-2184864857-1076823462-3011522754-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.seznam.cz/
URLSearchHook: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 - (No Name) - {6d010537-9e99-400b-b652-b0d5a5757e5d} - C:\Program Files (x86)\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll No File
SearchScopes: HKLM-x32 -> {41226cbe-8f41-4df3-8d72-1cfbcffcfd0b} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^BA5^xdm007^YYA^cz&si=CL6X8ovl4cECFbDLtAodRj0AIg&ptb=5477A9B7-1432-44C8-9262-C8076807290D&ind=2014110415&n=780ce2cf&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {19E51EAF-6BCC-4FD5-BA32-C25DCA9A74DC} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {2C92C4CC-E6A6-46B5-9029-D2F89334D433} URL = hxxp://
www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {41226cbe-8f41-4df3-8d72-1cfbcffcfd0b} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^BA5^xdm007^YYA^cz&si=CL6X8ovl4cECFbDLtAodRj0AIg&ptb=5477A9B7-1432-44C8-9262-C8076807290D&ind=2014110415&n=780ce2cf&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {5A73B9ED-3C3D-475D-8A5F-6E8047A8B61C} URL = hxxp://
www.search.ask.com/web?tpid=ORJ-SPE&o=A ... psv=&pt=tb
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {77D844FF-4B69-4420-8C4F-D613510B1CDF} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {9FDE2344-FC0A-4EE9-88DB-6EBD783FBD06} URL = hxxp://
www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {B7BDB1BA-2457-4530-874A-85EAF4C93563} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {C19B27F4-B12A-4B94-AC10-085F0E36B463} URL = hxxp://
www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {D07BCFBA-3324-42ED-AA59-46644A31A15F} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {E53924F9-68A5-4628-A8FE-9E02541EAC2E} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> {FAA94AA0-B05F-4D47-9E76-9F4745572A9E} URL = hxxp://
www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
BHO-x32: No Name -> {6a79cdac-f710-4996-842b-fdc33b785a35} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-20] (Oracle Corporation)
BHO-x32: No Name -> {d9f16d8b-81b5-4667-af4d-25365bbf7fc9} -> No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-20] (Oracle Corporation)
Toolbar: HKLM - No Name - {4F524A2D-5350-4500-76A7-7A786E7484D7} - No File
Toolbar: HKLM-x32 - No Name - {4F524A2D-5350-4500-76A7-7A786E7484D7} - No File
Toolbar: HKLM-x32 - No Name - {f41a56d2-7b52-4d16-812c-a63c6ca9d4c5} - No File
Toolbar: HKU\S-1-5-21-2184864857-1076823462-3011522754-1001 -> No Name - {F41A56D2-7B52-4D16-812C-A63C6CA9D4C5} - No File
FireFox:
========
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 -> C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-20] (Oracle Corporation)
FF Plugin-x32: @OnlineMapFinder_9p.com/Plugin -> C:\Program Files (x86)\OnlineMapFinder_9p\bar\1.bin\NP9pStub.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-2184864857-1076823462-3011522754-1001: SkypePlugin -> C:\Users\Pavel\AppData\Local\SkypePlugin\7.30.0.98\npGatewayNpapi.dll [2016-12-28] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-2184864857-1076823462-3011522754-1001: SkypePlugin64 -> C:\Users\Pavel\AppData\Local\SkypePlugin\7.30.0.98\npGatewayNpapi-x64.dll [2016-12-28] (Skype Technologies S.A.)
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.seznam.cz/
CHR NewTab: Default -> Active:"chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR DefaultSearchURL: Default -> hxxp://search.seznam.cz/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSuggestURL: Default -> hxxp://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms}
CHR Profile: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default [2017-05-22]
CHR Extension: (Prezentace Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-15]
CHR Extension: (Dokumenty Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-15]
CHR Extension: (Disk Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-15]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2017-05-20]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2017-05-20]
CHR Extension: (YouTube) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-15]
CHR Extension: (Tabulky Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-15]
CHR Extension: (Dokumenty Google offline) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-15]
CHR Extension: (Skype) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-23]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2017-05-20]
CHR Extension: (Gmail) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-15]
CHR Extension: (Chrome Media Router) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-21]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Auhardwaregl; C:\Windows\SysWow64\Auhardwaregl.dll [454440 2017-05-20] ()
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1530376 2017-04-27] ()
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [245544 2016-07-10] (EasyAntiCheat Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [512576 2017-05-19] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7955008 2017-05-19] (GOG.com)
R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin Ltd. or its subsidiaries)
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [192304 2016-02-16] ()
R2 JszipService; C:\Program Files (x86)\Maoha\JiSuZip\JszipSvc.exe [130072 2017-02-16] (深圳市猫哈网络科技发展有限公司)
R2 MBAMScheduler; C:\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
R2 MBAMService; C:\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2162064 2017-05-20] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3136920 2017-05-20] (Electronic Arts)
S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2016-09-23] (SHAREit Technologies Co.Ltd)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
S2 Recover; C:\Program Files\Windows Media Player\ORYPS6G2SKIT9NTIP5Q\8'N&MA_hUv.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 HWHandSet; C:\WINDOWS\system32\DRIVERS\hw_quusbmdm.sys [223232 2016-02-16] (Huawei Technologies Co., Ltd.)
R1 JszipProtect; C:\Program Files (x86)\Maoha\JiSuZip\JsZipProtect64.sys [39256 2016-12-27] ()
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2017-05-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation)
R1 netboostmaster; C:\WINDOWS\system32\drivers\netboostmaster.sys [2911592 2017-05-22] () [File not signed]
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys [14199224 2017-01-04] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
R2 Uefochubsrv; C:\WINDOWS\system32\drivers\Uefochubsrv.sys [196640 2017-05-20] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R1 WiserIso; C:\WINDOWS\System32\Drivers\vcdrom.sys [25432 2016-12-27] ()
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-23 19:48 - 2017-05-23 19:48 - 00020495 _____ C:\Users\Pavel\Desktop\FRST.txt
2017-05-23 19:45 - 2017-05-23 19:45 - 00000000 _____ C:\Users\Pavel\Desktop\FRSTLauncher.exe
2017-05-23 19:38 - 2017-05-23 19:48 - 00000000 ____D C:\FRST
2017-05-23 19:33 - 2017-05-23 19:33 - 02429952 _____ (Farbar) C:\Users\Pavel\Desktop\FRST64.exe
2017-05-22 20:40 - 2017-05-22 20:40 - 00000000 ____D C:\WINDOWS\pss
2017-05-21 20:08 - 2017-05-21 20:10 - 00000000 ____D C:\Users\Pavel\Documents\cosi, co bylo na plose
2017-05-21 19:56 - 2017-05-21 19:56 - 00215012 _____ C:\Users\Pavel\Documents\cc_20170521_195630.reg
2017-05-21 19:55 - 2017-05-21 19:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-05-21 19:55 - 2017-05-21 19:55 - 00000000 ____D C:\Program Files\CCleaner
2017-05-21 19:49 - 2017-05-21 19:54 - 09548112 _____ (Piriform Ltd) C:\Users\Pavel\Downloads\ccsetup530.exe
2017-05-21 19:36 - 2017-05-21 19:55 - 00000414 _____ C:\WINDOWS\wininit.ini
2017-05-21 19:24 - 2017-05-21 19:27 - 08894896 _____ (IObit ) C:\Users\Pavel\Downloads\Nepotvrzeno 445552.crdownload
2017-05-21 18:44 - 2017-05-21 18:44 - 00000000 ____D C:\LocalData
2017-05-21 18:43 - 2017-05-21 18:43 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\IObit
2017-05-21 18:34 - 2017-05-21 18:38 - 15721672 _____ (IObit ) C:\Users\Pavel\Downloads\driver_booster_setup.exe
2017-05-20 21:27 - 2017-05-20 21:38 - 00000000 ____D C:\WINDOWS\Microsoft Antimalware
2017-05-20 20:59 - 2017-05-23 19:32 - 00000000 ____D C:\ProgramData\XLiPlatform
2017-05-20 20:56 - 2017-05-23 19:24 - 02793264 _____ C:\WINDOWS\netboostmasterHelp.dll
2017-05-20 20:56 - 2017-05-22 20:46 - 02911592 _____ C:\WINDOWS\system32\Drivers\netboostmaster.sys
2017-05-20 20:56 - 2017-05-20 20:56 - 02941800 _____ C:\WINDOWS\system32\Drivers\F785D4AC4C7B.dat
2017-05-20 20:48 - 2017-05-23 19:48 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-05-20 20:48 - 2017-05-20 20:56 - 00000000 ____D C:\ProgramData\Cache
2017-05-20 20:47 - 2017-05-20 20:47 - 00000738 _____ C:\Users\Pavel\Desktop\Malwarebytes Anti-Malware.lnk
2017-05-20 20:47 - 2017-05-20 20:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-05-20 20:47 - 2017-05-20 20:47 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-20 20:47 - 2017-05-20 20:47 - 00000000 ____D C:\Malwarebytes Anti-Malware
2017-05-20 20:47 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-05-20 20:47 - 2015-03-17 06:15 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2017-05-20 20:47 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2017-05-20 20:43 - 2017-05-20 20:43 - 00000000 ___HD C:\OneDriveTemp
2017-05-20 20:14 - 2017-05-20 20:14 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2017-05-20 20:14 - 2017-05-20 20:14 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2017-05-20 20:13 - 2017-05-20 20:13 - 00454440 _____ C:\WINDOWS\SysWOW64\Auhardwaregl.dll
2017-05-20 20:13 - 2017-05-20 20:13 - 00196640 _____ C:\WINDOWS\system32\Drivers\Uefochubsrv.sys
2017-05-20 20:13 - 2017-05-20 20:13 - 00000000 ____D C:\Users\Public\Documents\XMUpdate
2017-05-20 20:13 - 2017-05-20 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\WindowsTM
2017-05-20 20:13 - 2017-05-20 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\极速压缩
2017-05-20 20:13 - 2017-05-20 20:13 - 00000000 ____D C:\Program Files (x86)\Maoha
2017-05-20 20:13 - 2016-12-27 04:34 - 00025432 _____ C:\WINDOWS\system32\Drivers\vcdrom.sys
2017-05-20 20:12 - 2017-05-23 19:32 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Seznam.cz
2017-05-20 20:12 - 2017-05-20 20:12 - 00002914 _____ C:\WINDOWS\System32\Tasks\System HealerPeriod
2017-05-20 20:12 - 2017-05-20 20:12 - 00002620 _____ C:\WINDOWS\System32\Tasks\System HealerStartUp
2017-05-20 20:11 - 2017-05-22 20:26 - 00000198 _____ C:\ServiceLog.txt
2017-05-20 20:11 - 2017-05-20 20:11 - 00003278 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus_DEFAULT
2017-05-20 20:11 - 2017-05-20 20:11 - 00003104 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus_UPDATES
2017-05-20 20:10 - 2017-05-20 21:05 - 00000000 ____D C:\ProgramData\VideoMemoryDiagnostic
2017-05-20 20:10 - 2017-05-20 20:10 - 00016852 _____ C:\WINDOWS\System32\Tasks\Magia Virtual Basic
2017-05-20 20:10 - 2017-05-20 20:10 - 00003044 _____ C:\WINDOWS\System32\Tasks\Pritc
2017-05-20 20:08 - 2017-05-20 20:08 - 00002922 _____ C:\WINDOWS\System32\Tasks\One System CarePeriod
2017-05-20 19:49 - 2017-05-20 19:49 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\BANDISOFT
2017-05-20 19:39 - 2017-05-20 19:39 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Bandicam Company
2017-05-20 19:39 - 2017-05-20 19:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2017-05-20 15:22 - 2017-05-20 15:22 - 00000000 ____D C:\ProgramData\Sony
2017-05-20 15:20 - 2017-05-20 15:22 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Sony
2017-05-20 15:20 - 2017-05-20 15:20 - 00000000 ____D C:\Users\Pavel\AppData\Local\Sony
2017-05-20 15:18 - 2017-05-20 15:18 - 00001026 _____ C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Vegas Pro 13.0 (64-bit).lnk
2017-05-20 15:18 - 2017-05-20 15:18 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony
2017-05-20 15:18 - 2017-05-20 15:18 - 00000000 ____D C:\Program Files (x86)\Sony
2017-05-20 15:17 - 2017-05-20 15:18 - 00000000 ____D C:\Program Files\Sony
2017-05-16 08:37 - 2017-05-16 08:37 - 00276672 _____ C:\Users\Pavel\Downloads\Lada.jpeg
2017-05-16 08:29 - 2017-05-16 08:29 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Google
2017-05-13 12:34 - 2017-04-28 03:07 - 06759512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-05-13 12:34 - 2017-04-28 02:57 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-05-13 12:34 - 2017-04-28 02:56 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-05-13 12:34 - 2017-04-28 02:55 - 21353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-05-13 12:34 - 2017-04-28 02:51 - 20505600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-05-13 12:34 - 2017-04-28 02:46 - 19335168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-05-13 12:34 - 2017-04-28 02:40 - 11870208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-05-13 12:34 - 2017-04-28 02:40 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-05-13 12:34 - 2017-04-28 02:26 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-05-13 12:34 - 2017-04-28 02:04 - 23681024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-05-13 12:34 - 2017-04-28 02:00 - 08244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-05-13 12:34 - 2017-04-28 01:58 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-05-13 12:34 - 2017-04-28 01:57 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-05-13 12:33 - 2017-04-28 03:38 - 01411128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-05-13 12:33 - 2017-04-28 03:19 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-05-13 12:33 - 2017-04-28 03:19 - 00605936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-05-13 12:33 - 2017-04-28 03:18 - 02259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-05-13 12:33 - 2017-04-28 03:16 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-05-13 12:33 - 2017-04-28 03:12 - 01604312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-05-13 12:33 - 2017-04-28 03:12 - 00543640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-05-13 12:33 - 2017-04-28 03:11 - 02158544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-05-13 12:33 - 2017-04-28 03:09 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-05-13 12:33 - 2017-04-28 03:08 - 08320920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-05-13 12:33 - 2017-04-28 03:08 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-05-13 12:33 - 2017-04-28 03:08 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-05-13 12:33 - 2017-04-28 03:08 - 00775824 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-05-13 12:33 - 2017-04-28 03:07 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-05-13 12:33 - 2017-04-28 03:06 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-05-13 12:33 - 2017-04-28 03:06 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-05-13 12:33 - 2017-04-28 03:05 - 00923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-05-13 12:33 - 2017-04-28 03:04 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-05-13 12:33 - 2017-04-28 03:03 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-05-13 12:33 - 2017-04-28 03:00 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-05-13 12:33 - 2017-04-28 02:59 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-05-13 12:33 - 2017-04-28 02:59 - 02635336 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-05-13 12:33 - 2017-04-28 02:59 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-05-13 12:33 - 2017-04-28 02:59 - 00207264 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-05-13 12:33 - 2017-04-28 02:59 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-05-13 12:33 - 2017-04-28 02:58 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-05-13 12:33 - 2017-04-28 02:58 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-05-13 12:33 - 2017-04-28 02:55 - 01325456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-05-13 12:33 - 2017-04-28 02:53 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-05-13 12:33 - 2017-04-28 02:52 - 02957824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-05-13 12:33 - 2017-04-28 02:52 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-05-13 12:33 - 2017-04-28 02:52 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-05-13 12:33 - 2017-04-28 02:49 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-05-13 12:33 - 2017-04-28 02:49 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-05-13 12:33 - 2017-04-28 02:46 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2017-05-13 12:33 - 2017-04-28 02:46 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-05-13 12:33 - 2017-04-28 02:45 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-05-13 12:33 - 2017-04-28 02:44 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-05-13 12:33 - 2017-04-28 02:44 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-05-13 12:33 - 2017-04-28 02:42 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-05-13 12:33 - 2017-04-28 02:42 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-05-13 12:33 - 2017-04-28 02:42 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-05-13 12:33 - 2017-04-28 02:42 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-05-13 12:33 - 2017-04-28 02:41 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-05-13 12:33 - 2017-04-28 02:40 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-05-13 12:33 - 2017-04-28 02:40 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-05-13 12:33 - 2017-04-28 02:40 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-05-13 12:33 - 2017-04-28 02:40 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-05-13 12:33 - 2017-04-28 02:39 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-05-13 12:33 - 2017-04-28 02:39 - 03655680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-05-13 12:33 - 2017-04-28 02:39 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-05-13 12:33 - 2017-04-28 02:38 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-05-13 12:33 - 2017-04-28 02:38 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-05-13 12:33 - 2017-04-28 02:37 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-05-13 12:33 - 2017-04-28 02:37 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-05-13 12:33 - 2017-04-28 02:34 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2017-05-13 12:33 - 2017-04-28 02:33 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-05-13 12:33 - 2017-04-28 02:15 - 03672064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-05-13 12:33 - 2017-04-28 02:15 - 01051648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-05-13 12:33 - 2017-04-28 02:14 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-13 12:33 - 2017-04-28 02:11 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-05-13 12:33 - 2017-04-28 02:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-05-13 12:33 - 2017-04-28 02:11 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-05-13 12:33 - 2017-04-28 02:09 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2017-05-13 12:33 - 2017-04-28 02:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-13 12:33 - 2017-04-28 02:08 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2017-05-13 12:33 - 2017-04-28 02:08 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-05-13 12:33 - 2017-04-28 02:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-05-13 12:33 - 2017-04-28 02:07 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-05-13 12:33 - 2017-04-28 02:06 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-05-13 12:33 - 2017-04-28 02:06 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-05-13 12:33 - 2017-04-28 02:06 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-05-13 12:33 - 2017-04-28 02:06 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-05-13 12:33 - 2017-04-28 02:05 - 01075712 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-05-13 12:33 - 2017-04-28 02:05 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-05-13 12:33 - 2017-04-28 02:04 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-13 12:33 - 2017-04-28 02:04 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-05-13 12:33 - 2017-04-28 02:04 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-05-13 12:33 - 2017-04-28 02:03 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-13 12:33 - 2017-04-28 02:03 - 01027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-05-13 12:33 - 2017-04-28 02:03 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-13 12:33 - 2017-04-28 02:03 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-05-13 12:33 - 2017-04-28 02:03 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-05-13 12:33 - 2017-04-28 02:02 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-05-13 12:33 - 2017-04-28 02:01 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-05-13 12:33 - 2017-04-28 02:01 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-05-13 12:33 - 2017-04-28 01:59 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-13 12:33 - 2017-04-28 01:59 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-05-13 12:33 - 2017-04-28 01:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-05-13 12:33 - 2017-04-28 01:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-05-13 12:33 - 2017-04-28 01:59 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-05-13 12:33 - 2017-04-28 01:58 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-05-13 12:33 - 2017-04-28 01:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-05-13 12:33 - 2017-04-28 01:57 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-05-13 12:33 - 2017-04-28 01:57 - 01803264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-05-13 12:33 - 2017-04-28 01:54 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-05-13 12:33 - 2017-04-28 01:54 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-05-13 12:33 - 2017-04-28 01:54 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-05-13 12:33 - 2017-04-28 01:54 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-05-13 12:33 - 2017-04-28 01:52 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-05-01 15:12 - 2017-05-01 15:12 - 00000000 ____D C:\Users\Pavel\AppData\Local\DBG
2017-05-01 13:42 - 2017-05-01 13:42 - 20374424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 04848440 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 04446208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02651648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02443776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02435584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02298880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01295872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01291776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 01103872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 01024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-05-01 13:42 - 2017-05-01 13:42 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00626520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-05-01 13:42 - 2017-05-01 13:42 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-05-01 13:42 - 2017-05-01 13:42 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-05-01 13:42 - 2017-05-01 13:42 - 00409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-05-01 13:42 - 2017-05-01 13:42 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00142240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-05-01 13:42 - 2017-05-01 13:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-05-01 13:42 - 2017-05-01 13:42 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-05-01 13:42 - 2017-05-01 13:42 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
2017-05-01 13:37 - 2017-05-01 13:37 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-05-01 13:37 - 2017-05-01 12:48 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-05-01 13:35 - 2017-05-20 20:10 - 00000000 ____D C:\Program Files\MSBuild
2017-05-01 13:35 - 2017-05-01 13:35 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-05-01 13:35 - 2017-05-01 13:35 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-05-01 13:35 - 2017-05-01 13:35 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-05-01 13:35 - 2017-05-01 13:35 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-05-01 13:35 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-05-01 13:35 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-05-01 13:35 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-05-01 13:35 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-05-01 13:35 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-05-01 13:35 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-05-01 13:17 - 2017-05-01 13:17 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-05-01 13:14 - 2017-05-01 13:14 - 00000020 ___SH C:\Users\Pavel\ntuser.ini
2017-05-01 13:10 - 2017-05-01 13:12 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2017-05-01 13:10 - 2017-05-01 13:12 - 00007623 _____ C:\WINDOWS\diagerr.xml
2017-05-01 13:07 - 2017-05-23 19:31 - 02105994 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-01 13:05 - 2017-05-23 19:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-01 13:05 - 2017-05-02 17:19 - 00004052 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C25D6FB6-1E7D-4945-B59E-51B8AB958B50}
2017-05-01 13:05 - 2017-05-01 13:21 - 00003276 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-05-01 13:05 - 2017-05-01 13:06 - 00003398 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-01 13:05 - 2017-05-01 13:06 - 00002812 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2184864857-1076823462-3011522754-1001
2017-05-01 13:05 - 2017-05-01 13:06 - 00002702 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
2017-05-01 13:05 - 2017-05-01 13:06 - 00002318 _____ C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask
2017-05-01 13:05 - 2017-05-01 13:05 - 00003174 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-05-01 13:05 - 2017-05-01 13:05 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2017-05-01 12:59 - 2017-05-01 12:59 - 00000000 ____D C:\ProgramData\USOShared
2017-05-01 12:58 - 2017-05-01 12:58 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-05-01 12:54 - 2017-05-01 12:59 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-05-01 12:52 - 2017-05-21 18:24 - 00000000 ____D C:\Users\Pavel
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Šablony
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Soubory cookie
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Poslední
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Okolní tiskárny
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Okolní síť
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Nabídka Start
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Dokumenty
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Documents\Obrázky
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Documents\Hudba
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Documents\Filmy
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\Data aplikací
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-05-01 12:52 - 2017-05-01 12:52 - 00000000 _SHDL C:\Users\Pavel\AppData\Local\Data aplikací
2017-05-01 12:51 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 06386232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 02477624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 00546752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-05-01 12:51 - 2016-12-29 14:44 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-05-01 12:51 - 2016-12-19 09:26 - 07651057 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-05-01 12:50 - 2017-05-01 12:55 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-05-01 12:50 - 2017-05-01 12:55 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-05-01 12:50 - 2017-05-01 12:55 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-05-01 12:50 - 2017-05-01 12:50 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-05-01 12:48 - 2017-05-19 21:58 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-05-01 12:48 - 2017-05-17 18:56 - 00291856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-04-30 11:02 - 2017-05-21 20:00 - 00000000 ___DC C:\WINDOWS\Panther
2017-04-29 12:27 - 2017-04-29 12:27 - 00001256 _____ C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aktualizace a nastavení ochrany osobních údajů.lnk
2017-04-29 12:27 - 2017-04-29 12:27 - 00000000 ____D C:\Users\Pavel\AppData\Local\UNP
2017-04-28 18:43 - 2017-05-01 12:59 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-04-28 18:43 - 2017-04-28 18:44 - 00000000 ____D C:\Program Files\UNP
2017-04-27 17:44 - 2017-04-27 17:44 - 00000000 ____D C:\Users\Pavel\AppData\Local\GOG.com
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-23 19:31 - 2017-03-20 06:43 - 00918758 _____ C:\WINDOWS\system32\perfh005.dat
2017-05-23 19:31 - 2017-03-20 06:43 - 00201710 _____ C:\WINDOWS\system32\perfc005.dat
2017-05-23 19:27 - 2015-10-30 17:28 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Skype
2017-05-23 19:27 - 2015-05-15 21:17 - 00000000 __RDO C:\Users\Pavel\OneDrive
2017-05-23 15:41 - 2014-07-11 00:24 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-23 15:38 - 2014-07-11 00:24 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-23 15:36 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-23 15:36 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-22 21:00 - 2015-03-25 17:37 - 00000000 ____D C:\Users\Pavel\Desktop\Pavlovo
2017-05-22 20:34 - 2017-03-23 17:15 - 00001281 _____ C:\Users\Pavel\Desktop\Facebook Gameroom.lnk
2017-05-22 20:34 - 2017-03-23 17:15 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
2017-05-22 20:33 - 2017-03-23 17:15 - 00000000 ____D C:\Users\Pavel\AppData\Local\Facebook
2017-05-22 20:32 - 2014-12-30 20:02 - 00000000 ____D C:\ProgramData\Origin
2017-05-22 19:05 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF
2017-05-21 20:51 - 2014-07-12 09:46 - 00000000 ____D C:\Program Files (x86)\Steam
2017-05-21 20:10 - 2017-03-10 17:59 - 00000000 ____D C:\Users\Pavel\Desktop\Trash
2017-05-21 20:00 - 2014-09-27 20:01 - 00000000 ____D C:\Users\Pavel\AppData\Local\CrashDumps
2017-05-21 19:36 - 2016-04-18 19:13 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MobiKin
2017-05-21 19:36 - 2016-04-18 19:13 - 00000000 ____D C:\Program Files (x86)\MobiKin
2017-05-21 19:33 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-05-21 18:44 - 2014-07-12 10:31 - 00000000 ____D C:\Program Files (x86)\IObit
2017-05-21 18:43 - 2014-07-12 10:31 - 00000000 ____D C:\ProgramData\IObit
2017-05-21 18:40 - 2015-12-14 19:49 - 00000000 ____D C:\Users\Pavel\AppData\Local\Ubisoft Game Launcher
2017-05-21 18:08 - 2017-03-18 13:40 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-05-21 09:35 - 2017-02-01 20:55 - 00000988 _____ C:\Users\Public\Desktop\TomTom MyDrive Connect.lnk
2017-05-21 09:34 - 2017-02-01 20:55 - 00000000 ____D C:\Program Files (x86)\MyDrive Connect
2017-05-20 21:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\vpnplugins
2017-05-20 20:44 - 2014-12-30 20:08 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Origin
2017-05-20 20:10 - 2014-10-29 22:11 - 00000000 ____D C:\Program Files\Bandizip
2017-05-20 19:37 - 2014-12-31 10:05 - 00000000 ____D C:\Program Files (x86)\Origin
2017-05-20 15:44 - 2014-08-16 07:38 - 00000000 ___RD C:\Users\Pavel\Documents\Scanned Documents
2017-05-19 19:53 - 2015-10-12 10:18 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
2017-05-17 19:34 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache
2017-05-17 19:06 - 2016-10-15 11:16 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-17 19:06 - 2016-10-15 11:16 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-17 18:57 - 2016-04-27 08:56 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-16 08:38 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-05-16 08:38 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-05-16 08:38 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-16 08:38 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-16 08:22 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-04 20:28 - 2016-07-10 18:13 - 00620072 _____ C:\WINDOWS\system32\Drivers\EasyAntiCheat.sys
2017-05-03 18:53 - 2014-07-10 21:41 - 00000000 ____D C:\Users\Pavel\AppData\Local\Packages
2017-05-02 19:40 - 2017-02-01 18:15 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\TS3Client
2017-05-02 17:18 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat
2017-05-01 13:47 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-05-01 13:44 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup
2017-05-01 13:43 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-01 13:43 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-01 13:43 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-05-01 13:43 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-05-01 13:43 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Provisioning
2017-05-01 13:43 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-05-01 13:35 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-05-01 13:35 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-05-01 13:21 - 2016-06-28 16:29 - 00002429 _____ C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-05-01 13:16 - 2016-11-09 18:33 - 00000000 ____D C:\Users\Pavel\AppData\Local\ConnectedDevicesPlatform
2017-05-01 13:15 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-01 13:14 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT
2017-05-01 13:13 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-05-01 13:13 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration
2017-05-01 13:13 - 2017-03-18 13:40 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-05-01 13:10 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-05-01 13:06 - 2017-03-20 06:46 - 00000000 ____D C:\WINDOWS\HoloShell
2017-05-01 13:06 - 2014-07-11 17:47 - 00023020 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-05-01 13:05 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-05-01 12:59 - 2017-04-01 18:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2017-05-01 12:59 - 2017-03-23 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher Enhanced Edition [GOG.com]
2017-05-01 12:59 - 2017-03-23 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2 [GOG.com]
2017-05-01 12:59 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate
2017-05-01 12:59 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-01 12:59 - 2017-02-01 20:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2017-05-01 12:59 - 2016-04-18 19:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite
2017-05-01 12:59 - 2016-03-19 20:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.0
2017-05-01 12:59 - 2015-12-29 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Papers, Please [GOG.com]
2017-05-01 12:59 - 2015-11-11 18:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlast [GOG.com]
2017-05-01 12:59 - 2015-10-31 00:25 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2017-05-01 12:59 - 2015-10-31 00:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2017-05-01 12:59 - 2015-05-02 18:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed™ Most Wanted
2017-05-01 12:59 - 2014-12-31 10:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15
2017-05-01 12:59 - 2014-12-30 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2017-05-01 12:59 - 2014-10-29 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandizip
2017-05-01 12:59 - 2014-10-02 21:19 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-05-01 12:59 - 2014-09-27 15:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zoner Photo Studio 16
2017-05-01 12:59 - 2014-07-20 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-05-01 12:59 - 2014-07-12 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-05-01 12:59 - 2014-07-12 09:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\IME
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\et-EE
2017-05-01 12:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\en-GB
2017-05-01 12:56 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2017-05-01 12:56 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2017-05-01 12:55 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\InputMethod
2017-05-01 12:55 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-05-01 12:55 - 2016-04-18 19:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit
2017-05-01 12:55 - 2016-01-08 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-05-01 12:55 - 2015-10-31 00:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codemasters
2017-05-01 12:55 - 2015-10-12 10:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-05-01 12:55 - 2014-10-09 20:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eidos Interactive
2017-05-01 12:55 - 2014-10-09 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eidos
2017-05-01 12:54 - 2015-12-14 19:49 - 00000000 ____D C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2017-05-01 12:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help
2017-05-01 12:51 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-04-29 15:30 - 2016-09-17 14:12 - 00000000 ____D C:\Users\Pavel\AppData\Local\GeometryDash
2017-04-29 03:05 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-04-29 03:05 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2014-07-12 10:33 - 2014-07-15 17:34 - 0007614 _____ () C:\Users\Pavel\AppData\Local\Resmon.ResmonCfg
Some files in TEMP:
====================
2017-05-21 18:44 - 2017-05-21 18:38 - 15721672 _____ (IObit ) C:\Users\Pavel\AppData\Local\Temp\driver_booster_setup.42876,7810244444.exe
2017-05-20 20:10 - 2017-05-20 20:10 - 3020288 _____ (isMiner worker and updater for windows of isMiner inc ) C:\Users\Pavel\AppData\Local\Temp\isminer.exe
2017-05-20 20:09 - 2017-05-20 20:09 - 0755695 _____ ( ) C:\Users\Pavel\AppData\Local\Temp\Setup.exe
2017-05-20 20:10 - 2017-05-20 20:10 - 1199825 _____ () C:\Users\Pavel\AppData\Local\Temp\unins000.exe
2017-05-20 20:10 - 2017-05-20 20:10 - 0596541 _____ (VideoBox ) C:\Users\Pavel\AppData\Local\Temp\vbsetup.exe
2017-05-20 20:10 - 2017-05-20 20:10 - 3053319 _____ ( ) C:\Users\Pavel\AppData\Local\Temp\yeadesktop.exe
2017-05-23 15:35 - 2017-05-23 15:35 - 0534528 _____ () C:\Users\Pavel\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD.
LastRegBack: 2017-05-22 18:58
==================== End of FRST.txt ============================