Pomalý počítač, nelze nic instalovat
Napsal: 21 čer 2017 21:06
Dobrý den,
prosím o pomoc, mám zpomalený počítač, nelze mi instalovat programy na zbavení malware a také mi špatně funguje stahování přes Chrome - těsně před koncem se to sekne.
Posílám FRST log.
Díky moc
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-06-2017 01
Ran by Tomáš (administrator) on TOMAS_NOTEBOOK (21-06-2017 22:01:47)
Running from C:\Users\Tomáš\Desktop
Loaded Profiles: Tomáš (Available Profiles: Tomáš & Anička & zspin)
Platform: Windows 10 Home Version 1607 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent, Inc.) C:\Users\Tomáš\AppData\Roaming\uTorrent\utorrent.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Tomáš\Desktop\FRSTLauncher (1).exe
(Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\18b5353c449735dba57d08446a7d4a0b\WindowsUpdateBox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [401896 2016-11-02] ()
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-08-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [561672 2015-06-12] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [620152 2006-10-23] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe_ID0EZEHM] => C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe [1884160 2007-04-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318128 2016-11-16] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\...\Run: [uTorrent] => C:\Users\Tomáš\AppData\Roaming\uTorrent\utorrent.exe [398760 2014-04-14] (BitTorrent, Inc.)
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\...\Run: [GoogleChromeAutoLaunch_261D675795E727AD201BBDEE2B3C4324] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1143640 2017-05-09] (Google Inc.)
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4299968 2016-07-29] (Disc Soft Ltd)
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2015-01-30]
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1029-0000-7760-000000000003}\_SC_Acrobat.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk [2015-01-30]
ShortcutTarget: Adobe Acrobat Synchronizer.lnk -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe ()
BootExecute: autocheck autochk /p \??\G:autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-798434008-2211677849-4096002834-1001] => cache.natur.cuni.cz:3128
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{0ec779b1-7add-42de-99b7-2dd1d6675e85}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{682ffc7d-7757-41f1-a060-34d5c6d32678}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{d2a39944-62a6-4098-b6af-e61ff3bc9624}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
SearchScopes: HKU\S-1-5-21-798434008-2211677849-4096002834-1001 -> DefaultScope {76BC9401-0695-4C33-94F4-9422F972CC21} URL =
SearchScopes: HKU\S-1-5-21-798434008-2211677849-4096002834-1001 -> {76BC9401-0695-4C33-94F4-9422F972CC21} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-23] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-23] (Adobe Systems Incorporated)
FireFox:
========
FF DefaultProfile: m97ramew.default
FF ProfilePath: C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\m97ramew.default [2017-02-17]
FF Extension: (No Name) - C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\m97ramew.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [not found]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://gmail.com/","hxxp://zseden.cz/","hxxp://mail.zseden.cz/login.php"
CHR Profile: C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default [2017-06-21]
CHR Extension: (Prezentace Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-04-11]
CHR Extension: (Dokumenty Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-11]
CHR Extension: (Disk Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-11]
CHR Extension: (YouTube) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-11]
CHR Extension: (Adblock Plus) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-04-11]
CHR Extension: (Proxy SwitchySharp) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpplabbmogkhghncfbfdeeokoefdjegm [2017-04-11]
CHR Extension: (Tabulky Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-11]
CHR Extension: (AdBlock) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-06-16]
CHR Extension: (Coggle - Collaborative Mind Maps) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcapocoafbfccjgdgammadkndakcfoi [2017-04-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-11]
CHR Extension: (Adblock Pro) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2017-04-11]
CHR Extension: (Gmail) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-11]
CHR Extension: (Chrome Media Router) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-07-29] (Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2836296 2016-12-14] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2015-01-30] (Macrovision Europe Ltd.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-02] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-12-02] (Lenovo(beijing) Limited)
S3 LSC.Services.SystemService; C:\Program Files\lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe [273232 2016-08-24] (Lenovo)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-01-23] (Electronic Arts)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-25] ()
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [338944 2013-08-11] (IDT, Inc.) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-08-10] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-08-10] (Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132272 2017-01-17] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [106768 2017-01-17] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15488 2016-06-28] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180544 2017-01-17] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [49672 2017-01-17] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [77616 2017-01-17] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [96856 2017-01-17] (ESET)
R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [74344 2013-07-03] (Intel Corporation)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_0221ce4ec0827f74\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [39200 2013-12-28] (NVIDIA Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [802312 2015-06-12] (Vimicro Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-21 22:01 - 2017-06-21 22:02 - 00023320 _____ C:\Users\Tomáš\Desktop\FRST.txt
2017-06-21 22:01 - 2017-06-21 22:01 - 00000000 ___HD C:\$WINDOWS.~BT
2017-06-21 22:01 - 2017-06-21 22:01 - 00000000 ____D C:\FRST
2017-06-21 22:00 - 2017-06-21 22:01 - 00112640 _____ (forum.viry.cz) C:\Users\Tomáš\Desktop\FRSTLauncher (1).exe
2017-06-21 21:52 - 2017-06-21 21:52 - 02439680 _____ (Farbar) C:\Users\Tomáš\Desktop\FRST64.exe
2017-06-21 21:38 - 2017-06-21 21:38 - 64232976 _____ (Malwarebytes ) C:\Users\zspin\Downloads\Nepotvrzeno 580676.crdownload
2017-06-21 21:37 - 2017-06-21 21:37 - 00000000 ____D C:\Users\zspin\AppData\Local\Publishers
2017-06-21 21:37 - 2017-06-21 21:37 - 00000000 ____D C:\Users\zspin\AppData\Local\NVIDIA Corporation
2017-06-21 21:31 - 2017-06-21 21:31 - 00000000 ____D C:\Users\zspin\AppData\Local\NVIDIA
2017-06-21 21:27 - 2017-06-21 21:27 - 00000000 ____D C:\Users\zspin\AppData\Roaming\Hightail for Lenovo
2017-06-21 21:27 - 2017-06-21 21:27 - 00000000 ____D C:\Users\zspin\AppData\Local\VirtualStore
2017-06-21 21:22 - 2017-06-21 21:37 - 00000000 ____D C:\Users\zspin\AppData\Local\ConnectedDevicesPlatform
2017-06-21 21:21 - 2017-06-21 21:40 - 00000000 ____D C:\Users\zspin
2017-06-21 21:21 - 2017-06-21 21:38 - 00000000 ____D C:\Users\zspin\AppData\Local\Packages
2017-06-21 21:21 - 2017-06-21 21:36 - 00000000 __SHD C:\Users\zspin\IntelGraphicsProfiles
2017-06-21 21:21 - 2017-06-21 21:21 - 00000020 ___SH C:\Users\zspin\ntuser.ini
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\My Documents
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\Documents\My Videos
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\Documents\My Pictures
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\Documents\My Music
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 ____D C:\Users\zspin\AppData\Roaming\Adobe
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 ____D C:\Users\zspin\AppData\Local\TileDataLayer
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 ____D C:\Users\zspin\AppData\Local\ESET
2017-06-21 21:21 - 2017-02-17 14:09 - 00000000 ____D C:\Users\zspin\AppData\Local\MicrosoftEdge
2017-06-21 21:21 - 2017-02-17 14:09 - 00000000 ____D C:\Users\zspin\AppData\Local\Google
2017-06-21 21:21 - 2016-11-23 21:56 - 00000000 ____D C:\Users\zspin\AppData\Roaming\Macromedia
2017-06-21 21:21 - 2016-11-23 21:56 - 00000000 ____D C:\Users\zspin\AppData\Local\Microsoft Help
2017-06-21 21:21 - 2014-12-02 12:28 - 00000126 _____ C:\Users\zspin\Desktop\Adobe Photo Offer.url
2017-06-21 21:21 - 2014-03-27 04:21 - 00000190 _____ C:\Users\zspin\Desktop\FREE CALLS with Voxox.url
2017-06-21 21:12 - 2017-06-21 21:12 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-21 21:12 - 2017-06-21 21:12 - 00000000 ____D C:\Program Files\Malwarebytes
2017-06-21 20:41 - 2017-06-21 20:41 - 64232976 _____ (Malwarebytes ) C:\Users\Tomáš\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092.exe
2017-06-20 23:47 - 2017-06-20 23:57 - 02753658 _____ C:\Users\Tomáš\Desktop\ochutnávka ovoce.pptx
2017-06-20 23:46 - 2017-06-20 23:46 - 00347243 _____ C:\Users\Tomáš\Downloads\97D7.tmp
2017-06-20 23:26 - 2017-06-20 23:26 - 00043969 _____ C:\Users\Tomáš\Downloads\83C6.tmp
2017-06-20 22:53 - 2017-06-20 22:54 - 00000000 ____D C:\Users\Tomáš\Downloads\praktická botanika
2017-06-20 21:21 - 2017-06-20 21:21 - 00427933 _____ C:\Users\Tomáš\Downloads\Vydana faktura - 201751282.pdf
2017-06-20 21:20 - 2017-06-20 21:20 - 00018802 _____ C:\Users\Tomáš\Downloads\252-2.pdf
2017-06-19 15:38 - 2017-06-19 16:08 - 2413901824 _____ C:\Users\Tomáš\Downloads\All the President's Men - Všichni prezidentovi muži.avi
2017-06-19 15:38 - 2017-06-19 15:38 - 00012022 _____ C:\Users\Tomáš\Downloads\[CzT]Vsichni_prezidentovi_muzi_All_the_President_s_Men_1976_CZ_.torrent
2017-06-17 21:21 - 2017-06-17 21:21 - 00010922 _____ C:\Users\Tomáš\Desktop\objednávka ovoce.xlsx
2017-06-17 09:33 - 2017-06-17 09:33 - 00000000 ____D C:\Users\Tomáš\Documents\toxi
2017-06-17 09:32 - 2017-06-17 09:32 - 06566724 _____ C:\Users\Tomáš\Documents\toxi.zip
2017-06-16 23:31 - 2017-06-16 23:31 - 00040960 _____ C:\Users\Tomáš\20170616_233150_domácnost.db
2017-06-09 19:12 - 2017-06-20 23:57 - 00000000 ____D C:\WINDOWS\Panther
2017-06-08 21:34 - 2017-06-08 21:34 - 00000017 _____ C:\Users\Tomáš\AppData\Local\resmon.resmoncfg
2017-06-08 21:33 - 2017-06-08 21:33 - 00001406 _____ C:\Users\Tomáš\Desktop\práce.lnk
2017-06-08 21:32 - 2017-06-08 21:32 - 00001406 _____ C:\Users\Tomáš\Desktop\škola.lnk
2017-06-08 21:31 - 2017-06-17 23:12 - 00000000 ____D C:\Users\Tomáš\Downloads\merta
2017-06-08 21:31 - 2017-06-08 21:31 - 00001404 _____ C:\Users\Tomáš\Desktop\merta.lnk
2017-06-08 21:30 - 2017-06-08 21:30 - 00001426 _____ C:\Users\Tomáš\Desktop\tureček.lnk
2017-06-08 21:28 - 2017-06-08 21:29 - 00000000 ____D C:\Users\Tomáš\Downloads\škola
2017-06-08 21:23 - 2017-06-08 21:24 - 00000000 ____D C:\Users\Tomáš\Downloads\práce
2017-06-06 22:03 - 2017-06-06 22:04 - 00193047 _____ C:\Users\Tomáš\Downloads\VY_32_INOVACE_2_19_Procenta.pdf
2017-06-05 23:10 - 2017-06-05 23:10 - 00014407 _____ C:\Users\Tomáš\Downloads\sběr.xlsx
2017-06-05 23:08 - 2017-06-05 23:19 - 00019487 _____ C:\Users\Tomáš\Desktop\grafy - hluk.xlsx
2017-06-05 19:21 - 2017-06-05 19:21 - 00037888 _____ C:\Users\Tomáš\20170605_192145_domácnost.db
2017-06-05 16:27 - 2017-06-05 16:27 - 00060499 _____ C:\Users\Tomáš\Downloads\210995798_20170531_5_MCZB.pdf
2017-06-04 22:22 - 2017-06-04 22:50 - 00000000 ____D C:\Users\Tomáš\Downloads\matematika - závěrečná práce
2017-06-04 13:49 - 2017-06-04 13:49 - 00000000 ____D C:\Users\Tomáš\AppData\Local\UNP
2017-06-02 22:55 - 2017-06-02 23:11 - 286985520 _____ C:\Users\Tomáš\Downloads\Florenc-13.30-1957-ÄŚeskĂ˝-film-do-mobilu-mĂša.mp4
2017-06-02 22:49 - 2017-06-02 22:50 - 00000000 ____D C:\Program Files\UNP
2017-06-02 22:49 - 2017-06-02 22:49 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-06-01 00:46 - 2017-06-01 12:06 - 00000000 ____D C:\Users\Tomáš\Downloads\adaptace
2017-06-01 00:44 - 2017-06-01 00:45 - 101265781 _____ C:\Users\Tomáš\Downloads\zasilka-MB8XCVKNDFKVWD3S.zip
2017-05-28 13:27 - 2017-05-31 21:46 - 00000000 ___RD C:\Users\Tomáš\Downloads\krkonoše
2017-05-28 13:09 - 2017-05-28 13:17 - 1112319812 _____ C:\Users\Tomáš\Downloads\drive-download-20170528T110646Z-001.zip
2017-05-23 22:53 - 2017-05-23 22:53 - 00344490 _____ C:\Users\Tomáš\Downloads\VR_HP_Mgr_11_042017.pdf
2017-05-23 22:53 - 2017-05-23 22:53 - 00331127 _____ C:\Users\Tomáš\Downloads\Odborný_rada_EPI_ZP_05.2017.pdf
2017-05-23 22:52 - 2017-05-23 22:52 - 00331375 _____ C:\Users\Tomáš\Downloads\VR_HDM_DiS_Bc_18_05_2017.pdf
2017-05-23 22:52 - 2017-05-23 22:52 - 00331375 _____ C:\Users\Tomáš\Downloads\VR_HDM_DiS_Bc_18_05_2017 (1).pdf
2017-05-23 22:50 - 2017-05-23 22:51 - 00443351 _____ C:\Users\Tomáš\Downloads\VĹ_ORA_HDM_-doba_neurÄŤitá_-_19.05.2017_-_19.06.2017.pdf
2017-05-23 21:09 - 2017-05-23 21:09 - 00257951 _____ C:\Users\Tomáš\Downloads\DPP_2016n Pinkr Tomáš 2017.07 ZZA.pdf
2017-05-23 17:54 - 2017-05-23 17:54 - 00000000 __SHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-05-23 17:54 - 2017-05-23 17:54 - 00000000 ____D C:\ProgramData\ESET
2017-05-23 17:54 - 2017-05-23 17:54 - 00000000 ____D C:\Program Files\ESET
2017-05-22 22:05 - 2017-05-22 22:05 - 00036864 _____ C:\Users\Tomáš\20170522_220514_domácnost.db
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-21 22:00 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-21 22:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-21 22:00 - 2015-01-30 18:20 - 00000000 ____D C:\Users\Tomáš\AppData\Local\Packages
2017-06-21 21:57 - 2015-02-13 21:17 - 00000000 ____D C:\Users\Tomáš\AppData\Roaming\uTorrent
2017-06-21 21:56 - 2016-11-23 22:07 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-21 21:56 - 2016-11-23 21:47 - 00000000 ____D C:\Users\Tomáš
2017-06-21 21:56 - 2016-11-23 21:43 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-06-21 21:56 - 2016-11-23 21:42 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-21 21:56 - 2016-11-23 21:36 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-21 21:56 - 2015-01-30 23:01 - 00000000 __SHD C:\Users\Tomáš\IntelGraphicsProfiles
2017-06-21 21:55 - 2015-01-30 20:03 - 00000000 ____D C:\Users\Tomáš\AppData\Local\CrashDumps
2017-06-21 21:54 - 2015-10-10 20:45 - 00000000 ____D C:\Users\Tomáš\AppData\Local\MicrosoftEdge
2017-06-21 21:21 - 2015-09-10 07:42 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-21 20:46 - 2016-07-16 08:04 - 01048576 _____ C:\WINDOWS\system32\config\BBI
2017-06-21 20:29 - 2015-02-14 21:20 - 00000000 ___RD C:\Users\Tomáš\OneDrive
2017-06-21 20:27 - 2017-02-17 14:08 - 00000000 ____D C:\Users\Tomáš\AppData\Roaming\Seznam.cz
2017-06-20 23:49 - 2015-02-01 16:09 - 00000000 ____D C:\ProgramData\CanonIJPLM
2017-06-20 22:49 - 2015-02-01 18:18 - 00000000 ____D C:\Users\Tomáš\AppData\Roaming\vlc
2017-06-19 20:27 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-19 18:54 - 2015-01-30 19:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-19 18:50 - 2015-01-30 19:46 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-17 22:36 - 2017-01-21 21:10 - 00000000 ____D C:\Users\Tomáš\Downloads\tureček
2017-06-17 12:20 - 2015-02-02 17:33 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-06-10 18:31 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-08 21:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-06-08 21:34 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2017-06-08 21:32 - 2015-01-30 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-06-08 21:28 - 2016-12-18 17:01 - 00000000 ____D C:\Users\Tomáš\Downloads\referáty
2017-06-03 08:36 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-03 08:36 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-02 22:38 - 2015-01-30 23:26 - 00000000 ____D C:\ProgramData\FLEXnet
2017-05-31 01:40 - 2016-03-10 22:08 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-25 23:33 - 2016-11-20 18:00 - 00000000 ____D C:\Users\Tomáš\Downloads\evoluce
2017-05-23 17:54 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
==================== Files in the root of some directories =======
2017-06-08 21:34 - 2017-06-08 21:34 - 0000017 _____ () C:\Users\Tomáš\AppData\Local\resmon.resmoncfg
2014-12-02 11:56 - 2014-12-02 11:56 - 0000000 ____N () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2017-06-15 21:58 - 2017-06-21 20:27 - 0534528 _____ () C:\Users\Tomáš\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Tom ç\Desktop" je 398 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================
prosím o pomoc, mám zpomalený počítač, nelze mi instalovat programy na zbavení malware a také mi špatně funguje stahování přes Chrome - těsně před koncem se to sekne.
Posílám FRST log.
Díky moc
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-06-2017 01
Ran by Tomáš (administrator) on TOMAS_NOTEBOOK (21-06-2017 22:01:47)
Running from C:\Users\Tomáš\Desktop
Loaded Profiles: Tomáš (Available Profiles: Tomáš & Anička & zspin)
Platform: Windows 10 Home Version 1607 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent, Inc.) C:\Users\Tomáš\AppData\Roaming\uTorrent\utorrent.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Tomáš\Desktop\FRSTLauncher (1).exe
(Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\18b5353c449735dba57d08446a7d4a0b\WindowsUpdateBox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [401896 2016-11-02] ()
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-09-24] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-08-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [561672 2015-06-12] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [620152 2006-10-23] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe_ID0EZEHM] => C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe [1884160 2007-04-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318128 2016-11-16] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\...\Run: [uTorrent] => C:\Users\Tomáš\AppData\Roaming\uTorrent\utorrent.exe [398760 2014-04-14] (BitTorrent, Inc.)
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\...\Run: [GoogleChromeAutoLaunch_261D675795E727AD201BBDEE2B3C4324] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1143640 2017-05-09] (Google Inc.)
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4299968 2016-07-29] (Disc Soft Ltd)
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2015-01-30]
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1029-0000-7760-000000000003}\_SC_Acrobat.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk [2015-01-30]
ShortcutTarget: Adobe Acrobat Synchronizer.lnk -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe ()
BootExecute: autocheck autochk /p \??\G:autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-798434008-2211677849-4096002834-1001] => cache.natur.cuni.cz:3128
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{0ec779b1-7add-42de-99b7-2dd1d6675e85}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{682ffc7d-7757-41f1-a060-34d5c6d32678}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{d2a39944-62a6-4098-b6af-e61ff3bc9624}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-798434008-2211677849-4096002834-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
SearchScopes: HKU\S-1-5-21-798434008-2211677849-4096002834-1001 -> DefaultScope {76BC9401-0695-4C33-94F4-9422F972CC21} URL =
SearchScopes: HKU\S-1-5-21-798434008-2211677849-4096002834-1001 -> {76BC9401-0695-4C33-94F4-9422F972CC21} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-23] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-23] (Adobe Systems Incorporated)
FireFox:
========
FF DefaultProfile: m97ramew.default
FF ProfilePath: C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\m97ramew.default [2017-02-17]
FF Extension: (No Name) - C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\m97ramew.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [not found]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://gmail.com/","hxxp://zseden.cz/","hxxp://mail.zseden.cz/login.php"
CHR Profile: C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default [2017-06-21]
CHR Extension: (Prezentace Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-04-11]
CHR Extension: (Dokumenty Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-11]
CHR Extension: (Disk Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-11]
CHR Extension: (YouTube) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-11]
CHR Extension: (Adblock Plus) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-04-11]
CHR Extension: (Proxy SwitchySharp) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpplabbmogkhghncfbfdeeokoefdjegm [2017-04-11]
CHR Extension: (Tabulky Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-11]
CHR Extension: (AdBlock) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-06-16]
CHR Extension: (Coggle - Collaborative Mind Maps) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcapocoafbfccjgdgammadkndakcfoi [2017-04-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-11]
CHR Extension: (Adblock Pro) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2017-04-11]
CHR Extension: (Gmail) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-11]
CHR Extension: (Chrome Media Router) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-07-29] (Disc Soft Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2836296 2016-12-14] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2015-01-30] (Macrovision Europe Ltd.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-09-24] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-02] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-12-02] (Lenovo(beijing) Limited)
S3 LSC.Services.SystemService; C:\Program Files\lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe [273232 2016-08-24] (Lenovo)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-01-23] (Electronic Arts)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-25] ()
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [338944 2013-08-11] (IDT, Inc.) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-08-10] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-08-10] (Disc Soft Ltd)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132272 2017-01-17] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [106768 2017-01-17] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15488 2016-06-28] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180544 2017-01-17] (ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [49672 2017-01-17] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [77616 2017-01-17] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [96856 2017-01-17] (ESET)
R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [74344 2013-07-03] (Intel Corporation)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_0221ce4ec0827f74\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [39200 2013-12-28] (NVIDIA Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [802312 2015-06-12] (Vimicro Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-21 22:01 - 2017-06-21 22:02 - 00023320 _____ C:\Users\Tomáš\Desktop\FRST.txt
2017-06-21 22:01 - 2017-06-21 22:01 - 00000000 ___HD C:\$WINDOWS.~BT
2017-06-21 22:01 - 2017-06-21 22:01 - 00000000 ____D C:\FRST
2017-06-21 22:00 - 2017-06-21 22:01 - 00112640 _____ (forum.viry.cz) C:\Users\Tomáš\Desktop\FRSTLauncher (1).exe
2017-06-21 21:52 - 2017-06-21 21:52 - 02439680 _____ (Farbar) C:\Users\Tomáš\Desktop\FRST64.exe
2017-06-21 21:38 - 2017-06-21 21:38 - 64232976 _____ (Malwarebytes ) C:\Users\zspin\Downloads\Nepotvrzeno 580676.crdownload
2017-06-21 21:37 - 2017-06-21 21:37 - 00000000 ____D C:\Users\zspin\AppData\Local\Publishers
2017-06-21 21:37 - 2017-06-21 21:37 - 00000000 ____D C:\Users\zspin\AppData\Local\NVIDIA Corporation
2017-06-21 21:31 - 2017-06-21 21:31 - 00000000 ____D C:\Users\zspin\AppData\Local\NVIDIA
2017-06-21 21:27 - 2017-06-21 21:27 - 00000000 ____D C:\Users\zspin\AppData\Roaming\Hightail for Lenovo
2017-06-21 21:27 - 2017-06-21 21:27 - 00000000 ____D C:\Users\zspin\AppData\Local\VirtualStore
2017-06-21 21:22 - 2017-06-21 21:37 - 00000000 ____D C:\Users\zspin\AppData\Local\ConnectedDevicesPlatform
2017-06-21 21:21 - 2017-06-21 21:40 - 00000000 ____D C:\Users\zspin
2017-06-21 21:21 - 2017-06-21 21:38 - 00000000 ____D C:\Users\zspin\AppData\Local\Packages
2017-06-21 21:21 - 2017-06-21 21:36 - 00000000 __SHD C:\Users\zspin\IntelGraphicsProfiles
2017-06-21 21:21 - 2017-06-21 21:21 - 00000020 ___SH C:\Users\zspin\ntuser.ini
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\My Documents
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\Documents\My Videos
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\Documents\My Pictures
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 _SHDL C:\Users\zspin\Documents\My Music
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 ____D C:\Users\zspin\AppData\Roaming\Adobe
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 ____D C:\Users\zspin\AppData\Local\TileDataLayer
2017-06-21 21:21 - 2017-06-21 21:21 - 00000000 ____D C:\Users\zspin\AppData\Local\ESET
2017-06-21 21:21 - 2017-02-17 14:09 - 00000000 ____D C:\Users\zspin\AppData\Local\MicrosoftEdge
2017-06-21 21:21 - 2017-02-17 14:09 - 00000000 ____D C:\Users\zspin\AppData\Local\Google
2017-06-21 21:21 - 2016-11-23 21:56 - 00000000 ____D C:\Users\zspin\AppData\Roaming\Macromedia
2017-06-21 21:21 - 2016-11-23 21:56 - 00000000 ____D C:\Users\zspin\AppData\Local\Microsoft Help
2017-06-21 21:21 - 2014-12-02 12:28 - 00000126 _____ C:\Users\zspin\Desktop\Adobe Photo Offer.url
2017-06-21 21:21 - 2014-03-27 04:21 - 00000190 _____ C:\Users\zspin\Desktop\FREE CALLS with Voxox.url
2017-06-21 21:12 - 2017-06-21 21:12 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-21 21:12 - 2017-06-21 21:12 - 00000000 ____D C:\Program Files\Malwarebytes
2017-06-21 20:41 - 2017-06-21 20:41 - 64232976 _____ (Malwarebytes ) C:\Users\Tomáš\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092.exe
2017-06-20 23:47 - 2017-06-20 23:57 - 02753658 _____ C:\Users\Tomáš\Desktop\ochutnávka ovoce.pptx
2017-06-20 23:46 - 2017-06-20 23:46 - 00347243 _____ C:\Users\Tomáš\Downloads\97D7.tmp
2017-06-20 23:26 - 2017-06-20 23:26 - 00043969 _____ C:\Users\Tomáš\Downloads\83C6.tmp
2017-06-20 22:53 - 2017-06-20 22:54 - 00000000 ____D C:\Users\Tomáš\Downloads\praktická botanika
2017-06-20 21:21 - 2017-06-20 21:21 - 00427933 _____ C:\Users\Tomáš\Downloads\Vydana faktura - 201751282.pdf
2017-06-20 21:20 - 2017-06-20 21:20 - 00018802 _____ C:\Users\Tomáš\Downloads\252-2.pdf
2017-06-19 15:38 - 2017-06-19 16:08 - 2413901824 _____ C:\Users\Tomáš\Downloads\All the President's Men - Všichni prezidentovi muži.avi
2017-06-19 15:38 - 2017-06-19 15:38 - 00012022 _____ C:\Users\Tomáš\Downloads\[CzT]Vsichni_prezidentovi_muzi_All_the_President_s_Men_1976_CZ_.torrent
2017-06-17 21:21 - 2017-06-17 21:21 - 00010922 _____ C:\Users\Tomáš\Desktop\objednávka ovoce.xlsx
2017-06-17 09:33 - 2017-06-17 09:33 - 00000000 ____D C:\Users\Tomáš\Documents\toxi
2017-06-17 09:32 - 2017-06-17 09:32 - 06566724 _____ C:\Users\Tomáš\Documents\toxi.zip
2017-06-16 23:31 - 2017-06-16 23:31 - 00040960 _____ C:\Users\Tomáš\20170616_233150_domácnost.db
2017-06-09 19:12 - 2017-06-20 23:57 - 00000000 ____D C:\WINDOWS\Panther
2017-06-08 21:34 - 2017-06-08 21:34 - 00000017 _____ C:\Users\Tomáš\AppData\Local\resmon.resmoncfg
2017-06-08 21:33 - 2017-06-08 21:33 - 00001406 _____ C:\Users\Tomáš\Desktop\práce.lnk
2017-06-08 21:32 - 2017-06-08 21:32 - 00001406 _____ C:\Users\Tomáš\Desktop\škola.lnk
2017-06-08 21:31 - 2017-06-17 23:12 - 00000000 ____D C:\Users\Tomáš\Downloads\merta
2017-06-08 21:31 - 2017-06-08 21:31 - 00001404 _____ C:\Users\Tomáš\Desktop\merta.lnk
2017-06-08 21:30 - 2017-06-08 21:30 - 00001426 _____ C:\Users\Tomáš\Desktop\tureček.lnk
2017-06-08 21:28 - 2017-06-08 21:29 - 00000000 ____D C:\Users\Tomáš\Downloads\škola
2017-06-08 21:23 - 2017-06-08 21:24 - 00000000 ____D C:\Users\Tomáš\Downloads\práce
2017-06-06 22:03 - 2017-06-06 22:04 - 00193047 _____ C:\Users\Tomáš\Downloads\VY_32_INOVACE_2_19_Procenta.pdf
2017-06-05 23:10 - 2017-06-05 23:10 - 00014407 _____ C:\Users\Tomáš\Downloads\sběr.xlsx
2017-06-05 23:08 - 2017-06-05 23:19 - 00019487 _____ C:\Users\Tomáš\Desktop\grafy - hluk.xlsx
2017-06-05 19:21 - 2017-06-05 19:21 - 00037888 _____ C:\Users\Tomáš\20170605_192145_domácnost.db
2017-06-05 16:27 - 2017-06-05 16:27 - 00060499 _____ C:\Users\Tomáš\Downloads\210995798_20170531_5_MCZB.pdf
2017-06-04 22:22 - 2017-06-04 22:50 - 00000000 ____D C:\Users\Tomáš\Downloads\matematika - závěrečná práce
2017-06-04 13:49 - 2017-06-04 13:49 - 00000000 ____D C:\Users\Tomáš\AppData\Local\UNP
2017-06-02 22:55 - 2017-06-02 23:11 - 286985520 _____ C:\Users\Tomáš\Downloads\Florenc-13.30-1957-ÄŚeskĂ˝-film-do-mobilu-mĂša.mp4
2017-06-02 22:49 - 2017-06-02 22:50 - 00000000 ____D C:\Program Files\UNP
2017-06-02 22:49 - 2017-06-02 22:49 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-06-01 00:46 - 2017-06-01 12:06 - 00000000 ____D C:\Users\Tomáš\Downloads\adaptace
2017-06-01 00:44 - 2017-06-01 00:45 - 101265781 _____ C:\Users\Tomáš\Downloads\zasilka-MB8XCVKNDFKVWD3S.zip
2017-05-28 13:27 - 2017-05-31 21:46 - 00000000 ___RD C:\Users\Tomáš\Downloads\krkonoše
2017-05-28 13:09 - 2017-05-28 13:17 - 1112319812 _____ C:\Users\Tomáš\Downloads\drive-download-20170528T110646Z-001.zip
2017-05-23 22:53 - 2017-05-23 22:53 - 00344490 _____ C:\Users\Tomáš\Downloads\VR_HP_Mgr_11_042017.pdf
2017-05-23 22:53 - 2017-05-23 22:53 - 00331127 _____ C:\Users\Tomáš\Downloads\Odborný_rada_EPI_ZP_05.2017.pdf
2017-05-23 22:52 - 2017-05-23 22:52 - 00331375 _____ C:\Users\Tomáš\Downloads\VR_HDM_DiS_Bc_18_05_2017.pdf
2017-05-23 22:52 - 2017-05-23 22:52 - 00331375 _____ C:\Users\Tomáš\Downloads\VR_HDM_DiS_Bc_18_05_2017 (1).pdf
2017-05-23 22:50 - 2017-05-23 22:51 - 00443351 _____ C:\Users\Tomáš\Downloads\VĹ_ORA_HDM_-doba_neurÄŤitá_-_19.05.2017_-_19.06.2017.pdf
2017-05-23 21:09 - 2017-05-23 21:09 - 00257951 _____ C:\Users\Tomáš\Downloads\DPP_2016n Pinkr Tomáš 2017.07 ZZA.pdf
2017-05-23 17:54 - 2017-05-23 17:54 - 00000000 __SHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-05-23 17:54 - 2017-05-23 17:54 - 00000000 ____D C:\ProgramData\ESET
2017-05-23 17:54 - 2017-05-23 17:54 - 00000000 ____D C:\Program Files\ESET
2017-05-22 22:05 - 2017-05-22 22:05 - 00036864 _____ C:\Users\Tomáš\20170522_220514_domácnost.db
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-21 22:00 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-21 22:00 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-21 22:00 - 2015-01-30 18:20 - 00000000 ____D C:\Users\Tomáš\AppData\Local\Packages
2017-06-21 21:57 - 2015-02-13 21:17 - 00000000 ____D C:\Users\Tomáš\AppData\Roaming\uTorrent
2017-06-21 21:56 - 2016-11-23 22:07 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-21 21:56 - 2016-11-23 21:47 - 00000000 ____D C:\Users\Tomáš
2017-06-21 21:56 - 2016-11-23 21:43 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-06-21 21:56 - 2016-11-23 21:42 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-21 21:56 - 2016-11-23 21:36 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-21 21:56 - 2015-01-30 23:01 - 00000000 __SHD C:\Users\Tomáš\IntelGraphicsProfiles
2017-06-21 21:55 - 2015-01-30 20:03 - 00000000 ____D C:\Users\Tomáš\AppData\Local\CrashDumps
2017-06-21 21:54 - 2015-10-10 20:45 - 00000000 ____D C:\Users\Tomáš\AppData\Local\MicrosoftEdge
2017-06-21 21:21 - 2015-09-10 07:42 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-21 20:46 - 2016-07-16 08:04 - 01048576 _____ C:\WINDOWS\system32\config\BBI
2017-06-21 20:29 - 2015-02-14 21:20 - 00000000 ___RD C:\Users\Tomáš\OneDrive
2017-06-21 20:27 - 2017-02-17 14:08 - 00000000 ____D C:\Users\Tomáš\AppData\Roaming\Seznam.cz
2017-06-20 23:49 - 2015-02-01 16:09 - 00000000 ____D C:\ProgramData\CanonIJPLM
2017-06-20 22:49 - 2015-02-01 18:18 - 00000000 ____D C:\Users\Tomáš\AppData\Roaming\vlc
2017-06-19 20:27 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-19 18:54 - 2015-01-30 19:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-19 18:50 - 2015-01-30 19:46 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-17 22:36 - 2017-01-21 21:10 - 00000000 ____D C:\Users\Tomáš\Downloads\tureček
2017-06-17 12:20 - 2015-02-02 17:33 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-06-10 18:31 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-08 21:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-06-08 21:34 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2017-06-08 21:32 - 2015-01-30 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-06-08 21:28 - 2016-12-18 17:01 - 00000000 ____D C:\Users\Tomáš\Downloads\referáty
2017-06-03 08:36 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-03 08:36 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-02 22:38 - 2015-01-30 23:26 - 00000000 ____D C:\ProgramData\FLEXnet
2017-05-31 01:40 - 2016-03-10 22:08 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-25 23:33 - 2016-11-20 18:00 - 00000000 ____D C:\Users\Tomáš\Downloads\evoluce
2017-05-23 17:54 - 2016-07-16 08:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
==================== Files in the root of some directories =======
2017-06-08 21:34 - 2017-06-08 21:34 - 0000017 _____ () C:\Users\Tomáš\AppData\Local\resmon.resmoncfg
2014-12-02 11:56 - 2014-12-02 11:56 - 0000000 ____N () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2017-06-15 21:58 - 2017-06-21 20:27 - 0534528 _____ () C:\Users\Tomáš\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Tom ç\Desktop" je 398 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
==================== End Of Log ==============================