z nějakého neznámého důvodu, se mi často poslední půl rok využívá disk na 100%(na disku je dost místa) i když žádné náročné aplikace nejsou spuštěné. Podle TM mi disk zabírá především "System" a "Service Host: Local Service". Celkově PC je o dost zpomalené(PC a aplikace se zapínají pomaleji, časté zmražení Chrome a dalších aplikací, etc...) než před půl rokem. Také se mi stává, téměř automaticky po každém zapnutí a po dobu běžení PC náhodně, že se Windows Defender samovolně vypíná a po sekundě se mi hned zapne. Díky moc za každou pomoc nebo radu

Zde posílám log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2017
Ran by ERIK (administrator) on DOMA225 (03-12-2017 12:43:08)
Running from C:\Users\ERIK\Desktop
Loaded Profiles: ERIK (Available Profiles: ERIK & Guest)
Platform: Windows 8 Enterprise (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mega Limited) C:\Users\ERIK\AppData\Local\MEGAsync\MEGAsync.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
() C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AimerSoft) C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
() C:\Program Files (x86)\Gaming Keyboard\OSD.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Origin\QtWebEngineProcess.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(forum.viry.cz) C:\Users\ERIK\Desktop\FRSTLauncher (3).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7199448 2013-10-01] (Realtek Semiconductor)
HKLM\...\Run: [V0700Pin.dll] => RunDLL32.exe V0700Pin.dll,RunDLL32EP 514,/d:2
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-03-22] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.)
HKLM-x32\...\Run: [V0700Mon.exe] => C:\Windows\V0700Mon.exe [28672 2011-08-22] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2313408 2016-04-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
HKLM-x32\...\Run: [Gaming Keyboard] => C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [479232 2014-01-16] ()
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-06-08] (Power Software Ltd)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (AimerSoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\KeepVid\KeepVid Pro\DelayPluginI.exe [1974432 2016-10-18] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5885352 2017-06-29] (LogMeIn Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [DAEMON Tools Lite] => D:\hry\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3503088 2016-10-09] (Electronic Arts)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\ERIK\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\ERIK\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [GoogleChromeAutoLaunch_5998AE56BE14438E63B1EE3391313A39] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1556312 2017-11-10] (Google Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Steam] => D:\Steam\steam.exe [3101984 2017-10-14] (Valve Corporation)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [5345672 2017-11-09] (Nota Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [CyberGhost] => "C:\Program Files\CyberGhost 6\CyberGhost.exe" /autostart /min
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [World of Warships] => "D:\hry\World_of_Warships\WargamingGameUpdater.exe"
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-10-22]
ShortcutTarget: MEGAsync.lnk -> C:\Users\ERIK\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3520 series.lnk [2016-10-10]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 3520 series.lnk -> (No File)
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vyrezy obrazovky a spustení aplikace OneNote 2010.lnk [2016-10-10]
ShortcutTarget: Vyrezy obrazovky a spustení aplikace OneNote 2010.lnk -> (No File)
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2017-10-11]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * aswBoot.exe /M:76e4596291 /wow /dir:"C:\Program Files\AVAST Software\Avast"
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{D7BF9759-483B-4DF8-9D39-8EE151365322}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D7BF9759-483B-4DF8-9D39-8EE151365322}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{E0087B95-8734-48CD-A2BC-7B412C45FC2E}: [DhcpNameServer] 7.254.254.254
ManualProxies:
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 16944E13E82DEFA97D39592013C2B7A8 URL = hxxp://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 33D267CDA73706E77445E11F79A59BC4 URL = hxxp://www.mapy.cz/?sourceid=quicksearch_6826& ... earchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> D409C7645CA7CA4C24B1AFA73B1AEF36 URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> DF91290F8D6EC8584060B5957DE2FB6C URL = hxxp://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: KeepVid Pro 4.10.0 -> {F9B65201-3D7F-48DA-AAB3-57A6FAD648FD} -> C:\ProgramData\KeepVid\KeepVid Pro\WSBrowserAppMgr.dll [2016-10-18] ()
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security)
Toolbar: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - No File
FireFox:
========
FF ProfilePath: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default [2017-10-01]
FF Extension: (Tab Auto Reload) - C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\TabAutoReload@schuzak.jp.xpi [2017-09-18] [Lagacy]
FF Extension: (iMacros for Firefox) - C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}.xpi [2016-10-16] [Lagacy]
FF Extension: (Seznam lištička) - C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-09-18] [Lagacy]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\firmy.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\mapy.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\seznam.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\videa.seznam.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\zbozi.cz-080222.xml [2015-10-27]
FF HKLM-x32\...\Firefox\Extensions: [KVAllmytube@KeepVid.com] - C:\ProgramData\KeepVid\KeepVid Pro\KVAllmytube@KeepVid.com_xpi
FF Extension: (KeepVid Pro) - C:\ProgramData\KeepVid\KeepVid Pro\KVAllmytube@KeepVid.com_xpi [2016-11-06] [Lagacy]
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [No File]
FF Plugin: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelogx64.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-04-07] (Adobe Systems)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [No File]
FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @virtools.com/3DviaPlayer -> C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll [2012-04-05] (Dassault Systèmes)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-04-07] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2796967165-1696306274-2783790974-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\ERIK\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2796967165-1696306274-2783790974-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ERIK\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-10-20] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "","www.google.com"
CHR DefaultSearchURL: Default -> hxxp://music.eanswers.com/go/?category=web&s=scds&vert=music&q={searchTerms}
CHR DefaultSearchKeyword: Default -> songsCenter
CHR DefaultSuggestURL: Default -> hxxp://sug.eanswers.com/search/index_sg.php?q={searchTerms}
CHR Profile: C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default [2017-12-03]
CHR Extension: (Easy Auto Refresh) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2017-09-27]
CHR Extension: (Prezentace) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Dokumenty) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Disk Google) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-11]
CHR Extension: (YouTube) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-11]
CHR Extension: (GameLoad - play Unity Games (Win only)) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\cajoopobkbcpiniljegibngikdbidbkh [2017-01-14]
CHR Extension: (Adobe Acrobat) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-07-26]
CHR Extension: (Tabulky) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (KB SSL Enforcer) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcpelgcagfhfoegekianiofphddckof [2016-11-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-11]
CHR Extension: (AdBlock) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-11-28]
CHR Extension: (Invite All Friends on Facebook) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmhkeajgflmokoaaoadgkhhmibjbpj [2017-11-26]
CHR Extension: (Skype) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (songsCenter Search) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojbimichjpkfdgpoiedkbjlphjnjclli [2017-11-04]
CHR Extension: (Seznam pro Chrome - Esko) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2017-11-29]
CHR Extension: (TunnelBear Inc.) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdakjcmkglenbhjadbccaookpfjihpa [2017-11-17]
CHR Extension: (Визуальные закладки) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchfckkccldkbclgdepkaonamkignanh [2017-09-16]
CHR Extension: (Gmail) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-11]
CHR Extension: (Chrome Media Router) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-17]
CHR HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [pchfckkccldkbclgdepkaonamkignanh] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [694464 2016-04-07] (Adobe Systems Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1536520 2017-05-16] ()
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [236840 2015-04-13] (EasyAntiCheat Ltd)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3418024 2017-06-29] (LogMeIn Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [323952 2017-09-27] (HP Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-03-23] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-05-21] ()
S2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [1001920 2017-06-26] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16928 2017-06-26] (McAfee, Inc.)
S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [87760 2017-06-26] (McAfee, Inc.)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [872432 2016-06-23] (Tunngle.net GmbH)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1164688 2015-12-26] ()
S3 Origin Client Service; "C:\Program Files (x86)\Origin\OriginClientService.exe" [X]
S2 Origin Web Helper Service; "C:\Program Files (x86)\Origin\OriginWebHelperService.exe" [X]
S3 OverwolfUpdater; "C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe" /RunningFrom SCM" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-05-29] (Disc Soft Ltd)
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2017-06-29] (LogMeIn Inc.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2017-12-03] (Malwarebytes)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S1 prodrv05; C:\Windows\SysWOW64\drivers\prodrv05.sys [53376 2002-10-05] (Protection Technology Co.) [File not signed]
S1 prodrv06; C:\Windows\SysWOW64\drivers\prodrv06.sys [50816 2003-04-28] (StarForce Technologies, Inc.) [File not signed]
S0 prohlp01; C:\Windows\SysWOW64\drivers\prohlp01.sys [75936 2002-10-05] (Protection Technology Co.) [File not signed]
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [94464 2003-04-28] (StarForce Technologies, Inc.) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [6848 2003-04-04] (StarForce Technologies, Inc.) [File not signed]
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4448 2003-04-29] (StarForce Technologies, Inc.) [File not signed]
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
R3 tap0901t; C:\Windows\system32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 V0700Vid; C:\Windows\system32\DRIVERS\V0700Vid.sys [393920 2011-09-06] (Creative Technology Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-06] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [281944 2015-07-06] (Microsoft Corporation)
S3 aswHdsKe; \??\C:\Windows\system32\drivers\aswHdsKe.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\Users\ERIK\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-03 12:43 - 2017-12-03 12:43 - 000029240 _____ C:\Users\ERIK\Desktop\FRST.txt
2017-12-03 12:42 - 2017-12-03 12:43 - 000000000 ____D C:\FRST
2017-12-03 12:42 - 2017-12-03 12:40 - 000112640 _____ (forum.viry.cz) C:\Users\ERIK\Desktop\FRSTLauncher (3).exe
2017-12-03 12:40 - 2017-12-03 12:40 - 000112640 _____ (forum.viry.cz) C:\Users\ERIK\Downloads\FRSTLauncher (3).exe
2017-12-03 12:33 - 2017-12-03 12:33 - 000112640 _____ (forum.viry.cz) C:\Users\ERIK\Downloads\Nepotvrzeno 338787.crdownload
2017-12-03 12:33 - 2017-12-03 12:33 - 000112640 _____ (forum.viry.cz) C:\Users\ERIK\Downloads\Nepotvrzeno 136927.crdownload
2017-12-03 12:31 - 2017-12-03 12:31 - 002391552 _____ (Farbar) C:\Users\ERIK\Downloads\FRST64.exe
2017-12-03 12:31 - 2017-12-03 12:31 - 002391552 _____ (Farbar) C:\Users\ERIK\Desktop\FRST64.exe
2017-11-29 23:11 - 2017-12-03 12:41 - 000003918 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C4C40D8A-BD3F-4695-A9B2-80E44222EDC8}
2017-11-29 23:11 - 2017-11-29 23:11 - 000000000 ____D C:\Users\ERIK\Desktop\httpsgyazo.com25742543a02b56f1dbacde0cc63c4ef3
2017-11-27 11:03 - 2017-11-27 11:03 - 000139229 _____ C:\Users\ERIK\Documents\Scan0051.pdf
2017-11-27 11:02 - 2017-11-27 11:02 - 000142957 _____ C:\Users\ERIK\Documents\Scan0050.pdf
2017-11-27 10:56 - 2017-11-27 10:56 - 000646949 _____ C:\Users\ERIK\Documents\Scan0048.pdf
2017-11-27 10:56 - 2017-11-27 10:56 - 000568104 _____ C:\Users\ERIK\Documents\Scan0049.pdf
2017-11-27 10:53 - 2017-11-27 10:53 - 000683651 _____ C:\Users\ERIK\Documents\Scan0047.pdf
2017-11-27 10:53 - 2017-11-27 10:53 - 000643174 _____ C:\Users\ERIK\Documents\Scan0046.pdf
2017-11-27 10:51 - 2017-11-27 10:51 - 000630403 _____ C:\Users\ERIK\Documents\Scan0045.pdf
2017-11-22 19:24 - 2017-11-22 19:24 - 000139983 _____ C:\Users\ERIK\Downloads\2127922_634273_priloha_c._1.xlsx
2017-11-21 20:46 - 2017-11-21 20:46 - 000266326 _____ C:\Users\ERIK\Documents\Scan0044.pdf
2017-11-20 21:03 - 2017-11-20 21:02 - 006156504 _____ C:\Users\ERIK\Desktop\planovac_ACOS_2017.pdf
2017-11-20 21:02 - 2017-11-20 21:02 - 006156504 _____ C:\Users\ERIK\Downloads\planovac_ACOS_2017.pdf
2017-11-17 11:57 - 2017-11-17 11:57 - 000000000 ____D C:\Windows\System32\Tasks\MEGA
2017-11-16 18:00 - 2017-11-16 18:00 - 000505531 _____ C:\Users\ERIK\Downloads\Strategie_České_republiky_pro_boj_proti_terorismu.pdf
2017-11-13 22:19 - 2017-11-13 23:48 - 000796487 _____ C:\Users\ERIK\Documents\Dynamika.pptx
2017-11-13 20:48 - 2017-11-13 23:42 - 000000000 ____D C:\Users\ERIK\Downloads\Škola
2017-11-13 19:53 - 2017-11-13 19:53 - 001122304 _____ C:\Users\ERIK\Downloads\dynamika.ppt
2017-11-08 20:13 - 2017-11-08 20:13 - 000495501 _____ C:\Users\ERIK\Downloads\VY_32_INOVACE_9_28_radioaktivita.pptx
2017-11-05 22:03 - 2017-11-05 22:23 - 925397297 _____ C:\Users\ERIK\Downloads\ROANE_COUNTY_TN_USA.zip
2017-11-04 22:35 - 2017-11-04 22:52 - 509920765 _____ C:\Users\ERIK\Downloads\DesertHighway.zip
2017-11-04 22:30 - 2017-11-04 22:31 - 046865833 _____ C:\Users\ERIK\Downloads\copsandrobbers.zip
2017-11-04 22:30 - 2017-11-04 22:31 - 016170194 _____ C:\Users\ERIK\Downloads\Hirochi_Super_Race_ryakra.zip
2017-11-04 22:29 - 2017-11-04 22:29 - 010910826 _____ C:\Users\ERIK\Downloads\GhostsParkade.zip
2017-11-04 17:37 - 2017-11-04 17:57 - 000000000 ____D C:\Users\ERIK\Desktop\BMD
2017-11-04 16:46 - 2017-11-04 16:46 - 000005962 _____ C:\Users\ERIK\Downloads\AI.zip
2017-11-04 15:26 - 2017-11-23 19:50 - 000000000 ____D C:\Users\ERIK\Documents\BeamNG.drive
2017-11-04 15:22 - 2017-11-08 16:15 - 000000000 ____D C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BeamNG Drive
2017-11-04 14:34 - 2017-11-04 14:34 - 000020347 _____ C:\Users\ERIK\Downloads\BeamNG Drive.exe.torrent
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-03 12:28 - 2016-10-09 23:26 - 000192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-12-03 12:26 - 2014-08-08 18:05 - 000000000 ____D C:\Users\ERIK\AppData\Local\Adobe
2017-12-03 12:23 - 2014-06-01 16:34 - 000000000 ____D C:\ProgramData\Origin
2017-12-03 12:22 - 2013-12-11 18:40 - 000000000 ____D C:\Users\ERIK\AppData\Roaming\Skype
2017-12-03 12:21 - 2015-07-07 16:28 - 000000000 ____D C:\Users\ERIK\AppData\Local\LogMeIn Hamachi
2017-12-03 12:17 - 2015-05-04 16:50 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2017-12-03 12:17 - 2013-12-10 22:20 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-03 12:17 - 2012-07-26 08:22 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-02 14:57 - 2012-07-26 09:12 - 000000000 ____D C:\Windows\tracing
2017-12-02 14:49 - 2012-07-26 06:37 - 000000000 ____D C:\Windows\Inf
2017-12-01 17:08 - 2017-10-11 18:13 - 127017032 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-12-01 17:08 - 2013-12-10 22:34 - 127017032 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-12-01 17:08 - 2013-12-10 22:34 - 000000000 ____D C:\Windows\system32\MRT
2017-11-30 20:49 - 2016-02-05 13:25 - 000000344 _____ C:\Windows\Tasks\HPCeeScheduleForERIK.job
2017-11-30 19:29 - 2016-11-09 14:08 - 000001350 _____ C:\Users\ERIK\Desktop\Roblox Player.lnk
2017-11-30 19:29 - 2016-10-01 10:51 - 000001169 _____ C:\Users\ERIK\Desktop\Roblox Studio.lnk
2017-11-30 19:29 - 2016-10-01 10:51 - 000000000 ____D C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2017-11-30 17:27 - 2017-07-19 20:29 - 000003156 _____ C:\Windows\System32\Tasks\HPCeeScheduleForERIK
2017-11-30 17:27 - 2013-12-10 21:57 - 000000000 ____D C:\Users\ERIK
2017-11-30 17:23 - 2015-11-01 14:13 - 000000000 ____D C:\Users\ERIK\AppData\Local\MEGAsync
2017-11-29 21:07 - 2016-06-21 10:58 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-11-29 21:06 - 2012-07-26 09:12 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-29 21:06 - 2012-07-26 09:12 - 000000000 ____D C:\Windows\AUInstallAgent
2017-11-28 21:48 - 2012-07-26 06:26 - 000262144 ___SH C:\Windows\system32\config\BBI
2017-11-20 21:32 - 2013-12-10 23:11 - 000545440 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-11-16 17:56 - 2013-12-11 18:59 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-11-16 17:48 - 2016-12-16 21:07 - 000003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-11-16 17:48 - 2016-12-16 21:07 - 000003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-11-15 21:14 - 2016-06-21 10:59 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-11-14 18:29 - 2017-01-14 16:12 - 000004422 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-11-14 18:29 - 2017-01-14 16:12 - 000004288 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-11-14 18:29 - 2012-07-26 09:12 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-11-14 18:29 - 2012-07-26 09:12 - 000000000 ____D C:\Windows\system32\Macromed
2017-11-14 18:26 - 2016-03-26 14:58 - 000123904 ___SH C:\Users\ERIK\Desktop\Thumbs.db
2017-11-14 00:07 - 2016-03-26 15:16 - 000164352 ___SH C:\Users\ERIK\Documents\Thumbs.db
2017-11-13 20:49 - 2014-04-14 20:03 - 010208256 ___SH C:\Users\ERIK\Downloads\Thumbs.db
2017-11-13 17:16 - 2016-10-16 19:10 - 000003402 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2017-11-13 17:16 - 2016-10-16 19:10 - 000003276 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine
2017-11-13 17:16 - 2016-10-16 19:10 - 000000000 ____D C:\Program Files (x86)\Gyazo
2017-11-12 13:16 - 2017-07-10 10:24 - 000000000 ____D C:\Users\ERIK\AppData\Roaming\Apple Computer
2017-11-04 15:41 - 2014-05-31 15:39 - 000000000 ____D C:\Users\ERIK\AppData\Roaming\uTorrent
==================== Files in the root of some directories =======
2014-05-31 13:17 - 2014-05-31 13:17 - 000000000 _____ () C:\Users\ERIK\AppData\Roaming\bitlord_log.txt
2016-08-11 10:48 - 2016-08-11 10:48 - 000138240 _____ () C:\Users\ERIK\AppData\Roaming\Installer.dat
2016-08-11 10:48 - 2016-08-11 10:48 - 000018432 _____ () C:\Users\ERIK\AppData\Roaming\Main.dat
2016-03-25 10:35 - 2016-03-25 10:35 - 000000000 ___SH () C:\Users\ERIK\AppData\Local\LumaEmu
2017-04-24 15:19 - 2017-04-24 15:19 - 000000000 _____ () C:\Users\ERIK\AppData\Local\{0EBB4171-0118-4C9A-9C24-DC0ECE45E6F6}
Some files in TEMP:
====================
2017-07-10 10:24 - 2017-07-10 10:24 - 000010520 _____ () C:\Users\ERIK\AppData\Local\Temp\BullseyeCoverage-x86-3.dll
2014-07-16 09:24 - 2014-07-16 09:24 - 000026936 _____ (TuneUp Software) C:\Users\ERIK\AppData\Local\Temp\DseShExt-x64.dll
2014-07-16 09:24 - 2014-07-16 09:24 - 000028984 _____ (TuneUp Software) C:\Users\ERIK\AppData\Local\Temp\DseShExt-x86.dll
2014-07-16 09:24 - 2014-07-16 09:24 - 000032568 _____ (TuneUp Software) C:\Users\ERIK\AppData\Local\Temp\SDShelEx-win32.dll
2014-07-16 09:24 - 2014-07-16 09:24 - 000032056 _____ (TuneUp Software) C:\Users\ERIK\AppData\Local\Temp\SDShelEx-x64.dll
2017-03-15 20:25 - 2017-03-15 20:25 - 014456872 _____ (Microsoft Corporation) C:\Users\ERIK\AppData\Local\Temp\vc_redist.x86.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\HPCeeScheduleForERIK.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\ERIK\Desktop" je 3138 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================