Prosím o kontrolu FRST logu
Napsal: 19 úno 2018 15:32
Dobrý den, prosím o kontrolu logu. Zdá se mi, že mám spomalený internet (Firefox). Provedl jsem scan přes Malwarebytes a nenalezlo to žádné hrozby.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.02.2018
Ran by mamka (administrator) on LAPTOP-T71UOKM3 (19-02-2018 15:14:45)
Running from C:\Users\mamka\Desktop
Loaded Profiles: mamka (Available Profiles: mamka)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\MsMpEng.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Lenovo) C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(SweetLabs, Inc) C:\Users\mamka\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-07-22] (Intel Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [230104 2015-07-11] (Realtek Semiconductor Corporation)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (Lenovo(beijing) Limited)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [718720 2010-12-21] (Microsoft Corporation)
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{22f10b18-cca7-4290-a9d8-68c657793934}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Internet Explorer:
==================
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: enyhamoj.default
FF ProfilePath: C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\enyhamoj.default [2018-02-19]
FF Homepage: Mozilla\Firefox\Profiles\enyhamoj.default -> seznam.cz
FF Extension: (Adblock Plus) - C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\enyhamoj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-12]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default [2017-10-07]
CHR Extension: (Prezentace Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-08-06]
CHR Extension: (Dokumenty Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-08-06]
CHR Extension: (Disk Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-06]
CHR Extension: (YouTube) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-06]
CHR Extension: (Tabulky Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-08-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-07]
CHR Extension: (Gmail) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-06]
CHR Extension: (Chrome Media Router) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [41176 2015-03-03] (Realtek Semiconductor Corporation)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [120024 2015-07-02] ()
S2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [688992 2017-02-27] (Lenovo)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-12-17] (Macrovision Europe Ltd.) [File not signed]
R2 GDCAgent; C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe [1155512 2015-07-30] (Lenovo)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-07-22] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373680 2017-05-26] (Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [68408 2017-11-12] (Lenovo Group Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271296 2015-08-07] (Lenovo)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [267328 2017-05-16] (Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-21] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-21] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 glavcam; C:\WINDOWS\system32\DRIVERS\glavcam.sys [3476736 2015-10-16] (Windows (R) Codename Longhorn DDK provider)
R1 MpKsldaaf0983; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A3391A5C-BCAF-42BF-AE11-AE840906679C}\MpKsldaaf0983.sys [58120 2018-02-18] (Microsoft Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [607512 2015-07-09] (Realtek Semiconductor Corporation)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\system32\DRIVERS\rtwlane.sys [6813664 2017-05-19] (Realtek Semiconductor Corporation )
S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-01-21] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2018-01-21] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-21] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-19 15:17 - 2018-02-19 15:17 - 067716016 _____ (Malwarebytes ) C:\Users\mamka\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3992.exe.part
2018-02-19 15:17 - 2018-02-19 15:17 - 000000000 _____ C:\Users\mamka\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3992.exe
2018-02-19 15:14 - 2018-02-19 15:16 - 000013204 _____ C:\Users\mamka\Desktop\FRST.txt
2018-02-19 15:14 - 2018-02-19 15:14 - 000000000 ____D C:\FRST
2018-02-19 15:13 - 2018-02-19 15:13 - 002403840 _____ (Farbar) C:\Users\mamka\Desktop\FRST64.exe
2018-02-16 15:42 - 2018-02-16 15:42 - 000136315 _____ C:\Users\mamka\Desktop\Odpočinková Severní Morava v populárním hotelu u zámku Hradec nad Moravicí s wellness neomezeně, masáží a polopenzí - Slevoteka.cz.html
2018-02-16 15:42 - 2018-02-16 15:42 - 000000000 ____D C:\Users\mamka\Desktop\Odpočinková Severní Morava v populárním hotelu u zámku Hradec nad Moravicí s wellness neomezeně, masáží a polopenzí - Slevoteka.cz_soubory
2018-02-16 14:07 - 2018-02-16 14:07 - 000349735 _____ C:\Users\mamka\Desktop\Romantický pobyt s neomezeným wellness a masáží Slevomat.cz.html
2018-02-16 14:07 - 2018-02-16 14:07 - 000000000 ____D C:\Users\mamka\Desktop\Romantický pobyt s neomezeným wellness a masáží Slevomat.cz_soubory
2018-02-07 13:19 - 2018-02-07 13:19 - 000002252 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2018-02-07 13:19 - 2018-02-07 13:19 - 000002214 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2018-02-07 13:19 - 2018-02-07 13:19 - 000000000 ____D C:\Program Files\Google
2018-02-05 06:57 - 2018-02-18 12:26 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-02-05 06:57 - 2018-02-06 03:49 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-02-05 06:57 - 2018-02-06 03:49 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-31 16:04 - 2018-01-31 16:04 - 000093839 _____ C:\Users\mamka\Desktop\zrcadleni.php
2018-01-28 13:34 - 2018-01-28 13:34 - 000365258 _____ C:\Users\mamka\Desktop\Wellness pobyt v Trenčianských Teplicích _ Slevomat.cz.html
2018-01-28 13:34 - 2018-01-28 13:34 - 000000000 ____D C:\Users\mamka\Desktop\Wellness pobyt v Trenčianských Teplicích _ Slevomat.cz_soubory
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-19 14:49 - 2016-12-26 09:20 - 000704037 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2018-02-19 14:47 - 2016-12-17 12:41 - 000000000 ____D C:\Users\mamka\AppData\Roaming\Skype
2018-02-19 14:46 - 2016-11-19 09:30 - 000000000 ____D C:\Users\mamka\AppData\Local\Host App Service
2018-02-19 14:44 - 2016-12-17 12:48 - 000000000 ____D C:\Users\mamka\AppData\LocalLow\Mozilla
2018-02-19 14:43 - 2017-07-20 16:35 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-02-19 14:43 - 2016-11-19 09:31 - 000000000 __SHD C:\Users\mamka\IntelGraphicsProfiles
2018-02-18 20:36 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-02-18 13:16 - 2017-12-24 21:54 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-02-18 10:56 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-18 10:56 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-02-14 20:00 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\rescache
2018-02-14 19:38 - 2017-01-16 20:16 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-02-14 19:34 - 2017-10-11 13:58 - 130067560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-02-14 19:34 - 2017-01-16 20:15 - 130067560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-02-13 21:40 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-02-13 21:07 - 2017-12-24 22:15 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-147898541-2157023476-1376344096-1001
2018-02-13 21:07 - 2017-01-28 09:44 - 000002394 _____ C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-02-13 21:07 - 2016-11-19 09:35 - 000000000 ___RD C:\Users\mamka\OneDrive
2018-02-12 16:29 - 2016-12-17 12:43 - 000001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-12 16:29 - 2016-12-17 12:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-02-12 16:28 - 2016-12-17 12:42 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-02-06 11:33 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF
2018-02-06 11:32 - 2017-08-06 14:31 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-05 07:03 - 2017-12-24 22:12 - 001843520 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-02-05 07:03 - 2017-09-30 15:31 - 000786218 _____ C:\WINDOWS\system32\perfh005.dat
2018-02-05 07:03 - 2017-09-30 15:31 - 000161160 _____ C:\WINDOWS\system32\perfc005.dat
2018-02-05 06:58 - 2017-12-24 22:17 - 000000000 ___RD C:\Users\mamka\3D Objects
2018-02-05 06:58 - 2016-11-21 05:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-02-05 06:56 - 2017-12-24 22:15 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-02-05 06:56 - 2017-12-24 21:54 - 000248184 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-02-05 06:55 - 2017-09-29 09:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-02-05 06:54 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-02-05 06:54 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-02-05 06:54 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-02-05 06:53 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-24 19:25 - 2016-12-26 09:18 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2016-11-19 09:31 - 2018-02-19 14:44 - 002627291 _____ () C:\Users\mamka\AppData\Local\BTServer.log
Some files in TEMP:
====================
2018-02-14 19:38 - 2018-02-14 19:38 - 021730672 _____ (SweetLabs,Inc.) C:\Users\mamka\AppData\Local\Temp\octF7D0.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-02-18 12:26
==================== End of FRST.txt ============================
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.02.2018
Ran by mamka (administrator) on LAPTOP-T71UOKM3 (19-02-2018 15:14:45)
Running from C:\Users\mamka\Desktop
Loaded Profiles: mamka (Available Profiles: mamka)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\MsMpEng.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Lenovo) C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe
(Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(SweetLabs, Inc) C:\Users\mamka\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-07-22] (Intel Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [230104 2015-07-11] (Realtek Semiconductor Corporation)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (Lenovo(beijing) Limited)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [718720 2010-12-21] (Microsoft Corporation)
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{22f10b18-cca7-4290-a9d8-68c657793934}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Internet Explorer:
==================
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
HKU\S-1-5-21-147898541-2157023476-1376344096-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: enyhamoj.default
FF ProfilePath: C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\enyhamoj.default [2018-02-19]
FF Homepage: Mozilla\Firefox\Profiles\enyhamoj.default -> seznam.cz
FF Extension: (Adblock Plus) - C:\Users\mamka\AppData\Roaming\Mozilla\Firefox\Profiles\enyhamoj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-12]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default [2017-10-07]
CHR Extension: (Prezentace Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-08-06]
CHR Extension: (Dokumenty Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-08-06]
CHR Extension: (Disk Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-06]
CHR Extension: (YouTube) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-06]
CHR Extension: (Tabulky Google) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-08-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-07]
CHR Extension: (Gmail) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-06]
CHR Extension: (Chrome Media Router) - C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [41176 2015-03-03] (Realtek Semiconductor Corporation)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [120024 2015-07-02] ()
S2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [688992 2017-02-27] (Lenovo)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-12-17] (Macrovision Europe Ltd.) [File not signed]
R2 GDCAgent; C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe [1155512 2015-07-30] (Lenovo)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-07-22] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373680 2017-05-26] (Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [68408 2017-11-12] (Lenovo Group Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271296 2015-08-07] (Lenovo)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [267328 2017-05-16] (Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-21] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-21] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 glavcam; C:\WINDOWS\system32\DRIVERS\glavcam.sys [3476736 2015-10-16] (Windows (R) Codename Longhorn DDK provider)
R1 MpKsldaaf0983; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A3391A5C-BCAF-42BF-AE11-AE840906679C}\MpKsldaaf0983.sys [58120 2018-02-18] (Microsoft Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [607512 2015-07-09] (Realtek Semiconductor Corporation)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\system32\DRIVERS\rtwlane.sys [6813664 2017-05-19] (Realtek Semiconductor Corporation )
S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-01-21] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2018-01-21] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-21] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-19 15:17 - 2018-02-19 15:17 - 067716016 _____ (Malwarebytes ) C:\Users\mamka\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3992.exe.part
2018-02-19 15:17 - 2018-02-19 15:17 - 000000000 _____ C:\Users\mamka\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3992.exe
2018-02-19 15:14 - 2018-02-19 15:16 - 000013204 _____ C:\Users\mamka\Desktop\FRST.txt
2018-02-19 15:14 - 2018-02-19 15:14 - 000000000 ____D C:\FRST
2018-02-19 15:13 - 2018-02-19 15:13 - 002403840 _____ (Farbar) C:\Users\mamka\Desktop\FRST64.exe
2018-02-16 15:42 - 2018-02-16 15:42 - 000136315 _____ C:\Users\mamka\Desktop\Odpočinková Severní Morava v populárním hotelu u zámku Hradec nad Moravicí s wellness neomezeně, masáží a polopenzí - Slevoteka.cz.html
2018-02-16 15:42 - 2018-02-16 15:42 - 000000000 ____D C:\Users\mamka\Desktop\Odpočinková Severní Morava v populárním hotelu u zámku Hradec nad Moravicí s wellness neomezeně, masáží a polopenzí - Slevoteka.cz_soubory
2018-02-16 14:07 - 2018-02-16 14:07 - 000349735 _____ C:\Users\mamka\Desktop\Romantický pobyt s neomezeným wellness a masáží Slevomat.cz.html
2018-02-16 14:07 - 2018-02-16 14:07 - 000000000 ____D C:\Users\mamka\Desktop\Romantický pobyt s neomezeným wellness a masáží Slevomat.cz_soubory
2018-02-07 13:19 - 2018-02-07 13:19 - 000002252 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2018-02-07 13:19 - 2018-02-07 13:19 - 000002214 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2018-02-07 13:19 - 2018-02-07 13:19 - 000000000 ____D C:\Program Files\Google
2018-02-05 06:57 - 2018-02-18 12:26 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-02-05 06:57 - 2018-02-06 03:49 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-02-05 06:57 - 2018-02-06 03:49 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-31 16:04 - 2018-01-31 16:04 - 000093839 _____ C:\Users\mamka\Desktop\zrcadleni.php
2018-01-28 13:34 - 2018-01-28 13:34 - 000365258 _____ C:\Users\mamka\Desktop\Wellness pobyt v Trenčianských Teplicích _ Slevomat.cz.html
2018-01-28 13:34 - 2018-01-28 13:34 - 000000000 ____D C:\Users\mamka\Desktop\Wellness pobyt v Trenčianských Teplicích _ Slevomat.cz_soubory
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-02-19 14:49 - 2016-12-26 09:20 - 000704037 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2018-02-19 14:47 - 2016-12-17 12:41 - 000000000 ____D C:\Users\mamka\AppData\Roaming\Skype
2018-02-19 14:46 - 2016-11-19 09:30 - 000000000 ____D C:\Users\mamka\AppData\Local\Host App Service
2018-02-19 14:44 - 2016-12-17 12:48 - 000000000 ____D C:\Users\mamka\AppData\LocalLow\Mozilla
2018-02-19 14:43 - 2017-07-20 16:35 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-02-19 14:43 - 2016-11-19 09:31 - 000000000 __SHD C:\Users\mamka\IntelGraphicsProfiles
2018-02-18 20:36 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-02-18 13:16 - 2017-12-24 21:54 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-02-18 10:56 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-18 10:56 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-02-14 20:00 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\rescache
2018-02-14 19:38 - 2017-01-16 20:16 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-02-14 19:34 - 2017-10-11 13:58 - 130067560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-02-14 19:34 - 2017-01-16 20:15 - 130067560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-02-13 21:40 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-02-13 21:07 - 2017-12-24 22:15 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-147898541-2157023476-1376344096-1001
2018-02-13 21:07 - 2017-01-28 09:44 - 000002394 _____ C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-02-13 21:07 - 2016-11-19 09:35 - 000000000 ___RD C:\Users\mamka\OneDrive
2018-02-12 16:29 - 2016-12-17 12:43 - 000001235 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-12 16:29 - 2016-12-17 12:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-02-12 16:28 - 2016-12-17 12:42 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-02-06 11:33 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF
2018-02-06 11:32 - 2017-08-06 14:31 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-05 07:03 - 2017-12-24 22:12 - 001843520 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-02-05 07:03 - 2017-09-30 15:31 - 000786218 _____ C:\WINDOWS\system32\perfh005.dat
2018-02-05 07:03 - 2017-09-30 15:31 - 000161160 _____ C:\WINDOWS\system32\perfc005.dat
2018-02-05 06:58 - 2017-12-24 22:17 - 000000000 ___RD C:\Users\mamka\3D Objects
2018-02-05 06:58 - 2016-11-21 05:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-02-05 06:56 - 2017-12-24 22:15 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-02-05 06:56 - 2017-12-24 21:54 - 000248184 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-02-05 06:55 - 2017-09-29 09:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-02-05 06:54 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-02-05 06:54 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-02-05 06:54 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-02-05 06:53 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-02-05 06:53 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-24 19:25 - 2016-12-26 09:18 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2016-11-19 09:31 - 2018-02-19 14:44 - 002627291 _____ () C:\Users\mamka\AppData\Local\BTServer.log
Some files in TEMP:
====================
2018-02-14 19:38 - 2018-02-14 19:38 - 021730672 _____ (SweetLabs,Inc.) C:\Users\mamka\AppData\Local\Temp\octF7D0.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-02-18 12:26
==================== End of FRST.txt ============================