Stránka 1 z 1

Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 25 dub 2018 16:00
od WarWalker
Ahoj, moc prosím o kontrolu logu. Občas mi poslední dobou vyhodí Avast hlášku že našel trojan:gen, notobook je celkem svižný, bez symptomatologie zavirování :).
Děkuju moc.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Vít at 2018-04-25 16:56:18
Microsoft Windows 10 Home
System drive C: has 169 GB (38%) free of 452 GB
Total RAM: 3798 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:56:22, on 25.04.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.16299.0015)
Boot mode: Normal

Running processes:
c:\program files (x86)\ostotohotspot\Hotspot.exe
C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe
C:\Program Files (x86)\Samsung\Settings\sSettings.exe
C:\Windows\System32\TiltWheelMouse.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\IObit\Driver Booster\5.3.0\Pub\PubMonitor.exe
C:\Program Files\trend micro\Vít.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SafeQ Client] "C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [160WiFi] "C:\Program Files (x86)\OSTotoHotspot\Hotspot.exe" -auto
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [HP Deskjet 3520 series (NET)] "C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN42F2G0WK05SZ:NW" -scfn "HP Deskjet 3520 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Google Update] C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe
O4 - HKCU\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [Application Restart #0] C:\Program Files (x86)\Samsung\Settings\CmdServer\VendorAPIRun64.exe 999/c /RestartByRestartManager:5D737BD3-E2F1-42c1-836B-8100859F1856 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Application Restart #0] C:\Program Files (x86)\Samsung\Settings\CmdServer\VendorAPIRun64.exe 999/c /RestartByRestartManager:5D737BD3-E2F1-42c1-836B-8100859F1856 (User 'Default user')
O4 - Startup: cme.js
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (file missing) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: ArcSoft Exchange Service (ADExchange) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: DiskDrill Watcher (cfbackd) - CleverFiles - C:\Program Files (x86)\CleverFiles\Disk Drill\cfbackd.w32.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Easy Launcher - Samsung Electronics CO., LTD. - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Rapid Start Technology Service (irstrtsv) - Intel Corporation - C:\windows\SysWOW64\irstrtsv.exe
O23 - Service: Intel(R) Update Manager (iumsvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: SW Update Service (SWUpdateService) - Samsung Electronics Co., Ltd. - C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\WINDOWS\system32\xbgmsvc.exe (file missing)

--
End of file - 14115 bytes

======Listing Processes======








winlogon.exe

c:\windows\system32\svchost.exe -k dcomlaunch -p -s PlugPlay
"fontdrvhost.exe"
"fontdrvhost.exe"
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
c:\windows\system32\svchost.exe -k rpcss -p
c:\windows\system32\svchost.exe -k dcomlaunch -p -s LSM
"dwm.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s lmhosts
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -p -s ProfSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s EventLog
c:\windows\system32\svchost.exe -k netsvcs -p -s UserManager
c:\windows\system32\svchost.exe -k localservice -p -s SEMgrSvc
c:\windows\system32\svchost.exe -k localservice -p -s nsi
c:\windows\system32\svchost.exe -k localservice -p -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -p -s Themes
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s SysMain
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s Dhcp

c:\windows\system32\svchost.exe -k netsvcs -p -s SENS
c:\windows\system32\svchost.exe -k networkservice -p -s NlaSvc
C:\WINDOWS\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -p -s FontCache
c:\windows\system32\svchost.exe -k netsvcs -p -s lfsvc
c:\windows\system32\svchost.exe -k localservice -p -s netprofm
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
c:\windows\system32\svchost.exe -k networkservice -p -s Dnscache
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
c:\windows\system32\svchost.exe -k appmodel -p -s StateRepository
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k netsvcs -p -s Eaphost
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s WwanSvc
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s dot3svc
c:\windows\system32\svchost.exe -k netsvcs -p -s ShellHWDetection

C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -p -s LanmanWorkstation
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s DeviceAssociationService
dashost.exe {2e9cf6da-f997-46d0-b52abf619dbf55b3}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe"
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
c:\windows\system32\svchost.exe -k networkservice -p -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k utcsvc -p
C:\WINDOWS\System32\alg.exe
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s DPS
"C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
"C:\Program Files\Elantech\ETDService.exe"
c:\windows\syswow64\svchost.exe -k localwifiservice -s hwifisvc
c:\windows\system32\svchost.exe -k netsvcs -p -s Winmgmt
C:\windows\SysWOW64\irstrtsv.exe
c:\windows\system32\svchost.exe -k netsvcs -p -s LanmanServer
c:\windows\system32\svchost.exe -k networkservice -p -s TapiSrv

"C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe" /SERVICE
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s TrkWks
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k netsvcs -p -s WpnService
c:\windows\system32\svchost.exe -k localservice -p -s SstpSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s iphlpsvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s SSDPSRV
c:\windows\system32\svchost.exe -k netsvcs -p -s Appinfo
c:\windows\system32\svchost.exe -k localservice -p -s WdiServiceHost
C:\WINDOWS\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k netsvcs -p -s Browser
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -p -s PolicyAgent

"C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
/runbysrv
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe"
c:\windows\system32\svchost.exe -k netsvcs -p -s TokenBroker
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s TabletInputService
"ctfmon.exe"
"C:\Program Files\Elantech\ETDTouch.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s PcaSvc
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\Explorer.EXE
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NgcSvc
"C:\Program Files (x86)\Samsung\Settings\sSettings.exe" /s
c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s NgcCtnrSvc
C:\WINDOWS\system32\wbem\wmiprvse.exe
igfxEM.exe
igfxHK.exe
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\igfxext.exe -Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s NcdAutoSetup
c:\windows\system32\svchost.exe -k localservice -p -s fdPHost
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s FDResPub
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s Netman
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservice -p -s LicenseManager
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s HomeGroupProvider
"C:\Program Files\Samsung\S Agent\CommonAgent.exe"
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s WdiSystemHost
"C:\Windows\System32\TiltWheelMouse.exe"
AvastUI.exe /nogui
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe"
"C:\Windows\System32\WScript.exe" "C:\Users\Vít\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cme.js"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Windows\System32\schtasks.exe" /create /sc minute /mo 30 /tn Skype /tr "C:\Users\Vít\AppData\Local\cme.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\Program Files\Realtek\Audio\HDA\EP64.exe" -s
c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s StorSvc
"C:\Program Files (x86)\IObit\Driver Booster\5.3.0\Pub\PubMonitor.exe" /DB
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\System32\WScript.exe "C:\Users\Vít\AppData\Local\cme.js"
"C:\Windows\System32\schtasks.exe" /create /sc minute /mo 30 /tn Skype /tr "C:\Users\Vít\AppData\Local\cme.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s RmSvc
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="7152.0.1681362261\328685924" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" "C:\Users\Vít\AppData\LocalLow\Mozilla\Temp-{bba6ec4c-495a-40ec-ad5d-81b81985ee4f}" 7152 "\\.\pipe\gecko-crash-server-pipe.7152" gpu
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="7152.1.829753429\269162376" -childID 1 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:1|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{bba6ec4c-495a-40ec-ad5d-81b81985ee4f}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 7152 "\\.\pipe\gecko-crash-server-pipe.7152" tab
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="7152.13.980738579\1090579373" -childID 2 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:1|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{bba6ec4c-495a-40ec-ad5d-81b81985ee4f}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 7152 "\\.\pipe\gecko-crash-server-pipe.7152" tab
"C:\Program Files\CCleaner\CCleaner.exe" /uac
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="7152.34.1086900768\1352273219" -childID 5 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:1|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{bba6ec4c-495a-40ec-ad5d-81b81985ee4f}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 7152 "\\.\pipe\gecko-crash-server-pipe.7152" tab
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="7152.41.150019213\997608955" -childID 6 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:1|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{bba6ec4c-495a-40ec-ad5d-81b81985ee4f}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 7152 "\\.\pipe\gecko-crash-server-pipe.7152" tab
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="7152.48.554648778\811000665" -childID 7 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:1|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{bba6ec4c-495a-40ec-ad5d-81b81985ee4f}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 7152 "\\.\pipe\gecko-crash-server-pipe.7152" tab
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 740 744 752 8192 748

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc
"C:\Users\Vít\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core.job - C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA.job - C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\yevugtxg.default-1509452420247

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.140 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_140.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1214154.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@garmin.com/GpsControl]
"Description"=Garmin GPS Control for Firefox
"Path"=C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.140 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_140.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@garmin.com/GpsControl]
"Description"=Garmin GPS Control for Firefox
"Path"=C:\Program Files\Garmin GPS Plugin\npGarmin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-04-24 210096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-04-24 3229872]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-20 149696]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-01-20 2179240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-09-29 630168]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2018-04-02 18383328]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2016-11-11 3242200]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19 557768]
"MouseDriver"=C:\WINDOWS\system32\TiltWheelMouse.exe [2013-04-09 241152]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-05-09 213824]
"RtsCM"=C:\WINDOWS\RTSCM64.EXE [2018-04-02 168152]
"Wondershare Helper Compact.exe"=C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Deskjet 3520 series (NET)"=C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]
"Google Update"=C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [2018-04-15 601680]
"GarminExpressTrayApp"=C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [2017-01-09 1407912]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\Program32\ZPSTRAY.EXE [2018-04-05 576456]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-13 155488]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
"SafeQ Client"=C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe [2013-03-20 259072]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
"160WiFi"=C:\Program Files (x86)\OSTotoHotspot\Hotspot.exe [2017-03-15 855160]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2017-09-12 2133728]

C:\Users\Vít\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
cme.js

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2018-04-07 09:04:19 ----D---- C:\WINDOWS\SYSWOW64\sda
2018-04-07 09:04:19 ----D---- C:\Program Files (x86)\Genesys Logic
2018-04-07 09:04:18 ----D---- C:\WINDOWS\LastGood
2018-04-06 12:44:24 ----HD---- C:\$AV_ASW
2018-04-06 12:18:43 ----D---- C:\Program Files (x86)\Movavi Video Editor 14 Plus
2018-04-06 12:14:26 ----D---- C:\ProgramData\Movavi Video Editor 14 Plus
2018-04-06 12:07:09 ----D---- C:\Users\Vít\AppData\Roaming\MOVAVI
2018-04-06 11:48:47 ----D---- C:\ProgramData\Wondershare
2018-04-06 11:46:03 ----D---- C:\ProgramData\Wondershare Video Editor
2018-04-06 11:46:03 ----D---- C:\Program Files (x86)\Wondershare
2018-04-05 14:22:43 ----D---- C:\WINDOWS\LastGood.Tmp
2018-04-02 20:35:16 ----A---- C:\WINDOWS\system32\SRSWOW64.dll
2018-04-02 20:35:15 ----A---- C:\WINDOWS\system32\SRSTSX64.dll
2018-04-02 20:35:15 ----A---- C:\WINDOWS\system32\SRSTSH64.dll
2018-04-02 20:35:15 ----A---- C:\WINDOWS\system32\SRSHP64.dll
2018-04-02 20:35:11 ----A---- C:\WINDOWS\SYSWOW64\SFCOM.dll
2018-04-02 20:35:11 ----A---- C:\WINDOWS\system32\SFSS_APO.dll
2018-04-02 20:35:11 ----A---- C:\WINDOWS\system32\SFNHK64.dll
2018-04-02 20:35:11 ----A---- C:\WINDOWS\system32\SFCOM64.dll
2018-04-02 20:35:11 ----A---- C:\WINDOWS\system32\SFAPO64.dll
2018-04-02 20:35:10 ----A---- C:\WINDOWS\system32\RtPgEx64.dll
2018-04-02 20:35:10 ----A---- C:\WINDOWS\system32\RtlCPAPI64.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RtkCfg64.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RtkApi64.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RTEEP64A.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RTEEL64A.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RTEEG64A.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RTEED64A.dll
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RtDataProc64.dll
2018-04-02 20:35:08 ----A---- C:\WINDOWS\system32\RTCOM64.dll
2018-04-02 20:35:08 ----A---- C:\WINDOWS\system32\RP3DHT64.dll
2018-04-02 20:35:08 ----A---- C:\WINDOWS\system32\RP3DAA64.dll
2018-04-02 20:35:07 ----A---- C:\WINDOWS\SYSWOW64\RltkAPO.dll
2018-04-02 20:35:06 ----A---- C:\WINDOWS\system32\RCoInstII64.dll
2018-04-02 20:35:06 ----A---- C:\WINDOWS\system32\R4EEP64A.dll
2018-04-02 20:35:06 ----A---- C:\WINDOWS\system32\R4EEL64A.dll
2018-04-02 20:35:06 ----A---- C:\WINDOWS\system32\R4EEG64A.dll
2018-04-02 20:35:06 ----A---- C:\WINDOWS\system32\R4EED64A.dll
2018-04-02 20:35:06 ----A---- C:\WINDOWS\system32\R4EEA64A.dll
2018-04-02 20:35:04 ----A---- C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2018-04-02 20:35:04 ----A---- C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2018-04-02 20:35:04 ----A---- C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2018-04-02 20:35:04 ----A---- C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2018-04-02 20:35:04 ----A---- C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSLimiterDLL64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSLFXAPO64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSGFXAPONS64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSGFXAPO64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSBoostDLL64.dll
2018-04-02 20:35:03 ----A---- C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2018-04-02 20:35:02 ----A---- C:\WINDOWS\system32\DDPP64A.dll
2018-04-02 20:35:02 ----A---- C:\WINDOWS\system32\DDPO64A.dll
2018-04-02 20:35:02 ----A---- C:\WINDOWS\system32\DDPD64A.dll
2018-04-02 20:35:01 ----A---- C:\WINDOWS\system32\DDPA64.dll
2018-04-02 20:35:01 ----A---- C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2018-04-02 20:34:42 ----A---- C:\WINDOWS\system32\drivers\RTAIODAT.DAT
2018-04-02 20:34:41 ----A---- C:\WINDOWS\system32\RCoRes64.dat
2018-04-02 20:34:24 ----A---- C:\WINDOWS\system32\drivers\ssudmdm.sys
2018-04-02 20:34:23 ----A---- C:\WINDOWS\system32\drivers\ssudbus.sys
2018-04-02 20:33:43 ----A---- C:\WINDOWS\system32\WdfCoInstaller01011.dll
2018-04-02 20:33:43 ----A---- C:\WINDOWS\system32\GSCoinst.dll
2018-04-02 20:33:43 ----A---- C:\WINDOWS\system32\drivers\GeneStor.sys
2018-04-02 20:33:42 ----A---- C:\WINDOWS\system32\GeneIcon.dll
2018-04-02 20:33:10 ----A---- C:\WINDOWS\system32\drivers\NETwew01.sys
2018-04-02 20:33:08 ----A---- C:\WINDOWS\system32\drivers\Netwfw01.dat
2018-04-02 20:32:02 ----A---- C:\WINDOWS\system32\drivers\rtsuvc.sys
2018-04-02 20:32:02 ----A---- C:\WINDOWS\RtsCM64.exe
2018-04-02 20:32:01 ----A---- C:\WINDOWS\SYSWOW64\RtCamX.dll
2018-04-02 20:32:01 ----A---- C:\WINDOWS\system32\RtCamX64.dll
2018-04-02 20:32:00 ----A---- C:\WINDOWS\SYSWOW64\RsDecode.dll
2018-04-02 20:32:00 ----A---- C:\WINDOWS\RtCamU64.exe
2018-04-02 20:23:51 ----D---- C:\WINDOWS\IObit
2018-04-02 20:23:51 ----D---- C:\ProgramData\ProductData
2018-04-02 20:22:42 ----A---- C:\WINDOWS\SYSWOW64\drivers\HWiNFO64A.SYS
2018-04-02 20:22:17 ----D---- C:\Program Files (x86)\IObit
2018-04-02 20:21:32 ----D---- C:\Users\Vít\AppData\Roaming\IObit
2018-04-02 20:20:15 ----D---- C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
2018-04-02 20:20:14 ----D---- C:\ProgramData\IObit
2018-04-02 19:59:47 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe

======List of files/folders modified in the last 1 month======

2018-04-25 16:56:21 ----D---- C:\Program Files\trend micro
2018-04-25 16:55:52 ----D---- C:\WINDOWS\Temp
2018-04-25 16:53:22 ----D---- C:\Users\Vít\AppData\Roaming\uTorrent
2018-04-25 16:53:02 ----D---- C:\WINDOWS\INF
2018-04-25 16:52:56 ----D---- C:\WINDOWS\LiveKernelReports
2018-04-25 16:52:56 ----D---- C:\WINDOWS\debug
2018-04-25 16:52:56 ----D---- C:\Windows
2018-04-25 16:52:06 ----D---- C:\WINDOWS\Prefetch
2018-04-25 16:48:54 ----D---- C:\WINDOWS\system32\SleepStudy
2018-04-25 16:31:48 ----D---- C:\WINDOWS\DeliveryOptimization
2018-04-25 16:31:02 ----HD---- C:\Program Files\WindowsApps
2018-04-25 16:27:09 ----D---- C:\WINDOWS\system32\Tasks
2018-04-25 16:26:47 ----D---- C:\WINDOWS\AppReadiness
2018-04-25 16:26:22 ----D---- C:\ProgramData\WinClon
2018-04-24 23:24:09 ----D---- C:\WINDOWS\system32\sru
2018-04-24 17:22:50 ----D---- C:\WINDOWS\system32\config
2018-04-24 17:11:41 ----SHD---- C:\System Volume Information
2018-04-24 17:02:01 ----RD---- C:\WINDOWS\Microsoft.NET
2018-04-24 16:47:38 ----D---- C:\WINDOWS\system32\LogFiles
2018-04-24 09:37:30 ----SHD---- C:\WINDOWS\Installer
2018-04-24 09:37:27 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2018-04-24 09:37:24 ----D---- C:\ProgramData\Microsoft Help
2018-04-24 09:33:34 ----AD---- C:\Program Files (x86)\Microsoft Office
2018-04-24 09:15:24 ----D---- C:\WINDOWS\Logs
2018-04-18 15:36:15 ----D---- C:\WINDOWS\CbsTemp
2018-04-16 09:15:58 ----D---- C:\Users\Vít\AppData\Roaming\Google
2018-04-12 23:55:20 ----D---- C:\WINDOWS\system32\catroot2
2018-04-12 20:27:10 ----D---- C:\WINDOWS\system32\DriverStore
2018-04-12 20:27:00 ----D---- C:\WINDOWS\WinSxS
2018-04-12 20:16:28 ----D---- C:\WINDOWS\rescache
2018-04-12 10:20:09 ----D---- C:\WINDOWS\SysWOW64
2018-04-12 10:19:59 ----D---- C:\WINDOWS\system32\Macromed
2018-04-12 10:19:56 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2018-04-11 13:58:18 ----D---- C:\Users\Vít\AppData\Roaming\Skype
2018-04-11 09:41:27 ----D---- C:\WINDOWS\system32\MRT
2018-04-11 09:41:16 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2018-04-11 09:41:01 ----AC---- C:\WINDOWS\system32\MRT.exe
2018-04-09 18:27:59 ----D---- C:\WINDOWS\system32\WDI
2018-04-07 09:04:19 ----D---- C:\WINDOWS\System32
2018-04-07 09:04:19 ----D---- C:\Program Files (x86)
2018-04-07 09:04:17 ----D---- C:\WINDOWS\system32\drivers
2018-04-06 12:14:26 ----HD---- C:\ProgramData
2018-04-06 11:48:09 ----D---- C:\Program Files (x86)\Common Files
2018-04-06 11:46:36 ----RSD---- C:\WINDOWS\Fonts
2018-04-03 20:28:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2018-04-02 20:47:30 ----D---- C:\WINDOWS\system32\CatRoot
2018-04-02 20:36:57 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2018-04-02 20:35:09 ----A---- C:\WINDOWS\system32\RtkCoLDR64.dll
2018-04-02 20:35:08 ----A---- C:\WINDOWS\system32\RltkAPO64.dll
2018-04-02 20:32:39 ----D---- C:\WINDOWS\twain_32
2018-04-02 20:22:42 ----D---- C:\WINDOWS\SYSWOW64\drivers
2018-04-02 19:57:46 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-02 19:54:16 ----D---- C:\WINDOWS\TextInput
2018-04-02 19:54:16 ----D---- C:\WINDOWS\SYSWOW64\wbem
2018-04-02 19:54:16 ----D---- C:\WINDOWS\SYSWOW64\migration
2018-04-02 19:54:13 ----D---- C:\WINDOWS\system32\wbem
2018-04-02 19:54:13 ----D---- C:\WINDOWS\system32\oobe
2018-04-02 19:54:13 ----D---- C:\WINDOWS\system32\migration
2018-04-02 19:54:13 ----D---- C:\WINDOWS\system32\Boot
2018-04-02 19:54:13 ----D---- C:\WINDOWS\system32\appraiser
2018-04-02 19:54:04 ----D---- C:\WINDOWS\ShellExperiences
2018-04-02 19:54:02 ----D---- C:\WINDOWS\bcastdvr
2018-04-02 19:54:02 ----D---- C:\WINDOWS\apppatch
2018-04-02 19:53:47 ----D---- C:\WINDOWS\system32\drivers\UMDF
2018-03-27 21:55:45 ----AD---- C:\Program Files (x86)\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-05-09 190256]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-05-09 334576]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-05-09 49016]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-05-09 75704]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-05-09 339696]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-31 645952]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2017-09-29 56728]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-05-09 311808]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2017-05-09 32600]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-05-09 101152]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-05-09 1007160]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-05-09 569192]
R1 bam;@%SystemRoot%\system32\drivers\bam.sys,-100; C:\WINDOWS\system32\drivers\bam.sys [2018-01-01 59800]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2017-09-29 55808]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-09-29 8192]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [2018-04-02 27552]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-05-09 128648]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-07-12 167592]
R2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2018-02-10 385536]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2017-09-29 43520]
R3 AMPPAL;@oem136.inf,%AMPPAL.SVCDESC%;Virtuální adaptér Intel(r) Centrino(r) Wireless Bluetooth(r) + High Speed; C:\WINDOWS\System32\drivers\AMPPAL.sys [2013-05-21 165344]
R3 aswTap;@oem113.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\WINDOWS\System32\drivers\aswTap.sys [2014-08-06 44640]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2017-09-29 85504]
R3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2017-09-29 60312]
R3 ETD;@oem33.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2016-11-11 589392]
R3 ibtfltcoex;@oem193.inf,%PROVIDER_NAME%;Intel Corporation; C:\WINDOWS\system32\DRIVERS\ibtfltcoex.sys [2018-04-02 80144]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2016-05-03 3811288]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2018-04-02 5995944]
R3 IntcDAud;@oem109.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 irstrtdv;@oem135.inf,%Irstrt.DispName%;Intel(R) Rapid Start Technology Driver; C:\WINDOWS\System32\drivers\irstrtdv.sys [2012-07-20 43800]
R3 iwdbus;@oem166.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2015-12-01 38896]
R3 MEIx64;@oem183.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2018-04-02 186424]
R3 NETwNe64;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit; C:\WINDOWS\System32\drivers\NETwew01.sys [2018-04-02 3354384]
R3 RadioHIDMini;@oem87.inf,%RadioHIDMini%;Radio HID Mini-driver; C:\WINDOWS\System32\drivers\RadioHIDMini.sys [2012-07-27 23408]
R3 rt640x64;@oem197.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2018-04-02 1026896]
R3 rtsuvc;@oem190.inf,%rtsuvc.DeviceDesc%;Realtek USB2.0 PC Camera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2018-04-02 2599128]
S0 bttflt;@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter; C:\WINDOWS\System32\drivers\bttflt.sys [2017-09-29 37784]
S0 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-09-29 357272]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-09-29 123800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-09-29 103320]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-09-29 63520]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2017-09-29 58776]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2017-09-29 61848]
S0 Ramdisk;Windows RAM Disk Driver; C:\WINDOWS\system32\DRIVERS\ramdisk.sys [2017-09-29 39832]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-09-29 118168]
S1 HWifiNetPro;HWifiNetPro; \??\C:\Program Files (x86)\OSTotoHotspot\HWifiNetPro64.sys [2017-03-14 175416]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-09-29 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2017-09-29 18432]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-05-09 38296]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2018-02-10 1015296]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-09-29 39424]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2017-09-29 122368]
S3 dg_ssudbus;@oem195.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2018-04-02 131984]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2016-03-07 30264]
S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2016-03-07 47672]
S3 ETDSMBus;ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [2015-09-24 32328]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-09-29 20992]
S3 GeneStor;@oem192.inf,%GeneStor.SvcDesc%;Genesys Logic Storage Driver; C:\WINDOWS\system32\DRIVERS\GeneStor.sys [2018-04-02 130648]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-09-29 50584]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2017-09-29 73112]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver; C:\WINDOWS\System32\Drivers\mshwnclx.sys [2017-09-29 27136]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-09-29 1723288]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2017-09-29 36864]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2017-09-29 91648]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-09-29 79360]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-09-29 88576]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-09-29 171520]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-09-29 174592]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2017-09-29 526232]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-09-29 39424]
S3 intaud_WaveExtensible;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys []
S3 invdimm;@invdimm.inf,%invdimm.SvcDesc%;Microsoft iNVDIMM device driver; C:\WINDOWS\System32\drivers\invdimm.sys [2017-09-29 38912]
S3 IPT;IPT; C:\WINDOWS\System32\drivers\ipt.sys [2017-09-29 26112]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2017-09-29 119808]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2017-09-29 505240]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2017-09-29 55840]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-09-29 842648]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2017-09-29 108952]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2017-09-29 132608]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-09-29 88576]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2017-09-29 100352]
S3 PNPMEM;@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver; C:\WINDOWS\System32\drivers\pnpmem.sys [2017-09-29 16896]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2017-09-29 936856]
S3 rhproxy;@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver; C:\WINDOWS\System32\drivers\rhproxy.sys [2017-09-29 103936]
S3 rtport;rtport; \??\C:\windows\SysWOW64\drivers\rtport.sys [2012-11-23 15144]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\WINDOWS\System32\drivers\SDFRd.sys [2017-09-29 33176]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter; C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-09-30 56216]
S3 sshid;@oem182.inf,%sshid.SvcDesc%;SteelSeries HID Service; C:\WINDOWS\System32\drivers\sshid.sys [2018-01-10 47944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 ADExchange;ArcSoft Exchange Service; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [2012-02-16 43112]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-02-09 83984]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-05-09 263304]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R2 CDPUserSvc_499c4;Uživatelská služba platformy připojených zařízení_499c4; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-31 7761584]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
R2 Easy Launcher;Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [2015-06-19 1593664]
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2016-11-11 129752]
R2 hwifisvc;hwifisvc Service; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2016-05-03 337888]
R2 irstrtsv;Intel(R) Rapid Start Technology Service; C:\windows\SysWOW64\irstrtsv.exe [2012-07-19 193576]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-07-10 223520]
R2 OneSyncSvc_499c4;Hostitel synchronizace_499c4; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\WINDOWS\system32\SecurityHealthService.exe [2018-02-10 519144]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-05-09 7346208]
R3 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2017-12-04 43648]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
R3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R3 PimIndexMaintenanceSvc_499c4;Data kontaktů_499c4; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
R3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-02 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-07-18 317408]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-04-12 272384]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 camsvc;@%SystemRoot%\system32\CapabilityAccessManager.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 cfbackd;DiskDrill Watcher; C:\Program Files (x86)\CleverFiles\Disk Drill\cfbackd.w32.exe [2016-09-30 211520]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2016-05-03 299488]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 DevicesFlowUserSvc_499c4;Tok zařízení_499c4; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-09-29 85504]
S3 diagsvc;@%systemroot%\system32\DiagSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [2017-01-09 1038864]
S3 GraphicsPerfSvc;@%SystemRoot%\system32\GraphicsPerfSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-02 144200]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 InstallService;@%SystemRoot%\system32\InstallService.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-05-22 881152]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 iumsvc;Intel(R) Update Manager; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12 177376]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 MessagingService_499c4;Služba zasílání zpráv_499c4; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-03-27 194512]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2014-12-01 38200]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-31 213680]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 PrintWorkflowUserSvc;@%SystemRoot%\system32\PrintWorkflowService.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 PrintWorkflowUserSvc_499c4;PrintWorkflow_499c4; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 PushToInstall;@%SystemRoot%\system32\pushtoinstall.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-09-29 1288704]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 SharedRealitySvc;@%SystemRoot%\system32\SharedRealitySvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2017-09-29 48688]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2015-06-10 155520]
S3 spectrum;@%systemroot%\system32\spectrum.exe,-101; C:\WINDOWS\system32\spectrum.exe [2018-01-01 956416]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-09-29 48688]

-----------------EOF-----------------

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 25 dub 2018 22:12
od Conder
Ahoj :)

:arrow: V akom umiestneni hlasi Avast tento virus?

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
  • Klikni na Cisteni a opravy (Clean and Repair) a potvrd restart PC teraz
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah sem skopiruj

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 26 dub 2018 07:53
od WarWalker
Dobré ráno, tady jelog z adw cleaneru :).

# -------------------------------
# Malwarebytes AdwCleaner 7.1.0.0
# -------------------------------
# Build: 04-12-2018
# Database: 2018-04-24.1
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-25-2018
# Duration: 00:00:12
# OS: Windows 10 Home
# Cleaned: 13
# Failed: 0


***** [ Services ] *****

Deleted hwifisvc

***** [ Folders ] *****

Deleted C:\Users\Vít\AppData\Roaming\IObit\Advanced SystemCare
Deleted C:\ProgramData\pc faster
Deleted C:\Users\Public\Documents\pc faster

***** [ Files ] *****

Deleted C:\Users\Vít\Desktop\Free WiFi.lnk

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted C:\Windows\System32\Tasks\Driver Booster Scheduler

***** [ Registry ] *****

Deleted HKCU\Software\Conduit
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost|LocalWiFiService
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{30372E83-1CF0-432C-9122-E7F7CFF7ADD7}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{34F8EF77-AB62-4DD6-997E-CBC0DB8768DB}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\slunecnice.cz

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted Slunečnice

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************


########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########


avast
https://ctrlv.cz/eoPJ

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 26 dub 2018 15:03
od Conder
:arrow: Poprosim o obidva logy z FRST podla tohto navodu (FRST.txt a Addition.txt): https://forum.viry.cz/viewtopic.php?f=13&t=152707

:arrow: V pripade, ze sa FRSTLauncher nebude dat stiahnut alebo spustit, pouzi iba samotny FRST.

:arrow: Ak sa logy nezmestia do jedneho prispevku, zabal ich do archivu RAR alebo ZIP a posli ako prilohu.

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 26 dub 2018 19:42
od WarWalker
Ahoj, tady jsou logy :). Děkuju.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25.04.2018
Ran by VĂ­t (administrator) on VĂŤTEK (26-04-2018 20:30:38)
Running from C:\Users\VĂ­t\Desktop
Loaded Profiles: VĂ­t (Available Profiles: VĂ­t)
Platform: Windows 10 Home Version 1709 16299.248 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
() C:\Program Files (x86)\OSTotoHotspot\Hotspot.exe
(Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
() C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\EP64.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\VĂ­t\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18383328 2018-04-02] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242200 2016-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM\...\Run: [MouseDriver] => C:\WINDOWS\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-04-25] (AVAST Software)
HKLM\...\Run: [RtsCM] => C:\WINDOWS\RTSCM64.EXE [168152 2018-04-02] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [SafeQ Client] => C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe [259072 2013-03-20] ()
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [160WiFi] => C:\Program Files (x86)\OSTotoHotspot\Hotspot.exe [855160 2017-03-15] ()
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [Google Update] => C:\Users\VĂ­t\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2018-04-15] (Google Inc.)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-09] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\Program32\ZPSTRAY.EXE [576456 2018-04-05] (ZONER software)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [36864 2017-09-29] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Samsung\Settings\CmdServer\VendorAPIRun64.exe [2406208 2015-06-19] (Samsung Electronics CO., LTD.)
HKU\S-1-5-18\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Samsung\Settings\CmdServer\VendorAPIRun64.exe [2406208 2015-06-19] (Samsung Electronics CO., LTD.)
Startup: C:\Users\VĂ­t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cme.js [2018-02-21] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 147.251.199.1
Tcpip\..\Interfaces\{971b796a-98cc-4352-8c7d-9fb2d6471d51}: [DhcpNameServer] 147.251.6.10 147.251.4.33
Tcpip\..\Interfaces\{de6bf458-82d4-437c-b691-e4788b1d8860}: [DhcpNameServer] 192.168.3.1
Tcpip\..\Interfaces\{e4ac0910-dbab-4e8d-9f4c-4bf25067bab5}: [DhcpNameServer] 147.251.199.1

Internet Explorer:
==================
HKU\S-1-5-21-1228448097-215964479-906076251-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-1228448097-215964479-906076251-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-04-24] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-04-24] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-20] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1228448097-215964479-906076251-1001 -> hxxp://www.seznam.cz/

FireFox:
========
FF DefaultProfile: yevugtxg.default-1509452420247
FF ProfilePath: C:\Users\VĂ­t\AppData\Roaming\Mozilla\Firefox\Profiles\odwiweru.default [not found] <==== ATTENTION
FF ProfilePath: C:\Users\VĂ­t\AppData\Roaming\Mozilla\Firefox\Profiles\yevugtxg.default-1509452420247 [2018-04-26]
FF Homepage: Mozilla\Firefox\Profiles\yevugtxg.default-1509452420247 -> www.seznam.cz
FF Extension: (Avast SafePrice) - C:\Users\VĂ­t\AppData\Roaming\Mozilla\Firefox\Profiles\yevugtxg.default-1509452420247\Extensions\sp@avast.com.xpi [2018-03-08]
FF Extension: (Avast Online Security) - C:\Users\VĂ­t\AppData\Roaming\Mozilla\Firefox\Profiles\yevugtxg.default-1509452420247\Extensions\wrc@avast.com.xpi [2017-10-06]
FF Extension: (Adblock Plus) - C:\Users\VĂ­t\AppData\Roaming\Mozilla\Firefox\Profiles\yevugtxg.default-1509452420247\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-04-24]
FF ProfilePath: C:\Users\VĂ­t\AppData\Roaming\Flickr\Flickr Uploadr\Profiles\4hwxug34.default [2013-08-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_140.dll [2018-04-12] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-09-19] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_140.dll [2018-04-12] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-07] (Adobe Systems, Inc.)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-09-19] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\VĂ­t\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @talk.google.com/O1DPlugin -> C:\Users\VĂ­t\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @tools.google.com/Google Update;version=3 -> C:\Users\VĂ­t\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-04-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @tools.google.com/Google Update;version=9 -> C:\Users\VĂ­t\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-04-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\VĂ­t\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\VĂ­t\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\VĂ­t\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\VĂ­t\AppData\Local\Google\Chrome\User Data\Default [2018-04-25]
CHR Extension: (CacheList) - C:\Users\VĂ­t\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhhdbdhoghppijbjfdkiaconkmfbbpa [2018-04-16]
CHR Extension: (Dokumenty) - C:\Users\VĂ­t\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-30]
CHR Extension: (Tampermonkey) - C:\Users\VĂ­t\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-04-16]
CHR Extension: (AdBlock) - C:\Users\VĂ­t\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-04-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\VĂ­t\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-16]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43112 2012-02-16] (ArcSoft Inc.)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7603408 2018-04-25] (AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-25] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [313640 2018-04-25] (AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-25] (AVAST Software)
S3 cfbackd; C:\Program Files (x86)\CleverFiles\Disk Drill\cfbackd.w32.exe [211520 2016-09-30] (CleverFiles)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7761584 2018-03-31] (Microsoft Corporation)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593664 2015-06-19] (Samsung Electronics CO., LTD.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [129752 2016-11-11] (ELAN Microelectronics Corp.)
S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1038864 2017-01-09] (Garmin Ltd. or its subsidiaries)
R2 hwifisvc; C:\Program Files (x86)\OSTotoHotspot\hwifisvc.dll [150648 2017-03-13] ()
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R2 irstrtsv; C:\windows\SysWOW64\irstrtsv.exe [193576 2012-07-19] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [38200 2014-12-01] (The OpenVPN Project)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3298208 2017-10-11] (Samsung Electronics Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [196640 2018-04-25] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [227504 2018-04-25] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [199440 2018-04-25] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [343752 2018-04-25] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [57680 2018-04-25] (AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [227784 2018-04-25] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46968 2018-04-25] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [147224 2018-04-25] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111352 2018-04-25] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84368 2018-04-25] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1026696 2018-04-25] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460520 2018-04-25] (AVAST Software)
S2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [205976 2018-04-25] (AVAST Software)
R3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [44640 2014-08-06] (The OpenVPN Project)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [380528 2018-04-25] (AVAST Software)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-04-02] (Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-03-07] (Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-03-07] (Disc Soft Ltd)
S3 ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [32328 2015-09-24] (ELAN Microelectronic Corp.)
S3 GeneStor; C:\WINDOWS\system32\DRIVERS\GeneStor.sys [130648 2018-04-02] (GenesysLogic)
S1 HWifiNetPro; C:\Program Files (x86)\OSTotoHotspot\HWifiNetPro64.sys [175416 2017-03-14] ()
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-04-02] (REALiX(tm))
R3 irstrtdv; C:\WINDOWS\System32\drivers\irstrtdv.sys [43800 2012-07-20] (Intel Corporation)
R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2018-04-02] (Intel Corporation)
R3 RadioHIDMini; C:\WINDOWS\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1026896 2018-04-02] (Realtek )
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-11-23] (Windows (R) 2003 DDK 3790 provider)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2599128 2018-04-02] (Realtek Semiconductor Corp.)
S3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [47944 2018-01-10] (SteelSeries ApS)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2018-04-02] (Samsung Electronics Co., Ltd.)
S3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
R1 WiFiNat; C:\Program Files (x86)\OSTotoHotspot\driver\WiFiNat64.sys [46904 2017-03-15] ()
S3 intaud_WaveExtensible; \SystemRoot\system32\drivers\intelaud.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-26 20:30 - 2018-04-26 20:32 - 000023196 _____ C:\Users\VĂ­t\Desktop\FRST.txt
2018-04-26 20:30 - 2018-04-26 20:30 - 000000000 ____D C:\FRST
2018-04-26 20:28 - 2018-04-26 20:28 - 000112640 _____ (forum.viry.cz) C:\Users\VĂ­t\Desktop\FRSTLauncher.exe
2018-04-26 20:27 - 2018-04-26 20:27 - 002405888 _____ (Farbar) C:\Users\VĂ­t\Desktop\FRST64.exe
2018-04-25 22:02 - 2018-04-25 22:02 - 000002530 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2018-04-25 22:01 - 2018-04-25 22:01 - 000003512 _____ C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineUA
2018-04-25 22:01 - 2018-04-25 22:01 - 000003388 _____ C:\WINDOWS\System32\Tasks\AvastUpdateTaskMachineCore
2018-04-25 22:01 - 2018-04-25 22:01 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\AVAST Software
2018-04-25 22:01 - 2018-04-25 22:01 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2018-04-25 21:54 - 2018-04-25 21:54 - 007256272 _____ (Malwarebytes) C:\Users\VĂ­t\Desktop\adwcleaner_7.1.0.0.exe
2018-04-25 20:16 - 2018-04-25 20:16 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2018-04-25 18:51 - 2018-04-25 18:50 - 000196640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-04-25 18:51 - 2018-04-25 18:48 - 000227784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-04-25 18:50 - 2018-04-25 18:50 - 000376536 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-04-25 16:55 - 2018-04-25 16:55 - 001222144 _____ C:\Users\VĂ­t\Desktop\RSITx64.exe
2018-04-24 13:01 - 2018-04-24 13:01 - 000285374 _____ C:\Users\VĂ­t\Desktop\echinacin-sirup-spc.pdf
2018-04-24 11:31 - 2018-04-24 11:31 - 000000000 ____D C:\Users\Vít\Desktop\Infekční lékařství
2018-04-24 11:26 - 2018-04-24 11:27 - 424149340 _____ C:\Users\Vít\Desktop\Infekční lékařství.zip
2018-04-24 11:20 - 2018-04-24 11:20 - 009403473 _____ C:\Users\VĂ­t\Desktop\Medici_VH_2018.pdf
2018-04-24 11:07 - 2014-12-28 12:44 - 006251313 _____ C:\Users\Vít\Desktop\DERMA specka Novák.pdf
2018-04-24 11:06 - 2018-04-24 11:06 - 007838368 _____ C:\Users\VĂ­t\Desktop\Archive-3e7c.zip
2018-04-24 10:11 - 2018-04-24 10:11 - 016895342 _____ C:\Users\VĂ­t\Desktop\moravsky-kras-byci-skala.pdf
2018-04-24 09:32 - 2018-04-26 12:40 - 000003338 _____ C:\WINDOWS\System32\Tasks\Intel® Rapid Start Technology Manager
2018-04-13 13:39 - 2018-04-13 13:39 - 000000427 _____ C:\Users\VĂ­t\Desktop\Anesthetic_Agnets_Used_in_TCI.bibtex
2018-04-13 13:39 - 2018-04-13 13:39 - 000000399 _____ C:\Users\VĂ­t\Desktop\Anesthetic_Agnets_Used_in_TCI.ris
2018-04-13 13:39 - 2018-04-13 13:39 - 000000364 _____ C:\Users\VĂ­t\Desktop\Anesthetic_Agnets_Used_in_TCI.enw
2018-04-12 13:37 - 2018-04-12 12:32 - 127218304 _____ C:\Users\VĂ­t\Desktop\MVI_0077.MP4
2018-04-12 11:07 - 2018-04-12 11:07 - 000000000 ____D C:\Users\VĂ­t\Desktop\johana-20180412T084736Z-001
2018-04-12 10:51 - 2018-04-12 08:28 - 108967900 _____ C:\Users\VĂ­t\Desktop\uzel2 pripravapristroje, enverze.mp4
2018-04-12 10:47 - 2018-04-12 10:48 - 103639380 _____ C:\Users\VĂ­t\Desktop\johana-20180412T084736Z-001.zip
2018-04-12 10:42 - 2018-04-12 10:48 - 218290223 _____ C:\Users\VĂ­t\Desktop\zasilka-XS9M28YWZ44ZTVV4.zip
2018-04-12 10:33 - 2018-04-12 10:37 - 038886407 _____ C:\Users\VĂ­t\Desktop\uzel2, priprava pristroje, ceskaverze.mp4.part
2018-04-12 10:33 - 2018-04-12 08:28 - 109321963 _____ C:\Users\VĂ­t\Desktop\uzel2, priprava pristroje, ceskaverze.mp4
2018-04-11 08:41 - 2018-04-11 08:41 - 000947489 _____ C:\Users\VĂ­t\Desktop\wwwyhlidka.pdf
2018-04-11 08:39 - 2018-04-11 08:39 - 002582026 _____ C:\Users\VĂ­t\Desktop\vyhlidka.pdf
2018-04-07 09:20 - 2018-04-07 09:20 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\TempOfficeC2RA39A7ECB-0321-4815-91DB-C9FFB0C32193
2018-04-07 09:07 - 2018-04-06 20:10 - 019713250 _____ C:\Users\VĂ­t\Desktop\IMG_0019.CR2
2018-04-07 09:04 - 2018-04-07 09:04 - 000003076 _____ C:\WINDOWS\System32\Tasks\UMonitor Task
2018-04-07 09:04 - 2018-04-07 09:04 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2018-04-07 09:04 - 2018-04-07 09:04 - 000000000 ____D C:\WINDOWS\LastGood
2018-04-07 09:04 - 2018-04-07 09:04 - 000000000 ____D C:\Program Files (x86)\Genesys Logic
2018-04-07 09:02 - 2018-02-21 15:28 - 000033170 _____ C:\Users\VĂ­t\AppData\Local\cme.js
2018-04-06 12:44 - 2018-04-06 12:44 - 000000000 ___HD C:\$AV_ASW
2018-04-06 12:20 - 2018-04-06 12:20 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\VideoEditorPlus
2018-04-06 12:20 - 2018-04-06 12:20 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\Movavi
2018-04-06 12:19 - 2018-04-06 12:19 - 000001204 _____ C:\Users\Public\Desktop\Movavi Video Editor 14 Plus.lnk
2018-04-06 12:19 - 2018-04-06 12:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 14 Plus
2018-04-06 12:18 - 2018-04-06 12:19 - 000000000 ____D C:\Program Files (x86)\Movavi Video Editor 14 Plus
2018-04-06 12:16 - 2018-04-06 12:17 - 000000000 ____D C:\Users\VĂ­t\Downloads\Movavi Video Editor Plus 14.1.0 + Crack [CracksNow]
2018-04-06 12:14 - 2018-04-06 12:14 - 000004878 _____ C:\ProgramData\mklddvci.gqu
2018-04-06 12:14 - 2018-04-06 12:14 - 000003494 _____ C:\WINDOWS\System32\Tasks\Skype
2018-04-06 12:14 - 2018-04-06 12:14 - 000000016 _____ C:\ProgramData\mntemp
2018-04-06 12:14 - 2018-04-06 12:14 - 000000000 ____D C:\ProgramData\Movavi Video Editor 14 Plus
2018-04-06 12:13 - 2018-04-06 12:13 - 000000000 ____D C:\Users\VĂ­t\Desktop\Movavi Video Editor Plus 14.3.0 With Crack Is Here !
2018-04-06 12:07 - 2018-04-06 12:07 - 000000000 ____D C:\Users\VĂ­t\AppData\Roaming\MOVAVI
2018-04-06 12:04 - 2018-04-06 12:04 - 000000000 ____D C:\Users\VĂ­t\Desktop\Movavi Video Editor (with Crack)
2018-04-06 12:04 - 2018-04-06 12:04 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\Downloaded Installations
2018-04-06 12:01 - 2018-04-07 09:02 - 000000000 ____D C:\Users\VĂ­t\AppData\LocalLow\uTorrent
2018-04-06 11:48 - 2018-04-06 11:48 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\Wondershare
2018-04-06 11:48 - 2018-04-06 11:48 - 000000000 ____D C:\ProgramData\Wondershare
2018-04-06 11:47 - 2018-04-06 11:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2018-04-06 11:46 - 2018-04-06 11:55 - 000000000 ____D C:\Users\VĂ­t\Documents\Wondershare Filmora
2018-04-06 11:46 - 2018-04-06 11:46 - 000000000 ____D C:\ProgramData\Wondershare Video Editor
2018-04-06 11:46 - 2018-04-06 11:46 - 000000000 ____D C:\Program Files (x86)\Wondershare
2018-04-06 11:46 - 2017-03-17 11:43 - 001250304 _____ (CineForm Inc.) C:\WINDOWS\system32\CFDecode64.ax
2018-04-06 11:45 - 2018-04-06 11:48 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-04-05 15:33 - 2018-04-05 15:33 - 002021271 _____ C:\Users\VĂ­t\Desktop\17_Imunologie_magistri_Sliznicni_a_kozni_imunita.pdf
2018-04-05 14:22 - 2018-04-05 14:22 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2018-04-05 14:16 - 2018-04-05 14:16 - 000984665 _____ C:\Users\Vít\Desktop\DERMA-OBECNÁ.pdf
2018-04-02 20:38 - 2018-04-02 20:38 - 000003214 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_RUNEP
2018-04-02 20:35 - 2018-04-02 20:35 - 007172904 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 007096184 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 003509192 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 003205120 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 003135776 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 002922976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001965808 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001780616 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001591056 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001508928 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001348160 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000965016 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000743960 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000727432 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000708304 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000691672 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000532376 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000504296 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000447712 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000445392 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000441264 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000387304 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000343704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000327448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000321712 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000321704 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000272712 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000253896 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000253856 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000252864 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000231912 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000221960 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000214824 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000209528 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000192976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000166200 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000151784 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000134192 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000122312 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000110976 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000090912 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000088336 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000088312 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000084608 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000083616 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2018-04-02 20:34 - 2018-04-02 20:34 - 072520704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2018-04-02 20:34 - 2018-04-02 20:34 - 013831786 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2018-04-02 20:34 - 2018-04-02 20:34 - 003677152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2018-04-02 20:34 - 2018-04-02 20:34 - 000166288 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2018-04-02 20:34 - 2018-04-02 20:34 - 000131984 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus.sys
2018-04-02 20:33 - 2018-04-02 20:33 - 008108584 _____ C:\WINDOWS\system32\Drivers\Netwfw01.dat
2018-04-02 20:33 - 2018-04-02 20:33 - 005636288 _____ (Genesys) C:\WINDOWS\system32\GeneIcon.dll
2018-04-02 20:33 - 2018-04-02 20:33 - 003354384 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\NETwew01.sys
2018-04-02 20:33 - 2018-04-02 20:33 - 001804688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2018-04-02 20:33 - 2018-04-02 20:33 - 000159432 _____ (Genesys Logic) C:\WINDOWS\system32\GSCoinst.dll
2018-04-02 20:33 - 2018-04-02 20:33 - 000130648 _____ (GenesysLogic) C:\WINDOWS\system32\Drivers\GeneStor.sys
2018-04-02 20:32 - 2018-04-02 20:32 - 002628312 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtCamU64.exe
2018-04-02 20:32 - 2018-04-02 20:32 - 002599128 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\rtsuvc.sys
2018-04-02 20:32 - 2018-04-02 20:32 - 001971928 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsDecode.dll
2018-04-02 20:32 - 2018-04-02 20:32 - 000507096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCamX64.dll
2018-04-02 20:32 - 2018-04-02 20:32 - 000448728 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RtCamX.dll
2018-04-02 20:32 - 2018-04-02 20:32 - 000168152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtsCM64.exe
2018-04-02 20:23 - 2018-04-02 20:23 - 000000000 ____D C:\WINDOWS\IObit
2018-04-02 20:23 - 2018-04-02 20:23 - 000000000 ____D C:\ProgramData\ProductData
2018-04-02 20:22 - 2018-04-25 20:14 - 000003010 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (VĂ­t)
2018-04-02 20:22 - 2018-04-02 20:24 - 000000000 ____D C:\Users\VĂ­t\AppData\LocalLow\IObit
2018-04-02 20:22 - 2018-04-02 20:22 - 000027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2018-04-02 20:22 - 2018-04-02 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 5
2018-04-02 20:22 - 2018-04-02 20:22 - 000000000 ____D C:\Program Files (x86)\IObit
2018-04-02 20:21 - 2018-04-25 21:56 - 000000000 ____D C:\Users\VĂ­t\AppData\Roaming\IObit
2018-04-02 20:20 - 2018-04-02 20:24 - 000000000 ____D C:\ProgramData\IObit
2018-04-02 20:20 - 2018-04-02 20:20 - 000000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
2018-04-02 19:59 - 2018-03-02 23:09 - 000834552 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-04-02 19:59 - 2018-03-02 23:09 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-04-02 19:51 - 2018-04-02 19:52 - 000000000 ____D C:\Users\VĂ­t\Desktop\lezenĂ­

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-26 20:25 - 2017-12-04 23:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-04-26 20:25 - 2016-11-16 20:34 - 000000000 ____D C:\Users\VĂ­t\AppData\LocalLow\Mozilla
2018-04-26 20:14 - 2013-11-01 19:06 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\CrashDumps
2018-04-26 12:43 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-04-26 12:42 - 2017-09-29 15:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-04-26 12:42 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-04-26 12:39 - 2012-08-24 09:46 - 000000000 ____D C:\ProgramData\WinClon
2018-04-26 12:35 - 2017-05-26 22:47 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\ConnectedDevicesPlatform
2018-04-26 12:34 - 2014-06-11 11:27 - 000000000 __SHD C:\Users\VĂ­t\IntelGraphicsProfiles
2018-04-26 12:34 - 2014-06-05 12:55 - 000000675 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2018-04-26 12:33 - 2017-12-05 00:11 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-04-26 09:55 - 2017-09-29 10:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-04-25 22:04 - 2013-02-02 12:45 - 000000000 ____D C:\ProgramData\AVAST Software
2018-04-25 21:55 - 2017-01-14 17:23 - 000000000 ____D C:\AdwCleaner
2018-04-25 20:17 - 2017-12-04 21:48 - 000147224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-04-25 19:04 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-04-25 18:53 - 2017-12-05 00:11 - 000003990 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2018-04-25 18:50 - 2017-12-04 21:48 - 000460520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000380528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000205976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000111352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000084368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000046968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-04-25 18:49 - 2017-12-04 21:48 - 001026696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000343752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000227504 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000199440 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000057680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2018-04-25 16:56 - 2016-12-04 13:02 - 000000000 ____D C:\Program Files\trend micro
2018-04-25 16:53 - 2017-09-29 15:44 - 000000000 ____D C:\WINDOWS\INF
2018-04-25 16:53 - 2016-10-07 16:04 - 000000000 ____D C:\Users\VĂ­t\AppData\Roaming\uTorrent
2018-04-24 09:37 - 2017-09-29 15:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-04-24 09:33 - 2013-12-22 12:17 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-04-18 15:36 - 2017-09-29 15:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-04-16 09:15 - 2017-11-16 22:32 - 000000000 ____D C:\Users\VĂ­t\AppData\Roaming\Google
2018-04-15 21:58 - 2017-12-04 23:38 - 000000000 ____D C:\Users\VĂ­t\AppData\Local\Packages
2018-04-15 21:04 - 2013-01-17 17:18 - 000002525 _____ C:\Users\VĂ­t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-04-15 21:04 - 2013-01-17 17:18 - 000002488 _____ C:\Users\VĂ­t\Desktop\Google Chrome.lnk
2018-04-15 20:58 - 2017-12-05 00:11 - 000003752 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA1d268b54d11dc93
2018-04-15 20:58 - 2017-12-05 00:11 - 000003484 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core1d268b54cb52839
2018-04-12 23:55 - 2017-12-04 23:37 - 000000000 ____D C:\Users\VĂ­t
2018-04-12 20:16 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\rescache
2018-04-12 17:25 - 2017-10-23 21:01 - 000000000 ____D C:\Users\VĂ­t\Desktop\TCI
2018-04-12 10:20 - 2018-03-14 15:04 - 000004700 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-04-12 10:20 - 2017-12-05 00:11 - 000004470 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-04-12 10:19 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-04-12 10:19 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-04-11 13:58 - 2013-01-17 18:26 - 000000000 ____D C:\Users\VĂ­t\AppData\Roaming\Skype
2018-04-11 10:10 - 2013-08-21 13:45 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-04-11 09:41 - 2017-10-11 17:33 - 136971704 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-04-11 09:41 - 2013-01-18 18:57 - 136971704 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-04-07 08:59 - 2017-12-04 23:31 - 000398752 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-04-05 21:23 - 2017-09-29 10:45 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-04-03 20:28 - 2017-12-05 00:04 - 002237562 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-04-03 20:28 - 2017-09-30 16:31 - 000991622 _____ C:\WINDOWS\system32\perfh005.dat
2018-04-03 20:28 - 2017-09-30 16:31 - 000221494 _____ C:\WINDOWS\system32\perfc005.dat
2018-04-02 20:56 - 2018-01-28 13:20 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-04-02 20:56 - 2013-01-23 16:47 - 000000000 ___RD C:\Users\VĂ­t\Desktop\OstatnĂ­
2018-04-02 20:38 - 2017-12-05 00:11 - 000003216 _____ C:\WINDOWS\System32\Tasks\RTKCPL
2018-04-02 20:38 - 2015-09-23 16:52 - 001026896 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2018-04-02 20:36 - 2017-05-26 22:02 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-04-02 20:35 - 2015-09-19 08:14 - 005995944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2018-04-02 20:35 - 2015-09-19 08:14 - 003561920 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2018-04-02 20:35 - 2015-09-19 08:14 - 000023688 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2018-04-02 20:33 - 2015-07-01 21:17 - 000080144 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\ibtfltcoex.sys
2018-04-02 20:29 - 2015-07-07 20:45 - 000186424 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2018-04-02 20:03 - 2015-12-13 15:10 - 000000000 ___RD C:\Users\VĂ­t\3D Objects
2018-04-02 20:03 - 2013-01-17 15:46 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-04-02 19:57 - 2013-02-17 20:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-04-02 19:51 - 2017-01-24 21:53 - 000000000 ___RD C:\Users\VĂ­t\Desktop\ARO
2018-03-27 21:55 - 2015-08-31 07:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-03-27 21:55 - 2013-02-17 20:35 - 000001175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk

==================== Files in the root of some directories =======

2013-01-17 16:56 - 2013-01-18 17:12 - 000001507 _____ () C:\Users\VĂ­t\AppData\Roaming\AbsoluteReminder.xml
2018-04-07 09:02 - 2018-02-21 15:28 - 000033170 _____ () C:\Users\VĂ­t\AppData\Local\cme.js
2013-11-19 21:38 - 2013-11-19 21:38 - 000000758 _____ () C:\Users\VĂ­t\AppData\Local\recently-used.xbel
2013-02-17 16:08 - 2013-03-24 11:11 - 000007602 _____ () C:\Users\VĂ­t\AppData\Local\resmon.resmoncfg

Some files in TEMP:
====================
2018-04-25 22:05 - 2018-04-25 22:00 - 002661920 _____ () C:\Users\VĂ­t\AppData\Local\Temp\removeSZB.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core.job => C:\Users\VĂ­t\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA.job => C:\Users\VĂ­t\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Vˇt\Desktop" je 5151 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================


Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018
Ran by Vít (26-04-2018 20:33:35)
Running from C:\Users\Vít\Desktop
Windows 10 Home Version 1709 16299.248 (X64) (2017-12-04 22:12:45)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1228448097-215964479-906076251-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1228448097-215964479-906076251-503 - Limited - Disabled)
Guest (S-1-5-21-1228448097-215964479-906076251-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1228448097-215964479-906076251-1003 - Limited - Enabled)
Vít (S-1-5-21-1228448097-215964479-906076251-1001 - Administrator - Enabled) => C:\Users\Vít
WDAGUtilityAccount (S-1-5-21-1228448097-215964479-906076251-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\uTorrent) (Version: 3.5.0.44090 - BitTorrent Inc.)
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.1.0.8 - Absolute Software)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe Flash Player 29 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 29.0.0.140 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
ANT Drivers Installer x64 (HKLM\...\{6941244D-9995-4279-9281-4AD2EC7BD260}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Aplikace Intel® PROSet/Wireless (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
ArcSoft Panorama Maker 5 (HKLM-x32\...\{31B620F7-A6E7-4F91-AF10-6EC9DB2EA564}) (Version: 5.0.0.21 - ArcSoft)
ArcSoft Panorama Maker 6 (HKLM-x32\...\{8A7D0970-C0A4-4B56-94D4-E3A175AB45BB}) (Version: 6.0.0.94 - ArcSoft)
ATLAS Czech 2010 NT (HKLM-x32\...\{8AC5EBE3-DAD6-4968-AE53-98E6E9CAAFE9}) (Version: 9.00 - Picodas Praha, spol. s r.o.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.3.2333 - AVAST Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 65.0.412.162 - AVAST Software)
Baidu WiFi Hotspot (HKLM-x32\...\Baidu WiFi Hotspot) (Version: 5.1.4.124910 - Baidu, Inc.)
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Bandizip (HKLM\...\Bandizip) (Version: 6.12 - Bandisoft.com)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.64.1073 - AB Team, d.o.o.)
Bullzip PDF Printer 10.12.0.2361 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.12.0.2361 - Bullzip)
calibre (HKLM-x32\...\{B76A3B8A-CD1E-4260-BA4A-6A6EAA05715D}) (Version: 2.82.0 - Kovid Goyal)
CardRecovery (HKLM-x32\...\CardRecovery) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.41 - Piriform)
cGPSmapper Free 0100d (HKLM-x32\...\cGPSmapper Free_is1) (Version: - cGPSmapper)
CrystalDiskMark 3.0.3b (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.3b - Crystal Dew World)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Disk Drill 2.0.0.268 (HKLM-x32\...\{7A2A09EC-2485-4D6B-99BE-46AAAB400435}) (Version: 2.0.268 - CleverFiles)
Driver Booster 5 (HKLM-x32\...\Driver Booster_is1) (Version: 5.3.0 - IObit)
ELAN Touchpad driver X64 15.7.9.2_WHQL (HKLM\...\Elantech) (Version: 15.7.9.2 - ELAN Microelectronic Corp.)
Elevated Installer (HKLM-x32\...\{86E80D52-6DD3-4604-8CE9-4E7C2951151F}) (Version: 5.1.0.0 - Garmin Ltd or its subsidiaries) Hidden
E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.)
ExpressCache (HKLM\...\{3EA6AB5D-D434-4ACA-9609-48F1319518EF}) (Version: 1.0.94 - Condusiv Technologies)
Fast Flash Sleep Resume (HKLM-x32\...\{0FE5A4D8-08BF-4D73-AB4B-2820D637E02E}) (Version: 1.1.1 - Samsung) Hidden
Fotogaléria (HKLM-x32\...\{9093B0D5-EA59-4C9E-A2E3-CC130138DFCD}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerie (HKLM-x32\...\{A1FBD2B3-6768-472D-BA46-C00EACBCE16C}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (HKLM-x32\...\{1F0C818D-4A41-4E40-BAFB-BB940C82A518}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (HKLM-x32\...\{E50E3DBC-46AA-4827-B2A6-F995D81DF526}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Foxit PDF Editor (HKLM-x32\...\Foxit PDF Editor) (Version: 2.2.0.0205 - Foxit Software)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.2.8.1124 - Foxit Software Inc.)
FreeCommander XE (HKLM-x32\...\FreeCommander XE_is1) (Version: - Marek Jasinski)
Galerija fotografija (HKLM-x32\...\{C5B383EB-B85B-481C-9946-34FBF021678B}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Garmin BaseCamp (HKLM-x32\...\{EBAC8FD4-28EC-46F7-BF9E-89D6E6673001}) (Version: 4.2.5 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin (HKLM-x32\...\{032A13FF-D26D-4844-9597-7EF698627985}) (Version: 4.1.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{AFA301E1-B410-4F1B-B1C0-2E92FDCD94AD}) (Version: 4.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{7f65fe7f-fcc6-4c75-b83f-837e06afbc8c}) (Version: 5.1.0.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{DA9DAB72-69A7-4C9A-97A5-EC5865DF72CA}) (Version: 5.1.0.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (HKLM-x32\...\{984D1622-C082-445B-8A40-4A8788616E6E}) (Version: 5.1.0.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin MapSource (HKLM-x32\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin WebUpdater (HKLM-x32\...\{AE1EC58E-B2AC-4959-A4C2-C38202A25239}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries)
GeoGet verze 2.9.3.760 (HKLM-x32\...\GeoGet_is1) (Version: 2.9.3.760 - )
Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Chrome (HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Help Desk (HKLM\...\{C85A891D-7AB4-46AE-84F0-B0C3FAC82280}) (Version: 1.0.4 - Samsung Electronics CO., LTD.)
HP Deskjet 3520 series Nápověda (HKLM-x32\...\{D259C419-D776-4163-B27C-19722C555237}) (Version: 27.0.0 - Hewlett Packard)
HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7854AA22-A2F0-4F29-A2E9-D0C5A2B685E7}) (Version: 2.5.0.0248 - Motorola Solutions, Inc)
Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 2.1.0.1002 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.2.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation)
Jpeg Resampler Vs 6+ (HKLM-x32\...\JpegResampler2010_is1) (Version: - Jpeg Resampler)
JPEGmini 1.2.21.5 (HKLM-x32\...\JPEGmini 1.2.21.5) (Version: - )
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 365 ProPlus - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.8431.2242 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\OneDriveSetup.exe) (Version: 18.025.0204.0009 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Movavi Video Editor 14 Plus (HKLM-x32\...\Movavi Video Editor 14 Plus) (Version: 14.1.0 - Movavi)
Movie Maker (HKLM-x32\...\{719E4DA1-A17B-4B46-9D5D-925D4FBE4D69}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{751EB657-3F22-4150-8CE4-D79A262F1D92}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{8E6E8CBB-8E58-493C-943F-4664F5F2FEDB}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{9EDF46F0-2D4E-4C00-B2B6-0660666E9F60}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{A035950F-15BA-41C0-9D8F-165FC0536012}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{A47EA9D4-BB87-415E-9239-28860434E5A0}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{ED6C77F9-4D7E-447C-9EC0-9A212D075535}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 59.0.2.6656 - Mozilla)
MPC-HC 1.7.5 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.5 - MPC-HC Team)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8431.2242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
OpenVPN 2.3.6-I601 (HKLM\...\OpenVPN) (Version: 2.3.6-I601 - )
OpenVPN 64-bit (HKLM\...\{8EC02EDC-25C6-400C-91BC-2A5E90F13B99}) (Version: 1.2.0 - ÚVT MU)
OSTotoHotspot (HKLM-x32\...\OSTotoHotspot) (Version: 4.4.0.2 - )
PdfMerge (HKLM-x32\...\{238BE990-A412-4129-A434-D03B1A9E396E}) (Version: 1.22.0 - PdfMerge)
RajcePhotoDownloader (HKLM-x32\...\RajcePhotoDownloader_is1) (Version: verze - Rajce.net)
rajče průvodce verze 1.59.45.260 (HKLM-x32\...\rajče.net_is1) (Version: - rajče.net)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8264 - Realtek Semiconductor Corp.)
Realtek PC Camera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10291 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.1.0.3 - Samsung Electronics CO., LTD.)
RO.A.D.2008 (HKLM-x32\...\{A1D7AC59-0B14-4B41-B0A4-08D0308147C8}) (Version: 3.01 - SHEBA DISTRIBUTION SRL ROMANIA)
S Agent (HKLM\...\{061881E0-653B-41CA-839E-2BA6569B5FEE}) (Version: 1.1.69 - Samsung Electronics Co., Ltd.) Hidden
Sada Compatibility Pack pro systém Office 2007 (HKLM-x32\...\{90120000-0020-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.)
Samsung Settings (HKLM-x32\...\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
Samsung Update (HKLM-x32\...\{05068BA6-4AAB-4A47-8BAD-2141F4E9C15D}) (Version: 2.2.52 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Slovakia_Topo_v3_Beta2 (HKLM-x32\...\{3862105D-1AD3-470D-9CE5-94A2DB91D6CC}) (Version: 1.00 - CONAN s.r.o.)
Sony PC Companion 2.10.289 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.289 - Sony)
Stellarium 0.15.1.1 (HKLM\...\Stellarium_is1) (Version: 0.15.1.1 - Stellarium team)
Support Center FAQ (HKLM-x32\...\{5547725A-B333-475C-93C7-3B89267A72D4}) (Version: 1.0.0 - Samsung Electronics CO., LTD.) Hidden
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TAP-Windows 9.21.1 (HKLM\...\TAP-Windows) (Version: 9.21.1 - )
TivaTrainer version 9.1.4 (HKLM-x32\...\Tivatrainer_is1) (Version: - )
TOPO Czech 2 PRO (HKLM-x32\...\{24EE52EA-A74F-4770-ACFA-E1583B8FB665}) (Version: 2.00 - Picodas Praha, spol. s r.o.)
TOPO Czech 3 PRO (HKLM-x32\...\{4F50C25D-9236-42EE-86A4-F0BC39A543AE}) (Version: 3.00 - Picodas Praha, spol. s r.o.)
TrekMap v2 (HKLM-x32\...\{46E7E808-5AD2-44B6-B52C-68EB15182D8A}) (Version: 2.07 - Garmin Italia S.p.A.)
Unity Web Player (HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\UnityWebPlayer) (Version: 5.3.7f1 - Unity Technologies ApS)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.5.1 - VideoLAN)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (07/27/2012 20.57.1.735) (HKLM\...\9F04C462DAB591BDCCE784F77E4D4F1736010B92) (Version: 07/27/2012 20.57.1.735 - Samsung Electronics Co. Ltd.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Wondershare Filmora(Build 8.5.3) (HKLM\...\Wondershare Filmora_is1) (Version: - Wondershare Software)
Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare)
Základní software zařízení HP Deskjet 3520 series (HKLM\...\{7EBD8BA7-DF64-4BF9-9BC1-B0D53984FC6E}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Zoner Photo Studio 17 (HKLM\...\ZonerPhotoStudio17_CZ_is1) (Version: 17.0.1.12 - ZONER software)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1804.2.61 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{5B69A6B4-393B-459C-8EBB-214237A9E7AC}\InprocServer32 -> C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll (Bandisoft.com)
CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Vít\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-25] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-25] (AVAST Software)
ContextMenuHandlers1: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-25] (AVAST Software)
ContextMenuHandlers1: [JRcm] -> [CC]{C20B9A7B-ED5B-4CEB-B2A6-F1F62E99C539} => -> No File
ContextMenuHandlers1: [JRcm64] -> [CC]{013BF2A8-A4B1-11DF-A865-F509E0D72085} => -> No File
ContextMenuHandlers2: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-25] (AVAST Software)
ContextMenuHandlers4: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers5: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-25] (AVAST Software)
ContextMenuHandlers1_S-1-5-21-1228448097-215964479-906076251-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers2_S-1-5-21-1228448097-215964479-906076251-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers4_S-1-5-21-1228448097-215964479-906076251-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)
ContextMenuHandlers5_S-1-5-21-1228448097-215964479-906076251-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Users\Vít\AppData\Local\Bandizip\bdzshl64.dll [2018-02-18] (Bandisoft.com)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {026E045E-49F8-4432-BCCC-D774986AF0B8} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {08D26043-0454-4125-A5FB-E4ED21D803EB} - System32\Tasks\{72B163FC-830D-4FAB-BBFD-F5F6E48A9B98} => "c:\users\vít\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.3.0.105/cs/go/help.faq.installer?LastError=1603
Task: {0A242F09-C35C-4CE2-8700-265BA1396A85} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-20] ()
Task: {152A8229-FCF2-4F83-BC59-9C5C5FEE4E66} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core => C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {18260F88-449B-4FBB-87D3-081D7D6D83B7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core1d268b54cb52839 => C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {188087B0-D7DD-4DA6-9D6F-A275DB270ABA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-20] ()
Task: {1C8992D7-7104-41B6-A08B-519269A255B8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {1DF15264-4F8E-456B-BA38-EBB65657DF50} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {29E74C2F-8C9F-41B3-9364-163CCD522B99} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2017-04-26] (Samsung Electronics Co., Ltd.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {36CC1422-34BE-4411-8FEA-7B09085534CA} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {392843CD-E3BE-4B2A-89F9-C83736DF065F} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-07-19] (Intel)
Task: {40144BE5-479A-44BC-BE09-96A033EFB749} - System32\Tasks\Baidu LiveUpdate => C:\Program [Argument = Files (x86)\Baidu WiFiHotspot\liveupdate.exe]
Task: {416BB528-8C80-40CE-BF65-3A1036208D73} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA => C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {532C5D72-0357-4F71-82C2-378A96BFA891} - System32\Tasks\RtHDVBg_RUNEP => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2018-04-02] (Realtek Semiconductor)
Task: {55F9AD24-571F-4C23-B009-BFE77BC757D5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {5F055261-1E69-4A76-B97D-65DC1906FD2B} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {62567BA9-3174-449A-914C-32DC54C44C5B} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-01-09] ()
Task: {6684D558-6280-49DF-BFCA-2DEF5BB59F9A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {686FC84C-A1FB-466D-A14B-5D408FBBC818} - System32\Tasks\{800840B2-3E7C-487E-A324-C49F8084C47A} => "c:\users\vít\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.3.0.105/cs/go/help.faq.installer?LastError=1603
Task: {6A7513AD-E497-4543-B6F2-A3A024AD194E} - System32\Tasks\Skype => C:\Users\Vít\AppData\Local\cme.js [2018-02-21] ()
Task: {6DEBCD08-635D-4180-B5EF-D3E8302EE500} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2018-04-02] (Realtek Semiconductor)
Task: {733C7078-1F3B-408A-B238-2A11EA761199} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.)
Task: {75A1D77F-91FB-4DEB-87BB-3C1BD3988BD7} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [2018-04-25] (AVAST Software)
Task: {7ACF3036-5A2A-4FC4-B2F9-D970F402B9D4} - System32\Tasks\{F19030B5-A882-4656-A8E1-6E6C3660DAC9} => "c:\users\vít\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.3.59.105/cs/go/help.faq.installer?LastError=1603
Task: {7D9522C2-107B-46CC-A1C0-CE3BC88DA62C} - System32\Tasks\UMonitor Task => C:\WINDOWS\SysWOW64\UMonit64.exe
Task: {8039C7B7-5F13-4C8F-AFCA-E26DB7B93477} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {82E127F8-9AB4-4071-ABF7-854C9BD5916B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-03-31] (Microsoft Corporation)
Task: {8458CCF4-F652-423A-893B-B614CDFF1B48} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-03-31] (Microsoft Corporation)
Task: {85E83B56-0570-4D70-AE4C-7CEA0862BE61} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-03-06] (Piriform Ltd)
Task: {8D97C423-A58A-44D7-88A4-CF5D646599DE} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_140_Plugin.exe [2018-04-12] (Adobe Systems Incorporated)
Task: {917F7559-CBF9-4BB8-95E2-81F4409E8253} - System32\Tasks\Driver Booster SkipUAC (Vít) => C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe [2018-03-22] (IObit)
Task: {921E9F4D-3637-46E7-B0E2-C39A293CEF6B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {9308027B-63E6-471F-8CDA-B2A143E8FC61} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-04-24] (Microsoft Corporation)
Task: {97340CC0-20C1-46F5-9C15-F9F38427316F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9CA55D94-EC59-470D-A667-96F6BB329065} - System32\Tasks\{C267871B-DEB6-407E-BE18-81192543BF39} => "c:\users\vít\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.3.0.105/cs/go/help.faq.installer?LastError=1603
Task: {9FC204D6-2172-4DAC-ACC5-0DA571D94C3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {AAA9242A-C948-4034-944D-CE07FFE87C8E} - System32\Tasks\FFSRConfigurer => C:\Program Files (x86)\Samsung\Fast Flash Sleep Resume\FFSRConfigurer.exe [2012-08-22] (Samsung)
Task: {AB1F24C4-74B0-4586-A25B-4A454DEA83F3} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {AD6AC390-A4E6-4D56-92C2-22A199B660E5} - System32\Tasks\{1F30E8EF-DB5D-4BF3-B4A6-45030AAB22A5} => "c:\users\vít\appdata\local\google\chrome\application\chrome.exe" hxxp://ui.skype.com/ui/0/6.3.59.105/cs/go/help.faq.installer?LastError=1603
Task: {AE34020A-E773-4E6F-AD67-AF241A94C777} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA1d268b54d11dc93 => C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AE6D4102-FA2D-41D8-893D-548689FAE7F1} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\avast software\overseer\overseer.exe [2018-04-18] (AVAST Software)
Task: {B5F326B9-52F1-4B2D-91F8-3B82791C6A27} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2016-07-05] (SEC)
Task: {B7F717AE-14A8-4C9A-9EA3-84BD53987E18} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-04-12] (Adobe Systems Incorporated)
Task: {B93E12B9-E7FA-456C-BE43-7399AC678BAE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-04-24] (Microsoft Corporation)
Task: {BD511D87-B8A0-4EB1-806E-3E2137C6F532} - \Driver Booster Scheduler -> No File <==== ATTENTION
Task: {BD60E0BB-5FB9-4F62-966A-938E3CBA9BB6} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-04-25] (AVAST Software)
Task: {BED363CD-BDA8-4F21-9059-FF2AEBA4F681} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [2018-04-25] (AVAST Software)
Task: {BFE351A9-45DA-49FA-9050-29980BE60387} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2015-06-19] (Samsung Electronics CO., LTD.)
Task: {C1A00206-356B-459D-8935-D121DBE7F802} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {C233C533-6AF7-4B6A-8A22-589DF40E6A0C} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2018-02-02] (AVAST Software)
Task: {CAD43A58-59F4-46EF-906C-D9E348D08044} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-04-24] (Microsoft Corporation)
Task: {CC07185C-E5E7-45EC-9EC6-68A01491325A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-02] (Google Inc.)
Task: {DC5909EB-333F-4619-8E9C-189482A7476B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {EB4AED26-BBC9-47D8-B05A-50F5A4E77460} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {EFBDF2CA-A019-4E26-81B0-B88D97617D1E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {F627FC50-3935-484A-8693-F23E2E85F5C6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-03-06] (Piriform Ltd)
Task: {FF83089D-FDB0-47BB-83FC-D0B369D15DF6} - System32\Tasks\{70B76D51-C518-49B8-A122-0BD3DDFADEFB} => "c:\users\vít\appdata\local\google\chrome\application\chrome.exe" hxxp://www.skype.com/go/downloading?source=ins ... stError=-9

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core.job => C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA.job => C:\Users\Vít\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Vít\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AISLP\AISLP DOS.lnk -> C:\AISLP\MIKRO.BAT ()

==================== Loaded Modules (Whitelisted) ==============

2017-09-29 15:41 - 2017-09-29 15:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2013-10-20 18:53 - 2013-03-20 13:48 - 004062208 _____ () C:\WINDOWS\System32\SAFEQVS64.DLL
2013-10-20 18:53 - 2013-03-20 13:48 - 000683520 _____ () C:\WINDOWS\System32\SafeQCairoLib64.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000084800 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2017-04-26 21:09 - 2017-03-15 07:53 - 000855160 _____ () c:\program files (x86)\ostotohotspot\Hotspot.exe
2018-02-14 20:58 - 2018-02-10 06:39 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2018-02-14 20:58 - 2018-02-10 06:36 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-04-25 16:28 - 2018-04-25 16:29 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-04-25 16:28 - 2018-04-25 16:29 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-04-25 16:28 - 2018-04-25 16:29 - 022320128 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-04-25 16:28 - 2018-04-25 16:29 - 002603008 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\skypert.dll
2018-04-25 16:28 - 2018-04-25 16:29 - 000657408 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2013-10-20 18:53 - 2013-03-20 13:48 - 000259072 _____ () C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe
2013-10-20 18:53 - 2013-03-20 13:48 - 000005632 _____ () C:\Program Files (x86)\Y Soft\SafeQ Client\Client\cs-CZ\SafeQ Client.resources.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-04-26 12:41 - 2018-04-26 12:42 - 066407424 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-10-01 21:21 - 2017-10-01 21:21 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 004173312 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-04-05 13:16 - 2018-04-05 13:17 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 015356416 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 004018176 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 003281920 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 001386496 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2018-02-01 09:57 - 2018-02-01 09:58 - 004601048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000094208 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\BendRealityNode.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000878080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-04-05 13:16 - 2018-04-05 13:17 - 000043008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2018-04-26 12:41 - 2018-04-26 12:42 - 000165888 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18031.15040.0_x64__8wekyb3d8bbwe\SKU.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000150648 _____ () c:\program files (x86)\ostotohotspot\hwifisvc.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000119416 _____ () c:\program files (x86)\ostotohotspot\ServiceHelp.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000063096 _____ () c:\program files (x86)\ostotohotspot\HWiFiCtrlDll.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000172152 _____ () c:\program files (x86)\ostotohotspot\substat.dll
2017-04-26 21:09 - 2017-03-16 05:18 - 000110712 _____ () c:\program files (x86)\ostotohotspot\Updater\UpdateHelper.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000076920 _____ () c:\program files (x86)\ostotohotspot\IPC.dll
2017-04-26 21:09 - 2017-03-16 05:18 - 000265848 _____ () c:\program files (x86)\ostotohotspot\Updater\CheckUpdate.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000027968 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 001272128 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000111936 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000025920 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsAPI.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000800888 _____ () c:\program files (x86)\ostotohotspot\duilib.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000117368 _____ () c:\program files (x86)\ostotohotspot\svcapi.dll
2017-04-26 21:09 - 2017-03-16 03:15 - 000308856 _____ () c:\program files (x86)\ostotohotspot\WiFiCore.dll
2017-04-26 21:09 - 2017-03-16 03:15 - 000241272 _____ () c:\program files (x86)\ostotohotspot\WiFiWin7.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000221304 _____ () c:\program files (x86)\ostotohotspot\WiFiWinXP.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000128120 _____ () c:\program files (x86)\ostotohotspot\driver\DriverTool.dll
2017-04-26 21:09 - 2017-03-13 07:36 - 000197240 _____ () c:\program files (x86)\ostotohotspot\WifiDhcpSvr.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000025920 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000111936 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000059712 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2015-06-19 15:55 - 2015-06-19 15:55 - 000102720 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2018-04-06 11:48 - 2016-07-21 10:54 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2018-04-06 11:48 - 2017-09-12 10:34 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2018-04-25 18:49 - 2018-04-25 18:49 - 000282840 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2018-04-25 18:49 - 2018-04-25 18:49 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-04-25 18:49 - 2018-04-25 18:49 - 000349912 _____ () C:\Program Files\AVAST Software\Avast\streamback_avast.dll
2018-04-25 18:49 - 2018-04-25 18:49 - 000295640 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-04-25 18:48 - 2018-04-25 18:48 - 000281816 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2018-01-20 10:22 - 2018-01-20 10:22 - 000094920 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\officevoicemanager.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\sharepoint.com -> hxxps://ucnmuni.sharepoint.com
IE restricted site: HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\skype.com -> hxxps://apps.skype.com

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2015-11-11 18:27 - 000000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1228448097-215964479-906076251-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Vít\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
DNS Servers: 147.251.199.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run32: => "GrooveMonitor"
HKLM\...\StartupApproved\Run32: => "ArcSoft Connection Service"
HKLM\...\StartupApproved\Run32: => "ConnecitfyTemp 6"
HKLM\...\StartupApproved\Run32: => "ConnecitfyTemp d"
HKLM\...\StartupApproved\Run32: => "Connectify Dispatch"
HKLM\...\StartupApproved\Run32: => "Connectify Hotspot"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\StartupFolder: => "Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\Run: => "Zoner Photo Studio Autoupdate"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\Run: => "GarminExpressTrayApp"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\StartupApproved\Run: => "HP Deskjet 3520 series (NET)"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{446A294B-B9D2-4E19-933E-5085A8A4E8D4}C:\program files (x86)\company of heroes 2\reliccoh2.exe] => (Allow) C:\program files (x86)\company of heroes 2\reliccoh2.exe
FirewallRules: [TCP Query User{AE2A3621-506D-427B-839A-4CCD44362357}C:\program files (x86)\company of heroes 2\reliccoh2.exe] => (Allow) C:\program files (x86)\company of heroes 2\reliccoh2.exe
FirewallRules: [{81E89FA8-E94B-4E27-982B-77A6C4B2F637}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{AF09AE3C-A7B0-4020-B4ED-55F8D03FDF68}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe
FirewallRules: [{78FDAF59-46B9-4C85-9FFB-ABABE5B78AD8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{189FA77D-013D-43BD-A22E-294617AFA94B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{22793574-297C-49FE-B84E-76F0EF295B02}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{20DFF07E-E0A4-4D12-86A3-B61AC80115EE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{175D3641-814D-4706-8645-310D263F8AFE}] => (Block) C:\users\vít\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [{A778AF8F-E505-44BB-A09F-CAB8447C21D2}] => (Block) C:\users\vít\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [UDP Query User{9C0ACDDC-2522-4555-9CBA-025B5C91FEA1}C:\users\vít\games\company of heroes\bugreport\bugreport.exe] => (Allow) C:\users\vít\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [TCP Query User{0BF5A267-A4B9-4E4B-9954-F854F6E200DA}C:\users\vít\games\company of heroes\bugreport\bugreport.exe] => (Allow) C:\users\vít\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [{1D8F1A80-53FA-4FA9-9DFE-978B468D6BA9}] => (Allow) C:\Program Files\Zoner\Photo Studio 17\Program32\MediaServer.exe
FirewallRules: [UDP Query User{DA941AD8-58B3-473C-ABB0-55411EC8BAEB}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{2768C666-EB21-4191-A1B8-80CCBA380ED6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{55BDD998-75A0-4A20-BA90-3E7322FE99EB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CECA236E-AB4C-4979-82CB-0EB8B467AABE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7ABD6284-923C-4FB4-BAD0-85A6E4EC23FE}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{AAFABB03-A92E-48E5-B954-1A4446E86C93}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{9BE7516C-29FC-490E-933D-37217F317DDA}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\DeviceSetup.exe
FirewallRules: [{80007929-F4E4-4CF7-AA93-FB3030D2A070}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{EC78DA3D-1D14-4DAA-A7B8-0687976C9A66}] => (Allow) LPort=2869
FirewallRules: [{E73928DE-40EB-4080-9B0C-88E781A03815}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{640E6755-4450-46F3-9257-499991018AD1}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{6BB343F6-9EF7-451E-A17F-0952C31AC8CB}C:\program files\foxit software\pdf editor\pdfedit.exe] => (Block) C:\program files\foxit software\pdf editor\pdfedit.exe
FirewallRules: [UDP Query User{A228241F-C4E8-46FE-B653-C1F995E8D45E}C:\program files\foxit software\pdf editor\pdfedit.exe] => (Block) C:\program files\foxit software\pdf editor\pdfedit.exe
FirewallRules: [{8F9D3876-5BB4-4F1D-A9ED-22CA6CCCE6F4}] => (Allow) C:\Program Files (x86)\Samsung\SW Update\sManager.exe
FirewallRules: [{F1D01C5C-B1BA-43F2-A473-6E1E080963F6}] => (Allow) C:\Program Files (x86)\Samsung\SW Update\sManager.exe
FirewallRules: [{2115EA5E-13DA-414E-8D2E-5CA969D9889D}] => (Allow) C:\Program Files (x86)\Samsung\SW Update\sManager.exe
FirewallRules: [{771352A9-1816-4268-8B74-B44FF2EDBD8D}] => (Allow) C:\Program Files (x86)\Samsung\SW Update\sManager.exe
FirewallRules: [TCP Query User{59B6CB61-D582-4E99-BB7C-B8AF99705726}C:\program files\openvpn\bin\openvpn.exe] => (Allow) C:\program files\openvpn\bin\openvpn.exe
FirewallRules: [UDP Query User{40CEF78A-07F8-454E-B6CE-274A222F1F69}C:\program files\openvpn\bin\openvpn.exe] => (Allow) C:\program files\openvpn\bin\openvpn.exe
FirewallRules: [TCP Query User{0256EF32-7E92-4D9A-83BF-CC35CBA9C49A}C:\users\vít\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\vít\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{52FB9B35-698C-4C46-A834-461241C5D073}C:\users\vít\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\vít\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [{8FDE4773-2203-44C3-8FBF-F72054E2BDD8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9B839C5E-FB97-494E-8ED3-C05E156ADEDA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{25F6CB92-F2AC-4924-9A41-228944FD766D}] => (Allow) C:\Users\Vít\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{84358856-AED8-45D4-86F2-592C9F61010F}] => (Allow) C:\Users\Vít\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{90F72B7B-E77F-44FE-92C8-BB84813AA1AE}] => (Allow) C:\Users\Vít\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8360956F-AEBA-41F4-A68D-794BA1A47D3A}] => (Allow) C:\Users\Vít\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{4192D627-1C54-478A-B63A-D5AF0837E689}] => (Allow) C:\Users\Vít\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{AEB2EE2B-5EB3-4A1D-81F9-F7E61FB77D97}] => (Allow) C:\Users\Vít\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{4B40239E-10DE-416F-9F45-45D1325E580C}C:\program files (x86)\ostotohotspot\hotspot.exe] => (Allow) C:\program files (x86)\ostotohotspot\hotspot.exe
FirewallRules: [UDP Query User{1740008A-D847-49C0-8997-02467F608EB6}C:\program files (x86)\ostotohotspot\hotspot.exe] => (Allow) C:\program files (x86)\ostotohotspot\hotspot.exe
FirewallRules: [{E4D14F8D-B684-4950-A415-569DAA7F6428}] => (Block) C:\program files (x86)\ostotohotspot\hotspot.exe
FirewallRules: [{0EA4656E-53D5-430B-A527-93F1979153F5}] => (Block) C:\program files (x86)\ostotohotspot\hotspot.exe
FirewallRules: [{A02E41EE-04A3-4112-ABDA-294657C330CD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{956C61D5-C6EF-4B32-BAF1-E1EC4CA5DC04}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe
FirewallRules: [{8E2F398C-4496-4F9A-A134-F39A95F3DFAB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe
FirewallRules: [{4D46FD9A-0305-46D5-AA58-878A0E0680B6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DBDownloader.exe
FirewallRules: [{356043B0-3C51-43E6-9080-556051526D78}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DBDownloader.exe
FirewallRules: [{064A4FF0-E0E3-4D09-B4E9-903C469BD9C2}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\AutoUpdate.exe
FirewallRules: [{EBCD6BC1-F897-4DE1-B566-0BB3E014EB6A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\AutoUpdate.exe
FirewallRules: [{1FB81A67-93D7-4376-A1E1-209F2BA097E7}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe

==================== Restore Points =========================

06-04-2018 12:05:02 Installed Movavi Video Editor 4.
11-04-2018 09:06:25 Windows Update
17-04-2018 16:42:40 Windows Update
24-04-2018 17:11:05 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/26/2018 08:14:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: WScript.exe, verze: 5.812.10240.16384, časové razítko: 0xb09bb563
Název chybujícího modulu: VCRUNTIME140.dll, verze: 14.11.25325.0, časové razítko: 0x59273894
Kód výjimky: 0xc00000fd
Posun chyby: 0x0000000000004992
ID chybujícího procesu: 0x2a34
Čas spuštění chybující aplikace: 0x01d3dd8a59b350d5
Cesta k chybující aplikaci: C:\Windows\System32\WScript.exe
Cesta k chybujícímu modulu: C:\WINDOWS\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.25325.0_none_586e9d411a1940c6\VCRUNTIME140.dll
ID zprávy: 06c13597-06e2-468a-9a6e-1d02973c256b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (04/26/2018 08:06:31 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.

Error: (04/26/2018 07:44:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: WScript.exe, verze: 5.812.10240.16384, časové razítko: 0xb09bb563
Název chybujícího modulu: VCRUNTIME140.dll, verze: 14.11.25325.0, časové razítko: 0x59273894
Kód výjimky: 0xc00000fd
Posun chyby: 0x00000000000045cd
ID chybujícího procesu: 0x680
Čas spuštění chybující aplikace: 0x01d3dd8628d08eff
Cesta k chybující aplikaci: C:\Windows\System32\WScript.exe
Cesta k chybujícímu modulu: C:\WINDOWS\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.25325.0_none_586e9d411a1940c6\VCRUNTIME140.dll
ID zprávy: 37a62a37-2cb0-4dca-8064-c6b4365536d9
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (04/26/2018 07:14:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: WScript.exe, verze: 5.812.10240.16384, časové razítko: 0xb09bb563
Název chybujícího modulu: aswAMSI.dll, verze: 18.3.3860.309, časové razítko: 0x5abd18d6
Kód výjimky: 0xc00000fd
Posun chyby: 0x0000000000026558
ID chybujícího procesu: 0x330
Čas spuštění chybující aplikace: 0x01d3dd81f7f3be0f
Cesta k chybující aplikaci: C:\Windows\System32\WScript.exe
Cesta k chybujícímu modulu: C:\Program Files\AVAST Software\Avast\x64\aswAMSI.dll
ID zprávy: 254a87b5-c5f9-4c4d-bade-21ce80a054ab
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (04/26/2018 07:06:33 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.

Error: (04/26/2018 06:44:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: WScript.exe, verze: 5.812.10240.16384, časové razítko: 0xb09bb563
Název chybujícího modulu: ntdll.dll, verze: 10.0.16299.248, časové razítko: 0xeffc9126
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000001e154
ID chybujícího procesu: 0x167c
Čas spuštění chybující aplikace: 0x01d3dd7dc70a85be
Cesta k chybující aplikaci: C:\Windows\System32\WScript.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: b2d0280a-3707-49b4-82b6-870d74832259
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (04/26/2018 06:14:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: WScript.exe, verze: 5.812.10240.16384, časové razítko: 0xb09bb563
Název chybujícího modulu: VCRUNTIME140.dll, verze: 14.11.25325.0, časové razítko: 0x59273894
Kód výjimky: 0xc00000fd
Posun chyby: 0x0000000000004992
ID chybujícího procesu: 0x1738
Čas spuštění chybující aplikace: 0x01d3dd7996277179
Cesta k chybující aplikaci: C:\Windows\System32\WScript.exe
Cesta k chybujícímu modulu: C:\WINDOWS\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.25325.0_none_586e9d411a1940c6\VCRUNTIME140.dll
ID zprávy: 746914c6-4b00-42f1-a863-91b4f143bad7
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (04/26/2018 06:06:30 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.


System errors:
=============
Error: (04/26/2018 12:48:55 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (04/26/2018 12:43:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (04/26/2018 12:36:02 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server {784E29F4-5EBE-4279-9948-1E8FE941646D} se v daném časovém limitu neregistroval u služby DCOM.

Error: (04/26/2018 12:35:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba HWifiNetPro neuspěla při spuštění v důsledku následující chyby:
Zařízení připojené k systému nefunguje.

Error: (04/26/2018 12:34:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Presentation Foundation Font Cache 3.0.0.0 neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (04/26/2018 12:34:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby FontCache3.0.0.0 bylo dosaženo časového limitu (30000 ms).

Error: (04/26/2018 12:34:02 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (04/26/2018 12:34:02 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz
Percentage of memory in use: 77%
Total physical RAM: 3797.53 MB
Available physical RAM: 848.62 MB
Total Virtual: 5491.91 MB
Available Virtual: 1872.31 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:441.01 GB) (Free:164.21 GB) NTFS

\\?\Volume{6a7d3875-dc22-4359-ae85-b7f150b281b9}\ (Windows RE tools) (Fixed) (Total:0.49 GB) (Free:0.16 GB) NTFS
\\?\Volume{9d592edb-c96c-4db0-812b-f4e2fdd690b8}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.25 GB) FAT32
\\?\Volume{b63e05e4-03e6-4114-9eec-50d7a4157edd}\ () (Fixed) (Total:0.86 GB) (Free:0.35 GB) NTFS
\\?\Volume{a037b05e-3fb1-4a58-ba06-02a9b84138f5}\ (SAMSUNG_REC2) (Fixed) (Total:21.99 GB) (Free:0.94 GB) NTFS
\\?\Volume{2f1d3d32-a27a-45e6-4173-636c65706975}\ (SAMSUNG_REC) (Fixed) (Total:1 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: A41BCEB5)

Partition: GPT.

========================================================
Disk: 1 (Size: 22.4 GB) (Disk ID: 241D6A75)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 27 dub 2018 15:22
od Conder
:arrow: Odinstaluj vsetky IObit programy (Driver Booster, Advanced SystemCare, atd) - su to cinske smejdy, ktore mozu poskodit system. Tento krok vykonaj este pred spustenim fixlistu nizsie.

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    VirusTotal: C:\Users\Vít\AppData\Local\cme.js
    File: C:\Users\Vít\AppData\Local\cme.js
    
    HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
    HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
    Startup: C:\Users\VĂ­t\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cme.js [2018-02-21] ()
    FF ProfilePath: C:\Users\VĂ­t\AppData\Roaming\Mozilla\Firefox\Profiles\odwiweru.default [not found] <==== ATTENTION
    S3 intaud_WaveExtensible; \SystemRoot\system32\drivers\intelaud.sys [X]
    2018-04-07 09:02 - 2018-02-21 15:28 - 000033170 _____ C:\Users\VĂ­t\AppData\Local\cme.js
    2018-04-02 20:23 - 2018-04-02 20:23 - 000000000 ____D C:\WINDOWS\IObit
    2018-04-02 20:22 - 2018-04-02 20:24 - 000000000 ____D C:\Users\VĂ­t\AppData\LocalLow\IObit
    2018-04-02 20:22 - 2018-04-02 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 5
    2018-04-02 20:22 - 2018-04-02 20:22 - 000000000 ____D C:\Program Files (x86)\IObit
    2018-04-02 20:21 - 2018-04-25 21:56 - 000000000 ____D C:\Users\VĂ­t\AppData\Roaming\IObit
    2018-04-02 20:20 - 2018-04-02 20:24 - 000000000 ____D C:\ProgramData\IObit
    2018-04-07 09:02 - 2018-02-21 15:28 - 000033170 _____ () C:\Users\VĂ­t\AppData\Local\cme.js
    CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Vít\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
    ContextMenuHandlers1: [JRcm] -> [CC]{C20B9A7B-ED5B-4CEB-B2A6-F1F62E99C539} =>  -> No File
    ContextMenuHandlers1: [JRcm64] -> [CC]{013BF2A8-A4B1-11DF-A865-F509E0D72085} =>  -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
    Task: {026E045E-49F8-4432-BCCC-D774986AF0B8} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {1C8992D7-7104-41B6-A08B-519269A255B8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {1DF15264-4F8E-456B-BA38-EBB65657DF50} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {36CC1422-34BE-4411-8FEA-7B09085534CA} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {55F9AD24-571F-4C23-B009-BFE77BC757D5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    Task: {6A7513AD-E497-4543-B6F2-A3A024AD194E} - System32\Tasks\Skype => C:\Users\Vít\AppData\Local\cme.js [2018-02-21] ()
    Task: {8039C7B7-5F13-4C8F-AFCA-E26DB7B93477} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {917F7559-CBF9-4BB8-95E2-81F4409E8253} - System32\Tasks\Driver Booster SkipUAC (Vít) => C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe [2018-03-22] (IObit)
    Task: {921E9F4D-3637-46E7-B0E2-C39A293CEF6B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {97340CC0-20C1-46F5-9C15-F9F38427316F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {9FC204D6-2172-4DAC-ACC5-0DA571D94C3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {AB1F24C4-74B0-4586-A25B-4A454DEA83F3} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {BD511D87-B8A0-4EB1-806E-3E2137C6F532} - \Driver Booster Scheduler -> No File <==== ATTENTION
    Task: {C1A00206-356B-459D-8935-D121DBE7F802} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {EB4AED26-BBC9-47D8-B05A-50F5A4E77460} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {EFBDF2CA-A019-4E26-81B0-B88D97617D1E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
    IE trusted site: HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\sharepoint.com -> hxxps://ucnmuni.sharepoint.com
    IE restricted site: HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\skype.com -> hxxps://apps.skype.com
    FirewallRules: [{956C61D5-C6EF-4B32-BAF1-E1EC4CA5DC04}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe
    FirewallRules: [{8E2F398C-4496-4F9A-A134-F39A95F3DFAB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe
    FirewallRules: [{4D46FD9A-0305-46D5-AA58-878A0E0680B6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DBDownloader.exe
    FirewallRules: [{356043B0-3C51-43E6-9080-556051526D78}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DBDownloader.exe
    FirewallRules: [{064A4FF0-E0E3-4D09-B4E9-903C469BD9C2}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\AutoUpdate.exe
    FirewallRules: [{EBCD6BC1-F897-4DE1-B566-0BB3E014EB6A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\AutoUpdate.exe
    C:\Users\Vít\Downloads\*.tmp
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 28 dub 2018 08:11
od WarWalker
Ahoj, tady to je :).

Fix result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018
Ran by Vít (27-04-2018 17:01:12) Run:1
Running from C:\Users\Vít\Desktop
Loaded Profiles: Vít (Available Profiles: Vít)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

VirusTotal: C:\Users\V�t\AppData\Local\cme.js
File: C:\Users\V�t\AppData\Local\cme.js

HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
Startup: C:\Users\Vít\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cme.js [2018-02-21] ()
FF ProfilePath: C:\Users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\odwiweru.default [not found] <==== ATTENTION
S3 intaud_WaveExtensible; \SystemRoot\system32\drivers\intelaud.sys [X]
2018-04-07 09:02 - 2018-02-21 15:28 - 000033170 _____ C:\Users\Vít\AppData\Local\cme.js
2018-04-02 20:23 - 2018-04-02 20:23 - 000000000 ____D C:\WINDOWS\IObit
2018-04-02 20:22 - 2018-04-02 20:24 - 000000000 ____D C:\Users\Vít\AppData\LocalLow\IObit
2018-04-02 20:22 - 2018-04-02 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 5
2018-04-02 20:22 - 2018-04-02 20:22 - 000000000 ____D C:\Program Files (x86)\IObit
2018-04-02 20:21 - 2018-04-25 21:56 - 000000000 ____D C:\Users\Vít\AppData\Roaming\IObit
2018-04-02 20:20 - 2018-04-02 20:24 - 000000000 ____D C:\ProgramData\IObit
2018-04-07 09:02 - 2018-02-21 15:28 - 000033170 _____ () C:\Users\Vít\AppData\Local\cme.js
CustomCLSID: HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\V�t\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
ContextMenuHandlers1: [JRcm] -> [CC]{C20B9A7B-ED5B-4CEB-B2A6-F1F62E99C539} => -> No File
ContextMenuHandlers1: [JRcm64] -> [CC]{013BF2A8-A4B1-11DF-A865-F509E0D72085} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {026E045E-49F8-4432-BCCC-D774986AF0B8} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {1C8992D7-7104-41B6-A08B-519269A255B8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {1DF15264-4F8E-456B-BA38-EBB65657DF50} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {36CC1422-34BE-4411-8FEA-7B09085534CA} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {55F9AD24-571F-4C23-B009-BFE77BC757D5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {6A7513AD-E497-4543-B6F2-A3A024AD194E} - System32\Tasks\Skype => C:\Users\V�t\AppData\Local\cme.js [2018-02-21] ()
Task: {8039C7B7-5F13-4C8F-AFCA-E26DB7B93477} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {917F7559-CBF9-4BB8-95E2-81F4409E8253} - System32\Tasks\Driver Booster SkipUAC (V�t) => C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe [2018-03-22] (IObit)
Task: {921E9F4D-3637-46E7-B0E2-C39A293CEF6B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {97340CC0-20C1-46F5-9C15-F9F38427316F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9FC204D6-2172-4DAC-ACC5-0DA571D94C3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {AB1F24C4-74B0-4586-A25B-4A454DEA83F3} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {BD511D87-B8A0-4EB1-806E-3E2137C6F532} - \Driver Booster Scheduler -> No File <==== ATTENTION
Task: {C1A00206-356B-459D-8935-D121DBE7F802} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {EB4AED26-BBC9-47D8-B05A-50F5A4E77460} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {EFBDF2CA-A019-4E26-81B0-B88D97617D1E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
IE trusted site: HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\sharepoint.com -> hxxps://ucnmuni.sharepoint.com
IE restricted site: HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\skype.com -> hxxps://apps.skype.com
FirewallRules: [{956C61D5-C6EF-4B32-BAF1-E1EC4CA5DC04}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe
FirewallRules: [{8E2F398C-4496-4F9A-A134-F39A95F3DFAB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe
FirewallRules: [{4D46FD9A-0305-46D5-AA58-878A0E0680B6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DBDownloader.exe
FirewallRules: [{356043B0-3C51-43E6-9080-556051526D78}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DBDownloader.exe
FirewallRules: [{064A4FF0-E0E3-4D09-B4E9-903C469BD9C2}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\AutoUpdate.exe
FirewallRules: [{EBCD6BC1-F897-4DE1-B566-0BB3E014EB6A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.3.0\AutoUpdate.exe
C:\Users\V�t\Downloads\*.tmp

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.
"VirusTotal: C:\Users\V�t\AppData\Local\cme.js" => not found

========================= File: C:\Users\V�t\AppData\Local\cme.js ========================

"C:\Users\V�t\AppData\Local\cme.js" => not found
====== End of File: ======

"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Wondershare Helper Compact.exe" => removed successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
C:\Users\Vít\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cme.js => moved successfully
C:\Users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\odwiweru.default => path removed successfully
"HKLM\System\CurrentControlSet\Services\intaud_WaveExtensible" => removed successfully
intaud_WaveExtensible => service removed successfully
C:\Users\Vít\AppData\Local\cme.js => moved successfully
C:\WINDOWS\IObit => moved successfully
C:\Users\Vít\AppData\LocalLow\IObit => moved successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 5" => not found
"C:\Program Files (x86)\IObit" => not found
C:\Users\Vít\AppData\Roaming\IObit => moved successfully
C:\ProgramData\IObit => moved successfully
"C:\Users\Vít\AppData\Local\cme.js" => not found
"HKU\S-1-5-21-1228448097-215964479-906076251-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}" => removed successfully
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\JRcm" => removed successfully
HKLM\Software\Classes\CLSID\[CC]{C20B9A7B-ED5B-4CEB-B2A6-F1F62E99C539} => not found
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\JRcm64" => removed successfully
HKLM\Software\Classes\CLSID\[CC]{013BF2A8-A4B1-11DF-A865-F509E0D72085} => not found
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{026E045E-49F8-4432-BCCC-D774986AF0B8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{026E045E-49F8-4432-BCCC-D774986AF0B8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1C8992D7-7104-41B6-A08B-519269A255B8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1C8992D7-7104-41B6-A08B-519269A255B8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DF15264-4F8E-456B-BA38-EBB65657DF50}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DF15264-4F8E-456B-BA38-EBB65657DF50}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36CC1422-34BE-4411-8FEA-7B09085534CA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36CC1422-34BE-4411-8FEA-7B09085534CA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55F9AD24-571F-4C23-B009-BFE77BC757D5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55F9AD24-571F-4C23-B009-BFE77BC757D5}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A7513AD-E497-4543-B6F2-A3A024AD194E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A7513AD-E497-4543-B6F2-A3A024AD194E}" => removed successfully
C:\WINDOWS\System32\Tasks\Skype => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Skype" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8039C7B7-5F13-4C8F-AFCA-E26DB7B93477}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8039C7B7-5F13-4C8F-AFCA-E26DB7B93477}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{917F7559-CBF9-4BB8-95E2-81F4409E8253}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{917F7559-CBF9-4BB8-95E2-81F4409E8253}" => removed successfully
"C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (V�t)" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (V�t) => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{921E9F4D-3637-46E7-B0E2-C39A293CEF6B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{921E9F4D-3637-46E7-B0E2-C39A293CEF6B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97340CC0-20C1-46F5-9C15-F9F38427316F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97340CC0-20C1-46F5-9C15-F9F38427316F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9FC204D6-2172-4DAC-ACC5-0DA571D94C3E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FC204D6-2172-4DAC-ACC5-0DA571D94C3E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AB1F24C4-74B0-4586-A25B-4A454DEA83F3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB1F24C4-74B0-4586-A25B-4A454DEA83F3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BD511D87-B8A0-4EB1-806E-3E2137C6F532}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD511D87-B8A0-4EB1-806E-3E2137C6F532}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C1A00206-356B-459D-8935-D121DBE7F802}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1A00206-356B-459D-8935-D121DBE7F802}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB4AED26-BBC9-47D8-B05A-50F5A4E77460}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB4AED26-BBC9-47D8-B05A-50F5A4E77460}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFBDF2CA-A019-4E26-81B0-B88D97617D1E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFBDF2CA-A019-4E26-81B0-B88D97617D1E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => removed successfully
"HKU\S-1-5-21-1228448097-215964479-906076251-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sharepoint.com" => removed successfully
"HKU\S-1-5-21-1228448097-215964479-906076251-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\skype.com" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{956C61D5-C6EF-4B32-BAF1-E1EC4CA5DC04}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8E2F398C-4496-4F9A-A134-F39A95F3DFAB}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4D46FD9A-0305-46D5-AA58-878A0E0680B6}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{356043B0-3C51-43E6-9080-556051526D78}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{064A4FF0-E0E3-4D09-B4E9-903C469BD9C2}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EBCD6BC1-F897-4DE1-B566-0BB3E014EB6A}" => not found

=========== "C:\Users\V�t\Downloads\*.tmp" ==========

not found

========= End -> "C:\Users\V�t\Downloads\*.tmp" ========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 134171062 B
Java, Flash, Steam htmlcache => 1623 B
Windows/system/drivers => 1356244 B
Edge => 138064 B
Chrome => 262337 B
Firefox => 410556923 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 8268 B
NetworkService => 4012 B
Vít => 27776468 B

RecycleBin => 0 B
EmptyTemp: => 556.4 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 27-04-2018 17:07:06)


Result of scheduled keys to remove after reboot:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (V�t) => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler => could not remove. Access Denied.

==== End of Fixlog 17:07:08 ====

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 28 dub 2018 15:20
od Conder
:arrow: Ako to vyzera s PC?

:arrow: Poprosim spustit este tento fixlist:

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    VirusTotal: C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad
    File: C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad
    CMD: type "C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad"
    C:\Users\Vít\Downloads\*.tmp
    DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager
    DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Vít)
    DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler
    
    C:\Program Files\IObit
    C:\Program Files (x86)\IObit
    C:\Program Files\Common Files\IObit
    C:\ProgramData\IObit
    C:\ProgramData\ProductData
    C:\Users\Vít\AppData\Roaming\IObit
    C:\Users\Vít\AppData\LocalLow\IObit
    C:\Users\Default\AppData\Roaming\IObit
    C:\Users\Default\AppData\LocalLow\IObit
    C:\Windows\IObit
    C:\Windows\Tasks\ImCleanDisabled
    
    Hosts:
    EmptyTemp:
    End
  • Klikni na Subor a potom na Ulozit
  • Vpravo dole vyber kodovanie Unicode
  • Subor uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 28 dub 2018 17:48
od WarWalker
Komp v pohode :)

Fix result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018
Ran by Vít (28-04-2018 17:55:59) Run:2
Running from C:\Users\Vít\Desktop
Loaded Profiles: Vít (Available Profiles: Vít)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

VirusTotal: C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad
File: C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad
CMD: type "C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad"
C:\Users\Vít\Downloads\*.tmp
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Vít)
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler

C:\Program Files\IObit
C:\Program Files (x86)\IObit
C:\Program Files\Common Files\IObit
C:\ProgramData\IObit
C:\ProgramData\ProductData
C:\Users\Vít\AppData\Roaming\IObit
C:\Users\Vít\AppData\LocalLow\IObit
C:\Users\Default\AppData\Roaming\IObit
C:\Users\Default\AppData\LocalLow\IObit
C:\Windows\IObit
C:\Windows\Tasks\ImCleanDisabled

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.
VirusTotal: C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad => https://www.virustotal.com/file/31364f8 ... 521124937/

========================= File: C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad ========================

C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad
File not signed
MD5: 391E8E75AC4B5E18BABB105C2CFEE6A8
Creation and modification date: 2018-04-07 09:02 - 2018-02-21 15:28
Size: 000033170
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/file/31364f8 ... 521124937/

====== End of File: ======


========= type "C:\FRST\Quarantine\C\Users\Vít\AppData\Local\cme.js.xbad" =========

eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('1r 2C=[\'1f\\1S*\\1d(\\1S*\\1d)\',\'\\1d+\\1d+\\1S*(?:3s(?:[a-3t-9]){4,6}|(?:\\1P|\\2O)[a-3u-9]{1,4}(?:\\1P|\\2O))\',\'3v\',\'3r\',\'3q\',\'3m\',\'2W\',\'2F\',\'\\2J+\',\'1Q(1D(a,b,c,d,f,g){28(f=1D(h){1E\\3n.1M(2a)},!\\17\\17.1T(/^/,1R)){1J(;c--;)g[c.1M(26)]=d[c]||c.1M(26);d=[1D(h){1E\\3o[h]}],f=1D(){1E\\17\\1d\\2J+\\17},c=1}1J(;c--;)d[c]&&(a=a.1T(1Y\\3p(\\17\\1d\\1P\\17+f(c)+\\17\\1d\\1P\\17,\\2S\\17),d[c]));1E\\3w}(\\3x\\3E(o,h){1\\3F;1\\37=\\1d\\17\\1d\\17;1\\3G=(o+\\1d\\17\\1d\\17).6(\\1d\\17\\1d\\17);1\\3H=(h+\\1d\\17\\1d\\17).6(\\1d\\17\\1d\\17);1\\3D=p.4;a(1\\3C=0;i<d.4;i++){3=d.9(0);2+=8.c(+3-+k-(l+n))}m\\37}e{f(5(\\1d\\17\\1n\\1n\\q\\V\\O\\16\\r\\16\\q\\1k\\1b\\q\\N\\1H\\2r\\1g\\1l\\q\\1G\\q\\X\\K\\B\\r\\Q\\r\\w\\r\\31\\q\\2P\\3y\\q\\1h\\14\\B\\x\\x\\r\\w\\q\\1x\\q\\X\\K\\B\\r\\Q\\r\\w\\r\\31\\u\\v\\u\\v\\N\\E\\w\\q\\1w\\q\\G\\q\\Z\\y\\1i\\X\\J\\w\\B\\P\\x\\H\\X\\W\\r\\K\\K\\y\\R\\y\\X\\J\\w\\B\\P\\x\\B\\D\\12\\H\\1p\\B\\K\\r\\X\\1b\\C\\x\\r\\Q\\1e\\1k\\1w\\r\\J\\x\\y\\R\\y\\X\\W\\r\\K\\K\\H\\1s\\P\\P\\K\\B\\J\\E\\x\\B\\O\\D\\y\\R\\y\\1v\\B\\J\\w\\O\\C\\O\\I\\x\\H\\1z\\1v\\1U\\1B\\1h\\1h\\19\\y\\11\\F\\u\\v\\N\\E\\w\\q\\12\\q\\G\\q\\Z\\y\\1B\\1Z\\V\\1j\\y\\R\\y\\1B\\1Z\\1U\\1v\\y\\R\\y\\1B\\1Z\\V\\1j\\L\\L\\N\\1w\\14\\1g\\w\\Q\\y\\R\\y\\L\\L\\X\\O\\I\\x\\14\\E\\w\\r\\L\\L\\1v\\B\\J\\w\\O\\C\\O\\I\\x\\L\\L\\1i\\B\\D\\16\\O\\14\\C\\L\\L\\V\\M\\w\\w\\r\\D\\x\\1t\\r\\w\\C\\B\\O\\D\\L\\L\\1m\\M\\D\\L\\L\\y\\R\\y\\1B\\1Z\\1U\\1v\\L\\L\\X\\1e\\1p\\1h\\1i\\1s\\1m\\15\\L\\L\\V\\K\\E\\C\\C\\r\\C\\L\\L\\y\\R\\y\\1m\\15\\1X\\1H\\X\\3z\\y\\R\\y\\L\\L\\16\\r\\I\\E\\M\\K\\x\\B\\J\\O\\D\\L\\L\\y\\11\\F\\u\\v\\N\\E\\w\\q\\1b\\q\\G\\q\\Z\\y\\14\\B\\D\\Q\\12\\Q\\x\\C\\1x\\y\\R\\y\\14\\B\\D\\1I\\13\\1H\\K\\O\\12\\B\\J\\E\\K\\16\\B\\C\\1N\\y\\R\\y\\1i\\B\\D\\1I\\13\\1H\\1e\\P\\r\\w\\E\\x\\B\\D\\12\\X\\1b\\C\\x\\r\\Q\\y\\R\\1q\\1s\\D\\x\\B\\1t\\B\\w\\M\\C\\19\\w\\O\\16\\M\\J\\x\\1q\\11\\F\\u\\v\\u\\v\\N\\E\\w\\q\\C\\W\\q\\G\\q\\V\\w\\A\\1g\\z\\F\\u\\v\\N\\E\\w\\q\\I\\C\\q\\G\\q\\V\\w\\A\\1l\\z\\F\\u\\v\\N\\E\\w\\q\\C\\P\\K\\q\\G\\q\\y\\1G\\1t\\1G\\y\\F\\u\\v\\N\\E\\w\\q\\V\\W\\q\\G\\q\\y\\L\\L\\y\\F\\u\\v\\N\\E\\w\\q\\1t\\Y\\q\\G\\q\\y\\1Z\\1B\\y\\q\\S\\q\\y\\1H\\y\\q\\S\\q\\1e\\1k\\A\\2z\\z\\F\\u\\v\\N\\E\\w\\q\\I\\M\\q\\G\\q\\1i\\X\\J\\w\\B\\P\\x\\H\\X\\J\\w\\B\\P\\x\\1p\\M\\K\\K\\Y\\E\\Q\\r\\F\\u\\v\\N\\E\\w\\q\\14\\D\\q\\G\\q\\1i\\X\\J\\w\\B\\P\\x\\H\\X\\J\\w\\B\\P\\x\\Y\\E\\Q\\r\\F\\u\\v\\N\\E\\w\\q\\1j\\F\\u\\v\\x\\w\\1b\\q\\T\\u\\v\\1j\\q\\G\\q\\C\\W\\H\\1m\\r\\12\\1m\\r\\E\\16\\A\\12\\Z\\13\\11\\z\\F\\u\\v\\U\\q\\J\\E\\x\\J\\W\\A\\r\\w\\w\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\N\\q\\G\\q\\I\\M\\H\\C\\P\\K\\B\\x\\A\\y\\L\\L\\y\\z\\F\\u\\v\\B\\I\\q\\A\\y\\1x\\L\\L\\y\\q\\S\\q\\C\\N\\Z\\1l\\11\\q\\G\\G\\q\\y\\1x\\L\\L\\y\\q\\S\\q\\14\\D\\z\\q\\T\\u\\v\\1j\\q\\G\\q\\y\\1h\\1m\\1j\\15\\y\\F\\u\\v\\C\\W\\H\\1m\\r\\12\\1i\\w\\B\\x\\r\\A\\12\\Z\\13\\11\\R\\1j\\R\\12\\Z\\2t\\11\\z\\F\\u\\v\\U\\q\\r\\K\\C\\r\\q\\T\\u\\v\\1j\\q\\G\\q\\y\\1p\\1s\\1U\\X\\15\\y\\F\\u\\v\\C\\W\\H\\1m\\r\\12\\1i\\w\\B\\x\\r\\A\\12\\Z\\13\\11\\R\\1j\\R\\12\\Z\\2t\\11\\z\\F\\u\\v\\U\\u\\v\\U\\u\\v\\Y\\C\\A\\z\\F\\u\\v\\16\\O\\q\\T\\u\\v\\x\\w\\1b\\q\\T\\u\\v\\N\\E\\w\\q\\19\\q\\G\\q\\19\\x\\A\\1q\\1t\\w\\r\\1q\\R\\1q\\1q\\z\\F\\u\\v\\19\\q\\G\\q\\19\\H\\C\\P\\K\\B\\x\\A\\C\\P\\K\\z\\F\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\V\\K\\y\\z\\q\\T\\u\\v\\1i\\X\\J\\w\\B\\P\\x\\H\\2j\\M\\B\\x\\A\\1l\\z\\F\\u\\v\\U\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\X\\J\\y\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\13\\q\\G\\q\\15\\1a\\A\\y\\x\\r\\Q\\P\\y\\z\\q\\S\\q\\y\\L\\L\\y\\q\\S\\q\\19\\Z\\13\\11\\F\\u\\v\\N\\E\\w\\q\\I\\B\\q\\G\\q\\I\\C\\H\\V\\w\\r\\E\\x\\r\\1h\\r\\1a\\x\\1p\\B\\K\\r\\A\\C\\13\\R\\x\\w\\M\\r\\z\\F\\u\\v\\I\\B\\H\\1i\\w\\B\\x\\r\\A\\19\\Z\\1l\\11\\z\\F\\u\\v\\I\\B\\H\\V\\K\\O\\C\\r\\A\\z\\F\\u\\v\\C\\W\\H\\w\\M\\D\\A\\C\\13\\z\\F\\u\\v\\U\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\15\\1a\\y\\z\\q\\T\\u\\v\\r\\N\\E\\K\\A\\19\\Z\\1l\\11\\z\\F\\u\\v\\U\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\1m\\D\\y\\z\\q\\T\\u\\v\\N\\E\\w\\q\\w\\B\\q\\G\\q\\I\\C\\H\\1e\\P\\r\\D\\1h\\r\\1a\\x\\1p\\B\\K\\r\\A\\I\\M\\R\\1l\\z\\F\\u\\v\\N\\E\\w\\q\\I\\w\\q\\G\\q\\w\\B\\H\\1m\\r\\E\\16\\1s\\K\\K\\A\\z\\F\\u\\v\\w\\B\\H\\V\\K\\O\\C\\r\\A\\z\\F\\u\\v\\1t\\Y\\q\\G\\q\\1t\\Y\\H\\C\\P\\K\\B\\x\\A\\y\\1H\\y\\z\\F\\u\\v\\I\\w\\q\\G\\q\\I\\w\\H\\w\\r\\P\\K\\E\\J\\r\\A\\1t\\Y\\Z\\1g\\11\\R\\19\\Z\\1l\\11\\z\\F\\u\\v\\N\\E\\w\\q\\14\\B\\q\\G\\q\\I\\C\\H\\1e\\P\\r\\D\\1h\\r\\1a\\x\\1p\\B\\K\\r\\A\\I\\M\\R\\13\\R\\I\\E\\K\\C\\r\\z\\F\\u\\v\\14\\B\\H\\1i\\w\\B\\x\\r\\A\\I\\w\\z\\F\\u\\v\\14\\B\\H\\V\\K\\O\\C\\r\\A\\z\\F\\u\\v\\C\\W\\H\\w\\M\\D\\A\\y\\14\\C\\J\\w\\B\\P\\x\\H\\r\\1a\\r\\q\\1n\\1n\\2r\\q\\L\\y\\y\\q\\S\\q\\I\\M\\q\\S\\q\\y\\L\\y\\y\\z\\F\\u\\v\\1i\\X\\J\\w\\B\\P\\x\\H\\2j\\M\\B\\x\\A\\1l\\z\\F\\u\\v\\U\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\1j\\P\\y\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\13\\q\\G\\q\\15\\1a\\A\\y\\x\\r\\Q\\P\\y\\z\\q\\S\\q\\y\\L\\L\\y\\q\\S\\q\\19\\Z\\13\\11\\F\\u\\v\\N\\E\\w\\q\\J\\x\\I\\q\\G\\q\\I\\C\\H\\V\\w\\r\\E\\x\\r\\1h\\r\\1a\\x\\1p\\B\\K\\r\\A\\C\\13\\R\\x\\w\\M\\r\\z\\F\\u\\v\\N\\E\\w\\q\\12\\M\\q\\G\\q\\19\\Z\\1l\\11\\F\\u\\v\\12\\M\\q\\G\\q\\12\\M\\H\\w\\r\\P\\K\\E\\J\\r\\A\\y\\1G\\1j\\1G\\y\\R\\y\\1G\\1t\\1G\\y\\z\\F\\u\\v\\J\\x\\I\\H\\1i\\w\\B\\x\\r\\A\\12\\M\\z\\F\\u\\v\\J\\x\\I\\H\\V\\K\\O\\C\\r\\A\\z\\F\\u\\v\\C\\W\\H\\w\\M\\D\\A\\y\\14\\C\\J\\w\\B\\P\\x\\H\\r\\1a\\r\\q\\1n\\1n\\2r\\q\\L\\y\\y\\q\\S\\q\\C\\13\\q\\S\\q\\y\\L\\y\\y\\R\\2z\\z\\F\\u\\v\\1i\\X\\J\\w\\B\\P\\x\\H\\2j\\M\\B\\x\\A\\1l\\z\\F\\u\\v\\U\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\1j\\D\\y\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\13\\q\\G\\q\\19\\Z\\1l\\11\\F\\u\\v\\N\\E\\w\\q\\N\\16\\w\\q\\G\\q\\15\\1a\\A\\y\\1h\\r\\Q\\P\\y\\z\\q\\S\\q\\V\\W\\q\\S\\q\\14\\D\\F\\u\\v\\N\\E\\w\\q\\w\\r\\12\\B\\q\\G\\q\\y\\Y\\O\\x\\W\\B\\D\\12\\1L\\y\\F\\u\\v\\C\\13\\q\\G\\q\\C\\13\\H\\w\\r\\P\\K\\E\\J\\r\\A\\y\\1A\\I\\y\\R\\I\\M\\z\\H\\w\\r\\P\\K\\E\\J\\r\\A\\y\\1A\\D\\y\\R\\14\\D\\z\\H\\w\\r\\P\\K\\E\\J\\r\\A\\y\\1A\\C\\I\\16\\w\\y\\R\\N\\16\\w\\z\\H\\w\\r\\P\\K\\E\\J\\r\\A\\y\\1A\\1m\\12\\Y\\r\\1A\\y\\R\\w\\r\\12\\B\\z\\F\\u\\v\\r\\N\\E\\K\\A\\C\\13\\z\\F\\u\\v\\1i\\X\\J\\w\\B\\P\\x\\H\\2j\\M\\B\\x\\A\\1l\\z\\F\\u\\v\\U\\u\\v\\u\\v\\B\\I\\q\\A\\19\\Z\\1g\\11\\q\\G\\G\\G\\q\\y\\1m\\1p\\y\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\13\\q\\G\\q\\15\\1a\\A\\y\\x\\r\\Q\\P\\y\\z\\q\\S\\q\\y\\L\\L\\y\\q\\S\\q\\19\\Z\\13\\11\\F\\u\\v\\N\\E\\w\\q\\I\\B\\q\\G\\q\\I\\C\\H\\V\\w\\r\\E\\x\\r\\1h\\r\\1a\\x\\1p\\B\\K\\r\\A\\C\\13\\R\\x\\w\\M\\r\\z\\F\\u\\v\\I\\B\\H\\1i\\w\\B\\x\\r\\A\\19\\Z\\1l\\11\\z\\F\\u\\v\\I\\B\\H\\V\\K\\O\\C\\r\\A\\z\\F\\u\\v\\C\\W\\H\\w\\M\\D\\A\\C\\13\\z\\F\\u\\v\\U\\u\\v\\U\\q\\J\\E\\x\\J\\W\\A\\r\\w\\w\\z\\q\\T\\u\\v\\U\\u\\v\\1i\\X\\J\\w\\B\\P\\x\\H\\X\\K\\r\\r\\P\\A\\21\\1g\\1g\\1g\\z\\F\\u\\v\\u\\v\\U\\q\\14\\W\\B\\K\\r\\q\\A\\x\\w\\M\\r\\z\\q\\F\\u\\v\\u\\v\\u\\v\\I\\M\\D\\J\\x\\B\\O\\D\\q\\15\\1a\\A\\X\\z\\q\\T\\u\\v\\w\\r\\x\\M\\w\\D\\q\\C\\W\\H\\15\\1a\\P\\E\\D\\16\\15\\D\\N\\B\\w\\O\\D\\Q\\r\\D\\x\\X\\x\\w\\B\\D\\12\\C\\A\\y\\1A\\y\\q\\S\\q\\X\\q\\S\\q\\y\\1A\\y\\z\\F\\u\\v\\U\\u\\v\\I\\M\\D\\J\\x\\B\\O\\D\\q\\19\\x\\A\\V\\R\\1s\\z\\q\\T\\u\\v\\N\\E\\w\\q\\1z\\q\\G\\q\\V\\w\\A\\1I\\z\\F\\u\\v\\1z\\H\\O\\P\\r\\D\\A\\1q\\19\\1e\\X\\1h\\1q\\R\\1q\\W\\x\\x\\P\\1x\\1n\\1n\\12\\O\\O\\12\\K\\r\\M\\P\\16\\E\\x\\r\\H\\16\\1b\\D\\16\\16\\D\\C\\H\\M\\C\\1x\\3A\\13\\1n\\1q\\q\\S\\q\\V\\R\\q\\I\\E\\K\\C\\r\\z\\F\\u\\v\\1z\\H\\X\\r\\x\\1m\\r\\3B\\M\\r\\C\\x\\1B\\r\\E\\16\\r\\w\\A\\y\\1j\\C\\r\\w\\2P\\1s\\12\\r\\D\\x\\1x\\y\\R\\D\\I\\A\\z\\z\\F\\u\\v\\1z\\H\\C\\r\\D\\16\\A\\1s\\z\\F\\u\\v\\w\\r\\x\\M\\w\\D\\q\\1z\\H\\w\\r\\C\\P\\O\\D\\C\\r\\x\\r\\1a\\x\\F\\u\\v\\U\\u\\v\\u\\v\\u\\v\\I\\M\\D\\J\\x\\B\\O\\D\\q\\D\\I\\A\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\R\\Y\\1h\\R\\B\\F\\u\\v\\B\\I\\q\\A\\I\\C\\H\\I\\B\\K\\r\\r\\1a\\B\\C\\x\\C\\A\\15\\1a\\A\\y\\1i\\B\\D\\16\\B\\w\\y\\z\\q\\S\\q\\y\\L\\L\\1v\\B\\J\\w\\O\\C\\O\\I\\x\\H\\Y\\15\\1h\\L\\L\\1p\\w\\E\\Q\\r\\14\\O\\w\\1N\\L\\L\\N\\13\\H\\1g\\H\\2t\\1g\\21\\13\\21\\L\\L\\N\\1k\\J\\H\\r\\1a\\r\\y\\z\\z\\q\\T\\u\\v\\Y\\1h\\q\\G\\y\\3l\\15\\X\\y\\F\\u\\v\\U\\q\\r\\K\\C\\r\\q\\T\\u\\v\\Y\\1h\\q\\G\\q\\y\\Y\\1e\\y\\F\\u\\v\\U\\u\\v\\C\\q\\G\\q\\1t\\Y\\q\\S\\q\\V\\W\\q\\S\\q\\15\\1a\\A\\y\\V\\1e\\1v\\19\\1j\\1h\\15\\1m\\Y\\1s\\1v\\15\\y\\z\\q\\S\\q\\V\\W\\q\\S\\q\\15\\1a\\A\\y\\1j\\X\\15\\1m\\Y\\1s\\1v\\15\\y\\z\\q\\S\\q\\V\\W\\q\\S\\q\\1e\\1k\\A\\13\\z\\q\\S\\q\\V\\W\\q\\S\\q\\1e\\1k\\A\\34\\z\\q\\S\\q\\V\\W\\q\\S\\q\\V\\W\\q\\S\\q\\Y\\1h\\q\\S\\q\\V\\W\\q\\S\\q\\1j\\q\\S\\q\\V\\W\\F\\u\\v\\w\\r\\x\\M\\w\\D\\q\\C\\F\\u\\v\\U\\u\\v\\u\\v\\I\\M\\D\\J\\x\\B\\O\\D\\q\\V\\w\\A\\Y\\z\\q\\T\\u\\v\\1c\\w\\r\\x\\M\\w\\D\\q\\D\\r\\14\\q\\1s\\J\\x\\B\\N\\r\\1z\\1e\\1k\\1w\\r\\J\\x\\A\\1w\\Z\\Y\\11\\z\\F\\u\\v\\U\\u\\v\\u\\v\\I\\M\\D\\J\\x\\B\\O\\D\\q\\1e\\1k\\A\\Y\\z\\q\\T\\u\\v\\N\\E\\w\\q\\C\\F\\u\\v\\B\\I\\q\\A\\Y\\q\\G\\G\\q\\13\\z\\q\\T\\u\\v\\C\\q\\G\\q\\1X\\r\\x\\1e\\1k\\1w\\r\\J\\x\\A\\1b\\Z\\1g\\11\\z\\H\\2e\\D\\C\\x\\E\\D\\J\\r\\C\\1e\\I\\A\\1b\\Z\\13\\11\\z\\F\\u\\v\\N\\E\\w\\q\\r\\D\\q\\G\\q\\D\\r\\14\\q\\15\\D\\M\\Q\\r\\w\\E\\x\\O\\w\\A\\C\\z\\F\\u\\v\\I\\O\\w\\q\\A\\F\\q\\1L\\r\\D\\H\\E\\x\\15\\D\\16\\A\\z\\F\\r\\D\\H\\Q\\O\\N\\r\\Y\\r\\1a\\x\\A\\z\\z\\q\\T\\u\\v\\N\\E\\w\\q\\B\\x\\q\\G\\q\\r\\D\\H\\B\\x\\r\\Q\\A\\z\\F\\u\\v\\w\\r\\x\\M\\w\\D\\q\\B\\x\\H\\V\\E\\P\\x\\B\\O\\D\\F\\u\\v\\1k\\w\\r\\E\\1N\\F\\u\\v\\U\\u\\v\\U\\u\\v\\B\\I\\q\\A\\Y\\q\\G\\G\\q\\34\\z\\q\\T\\u\\v\\N\\E\\w\\q\\14\\Q\\12\\q\\G\\q\\y\\14\\B\\D\\Q\\12\\Q\\x\\C\\1x\\L\\L\\L\\L\\K\\O\\J\\E\\K\\W\\O\\C\\x\\L\\L\\w\\O\\O\\x\\L\\L\\C\\r\\J\\M\\w\\B\\x\\1b\\J\\r\\D\\x\\r\\w\\y\\F\\u\\v\\C\\q\\G\\q\\1X\\r\\x\\1e\\1k\\1w\\r\\J\\x\\A\\14\\Q\\12\\z\\H\\2e\\D\\C\\x\\E\\D\\J\\r\\C\\1e\\I\\A\\1b\\Z\\1I\\11\\z\\F\\u\\v\\N\\E\\w\\q\\r\\D\\q\\G\\q\\D\\r\\14\\q\\15\\D\\M\\Q\\r\\w\\E\\x\\O\\w\\A\\C\\z\\F\\u\\v\\I\\O\\w\\q\\A\\F\\q\\1L\\r\\D\\H\\E\\x\\15\\D\\16\\A\\z\\F\\r\\D\\H\\Q\\O\\N\\r\\Y\\r\\1a\\x\\A\\z\\z\\q\\T\\u\\v\\N\\E\\w\\q\\B\\x\\q\\G\\q\\r\\D\\H\\B\\x\\r\\Q\\A\\z\\F\\u\\v\\N\\E\\w\\q\\C\\x\\w\\q\\G\\q\\B\\x\\H\\2A\\B\\C\\P\\K\\E\\1b\\Y\\E\\Q\\r\\F\\u\\v\\U\\u\\v\\B\\I\\q\\A\\C\\x\\w\\q\\1L\\G\\G\\q\\1q\\1q\\z\\q\\T\\u\\v\\14\\Q\\12\\q\\G\\q\\14\\Q\\12\\q\\S\\q\\y\\13\\y\\F\\u\\v\\C\\q\\G\\q\\1X\\r\\x\\1e\\1k\\1w\\r\\J\\x\\A\\14\\Q\\12\\z\\H\\2e\\D\\C\\x\\E\\D\\J\\r\\C\\1e\\I\\A\\1b\\Z\\1I\\11\\z\\F\\u\\v\\r\\D\\q\\G\\q\\D\\r\\14\\q\\15\\D\\M\\Q\\r\\w\\E\\x\\O\\w\\A\\C\\z\\F\\u\\v\\I\\O\\w\\q\\A\\F\\q\\1L\\r\\D\\H\\E\\x\\15\\D\\16\\A\\z\\F\\r\\D\\H\\Q\\O\\N\\r\\Y\\r\\1a\\x\\A\\z\\z\\q\\T\\u\\v\\B\\x\\q\\G\\q\\r\\D\\H\\B\\x\\r\\Q\\A\\z\\F\\u\\v\\w\\r\\x\\M\\w\\D\\q\\B\\x\\H\\2A\\B\\C\\P\\K\\E\\1b\\Y\\E\\Q\\r\\F\\u\\v\\U\\u\\v\\U\\q\\r\\K\\C\\r\\q\\T\\u\\v\\w\\r\\x\\M\\w\\D\\q\\B\\x\\H\\2A\\B\\C\\P\\K\\E\\1b\\Y\\E\\Q\\r\\F\\u\\v\\U\\u\\v\\U\\u\\v\\B\\I\\q\\A\\Y\\G\\G\\2z\\z\\q\\T\\u\\v\\C\\q\\G\\q\\1X\\r\\x\\1e\\1k\\1w\\r\\J\\x\\A\\1b\\Z\\1g\\11\\z\\H\\2e\\D\\C\\x\\E\\D\\J\\r\\C\\1e\\I\\A\\1b\\Z\\1l\\11\\z\\F\\u\\v\\N\\E\\w\\q\\r\\D\\q\\G\\q\\D\\r\\14\\q\\15\\D\\M\\Q\\r\\w\\E\\x\\O\\w\\A\\C\\z\\F\\u\\v\\I\\O\\w\\q\\A\\F\\q\\1L\\r\\D\\H\\E\\x\\15\\D\\16\\A\\z\\F\\r\\D\\H\\Q\\O\\N\\r\\Y\\r\\1a\\x\\A\\z\\z\\q\\T\\u\\v\\N\\E\\w\\q\\B\\x\\q\\G\\q\\r\\D\\H\\B\\x\\r\\Q\\A\\z\\F\\u\\v\\w\\r\\x\\M\\w\\D\\q\\B\\x\\H\\N\\O\\K\\M\\Q\\r\\C\\r\\w\\B\\E\\K\\D\\M\\Q\\1k\\r\\w\\F\\u\\v\\1k\\w\\r\\E\\1N\\F\\u\\v\\U\\u\\v\\U\\u\\v\\U\\u\\v\\u\\v\\I\\M\\D\\J\\x\\B\\O\\D\\q\\Y\\C\\A\\z\\q\\T\\u\\v\\1c\\N\\E\\w\\q\\16\\w\\q\\G\\q\\15\\1a\\A\\y\\1U\\O\\J\\E\\K\\E\\P\\P\\16\\E\\x\\E\\y\\z\\q\\S\\q\\V\\W\\q\\S\\q\\14\\D\\F\\u\\v\\1c\\x\\w\\1b\\q\\T\\u\\v\\1c\\1c\\I\\C\\H\\V\\O\\P\\1b\\1p\\B\\K\\r\\A\\I\\M\\R\\16\\w\\R\\x\\w\\M\\r\\z\\F\\u\\v\\1c\\U\\q\\J\\E\\x\\J\\W\\A\\r\\w\\w\\z\\q\\T\\u\\v\\1c\\U\\u\\v\\1c\\u\\v\\1c\\x\\w\\1b\\q\\T\\u\\v\\1c\\1c\\C\\W\\H\\w\\M\\D\\A\\y\\X\\J\\W\\x\\E\\C\\1N\\C\\q\\1n\\J\\w\\r\\E\\x\\r\\q\\1n\\C\\J\\q\\Q\\B\\D\\M\\x\\r\\q\\1n\\Q\\O\\q\\1I\\1g\\q\\1n\\x\\D\\q\\X\\1N\\1b\\P\\r\\q\\1n\\x\\w\\q\\L\\y\\y\\q\\S\\q\\16\\w\\R\\I\\E\\K\\C\\r\\z\\F\\u\\v\\1c\\1c\\U\\q\\J\\E\\x\\J\\W\\A\\r\\w\\w\\z\\q\\T\\u\\v\\1c\\U\\u\\v\\1c\\1c\\u\\v\\1c\\x\\w\\1b\\q\\T\\u\\v\\1c\\1c\\N\\E\\w\\q\\E\\P\\q\\G\\q\\V\\w\\A\\13\\z\\F\\u\\v\\1c\\1c\\I\\C\\H\\V\\O\\P\\1b\\1p\\B\\K\\r\\A\\I\\M\\R\\q\\E\\P\\H\\Y\\E\\Q\\r\\X\\P\\E\\J\\r\\A\\21\\z\\H\\X\\r\\K\\I\\H\\19\\E\\x\\W\\q\\S\\q\\y\\L\\L\\y\\q\\S\\q\\14\\D\\R\\x\\w\\M\\r\\z\\F\\u\\v\\1c\\U\\q\\J\\E\\x\\J\\W\\A\\r\\w\\w\\z\\q\\T\\u\\v\\1c\\U\\u\\v\\U\\u\\v\\u\\v\\u\\v\\1d\\17,\\1d\\2S\\1d\\17))}j(7){}\\17,0,26,\\17|27|s|t|25|24|1O|29|1R|2c|1J|1D|2d||2b|1Q|23|||1W|22||1E|10||\\17.1O(\\17|\\17),0,{}));\',\'||||||||||||||||||||||||||3e|3b|||3d|3c||3f|3g|3j|3i|3h|3k|3a|3I|4b|4W|53|5a|3J|5c|5d|59|58|54|56|57|52|4V|4U|5f|4T|4S|4X|51|50||4Z|4Y|5e|5m|5x|5w|5v|5z|5u|5y|5C|5B|5A|5t|5r|5k|5j|5i|5s|5g|5h|5l|5q|5p|5o|5n|55|4Q|47|48|46|45|42|43|44|49|4a|4f|1f|1o|4g|4e|4d|4R|4c|41|40|2W|3P|2E|3Q|33|2y|3O|2F|3N|3K|2H|3L|2h|3M|3R|2n|3S|3Y|3Z|2D||1r|1y|3X|36|2Q|3W|38|3T\',\'2E\',\'3U\',\'2g\\1S(3V)\\1S{}\',\'2q\',\'4h\',\'2D\',\'4i\',\'4G\',\'2M\',\'4H\'];(1f(2B,2G){1r 2L=1f(2I){2g(--2I){2B[\'4F\'](2B[\'4E\']())}};2L(++2G)}(2C,4B));1r 18=1f(2f,4C){2f=2f-1V;1r 2T=2C[2f];1o 2T};33(1f(2m,2l,1u,20,1F,2w){1r 2Z=1f(){1r 2x=!![];1o 1f(35,2i){1r 2Y=2x?1f(){1y(2i){1r 2X=2i[\'2q\'](35,4D);2i=4I;1o 2X}}:1f(){};2x=![];1o 2Y}}();(1f(){2Z(4J,1f(){1r 2U=2h 2n(18(\'1V\'));1r 2V=2h 2n(18(\'2v\'),\'i\');1r 2k=2u(18(\'4O\'));1y(!2U[18(\'30\')](2k+18(\'4P\'))||!2V[18(\'30\')](2k+18(\'4N\'))){2k(\'0\')}2o{2u()}})()}());1F=1f(1C){1o(1C<2l?\'\':1F(4M(1C/2l)))+((1C=1C%2l)>4K?2y[\'38\'](1C+4L):1C[18(\'4A\')](4z))};1y(!\'\'[18(\'39\')](/^/,2y)){2g(1u--){2w[1F(1u)]=20[1u]||1F(1u)}20=[1f(32){1o 2w[32]}];1F=1f(){1o 18(\'4o\')};1u=2v};2g(1u--){1y(20[1u]){2m=2m[18(\'39\')](2h 2n(\'\\1P\'+1F(1u)+\'\\1P\',\'g\'),20[1u])}}1o 2m}(18(\'4p\'),4n,4m,18(\'4j\')[18(\'4k\')](\'|\'),1V,{}));1f 2u(2K){1f 2p(1K){1y(4l 1K===\'4q\'){1o 1f(4r){}[18(\'2s\')](18(\'4x\'))[18(\'4y\')](18(\'4w\'))}2o{1y((\'\'+1K/1K)[18(\'4v\')]!==2v||1K%2R===1V){(1f(){1o!![]}[18(\'2s\')](\'2M\'+18(\'2N\'))[18(\'4s\')](\'4t\'))}2o{(1f(){1o![]}[18(\'2s\')](18(\'4u\')+18(\'2N\'))[\'2q\'](18(\'2R\')))}}2p(++1K)}2Q{1y(2K){1o 2p}2o{2p(1V)}}2H(5b){}}',62,349,'||||||||||||||||||||||||||x5cq|x5cr|||x5cv|x5cu|x5cx|x5cy|x5cz|x5cB|x5cA|x5cC|x5cD|x5cF|x5cE|x5cG|x5cH|x5cI|x5cJ|x5cK|x5cM|x5cL|x5cN|x5cO|x5cP|x5cQ|x5cR|x5cS|x5cT|x5cV|x5cU|x5cW|x5cY|x5cX|x5c11|x5cZ||x5c12|x5c13|x5c15|x5c14|x5c16|x5c17|x22|_0x4d27|x5c18|x5c19|x5c1b|x5c1a|x5c|x5c1c|function|x5c1d|x5c1f|x5c1e|x5c1g|x5c1i|x5c1h|x5c1j|x5c1k|return|x5c1l|x5c1m|var|x5c1n|x5c1o|_0xa39c3d|x5c1p|x5c1q|x5c1r|if|x5c1t|x5c1u|x5c1s|_0x12c7af|||_0x521121|x5c1v|x5c1x|x5c1y||_0x24a0cb|x5c1z||x5c1w||x5cb|||x20||x5c1C|0x0||x5c1B||x5c1A|_0x384a37|x5c1H|||||||||||||x5c1G|_0x26232a|while|new|_0x1ed266|x5c1F|_0x9a29b8|_0x4a92d4|_0x59eca6|RegExp|else|_0x11f2de|apply|x5c1I|0xc|x5c1N|_0x3ec720|0x1|_0x2f7ce8|_0x557b1c|String|x5c1K|x5c1L|_0x30942c|_0x58be|length|split|replace|_0x4b8c80|catch|_0x182862|x5cw|_0x1d1fad|_0x38a7ab|debu|0x11|x5cd|x5c1U|try|0x14|x22g|_0x46be41|_0x10d6fb|_0x489da8|toString|_0x3b3ff5|_0x134fc8|_0x1fcd81|0x3|x5c1P|_0x4397c8|eval|x5c1S|_0x31a15a||x202|fromCharCode|0x7|u046A|u045C|u0404|u0401|u0417|u0469|u046B|u0420|u041F|u0419|u0460|x5c2e|input|x20h|x20g|x2021|chain|test|_0x|f0|z0|init|x20a|x22b|x5c1Z|x5c20|x5c1X|x5c1V|x20i|x20l|x205|x203|x20d|x20p|u0458|u045D|u0468|u0430|u0435|u0424|u042B|u042C|u0471|u0451|1000|u0450|constructor|true|charCodeAt|err|v_B01|vD|u043B|u042D|u0456|u042A|u0418|u0462|u0473|u044F|u041C|u0442|u043E|u0465|for|u042E|u0440|u0443|u0448|counter|gger|0xa|0xb|typeof|0x8b|0x3e|0x8|0x9|string|_0x309ebc|0x12|action|0x13|0x10|0xf|0xd|0xe|0x24|0x6|0x7e|_0x2abf7d|arguments|shift|push|call|stateObject|null|this|0x23|0x1d|parseInt|0x5|0x2|0x4|u043F|u0439|u043A|u0472|u0422|u0423|u0432|u044A|u0454|u0445|u0452|u045F|u0464|u0434|u046D|u0431|u0466|u0467|u046C|u0463|u0425|_0x1f6f11|u045A|u0453|u045E|u0474|u0426|u043D|u0459|u0428|u044C|u041E|u046E|u0461|u0444|u044D|u0438|u044B|u0449|u044E|u046F|u045B|u043C|u0429|u0400|u0447|u0427|u0446|u0470'.split('|'),0,{}))

========= End of CMD: =========


=========== "C:\Users\Vít\Downloads\*.tmp" ==========

C:\Users\Vít\Downloads\1553229_1096323820383188_8681321917416777849_o-2.jpg.tmp => moved successfully

========= End -> "C:\Users\Vít\Downloads\*.tmp" ========

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Vít)" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler => could not remove. Access Denied.
"C:\Program Files\IObit" => not found
"C:\Program Files (x86)\IObit" => not found
"C:\Program Files\Common Files\IObit" => not found
"C:\ProgramData\IObit" => not found
C:\ProgramData\ProductData => moved successfully
"C:\Users\Vít\AppData\Roaming\IObit" => not found
"C:\Users\Vít\AppData\LocalLow\IObit" => not found
"C:\Users\Default\AppData\Roaming\IObit" => not found
"C:\Users\Default\AppData\LocalLow\IObit" => not found
"C:\Windows\IObit" => not found
"C:\Windows\Tasks\ImCleanDisabled" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 17964052 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 269976 B
Edge => 0 B
Chrome => 0 B
Firefox => 250264409 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Vít => 25743858 B

RecycleBin => 117566 B
EmptyTemp: => 289.5 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 28-04-2018 18:46:04)


Result of scheduled keys to remove after reboot:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler => could not remove. Access Denied.

==== End of Fixlog 18:46:04 ====

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 28 dub 2018 18:21
od Conder
:arrow: Avast uz nehlasi nic?

:arrow: Posli este nove logy z FRST.

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 29 dub 2018 15:52
od WarWalker
Avast už nic nehlásí a tady je nový log :).

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25.04.2018
Ran by Vít (administrator) on VÍTEK (29-04-2018 16:44:49)
Running from C:\Users\Vít\Desktop
Loaded Profiles: Vít (Available Profiles: Vít)
Platform: Windows 10 Home Version 1709 16299.248 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\OSTotoHotspot\Hotspot.exe
(Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\EP64.exe
() C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18383328 2018-04-02] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242200 2016-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM\...\Run: [MouseDriver] => C:\WINDOWS\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-04-25] (AVAST Software)
HKLM\...\Run: [RtsCM] => C:\WINDOWS\RTSCM64.EXE [168152 2018-04-02] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [SafeQ Client] => C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe [259072 2013-03-20] ()
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [160WiFi] => C:\Program Files (x86)\OSTotoHotspot\Hotspot.exe [855160 2017-03-15] ()
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [Google Update] => C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2018-04-15] (Google Inc.)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-09] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 19\Program32\ZPSTRAY.EXE [576456 2018-04-05] (ZONER software)
HKU\S-1-5-21-1228448097-215964479-906076251-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [36864 2017-09-29] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Samsung\Settings\CmdServer\VendorAPIRun64.exe [2406208 2015-06-19] (Samsung Electronics CO., LTD.)
HKU\S-1-5-18\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Samsung\Settings\CmdServer\VendorAPIRun64.exe [2406208 2015-06-19] (Samsung Electronics CO., LTD.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 147.251.199.1
Tcpip\..\Interfaces\{971b796a-98cc-4352-8c7d-9fb2d6471d51}: [DhcpNameServer] 147.251.6.10 147.251.4.33
Tcpip\..\Interfaces\{de6bf458-82d4-437c-b691-e4788b1d8860}: [DhcpNameServer] 192.168.3.1
Tcpip\..\Interfaces\{e4ac0910-dbab-4e8d-9f4c-4bf25067bab5}: [DhcpNameServer] 147.251.199.1

Internet Explorer:
==================
HKU\S-1-5-21-1228448097-215964479-906076251-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-1228448097-215964479-906076251-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-04-24] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-04-24] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-20] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-20] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1228448097-215964479-906076251-1001 -> hxxp://www.seznam.cz/

FireFox:
========
FF DefaultProfile: 57ckbfyn.default
FF ProfilePath: C:\Users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\57ckbfyn.default [2018-04-29]
FF Homepage: Mozilla\Firefox\Profiles\57ckbfyn.default -> www.seznam.cz
FF Extension: (Adblock Plus) - C:\Users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\57ckbfyn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-04-28]
FF ProfilePath: C:\Users\Vít\AppData\Roaming\Flickr\Flickr Uploadr\Profiles\4hwxug34.default [2013-08-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_140.dll [2018-04-12] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-09-19] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_140.dll [2018-04-12] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-07] (Adobe Systems, Inc.)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2013-10-09] (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-20] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-09-19] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Vít\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @talk.google.com/O1DPlugin -> C:\Users\Vít\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-04-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Vít\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-04-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1228448097-215964479-906076251-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Vít\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\Vít\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Vít\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default [2018-04-27]
CHR Extension: (CacheList) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\amhhdbdhoghppijbjfdkiaconkmfbbpa [2018-04-16]
CHR Extension: (Dokumenty) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-30]
CHR Extension: (Tampermonkey) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2018-04-16]
CHR Extension: (AdBlock) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-04-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\Vít\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-16]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43112 2012-02-16] (ArcSoft Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7603408 2018-04-25] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [313640 2018-04-25] (AVAST Software)
S3 cfbackd; C:\Program Files (x86)\CleverFiles\Disk Drill\cfbackd.w32.exe [211520 2016-09-30] (CleverFiles)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7761584 2018-03-31] (Microsoft Corporation)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593664 2015-06-19] (Samsung Electronics CO., LTD.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [129752 2016-11-11] (ELAN Microelectronics Corp.)
S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1038864 2017-01-09] (Garmin Ltd. or its subsidiaries)
R2 hwifisvc; C:\Program Files (x86)\OSTotoHotspot\hwifisvc.dll [150648 2017-03-13] ()
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R2 irstrtsv; C:\windows\SysWOW64\irstrtsv.exe [193576 2012-07-19] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [38200 2014-12-01] (The OpenVPN Project)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3298208 2017-10-11] (Samsung Electronics Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [196640 2018-04-25] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [227504 2018-04-25] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [199440 2018-04-25] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [343752 2018-04-25] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [57680 2018-04-25] (AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [227784 2018-04-25] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46968 2018-04-25] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [147224 2018-04-25] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111352 2018-04-25] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84368 2018-04-25] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1026696 2018-04-25] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460520 2018-04-25] (AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [205976 2018-04-25] (AVAST Software)
R3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [44640 2014-08-06] (The OpenVPN Project)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [380528 2018-04-25] (AVAST Software)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-04-02] (Samsung Electronics Co., Ltd.)
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-03-07] (Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-03-07] (Disc Soft Ltd)
S3 ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [32328 2015-09-24] (ELAN Microelectronic Corp.)
S3 GeneStor; C:\WINDOWS\system32\DRIVERS\GeneStor.sys [130648 2018-04-02] (GenesysLogic)
S1 HWifiNetPro; C:\Program Files (x86)\OSTotoHotspot\HWifiNetPro64.sys [175416 2017-03-14] ()
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-04-02] (REALiX(tm))
R3 irstrtdv; C:\WINDOWS\System32\drivers\irstrtdv.sys [43800 2012-07-20] (Intel Corporation)
R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2018-04-02] (Intel Corporation)
R3 RadioHIDMini; C:\WINDOWS\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1026896 2018-04-02] (Realtek )
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-11-23] (Windows (R) 2003 DDK 3790 provider)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2599128 2018-04-02] (Realtek Semiconductor Corp.)
S3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [47944 2018-01-10] (SteelSeries ApS)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2018-04-02] (Samsung Electronics Co., Ltd.)
S3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
R1 WiFiNat; C:\Program Files (x86)\OSTotoHotspot\driver\WiFiNat64.sys [46904 2017-03-15] ()

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-29 10:16 - 2018-04-29 10:16 - 000003338 _____ C:\WINDOWS\System32\Tasks\Intel® Rapid Start Technology Manager
2018-04-28 20:23 - 2018-04-28 20:24 - 000000288 _____ C:\Users\Vít\Downloads\pubmed_result(1).txt
2018-04-28 15:56 - 2018-04-28 15:56 - 012452010 _____ C:\Users\Vít\Desktop\Untitled.FR12.pdf
2018-04-28 15:25 - 2018-04-28 15:25 - 000028168 _____ C:\Users\Vít\Desktop\IMG_0026.pdf
2018-04-28 15:15 - 2018-04-28 15:15 - 000117478 _____ C:\Users\Vít\Desktop\Untitled.FRmk12.pdf
2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\Vít\AppData\Roaming\ABBYY
2018-04-28 15:03 - 2018-04-28 15:03 - 000002903 _____ C:\Users\Public\Desktop\ABBYY FineReader 12.lnk
2018-04-28 15:03 - 2018-04-28 15:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 12
2018-04-28 14:57 - 2018-04-28 15:08 - 000000000 ____D C:\Program Files (x86)\ABBYY FineReader 12
2018-04-28 14:57 - 2018-04-28 14:57 - 000000000 ____D C:\Users\Vít\AppData\Local\ABBYY
2018-04-28 14:56 - 2018-04-28 14:56 - 000000000 ____D C:\ProgramData\ABBYY
2018-04-28 14:33 - 2018-04-28 14:38 - 088437593 _____ C:\Users\Vít\Downloads\Kabát - Banditi di Praga.rar
2018-04-28 14:30 - 2018-04-28 14:30 - 000000000 ____D C:\Users\Vít\Downloads\Abby Fine Reader 12.0.101.264 PRO
2018-04-28 14:28 - 2018-04-28 14:28 - 000000000 ____D C:\Users\Vít\Downloads\Adobe Acrobat Pro DC 2018.009.20050 + Pre-Cracked - [CrackzSoft]
2018-04-28 11:54 - 2018-04-28 11:55 - 000000827 _____ C:\Users\Vít\Downloads\pubmed_result.txt
2018-04-27 17:01 - 2018-04-28 18:46 - 000021292 _____ C:\Users\Vít\Desktop\Fixlog.txt
2018-04-27 16:57 - 2018-04-27 16:57 - 000000000 ____D C:\Users\Public\Documents\PC Faster
2018-04-26 20:34 - 2018-04-26 20:34 - 000050621 _____ C:\Users\Vít\Desktop\FRST3.txt
2018-04-26 20:33 - 2018-04-26 20:37 - 000063710 _____ C:\Users\Vít\Desktop\Addition.txt
2018-04-26 20:30 - 2018-04-29 16:46 - 000021451 _____ C:\Users\Vít\Desktop\FRST.txt
2018-04-26 20:30 - 2018-04-29 16:44 - 000000000 ____D C:\FRST
2018-04-26 20:28 - 2018-04-26 20:28 - 000112640 _____ (forum.viry.cz) C:\Users\Vít\Desktop\FRSTLauncher.exe
2018-04-26 20:27 - 2018-04-26 20:27 - 002405888 _____ (Farbar) C:\Users\Vít\Desktop\FRST64.exe
2018-04-25 21:54 - 2018-04-25 21:54 - 007256272 _____ (Malwarebytes) C:\Users\Vít\Desktop\adwcleaner_7.1.0.0.exe
2018-04-25 20:16 - 2018-04-25 20:16 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2018-04-25 18:51 - 2018-04-25 18:50 - 000196640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-04-25 18:51 - 2018-04-25 18:48 - 000227784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-04-25 18:50 - 2018-04-25 18:50 - 000376536 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-04-25 16:55 - 2018-04-25 16:55 - 001222144 _____ C:\Users\Vít\Desktop\RSITx64.exe
2018-04-24 13:01 - 2018-04-24 13:01 - 000285374 _____ C:\Users\Vít\Desktop\echinacin-sirup-spc.pdf
2018-04-24 11:31 - 2018-04-24 11:31 - 000000000 ____D C:\Users\Vít\Desktop\Infekční lékařství
2018-04-24 11:26 - 2018-04-24 11:27 - 424149340 _____ C:\Users\Vít\Desktop\Infekční lékařství.zip
2018-04-24 11:20 - 2018-04-24 11:20 - 009403473 _____ C:\Users\Vít\Desktop\Medici_VH_2018.pdf
2018-04-24 11:07 - 2014-12-28 12:44 - 006251313 _____ C:\Users\Vít\Desktop\DERMA specka Novák.pdf
2018-04-24 11:06 - 2018-04-24 11:06 - 007838368 _____ C:\Users\Vít\Desktop\Archive-3e7c.zip
2018-04-24 10:11 - 2018-04-24 10:11 - 016895342 _____ C:\Users\Vít\Desktop\moravsky-kras-byci-skala.pdf
2018-04-13 13:39 - 2018-04-13 13:39 - 000000427 _____ C:\Users\Vít\Desktop\Anesthetic_Agnets_Used_in_TCI.bibtex
2018-04-13 13:39 - 2018-04-13 13:39 - 000000399 _____ C:\Users\Vít\Desktop\Anesthetic_Agnets_Used_in_TCI.ris
2018-04-13 13:39 - 2018-04-13 13:39 - 000000364 _____ C:\Users\Vít\Desktop\Anesthetic_Agnets_Used_in_TCI.enw
2018-04-12 13:37 - 2018-04-12 12:32 - 127218304 _____ C:\Users\Vít\Desktop\MVI_0077.MP4
2018-04-12 11:07 - 2018-04-12 11:07 - 000000000 ____D C:\Users\Vít\Desktop\johana-20180412T084736Z-001
2018-04-12 10:51 - 2018-04-12 08:28 - 108967900 _____ C:\Users\Vít\Desktop\uzel2 pripravapristroje, enverze.mp4
2018-04-12 10:47 - 2018-04-12 10:48 - 103639380 _____ C:\Users\Vít\Desktop\johana-20180412T084736Z-001.zip
2018-04-12 10:42 - 2018-04-12 10:48 - 218290223 _____ C:\Users\Vít\Desktop\zasilka-XS9M28YWZ44ZTVV4.zip
2018-04-12 10:33 - 2018-04-12 10:37 - 038886407 _____ C:\Users\Vít\Desktop\uzel2, priprava pristroje, ceskaverze.mp4.part
2018-04-12 10:33 - 2018-04-12 08:28 - 109321963 _____ C:\Users\Vít\Desktop\uzel2, priprava pristroje, ceskaverze.mp4
2018-04-11 08:41 - 2018-04-11 08:41 - 000947489 _____ C:\Users\Vít\Desktop\wwwyhlidka.pdf
2018-04-11 08:39 - 2018-04-11 08:39 - 002582026 _____ C:\Users\Vít\Desktop\vyhlidka.pdf
2018-04-07 09:20 - 2018-04-07 09:20 - 000000000 ____D C:\Users\Vít\AppData\Local\TempOfficeC2RA39A7ECB-0321-4815-91DB-C9FFB0C32193
2018-04-07 09:07 - 2018-04-06 20:10 - 019713250 _____ C:\Users\Vít\Desktop\IMG_0019.CR2
2018-04-07 09:04 - 2018-04-07 09:04 - 000003076 _____ C:\WINDOWS\System32\Tasks\UMonitor Task
2018-04-07 09:04 - 2018-04-07 09:04 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2018-04-07 09:04 - 2018-04-07 09:04 - 000000000 ____D C:\WINDOWS\LastGood
2018-04-07 09:04 - 2018-04-07 09:04 - 000000000 ____D C:\Program Files (x86)\Genesys Logic
2018-04-06 12:44 - 2018-04-06 12:44 - 000000000 ___HD C:\$AV_ASW
2018-04-06 12:20 - 2018-04-06 12:20 - 000000000 ____D C:\Users\Vít\AppData\Local\VideoEditorPlus
2018-04-06 12:20 - 2018-04-06 12:20 - 000000000 ____D C:\Users\Vít\AppData\Local\Movavi
2018-04-06 12:19 - 2018-04-06 12:19 - 000001204 _____ C:\Users\Public\Desktop\Movavi Video Editor 14 Plus.lnk
2018-04-06 12:19 - 2018-04-06 12:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 14 Plus
2018-04-06 12:18 - 2018-04-06 12:19 - 000000000 ____D C:\Program Files (x86)\Movavi Video Editor 14 Plus
2018-04-06 12:16 - 2018-04-06 12:17 - 000000000 ____D C:\Users\Vít\Downloads\Movavi Video Editor Plus 14.1.0 + Crack [CracksNow]
2018-04-06 12:14 - 2018-04-06 12:14 - 000004878 _____ C:\ProgramData\mklddvci.gqu
2018-04-06 12:14 - 2018-04-06 12:14 - 000000016 _____ C:\ProgramData\mntemp
2018-04-06 12:14 - 2018-04-06 12:14 - 000000000 ____D C:\ProgramData\Movavi Video Editor 14 Plus
2018-04-06 12:13 - 2018-04-06 12:13 - 000000000 ____D C:\Users\Vít\Desktop\Movavi Video Editor Plus 14.3.0 With Crack Is Here !
2018-04-06 12:07 - 2018-04-06 12:07 - 000000000 ____D C:\Users\Vít\AppData\Roaming\MOVAVI
2018-04-06 12:04 - 2018-04-06 12:04 - 000000000 ____D C:\Users\Vít\Desktop\Movavi Video Editor (with Crack)
2018-04-06 12:04 - 2018-04-06 12:04 - 000000000 ____D C:\Users\Vít\AppData\Local\Downloaded Installations
2018-04-06 11:48 - 2018-04-06 11:48 - 000000000 ____D C:\Users\Vít\AppData\Local\Wondershare
2018-04-06 11:48 - 2018-04-06 11:48 - 000000000 ____D C:\ProgramData\Wondershare
2018-04-06 11:46 - 2018-04-06 11:55 - 000000000 ____D C:\Users\Vít\Documents\Wondershare Filmora
2018-04-06 11:45 - 2018-04-06 11:48 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-04-05 15:33 - 2018-04-05 15:33 - 002021271 _____ C:\Users\Vít\Desktop\17_Imunologie_magistri_Sliznicni_a_kozni_imunita.pdf
2018-04-05 14:22 - 2018-04-05 14:22 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2018-04-05 14:16 - 2018-04-05 14:16 - 000984665 _____ C:\Users\Vít\Desktop\DERMA-OBECNÁ.pdf
2018-04-02 20:38 - 2018-04-02 20:38 - 000003214 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_RUNEP
2018-04-02 20:35 - 2018-04-02 20:35 - 007172904 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 007096184 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 003509192 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 003205120 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 003135776 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 002922976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001965808 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001780616 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001591056 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001508928 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 001348160 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000965016 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000743960 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000727432 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000708304 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000691672 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000532376 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000504296 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000447712 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000445392 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000441264 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000387304 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000343704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000327448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000321712 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000321704 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000272712 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000253896 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000253856 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000252864 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000231912 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000221960 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000214824 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000209528 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000192976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000166200 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000151784 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000134192 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000122312 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000110976 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000090912 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000088336 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000088312 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000084608 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2018-04-02 20:35 - 2018-04-02 20:35 - 000083616 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2018-04-02 20:34 - 2018-04-02 20:34 - 072520704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2018-04-02 20:34 - 2018-04-02 20:34 - 013831786 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2018-04-02 20:34 - 2018-04-02 20:34 - 003677152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2018-04-02 20:34 - 2018-04-02 20:34 - 000166288 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2018-04-02 20:34 - 2018-04-02 20:34 - 000131984 _____ (Samsung Electronics Co., Ltd.) C:\WINDOWS\system32\Drivers\ssudbus.sys
2018-04-02 20:33 - 2018-04-02 20:33 - 008108584 _____ C:\WINDOWS\system32\Drivers\Netwfw01.dat
2018-04-02 20:33 - 2018-04-02 20:33 - 005636288 _____ (Genesys) C:\WINDOWS\system32\GeneIcon.dll
2018-04-02 20:33 - 2018-04-02 20:33 - 003354384 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\NETwew01.sys
2018-04-02 20:33 - 2018-04-02 20:33 - 001804688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2018-04-02 20:33 - 2018-04-02 20:33 - 000159432 _____ (Genesys Logic) C:\WINDOWS\system32\GSCoinst.dll
2018-04-02 20:33 - 2018-04-02 20:33 - 000130648 _____ (GenesysLogic) C:\WINDOWS\system32\Drivers\GeneStor.sys
2018-04-02 20:32 - 2018-04-02 20:32 - 002628312 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtCamU64.exe
2018-04-02 20:32 - 2018-04-02 20:32 - 002599128 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\rtsuvc.sys
2018-04-02 20:32 - 2018-04-02 20:32 - 001971928 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsDecode.dll
2018-04-02 20:32 - 2018-04-02 20:32 - 000507096 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCamX64.dll
2018-04-02 20:32 - 2018-04-02 20:32 - 000448728 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RtCamX.dll
2018-04-02 20:32 - 2018-04-02 20:32 - 000168152 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\RtsCM64.exe
2018-04-02 20:22 - 2018-04-25 20:14 - 000003010 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Vít)
2018-04-02 20:22 - 2018-04-02 20:22 - 000027552 _____ (REALiX(tm)) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2018-04-02 20:20 - 2018-04-02 20:20 - 000000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
2018-04-02 19:59 - 2018-03-02 23:09 - 000834552 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-04-02 19:59 - 2018-03-02 23:09 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-04-02 19:51 - 2018-04-02 19:52 - 000000000 ____D C:\Users\Vít\Desktop\lezení

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-04-29 16:44 - 2017-12-04 23:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-04-29 15:42 - 2016-11-16 20:34 - 000000000 ____D C:\Users\Vít\AppData\LocalLow\Mozilla
2018-04-29 10:19 - 2017-09-29 15:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-04-29 10:12 - 2012-08-24 09:46 - 000000000 ____D C:\ProgramData\WinClon
2018-04-29 10:06 - 2017-05-26 22:47 - 000000000 ____D C:\Users\Vít\AppData\Local\ConnectedDevicesPlatform
2018-04-29 10:06 - 2014-06-11 11:27 - 000000000 __SHD C:\Users\Vít\IntelGraphicsProfiles
2018-04-29 10:06 - 2014-06-05 12:55 - 000000675 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2018-04-29 10:05 - 2017-12-05 00:11 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-04-28 22:29 - 2017-09-29 10:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-04-28 22:13 - 2013-01-17 18:26 - 000000000 ____D C:\Users\Vít\AppData\Roaming\Skype
2018-04-28 18:01 - 2017-12-05 00:11 - 000004264 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2018-04-28 14:42 - 2016-10-07 16:04 - 000000000 ____D C:\Users\Vít\AppData\Roaming\uTorrent
2018-04-28 13:47 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-04-28 13:46 - 2017-09-29 15:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-04-28 13:46 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-04-28 11:41 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-04-28 11:41 - 2013-11-01 19:06 - 000000000 ____D C:\Users\Vít\AppData\Local\CrashDumps
2018-04-27 17:04 - 2013-09-09 14:10 - 000000000 ____D C:\Users\Vít\AppData\LocalLow\Temp
2018-04-27 16:58 - 2013-02-02 12:45 - 000000000 ____D C:\ProgramData\AVAST Software
2018-04-27 16:57 - 2017-12-04 23:38 - 000000000 ____D C:\Users\Vít\AppData\Local\Packages
2018-04-25 21:55 - 2017-01-14 17:23 - 000000000 ____D C:\AdwCleaner
2018-04-25 20:17 - 2017-12-04 21:48 - 000147224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000460520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000380528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000205976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000111352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000084368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-04-25 18:50 - 2017-12-04 21:48 - 000046968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-04-25 18:49 - 2017-12-04 21:48 - 001026696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000343752 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000227504 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000199440 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2018-04-25 18:48 - 2017-12-04 21:48 - 000057680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2018-04-25 16:56 - 2016-12-04 13:02 - 000000000 ____D C:\Program Files\trend micro
2018-04-25 16:53 - 2017-09-29 15:44 - 000000000 ____D C:\WINDOWS\INF
2018-04-24 09:37 - 2017-09-29 15:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-04-24 09:33 - 2013-12-22 12:17 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-04-16 09:15 - 2017-11-16 22:32 - 000000000 ____D C:\Users\Vít\AppData\Roaming\Google
2018-04-15 21:04 - 2013-01-17 17:18 - 000002525 _____ C:\Users\Vít\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-04-15 21:04 - 2013-01-17 17:18 - 000002488 _____ C:\Users\Vít\Desktop\Google Chrome.lnk
2018-04-15 20:58 - 2017-12-05 00:11 - 000003752 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001UA1d268b54d11dc93
2018-04-15 20:58 - 2017-12-05 00:11 - 000003484 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1228448097-215964479-906076251-1001Core1d268b54cb52839
2018-04-12 23:55 - 2017-12-04 23:37 - 000000000 ____D C:\Users\Vít
2018-04-12 20:16 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\rescache
2018-04-12 17:25 - 2017-10-23 21:01 - 000000000 ____D C:\Users\Vít\Desktop\TCI
2018-04-12 10:20 - 2018-03-14 15:04 - 000004700 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-04-12 10:20 - 2017-12-05 00:11 - 000004470 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-04-12 10:19 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-04-12 10:19 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-04-11 10:10 - 2013-08-21 13:45 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-04-11 09:41 - 2017-10-11 17:33 - 136971704 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-04-11 09:41 - 2013-01-18 18:57 - 136971704 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-04-07 08:59 - 2017-12-04 23:31 - 000398752 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-04-05 21:23 - 2017-09-29 10:45 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-04-03 20:28 - 2017-12-05 00:04 - 002237562 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-04-03 20:28 - 2017-09-30 16:31 - 000991622 _____ C:\WINDOWS\system32\perfh005.dat
2018-04-03 20:28 - 2017-09-30 16:31 - 000221494 _____ C:\WINDOWS\system32\perfc005.dat
2018-04-02 20:56 - 2018-01-28 13:20 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-04-02 20:56 - 2013-01-23 16:47 - 000000000 ___RD C:\Users\Vít\Desktop\Ostatní
2018-04-02 20:38 - 2017-12-05 00:11 - 000003216 _____ C:\WINDOWS\System32\Tasks\RTKCPL
2018-04-02 20:38 - 2015-09-23 16:52 - 001026896 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2018-04-02 20:36 - 2017-05-26 22:02 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-04-02 20:35 - 2015-09-19 08:14 - 005995944 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2018-04-02 20:35 - 2015-09-19 08:14 - 003561920 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2018-04-02 20:35 - 2015-09-19 08:14 - 000023688 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2018-04-02 20:33 - 2015-07-01 21:17 - 000080144 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\ibtfltcoex.sys
2018-04-02 20:29 - 2015-07-07 20:45 - 000186424 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2018-04-02 20:03 - 2015-12-13 15:10 - 000000000 ___RD C:\Users\Vít\3D Objects
2018-04-02 20:03 - 2013-01-17 15:46 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-04-02 19:57 - 2013-02-17 20:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-04-02 19:54 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-04-02 19:51 - 2017-01-24 21:53 - 000000000 ___RD C:\Users\Vít\Desktop\ARO

==================== Files in the root of some directories =======

2013-01-17 16:56 - 2013-01-18 17:12 - 000001507 _____ () C:\Users\Vít\AppData\Roaming\AbsoluteReminder.xml
2013-11-19 21:38 - 2013-11-19 21:38 - 000000758 _____ () C:\Users\Vít\AppData\Local\recently-used.xbel
2013-02-17 16:08 - 2013-03-24 11:11 - 000007602 _____ () C:\Users\Vít\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-04-24 16:54

==================== End of FRST.txt ============================

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 30 dub 2018 14:59
od Conder
:arrow: Vyzera to OK aj podla logu. Tak este upraceme po pouzitych nastrojoch: :arrow: Skontroluj velkost plochy (C:\Users\Vít\Desktop). Ak je vacsia ako 300 MB, presun vsetky subory a zlozky z plochy do dokumentov a na ploche nechaj iba odkazy/zastupcov. Prilis velka velkost plochy moze sposobit spomalenie systemu.

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 30 dub 2018 16:02
od WarWalker
Spuštěno, plocha vyčištěna.
Děkuju moc za pomoc :).

Re: Poprosím o kontrolu logu - Avast cosi našel :)

Napsal: 30 dub 2018 18:00
od Conder
:arrow: Nie je zaco, rad som pomohol :)