Problém s vytížením procesoru
Napsal: 06 dub 2018 18:51
Dobrý den
Mám problém že PC se po chvíli začne sekat ale ve správci je vytížení max. 50%
Mám podezření na úlohu conhost64
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Michal (administrator) on MICHAL4-PC (06-04-2018 19:46:07)
Running from C:\Users\Michal\Desktop
Loaded Profiles: Michal (Available Profiles: Michal)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Michal\Desktop\fixer.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [VX1000] => C:\Windows\vVX1000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [245608 2018-04-01] (AVAST Software)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\Run: [Google Update] => C:\Users\Michal\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-22] (Google Inc.)
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\Run: [Discord] => C:\Users\Michal\AppData\Local\Discord\app-0.0.300\Discord.exe [57821176 2018-01-08] (Discord Inc.)
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\MountPoints2: H - H:\Run.exe
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\MountPoints2: {6f7f6058-cfad-11e7-87c0-806e6f6e6963} - H:\DVDSetup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
CHR HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [26512 2014-06-06] (National Instruments Corporation)
Winsock: Catalog5-x64 07 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560 2014-06-06] (National Instruments Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{28EC8637-C771-4994-A0E7-7192A70601B0}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{636F8775-17D3-41FA-AC94-BB9613DC8870}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Internet Explorer:
==================
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180216__ya[browser]
SearchScopes: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2 ... -SearchBox
SearchScopes: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2 ... -SearchBox
SearchScopes: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180216__yaie&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-04-01] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-08-18] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-04-01] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-18] (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FireFox:
========
FF ProfilePath: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default [2018-04-02]
FF Homepage: Mozilla\Firefox\Profiles\niwzqn96.default -> hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180216__yaff
FF NewTab: Mozilla\Firefox\Profiles\niwzqn96.default -> hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180216__yaff
FF Extension: (Seznam pro Firefox - Esko) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\Extensions\sko-extension@firma.seznam.cz [2017-11-22]
FF Extension: (Avast SafePrice) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\Extensions\sp@avast.com.xpi [2017-12-21]
FF Extension: (Avast Online Security) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\Extensions\wrc@avast.com.xpi [2017-12-21]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\searchplugins\yahoo-lavasoft-ff59.xml [2018-03-30]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-21] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-21] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-08-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-08-18] (Oracle Corporation)
FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-11-28] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-11-28] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @nsroblox.roblox.com/launcher -> C:\Users\Michal\AppData\Local\Roblox\Versions\version-6a65e85da5fe4a75\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Michal\AppData\Local\Roblox\Versions\version-6a65e85da5fe4a75\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Michal\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Michal\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Michal\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-23] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxps://www.google.cz/","hxxps://www.seznam.cz/?clid=22668"
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default [2018-04-06]
CHR Extension: (Dokumenty) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-29]
CHR Extension: (Disk Google) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Battlefield Heroes) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2014-04-07]
CHR Extension: (Vyhledávání Google) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (ThemeBeta.com) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fggppdbjphfgaoeldicclbmjbabahobf [2018-01-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Total War:Warhammer II HD Wallpapers New Tab) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\olgejodgefbhglpajdcokioooeioimaa [2017-12-29]
CHR Extension: (Gmail) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR Extension: (Chrome Media Router) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-25]
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-02-24]
CHR Extension: (Dokumenty) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Seznam pro Chrome - Email) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2017-12-19]
CHR Extension: (Tampermonkey) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-02-24]
CHR Extension: (ScriptGate) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie [2018-02-24]
CHR Extension: (ThemeBeta.com) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fggppdbjphfgaoeldicclbmjbabahobf [2017-04-17]
CHR Extension: (Heroes & Generals) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2016-09-19]
CHR Extension: (Dokumenty Google offline) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Chrome Media Router) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-24]
CHR HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.K36U5SE2WG5CP2UXMT23R4EU64 - C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
Opera:
=======
OPR Extension: (Tampermonkey) - C:\Users\Michal\AppData\Roaming\Opera Software\Opera Stable\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-02-24]
OPR Extension: (ScriptGate) - C:\Users\Michal\AppData\Roaming\Opera Software\Opera Stable\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie [2018-02-24]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7556704 2018-04-01] (AVAST Software)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [303728 2018-04-01] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [5708808 2018-03-29] ()
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-03-08] (EasyAntiCheat Ltd)
S2 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-08-24] ()
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8077376 2017-06-06] (GOG.com)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3418024 2017-06-29] (LogMeIn Inc.)
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-07-12] (Hi-Rez Studios) [File not signed]
S2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2015-06-05] (National Instruments, Inc.)
S2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [50200 2016-06-08] (National Instruments Corporation)
S2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [60440 2016-06-08] (National Instruments Corporation)
S2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
S3 mracsvc; C:\Windows\System32\mracsvc.exe [7409368 2018-01-01] (LLC Mail.Ru)
S2 NIApplicationWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [65096 2016-05-31] (National Instruments Corporation)
S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [83528 2016-05-31] (National Instruments Corporation)
S2 niauth; C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe [594984 2016-05-27] (National Instruments Corporation)
S2 NIDomainService; C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe [394264 2016-06-08] (National Instruments Corporation)
S3 NILM License Manager; C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation)
S2 nimDNSResponder; C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [320368 2014-06-06] (National Instruments Corporation)
S2 NiSvcLoc; C:\Program Files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exe [102512 2016-05-19] (National Instruments Corporation)
S2 NISystemWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [65080 2016-05-31] (National Instruments Corporation)
S2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2016-08-30] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1453384 2018-04-02] (Overwolf LTD)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-09-30] ()
S2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AIDA64Driver; C:\Users\Michal\Desktop\Nepoužívané\AIDA64 Extreme 595\kerneld.x64 [45696 2017-11-26] ()
S2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
S1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [196648 2018-04-01] (AVAST Software)
S1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [227504 2018-04-01] (AVAST Software)
S0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199440 2018-04-01] (AVAST Software)
S0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343752 2018-04-01] (AVAST Software)
S0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57680 2018-04-01] (AVAST Software)
S1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [215320 2018-04-01] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-04-01] (AVAST Software)
S2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146656 2018-04-01] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-04-01] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-04-01] (AVAST Software)
S1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-04-01] (AVAST Software)
S1 aswSP; C:\Windows\System32\drivers\aswSP.sys [460520 2018-04-01] (AVAST Software)
S2 aswStm; C:\Windows\System32\drivers\aswStm.sys [205976 2018-04-01] (AVAST Software)
S0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [380528 2018-04-01] (AVAST Software)
S3 CX88VID; C:\Windows\System32\drivers\cxavsvid.sys [469248 2007-09-19] (Leadtek Research Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-25] (Disc Soft Ltd)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [6637344 2018-01-01] (LLC Mail.Ru)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31168 2018-03-14] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2017-12-15] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-11-28] (NVIDIA Corporation)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 NTIOLib_1_0_C; \??\H:\NTIOLib_X64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-06 19:37 - 2018-04-06 19:37 - 000406952 _____ C:\Windows\Minidump\040618-11934-01.dmp
2018-04-06 19:03 - 2018-04-06 19:37 - 000369938 _____ C:\Windows\ntbtlog.txt
2018-04-06 19:03 - 2018-04-06 19:03 - 000406992 _____ C:\Windows\Minidump\040618-15116-01.dmp
2018-04-06 18:33 - 2018-04-06 18:33 - 000407000 _____ C:\Windows\Minidump\040618-12558-01.dmp
2018-04-06 18:17 - 2018-04-06 18:17 - 000406944 _____ C:\Windows\Minidump\040618-12604-01.dmp
2018-04-05 18:19 - 2018-04-06 19:11 - 000000000 ____D C:\AdwCleaner
2018-04-05 18:19 - 2018-04-05 18:19 - 008222496 _____ (Malwarebytes) C:\Users\Michal\Downloads\adwcleaner_7.0.8.0.exe
2018-04-05 18:18 - 2018-04-06 18:19 - 000002815 _____ C:\Users\Michal\Desktop\Fixlog.txt
2018-04-05 18:15 - 2018-04-05 18:15 - 000406992 _____ C:\Windows\Minidump\040518-15927-01.dmp
2018-04-05 18:09 - 2018-04-06 19:14 - 000000000 ___HD C:\Users\Michal\AppData\Local\Canon
2018-04-02 21:01 - 2018-04-02 21:01 - 000083698 _____ C:\Users\Michal\Downloads\Addition.txt
2018-04-02 21:00 - 2018-04-06 19:46 - 000023336 _____ C:\Users\Michal\Desktop\FRST.txt
2018-04-02 21:00 - 2018-04-06 19:46 - 000000000 ____D C:\FRST
2018-04-02 20:59 - 2018-04-02 20:59 - 002403328 _____ (Farbar) C:\Users\Michal\Desktop\fixer.exe
2018-04-02 20:56 - 2018-04-02 20:56 - 000001083 _____ C:\Users\Michal\fixlist.txt
2018-04-02 20:43 - 2018-04-02 20:43 - 000407072 _____ C:\Windows\Minidump\040218-14289-01.dmp
2018-04-01 19:19 - 2018-04-02 20:32 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-04-01 19:19 - 2018-04-01 19:13 - 000380768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-04-01 19:18 - 2018-04-01 19:18 - 000007609 _____ C:\Users\Michal\AppData\Local\Resmon.ResmonCfg
2018-04-01 19:15 - 2018-04-01 19:15 - 000406624 _____ C:\Windows\Minidump\040118-18127-01.dmp
2018-04-01 18:47 - 2018-04-01 18:47 - 000407064 _____ C:\Windows\Minidump\040118-16489-01.dmp
2018-04-01 18:03 - 2018-04-01 18:03 - 000000000 ____D C:\ProgramData\SWCUTemp
2018-03-31 21:39 - 2018-03-31 21:39 - 000407008 _____ C:\Windows\Minidump\033118-14710-01.dmp
2018-03-30 18:04 - 2018-04-06 19:14 - 000153088 _____ C:\Windows\SysWOW64\conhost64.exe
2018-03-30 18:04 - 2018-04-03 18:05 - 000000000 ___HD C:\Users\Michal\AppData\Local\BitTorrent
2018-03-29 18:32 - 2018-03-29 18:32 - 000000000 __SHD C:\82ace7d6-0197-474d-bf4b-a2043e72329b
2018-03-29 09:06 - 2018-03-29 09:06 - 000000000 ___HD C:\Users\Michal\AppData\Local\EDBase64
2018-03-27 18:04 - 2018-03-28 18:08 - 000000000 ___HD C:\Users\Michal\AppData\Local\ActiveX
2018-03-23 19:02 - 2018-03-26 18:07 - 000000000 ___HD C:\Users\Michal\AppData\Local\Minidump
2018-03-20 19:05 - 2018-04-02 20:32 - 000003922 _____ C:\Windows\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-03-20 19:03 - 2017-12-15 04:03 - 000059240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2018-03-16 18:55 - 2018-03-22 19:06 - 000000000 ___HD C:\Users\Michal\AppData\Local\StdVCL
2018-03-10 20:03 - 2018-03-10 20:03 - 000000227 _____ C:\Users\Michal\Desktop\Total War SHOGUN 2.url
2018-03-08 19:28 - 2018-03-08 19:28 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-06 19:37 - 2018-02-26 17:08 - 725192353 _____ C:\Windows\MEMORY.DMP
2018-04-06 19:37 - 2013-12-29 15:54 - 000000000 ____D C:\Windows\Minidump
2018-04-06 19:35 - 2017-10-16 18:04 - 000000000 ____D C:\Users\Michal\AppData\Local\LogMeIn Hamachi
2018-04-06 19:34 - 2018-01-16 20:29 - 000000000 ____D C:\Users\Michal\AppData\Local\CrashDumps
2018-04-06 19:19 - 2016-05-21 09:31 - 000000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2018-04-06 19:14 - 2009-07-14 06:45 - 000014416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-06 19:14 - 2009-07-14 06:45 - 000014416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-06 19:09 - 2018-01-09 18:23 - 000000000 ____D C:\ProgramData\NVIDIA
2018-04-06 19:06 - 2017-11-23 06:32 - 000025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2018-04-06 19:06 - 2016-11-04 19:50 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-04-06 19:06 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-06 18:35 - 2016-12-19 19:13 - 000000000 ____D C:\Users\Michal\AppData\Roaming\discord
2018-04-04 20:13 - 2015-12-19 20:12 - 000000000 ____D C:\Program Files (x86)\Overwolf
2018-04-02 20:56 - 2013-12-25 14:37 - 000000000 ____D C:\Users\Michal
2018-04-02 20:41 - 2017-08-14 16:39 - 000000000 ____D C:\Users\Michal\AppData\LocalLow\Mozilla
2018-04-02 20:32 - 2018-02-24 19:07 - 000003640 _____ C:\Windows\System32\Tasks\{58BB0C33-30DC-4268-879C-9EDDF9458B86}
2018-04-02 20:32 - 2018-02-24 19:07 - 000003386 _____ C:\Windows\System32\Tasks\{99DA1DDE-97B7-468E-971A-A0A361E3C9CF}
2018-04-02 20:32 - 2018-02-16 07:04 - 000004078 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1518757467
2018-04-02 20:32 - 2018-01-09 18:52 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2017-12-21 12:39 - 000003298 _____ C:\Windows\System32\Tasks\{4F9E8B89-9D00-4155-A8A4-C6E0A03CA34F}
2018-04-02 20:32 - 2017-11-23 17:51 - 000003272 _____ C:\Windows\System32\Tasks\AMD ThankingURL
2018-04-02 20:32 - 2017-11-23 17:47 - 000003146 _____ C:\Windows\System32\Tasks\StartCN
2018-04-02 20:32 - 2017-10-15 18:23 - 000003538 _____ C:\Windows\System32\Tasks\NIUpdateServiceCheckTask
2018-04-02 20:32 - 2017-10-15 18:23 - 000003246 _____ C:\Windows\System32\Tasks\NIUpdateServiceStartupTask
2018-04-02 20:32 - 2016-05-21 09:31 - 000003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-04-02 20:32 - 2016-04-12 19:06 - 000002968 _____ C:\Windows\System32\Tasks\{8C556DD4-519E-49E0-B27B-212B64855FE3}
2018-04-02 20:32 - 2016-04-12 19:06 - 000002968 _____ C:\Windows\System32\Tasks\{52B4ACE8-8377-4CC4-B302-F34114473B96}
2018-04-02 20:32 - 2016-04-12 19:06 - 000002968 _____ C:\Windows\System32\Tasks\{392509CC-228F-4620-AB2A-3AAEF05517C4}
2018-04-02 20:32 - 2015-12-19 20:13 - 000003728 _____ C:\Windows\System32\Tasks\Overwolf Updater Task
2018-04-02 20:32 - 2015-04-13 14:07 - 000003118 _____ C:\Windows\System32\Tasks\{BEB96816-A0B9-4F81-9589-F3CF7FC9A45E}
2018-04-02 20:32 - 2015-04-01 17:21 - 000003060 _____ C:\Windows\System32\Tasks\{BF6E1418-AFF1-429D-86AA-B6070689D8EA}
2018-04-02 20:32 - 2014-08-16 19:42 - 000002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-04-02 20:32 - 2014-03-24 15:17 - 000003126 _____ C:\Windows\System32\Tasks\{FFA5BCE1-7580-48C4-994F-FA0BF62D1BD5}
2018-04-02 20:32 - 2014-03-24 15:17 - 000003120 _____ C:\Windows\System32\Tasks\{4BB52DC7-10C3-40A1-89D2-DD1B0A4A770B}
2018-04-02 20:32 - 2014-03-19 08:41 - 000003292 _____ C:\Windows\System32\Tasks\{1126949E-9FFF-454B-952F-C4D437453BF6}
2018-04-02 20:32 - 2013-12-25 15:41 - 000003564 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4203263230-2635384760-1339063134-1001UA
2018-04-02 20:32 - 2013-12-25 15:41 - 000003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4203263230-2635384760-1339063134-1001Core
2018-04-01 19:19 - 2017-08-15 18:10 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2018-04-01 19:19 - 2014-08-16 19:41 - 000000000 ____D C:\Program Files\CCleaner
2018-04-01 19:13 - 2017-12-21 19:11 - 000196648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-04-01 19:13 - 2017-11-22 20:00 - 000215320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000343752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000227504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000199440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000057680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2018-04-01 19:13 - 2014-08-09 18:27 - 000205976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-04-01 19:13 - 2014-08-09 18:27 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000460520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000380528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000146656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000110328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-04-01 19:09 - 2009-07-14 07:08 - 000032570 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-01 19:01 - 2018-03-05 19:08 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wargaming.net
2018-04-01 18:40 - 2018-01-22 19:08 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Battlerite
2018-03-30 21:38 - 2015-05-30 17:44 - 000000000 ____D C:\Users\Michal\AppData\Local\Battle.net
2018-03-30 21:38 - 2015-05-30 17:44 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-03-28 23:02 - 2018-02-14 19:20 - 000000999 _____ C:\Users\Michal\Desktop\The book of Grudges.txt
2018-03-27 17:59 - 2018-03-05 19:09 - 000000000 ____D C:\ProgramData\boost_interprocess
2018-03-23 19:17 - 2013-12-25 15:43 - 000002428 _____ C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-23 19:17 - 2013-12-25 15:43 - 000002391 _____ C:\Users\Michal\Desktop\Google Chrome.lnk
2018-03-21 18:59 - 2017-06-15 05:51 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-03-20 19:06 - 2018-01-09 18:25 - 000001416 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2018-03-20 19:06 - 2018-01-09 18:23 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-03-20 19:06 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-03-20 19:04 - 2018-01-09 18:17 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-03-14 15:05 - 2018-01-09 18:25 - 002480064 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2018-03-14 15:05 - 2018-01-09 18:25 - 002137024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2018-03-14 15:05 - 2018-01-09 18:25 - 001310144 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2018-03-14 14:44 - 2018-01-09 18:25 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-03-11 19:08 - 2018-03-05 19:09 - 000000000 ___HD C:\Users\Michal\AppData\Local\TabCntrl
==================== Files in the root of some directories =======
2015-12-22 09:08 - 2018-02-24 18:32 - 000000079 _____ () C:\Users\Michal\AppData\Local\CrystalDiskMark30.ini
2013-12-26 12:30 - 2013-12-26 12:30 - 000003584 _____ () C:\Users\Michal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-07-14 03:14 - 2009-07-14 03:14 - 000073216 ____N (Microsoft Corporation) C:\Users\Michal\AppData\Local\fEchOJYBVfD.exe
2013-12-26 16:30 - 2013-12-26 16:30 - 000000000 ___SH () C:\Users\Michal\AppData\Local\LumaEmu
2018-04-01 19:18 - 2018-04-01 19:18 - 000007609 _____ () C:\Users\Michal\AppData\Local\Resmon.ResmonCfg
2018-02-24 19:07 - 2018-02-24 19:07 - 000000002 _____ () C:\Users\Michal\AppData\Local\WMI.ini
Some files in TEMP:
====================
2018-02-23 19:07 - 2018-02-23 19:07 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018223713779.dll
2018-02-23 19:09 - 2018-02-23 19:09 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018223946131.dll
2018-02-24 20:14 - 2018-02-24 20:14 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182241410659.dll
2018-02-24 17:14 - 2018-02-24 17:14 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018224145453.dll
2018-02-24 18:29 - 2018-02-24 18:29 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182242910633.dll
2018-02-24 20:48 - 2018-02-24 20:48 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182244839795.dll
2018-02-24 18:51 - 2018-02-24 18:51 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245118362.dll
2018-02-24 21:52 - 2018-02-24 21:52 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245251785.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245446445.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245446499.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245446761.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245447852.dll
2018-02-24 17:08 - 2018-02-24 17:08 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018224825613.dll
Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\lastpass_1337.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-02-16 13:22
==================== End of FRST.txt ============================
Mám problém že PC se po chvíli začne sekat ale ve správci je vytížení max. 50%
Mám podezření na úlohu conhost64
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by Michal (administrator) on MICHAL4-PC (06-04-2018 19:46:07)
Running from C:\Users\Michal\Desktop
Loaded Profiles: Michal (Available Profiles: Michal)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Michal\Desktop\fixer.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8497368 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [VX1000] => C:\Windows\vVX1000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [245608 2018-04-01] (AVAST Software)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\Run: [Google Update] => C:\Users\Michal\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-22] (Google Inc.)
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\Run: [Discord] => C:\Users\Michal\AppData\Local\Discord\app-0.0.300\Discord.exe [57821176 2018-01-08] (Discord Inc.)
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\MountPoints2: H - H:\Run.exe
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\...\MountPoints2: {6f7f6058-cfad-11e7-87c0-806e6f6e6963} - H:\DVDSetup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
CHR HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [26512 2014-06-06] (National Instruments Corporation)
Winsock: Catalog5-x64 07 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560 2014-06-06] (National Instruments Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{28EC8637-C771-4994-A0E7-7192A70601B0}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{636F8775-17D3-41FA-AC94-BB9613DC8870}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Internet Explorer:
==================
HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180216__ya[browser]
SearchScopes: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2 ... -SearchBox
SearchScopes: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2 ... -SearchBox
SearchScopes: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180216__yaie&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-04-01] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-08-18] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-04-01] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-18] (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKU\S-1-5-21-4203263230-2635384760-1339063134-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FireFox:
========
FF ProfilePath: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default [2018-04-02]
FF Homepage: Mozilla\Firefox\Profiles\niwzqn96.default -> hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180216__yaff
FF NewTab: Mozilla\Firefox\Profiles\niwzqn96.default -> hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180216__yaff
FF Extension: (Seznam pro Firefox - Esko) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\Extensions\sko-extension@firma.seznam.cz [2017-11-22]
FF Extension: (Avast SafePrice) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\Extensions\sp@avast.com.xpi [2017-12-21]
FF Extension: (Avast Online Security) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\Extensions\wrc@avast.com.xpi [2017-12-21]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\niwzqn96.default\searchplugins\yahoo-lavasoft-ff59.xml [2018-03-30]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-21] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-21] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-08-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-08-18] (Oracle Corporation)
FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-11-28] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-11-28] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @nsroblox.roblox.com/launcher -> C:\Users\Michal\AppData\Local\Roblox\Versions\version-6a65e85da5fe4a75\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Michal\AppData\Local\Roblox\Versions\version-6a65e85da5fe4a75\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Michal\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Michal\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-22] (Google Inc.)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Michal\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-23] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-4203263230-2635384760-1339063134-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxps://www.google.cz/","hxxps://www.seznam.cz/?clid=22668"
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default [2018-04-06]
CHR Extension: (Dokumenty) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-29]
CHR Extension: (Disk Google) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Battlefield Heroes) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2014-04-07]
CHR Extension: (Vyhledávání Google) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (ThemeBeta.com) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fggppdbjphfgaoeldicclbmjbabahobf [2018-01-06]
CHR Extension: (Dokumenty Google offline) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Total War:Warhammer II HD Wallpapers New Tab) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\olgejodgefbhglpajdcokioooeioimaa [2017-12-29]
CHR Extension: (Gmail) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR Extension: (Chrome Media Router) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-25]
CHR Profile: C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-02-24]
CHR Extension: (Dokumenty) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Seznam pro Chrome - Email) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2017-12-19]
CHR Extension: (Tampermonkey) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-02-24]
CHR Extension: (ScriptGate) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie [2018-02-24]
CHR Extension: (ThemeBeta.com) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fggppdbjphfgaoeldicclbmjbabahobf [2017-04-17]
CHR Extension: (Heroes & Generals) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2016-09-19]
CHR Extension: (Dokumenty Google offline) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Chrome Media Router) - C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-24]
CHR HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4203263230-2635384760-1339063134-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.K36U5SE2WG5CP2UXMT23R4EU64 - C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
Opera:
=======
OPR Extension: (Tampermonkey) - C:\Users\Michal\AppData\Roaming\Opera Software\Opera Stable\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-02-24]
OPR Extension: (ScriptGate) - C:\Users\Michal\AppData\Roaming\Opera Software\Opera Stable\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie [2018-02-24]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7556704 2018-04-01] (AVAST Software)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [303728 2018-04-01] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [5708808 2018-03-29] ()
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-03-08] (EasyAntiCheat Ltd)
S2 ES lite Service; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [68136 2009-08-24] ()
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8077376 2017-06-06] (GOG.com)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3418024 2017-06-29] (LogMeIn Inc.)
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-07-12] (Hi-Rez Studios) [File not signed]
S2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2015-06-05] (National Instruments, Inc.)
S2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [50200 2016-06-08] (National Instruments Corporation)
S2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [60440 2016-06-08] (National Instruments Corporation)
S2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
S3 mracsvc; C:\Windows\System32\mracsvc.exe [7409368 2018-01-01] (LLC Mail.Ru)
S2 NIApplicationWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [65096 2016-05-31] (National Instruments Corporation)
S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [83528 2016-05-31] (National Instruments Corporation)
S2 niauth; C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe [594984 2016-05-27] (National Instruments Corporation)
S2 NIDomainService; C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe [394264 2016-06-08] (National Instruments Corporation)
S3 NILM License Manager; C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation)
S2 nimDNSResponder; C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [320368 2014-06-06] (National Instruments Corporation)
S2 NiSvcLoc; C:\Program Files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exe [102512 2016-05-19] (National Instruments Corporation)
S2 NISystemWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [65080 2016-05-31] (National Instruments Corporation)
S2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2016-08-30] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1453384 2018-04-02] (Overwolf LTD)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-09-30] ()
S2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AIDA64Driver; C:\Users\Michal\Desktop\Nepoužívané\AIDA64 Extreme 595\kerneld.x64 [45696 2017-11-26] ()
S2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
S1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [196648 2018-04-01] (AVAST Software)
S1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [227504 2018-04-01] (AVAST Software)
S0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199440 2018-04-01] (AVAST Software)
S0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343752 2018-04-01] (AVAST Software)
S0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57680 2018-04-01] (AVAST Software)
S1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [215320 2018-04-01] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-04-01] (AVAST Software)
S2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146656 2018-04-01] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110328 2018-04-01] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-04-01] (AVAST Software)
S1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-04-01] (AVAST Software)
S1 aswSP; C:\Windows\System32\drivers\aswSP.sys [460520 2018-04-01] (AVAST Software)
S2 aswStm; C:\Windows\System32\drivers\aswStm.sys [205976 2018-04-01] (AVAST Software)
S0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [380528 2018-04-01] (AVAST Software)
S3 CX88VID; C:\Windows\System32\drivers\cxavsvid.sys [469248 2007-09-19] (Leadtek Research Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-25] (Disc Soft Ltd)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [6637344 2018-01-01] (LLC Mail.Ru)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31168 2018-03-14] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2017-12-15] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-11-28] (NVIDIA Corporation)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 NTIOLib_1_0_C; \??\H:\NTIOLib_X64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-06 19:37 - 2018-04-06 19:37 - 000406952 _____ C:\Windows\Minidump\040618-11934-01.dmp
2018-04-06 19:03 - 2018-04-06 19:37 - 000369938 _____ C:\Windows\ntbtlog.txt
2018-04-06 19:03 - 2018-04-06 19:03 - 000406992 _____ C:\Windows\Minidump\040618-15116-01.dmp
2018-04-06 18:33 - 2018-04-06 18:33 - 000407000 _____ C:\Windows\Minidump\040618-12558-01.dmp
2018-04-06 18:17 - 2018-04-06 18:17 - 000406944 _____ C:\Windows\Minidump\040618-12604-01.dmp
2018-04-05 18:19 - 2018-04-06 19:11 - 000000000 ____D C:\AdwCleaner
2018-04-05 18:19 - 2018-04-05 18:19 - 008222496 _____ (Malwarebytes) C:\Users\Michal\Downloads\adwcleaner_7.0.8.0.exe
2018-04-05 18:18 - 2018-04-06 18:19 - 000002815 _____ C:\Users\Michal\Desktop\Fixlog.txt
2018-04-05 18:15 - 2018-04-05 18:15 - 000406992 _____ C:\Windows\Minidump\040518-15927-01.dmp
2018-04-05 18:09 - 2018-04-06 19:14 - 000000000 ___HD C:\Users\Michal\AppData\Local\Canon
2018-04-02 21:01 - 2018-04-02 21:01 - 000083698 _____ C:\Users\Michal\Downloads\Addition.txt
2018-04-02 21:00 - 2018-04-06 19:46 - 000023336 _____ C:\Users\Michal\Desktop\FRST.txt
2018-04-02 21:00 - 2018-04-06 19:46 - 000000000 ____D C:\FRST
2018-04-02 20:59 - 2018-04-02 20:59 - 002403328 _____ (Farbar) C:\Users\Michal\Desktop\fixer.exe
2018-04-02 20:56 - 2018-04-02 20:56 - 000001083 _____ C:\Users\Michal\fixlist.txt
2018-04-02 20:43 - 2018-04-02 20:43 - 000407072 _____ C:\Windows\Minidump\040218-14289-01.dmp
2018-04-01 19:19 - 2018-04-02 20:32 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-04-01 19:19 - 2018-04-01 19:13 - 000380768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-04-01 19:18 - 2018-04-01 19:18 - 000007609 _____ C:\Users\Michal\AppData\Local\Resmon.ResmonCfg
2018-04-01 19:15 - 2018-04-01 19:15 - 000406624 _____ C:\Windows\Minidump\040118-18127-01.dmp
2018-04-01 18:47 - 2018-04-01 18:47 - 000407064 _____ C:\Windows\Minidump\040118-16489-01.dmp
2018-04-01 18:03 - 2018-04-01 18:03 - 000000000 ____D C:\ProgramData\SWCUTemp
2018-03-31 21:39 - 2018-03-31 21:39 - 000407008 _____ C:\Windows\Minidump\033118-14710-01.dmp
2018-03-30 18:04 - 2018-04-06 19:14 - 000153088 _____ C:\Windows\SysWOW64\conhost64.exe
2018-03-30 18:04 - 2018-04-03 18:05 - 000000000 ___HD C:\Users\Michal\AppData\Local\BitTorrent
2018-03-29 18:32 - 2018-03-29 18:32 - 000000000 __SHD C:\82ace7d6-0197-474d-bf4b-a2043e72329b
2018-03-29 09:06 - 2018-03-29 09:06 - 000000000 ___HD C:\Users\Michal\AppData\Local\EDBase64
2018-03-27 18:04 - 2018-03-28 18:08 - 000000000 ___HD C:\Users\Michal\AppData\Local\ActiveX
2018-03-23 19:02 - 2018-03-26 18:07 - 000000000 ___HD C:\Users\Michal\AppData\Local\Minidump
2018-03-20 19:05 - 2018-04-02 20:32 - 000003922 _____ C:\Windows\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-03-20 19:03 - 2017-12-15 04:03 - 000059240 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2018-03-16 18:55 - 2018-03-22 19:06 - 000000000 ___HD C:\Users\Michal\AppData\Local\StdVCL
2018-03-10 20:03 - 2018-03-10 20:03 - 000000227 _____ C:\Users\Michal\Desktop\Total War SHOGUN 2.url
2018-03-08 19:28 - 2018-03-08 19:28 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-06 19:37 - 2018-02-26 17:08 - 725192353 _____ C:\Windows\MEMORY.DMP
2018-04-06 19:37 - 2013-12-29 15:54 - 000000000 ____D C:\Windows\Minidump
2018-04-06 19:35 - 2017-10-16 18:04 - 000000000 ____D C:\Users\Michal\AppData\Local\LogMeIn Hamachi
2018-04-06 19:34 - 2018-01-16 20:29 - 000000000 ____D C:\Users\Michal\AppData\Local\CrashDumps
2018-04-06 19:19 - 2016-05-21 09:31 - 000000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2018-04-06 19:14 - 2009-07-14 06:45 - 000014416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-06 19:14 - 2009-07-14 06:45 - 000014416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-06 19:09 - 2018-01-09 18:23 - 000000000 ____D C:\ProgramData\NVIDIA
2018-04-06 19:06 - 2017-11-23 06:32 - 000025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2018-04-06 19:06 - 2016-11-04 19:50 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-04-06 19:06 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-06 18:35 - 2016-12-19 19:13 - 000000000 ____D C:\Users\Michal\AppData\Roaming\discord
2018-04-04 20:13 - 2015-12-19 20:12 - 000000000 ____D C:\Program Files (x86)\Overwolf
2018-04-02 20:56 - 2013-12-25 14:37 - 000000000 ____D C:\Users\Michal
2018-04-02 20:41 - 2017-08-14 16:39 - 000000000 ____D C:\Users\Michal\AppData\LocalLow\Mozilla
2018-04-02 20:32 - 2018-02-24 19:07 - 000003640 _____ C:\Windows\System32\Tasks\{58BB0C33-30DC-4268-879C-9EDDF9458B86}
2018-04-02 20:32 - 2018-02-24 19:07 - 000003386 _____ C:\Windows\System32\Tasks\{99DA1DDE-97B7-468E-971A-A0A361E3C9CF}
2018-04-02 20:32 - 2018-02-16 07:04 - 000004078 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1518757467
2018-04-02 20:32 - 2018-01-09 18:52 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2018-01-09 18:25 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-02 20:32 - 2017-12-21 12:39 - 000003298 _____ C:\Windows\System32\Tasks\{4F9E8B89-9D00-4155-A8A4-C6E0A03CA34F}
2018-04-02 20:32 - 2017-11-23 17:51 - 000003272 _____ C:\Windows\System32\Tasks\AMD ThankingURL
2018-04-02 20:32 - 2017-11-23 17:47 - 000003146 _____ C:\Windows\System32\Tasks\StartCN
2018-04-02 20:32 - 2017-10-15 18:23 - 000003538 _____ C:\Windows\System32\Tasks\NIUpdateServiceCheckTask
2018-04-02 20:32 - 2017-10-15 18:23 - 000003246 _____ C:\Windows\System32\Tasks\NIUpdateServiceStartupTask
2018-04-02 20:32 - 2016-05-21 09:31 - 000003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-04-02 20:32 - 2016-04-12 19:06 - 000002968 _____ C:\Windows\System32\Tasks\{8C556DD4-519E-49E0-B27B-212B64855FE3}
2018-04-02 20:32 - 2016-04-12 19:06 - 000002968 _____ C:\Windows\System32\Tasks\{52B4ACE8-8377-4CC4-B302-F34114473B96}
2018-04-02 20:32 - 2016-04-12 19:06 - 000002968 _____ C:\Windows\System32\Tasks\{392509CC-228F-4620-AB2A-3AAEF05517C4}
2018-04-02 20:32 - 2015-12-19 20:13 - 000003728 _____ C:\Windows\System32\Tasks\Overwolf Updater Task
2018-04-02 20:32 - 2015-04-13 14:07 - 000003118 _____ C:\Windows\System32\Tasks\{BEB96816-A0B9-4F81-9589-F3CF7FC9A45E}
2018-04-02 20:32 - 2015-04-01 17:21 - 000003060 _____ C:\Windows\System32\Tasks\{BF6E1418-AFF1-429D-86AA-B6070689D8EA}
2018-04-02 20:32 - 2014-08-16 19:42 - 000002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-04-02 20:32 - 2014-03-24 15:17 - 000003126 _____ C:\Windows\System32\Tasks\{FFA5BCE1-7580-48C4-994F-FA0BF62D1BD5}
2018-04-02 20:32 - 2014-03-24 15:17 - 000003120 _____ C:\Windows\System32\Tasks\{4BB52DC7-10C3-40A1-89D2-DD1B0A4A770B}
2018-04-02 20:32 - 2014-03-19 08:41 - 000003292 _____ C:\Windows\System32\Tasks\{1126949E-9FFF-454B-952F-C4D437453BF6}
2018-04-02 20:32 - 2013-12-25 15:41 - 000003564 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4203263230-2635384760-1339063134-1001UA
2018-04-02 20:32 - 2013-12-25 15:41 - 000003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4203263230-2635384760-1339063134-1001Core
2018-04-01 19:19 - 2017-08-15 18:10 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2018-04-01 19:19 - 2014-08-16 19:41 - 000000000 ____D C:\Program Files\CCleaner
2018-04-01 19:13 - 2017-12-21 19:11 - 000196648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-04-01 19:13 - 2017-11-22 20:00 - 000215320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000343752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000227504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000199440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2018-04-01 19:13 - 2017-08-15 18:09 - 000057680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2018-04-01 19:13 - 2014-08-09 18:27 - 000205976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-04-01 19:13 - 2014-08-09 18:27 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000460520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000380528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000146656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000110328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-04-01 19:13 - 2013-12-25 16:13 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-04-01 19:09 - 2009-07-14 07:08 - 000032570 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-01 19:01 - 2018-03-05 19:08 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wargaming.net
2018-04-01 18:40 - 2018-01-22 19:08 - 000000000 ____D C:\Users\Michal\AppData\Roaming\Battlerite
2018-03-30 21:38 - 2015-05-30 17:44 - 000000000 ____D C:\Users\Michal\AppData\Local\Battle.net
2018-03-30 21:38 - 2015-05-30 17:44 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-03-28 23:02 - 2018-02-14 19:20 - 000000999 _____ C:\Users\Michal\Desktop\The book of Grudges.txt
2018-03-27 17:59 - 2018-03-05 19:09 - 000000000 ____D C:\ProgramData\boost_interprocess
2018-03-23 19:17 - 2013-12-25 15:43 - 000002428 _____ C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-23 19:17 - 2013-12-25 15:43 - 000002391 _____ C:\Users\Michal\Desktop\Google Chrome.lnk
2018-03-21 18:59 - 2017-06-15 05:51 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-03-20 19:06 - 2018-01-09 18:25 - 000001416 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2018-03-20 19:06 - 2018-01-09 18:23 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-03-20 19:06 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-03-20 19:04 - 2018-01-09 18:17 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-03-14 15:05 - 2018-01-09 18:25 - 002480064 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2018-03-14 15:05 - 2018-01-09 18:25 - 002137024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2018-03-14 15:05 - 2018-01-09 18:25 - 001310144 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2018-03-14 14:44 - 2018-01-09 18:25 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-03-11 19:08 - 2018-03-05 19:09 - 000000000 ___HD C:\Users\Michal\AppData\Local\TabCntrl
==================== Files in the root of some directories =======
2015-12-22 09:08 - 2018-02-24 18:32 - 000000079 _____ () C:\Users\Michal\AppData\Local\CrystalDiskMark30.ini
2013-12-26 12:30 - 2013-12-26 12:30 - 000003584 _____ () C:\Users\Michal\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-07-14 03:14 - 2009-07-14 03:14 - 000073216 ____N (Microsoft Corporation) C:\Users\Michal\AppData\Local\fEchOJYBVfD.exe
2013-12-26 16:30 - 2013-12-26 16:30 - 000000000 ___SH () C:\Users\Michal\AppData\Local\LumaEmu
2018-04-01 19:18 - 2018-04-01 19:18 - 000007609 _____ () C:\Users\Michal\AppData\Local\Resmon.ResmonCfg
2018-02-24 19:07 - 2018-02-24 19:07 - 000000002 _____ () C:\Users\Michal\AppData\Local\WMI.ini
Some files in TEMP:
====================
2018-02-23 19:07 - 2018-02-23 19:07 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018223713779.dll
2018-02-23 19:09 - 2018-02-23 19:09 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018223946131.dll
2018-02-24 20:14 - 2018-02-24 20:14 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182241410659.dll
2018-02-24 17:14 - 2018-02-24 17:14 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018224145453.dll
2018-02-24 18:29 - 2018-02-24 18:29 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182242910633.dll
2018-02-24 20:48 - 2018-02-24 20:48 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182244839795.dll
2018-02-24 18:51 - 2018-02-24 18:51 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245118362.dll
2018-02-24 21:52 - 2018-02-24 21:52 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245251785.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245446445.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245446499.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245446761.dll
2018-02-24 21:54 - 2018-02-24 21:54 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_20182245447852.dll
2018-02-24 17:08 - 2018-02-24 17:08 - 002157568 _____ (Opera Software) C:\Users\Michal\AppData\Local\Temp\Opera_installer_2018224825613.dll
Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\lastpass_1337.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-02-16 13:22
==================== End of FRST.txt ============================