Divné chování notebooku, děkuji
Napsal: 12 srp 2018 11:12
Dobrý den, na noťasu objevuji divné chování. Windows Update mi vůbec nejde spustit. Ani do Windows Defender se nedostanu. Vůbec nevím, co s tím.. Děkuji mnohokrát za pomoc
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.08.2018
Ran by Ivana (administrator) on DESKTOP-CPUQIHL (12-08-2018 11:45:15)
Running from C:\Users\Ivana\Downloads
Loaded Profiles: Ivana (Available Profiles: Ivana)
Platform: Windows 10 Pro Version 1803 17134.165 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Lenovo.) C:\Windows\System32\LPlatSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
() C:\Program Files (x86)\Lenovo\System Update\SUService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo.) C:\Windows\System32\LPlatSvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiScanner.exe
(Reimage) C:\Program Files\Reimage\Reimage Repair\REI_AVIRA.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [137464 2018-07-02] (Intel)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-1792014199-4145456807-672966040-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18534016 2018-07-20] (Piriform Ltd)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{02483b34-26a8-44a8-8c28-3e6249cda0b4}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{14ca1b2e-0e83-45d8-8e01-3faa303f359f}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{85e240c2-b712-46a0-b2e1-a8a7c1781c47}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-1792014199-4145456807-672966040-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-07-19] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-07-19] (Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 9mjdcly9.default
FF ProfilePath: C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\9mjdcly9.default [2018-08-12]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-07-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-07-19] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8522928 2018-06-30] (Microsoft Corporation)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23288 2018-07-02] (Intel)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [71408 2018-05-16] (Lenovo Group Limited)
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel Corporation)
R2 LPlatSvc; C:\WINDOWS\system32\LPlatSvc.exe [710144 2016-07-13] (Lenovo.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268968 2017-10-24] ()
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [9037680 2018-04-25] (Reimage®)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [23880 2018-03-26] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [255608 2016-04-21] (Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-08-01] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-08-01] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3758760 2017-10-24] (Intel® Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Huawei; C:\WINDOWS\system32\DRIVERS\ewdcsc.sys [29696 2009-12-15] (Huawei Tech. Co., Ltd.)
S3 hwusbdev; C:\WINDOWS\system32\DRIVERS\ewusbdev.sys [114304 2009-12-15] (Huawei Technologies Co., Ltd.)
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8213328 2018-01-31] (Realtek Semiconductor Corporation )
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52912 2015-08-07] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46584 2018-08-01] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-08-01] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-08-01] (Microsoft Corporation)
U4 ESRV_SVC_WILLAMETTE; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-08-12 11:45 - 2018-08-12 11:46 - 000011813 _____ C:\Users\Ivana\Downloads\FRST.txt
2018-08-12 11:44 - 2018-08-12 11:45 - 000000000 ____D C:\FRST
2018-08-12 11:41 - 2018-08-12 11:41 - 000000000 _____ C:\Users\Ivana\Downloads\FRSTLauncher.exe
2018-08-12 11:38 - 2018-08-12 11:38 - 002412544 _____ (Farbar) C:\Users\Ivana\Downloads\FRST64.exe
2018-08-10 14:52 - 2018-08-10 14:59 - 000014582 _____ C:\Users\Ivana\Desktop\10.8. 18 Predpremiery_Po cem muzi - IVANA.xlsx
2018-07-30 11:35 - 2018-07-30 15:18 - 000000000 ____D C:\Users\Ivana\Documents\DOKUMENT KUNDERA
2018-07-29 14:32 - 2018-08-12 11:30 - 000000000 ____D C:\ProgramData\Reimage Protector
2018-07-29 14:32 - 2018-07-29 14:32 - 000004352 _____ C:\WINDOWS\System32\Tasks\ReimageUpdater
2018-07-29 14:32 - 2018-07-29 14:32 - 000001886 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2018-07-29 14:32 - 2018-07-29 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2018-07-29 14:31 - 2018-07-29 14:33 - 000000150 _____ C:\WINDOWS\Reimage.ini
2018-07-29 14:31 - 2018-07-29 14:33 - 000000000 ____D C:\rei
2018-07-29 14:31 - 2018-07-29 14:32 - 000000000 ____D C:\Program Files\Reimage
2018-07-29 14:29 - 2018-07-29 14:29 - 000605424 _____ (Reimage) C:\Users\Ivana\Downloads\ReimageRepair.exe
2018-07-29 14:14 - 2018-08-12 11:29 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-07-29 14:14 - 2018-07-29 14:14 - 000002870 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-07-29 14:14 - 2018-07-29 14:14 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-07-29 14:14 - 2018-07-29 14:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-07-29 14:14 - 2018-07-29 14:14 - 000000000 ____D C:\Program Files\CCleaner
2018-07-29 14:13 - 2018-07-29 14:13 - 000000000 ____D C:\Program Files\Google
2018-07-29 14:12 - 2018-07-30 10:38 - 000000000 ____D C:\Program Files (x86)\Google
2018-07-29 14:12 - 2018-07-29 14:35 - 000000000 ____D C:\Users\Ivana\AppData\Local\Google
2018-07-29 14:12 - 2018-07-29 14:13 - 007417040 _____ (Malwarebytes) C:\Users\Ivana\Downloads\adwcleaner_7.2.2.exe
2018-07-29 14:11 - 2018-07-29 14:11 - 016625464 _____ (Piriform Ltd) C:\Users\Ivana\Downloads\ccsetup545.exe
2018-07-17 13:37 - 2018-07-17 13:37 - 000017566 _____ C:\Users\Ivana\Desktop\1 Václav Postránecký 5cyklus ze dne 17.7..pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-08-12 11:39 - 2016-08-22 17:38 - 000000000 ____D C:\Users\Ivana\AppData\Local\ClassicShell
2018-08-12 11:34 - 2017-10-26 22:24 - 000000000 ____D C:\Users\Ivana\AppData\LocalLow\Mozilla
2018-08-10 23:46 - 2018-05-24 23:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-08-10 15:24 - 2017-12-26 22:05 - 000000000 ____D C:\Users\Ivana\AppData\Local\Packages
2018-08-10 12:03 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-08-10 10:02 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-08-09 12:33 - 2018-03-23 13:41 - 000002270 _____ C:\Users\Ivana\Desktop\VÁCLAV POSTRÁNECKÝ 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-03-23 13:40 - 000002136 _____ C:\Users\Ivana\Desktop\POLÍVKOVÁ 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-03-23 13:39 - 000002241 _____ C:\Users\Ivana\Desktop\VERONIKA GAJEROVÁ 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002541 _____ C:\Users\Ivana\Desktop\Word 2016.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002518 _____ C:\Users\Ivana\Desktop\PowerPoint 2016.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002513 _____ C:\Users\Ivana\Desktop\Excel 2016.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002439 _____ C:\Users\Ivana\Desktop\Outlook 2016.lnk
2018-08-09 12:33 - 2018-01-05 01:47 - 000002169 _____ C:\Users\Ivana\Desktop\SANDEVA SARA 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-01-02 17:12 - 000002182 _____ C:\Users\Ivana\Desktop\BOUDOVÁ NELA 2018 – zástupce.lnk
2018-08-09 12:33 - 2016-08-23 12:29 - 000001452 _____ C:\Users\Ivana\Desktop\HERCI ZASTUPOVÁNÍ.lnk
2018-08-09 12:33 - 2016-08-22 17:38 - 000001283 _____ C:\Users\Ivana\Desktop\Internet Explorer.lnk
2018-08-08 08:38 - 2018-07-06 20:02 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
2018-08-06 10:46 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-08-06 10:45 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2018-08-01 13:14 - 2018-02-18 00:49 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-07-31 12:01 - 2016-08-22 19:29 - 000000000 ____D C:\Users\Ivana\Documents\CASTING FOTKY VÝBĚR
2018-07-30 12:29 - 2017-01-26 17:00 - 000000000 ____D C:\Users\Ivana\Documents\ČERTOVINA POHÁDKA
2018-07-30 12:11 - 2016-08-22 19:29 - 000000000 ____D C:\Users\Ivana\Documents\HERCI ZASTUPOVÁNÍ
2018-07-30 11:08 - 2016-08-22 19:30 - 000000000 ____D C:\Users\Ivana\Documents\MOJE FOTO
2018-07-29 14:24 - 2018-05-25 00:03 - 001601516 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-07-29 14:24 - 2018-04-12 17:51 - 000681858 _____ C:\WINDOWS\system32\perfh005.dat
2018-07-29 14:24 - 2018-04-12 17:51 - 000136754 _____ C:\WINDOWS\system32\perfc005.dat
2018-07-29 14:17 - 2018-05-25 00:11 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-29 14:17 - 2017-05-30 01:01 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-07-29 14:17 - 2016-08-22 17:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-07-29 14:16 - 2018-04-11 23:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-29 14:10 - 2017-12-31 13:03 - 000000000 ____D C:\Users\Ivana\AppData\Local\ElevatedDiagnostics
2018-07-29 14:02 - 2016-08-22 17:54 - 000001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-07-26 16:44 - 2018-07-06 19:58 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-07-26 13:47 - 2018-05-25 00:11 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1792014199-4145456807-672966040-1001
2018-07-26 13:47 - 2018-05-24 23:51 - 000002387 _____ C:\Users\Ivana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-07-26 13:47 - 2016-08-22 12:26 - 000000000 ___RD C:\Users\Ivana\OneDrive
2018-07-19 16:07 - 2018-02-05 12:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office 2016
2018-07-19 16:07 - 2016-08-22 18:01 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-07-18 12:34 - 2017-05-17 09:54 - 000000000 ____D C:\Users\Ivana\Documents\DOKONALÁ ŽENSKÁ
2018-07-17 13:24 - 2016-11-16 16:54 - 000671206 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2018-07-17 13:23 - 2016-08-22 12:59 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-05-24 23:46
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.08.2018
Ran by Ivana (administrator) on DESKTOP-CPUQIHL (12-08-2018 11:45:15)
Running from C:\Users\Ivana\Downloads
Loaded Profiles: Ivana (Available Profiles: Ivana)
Platform: Windows 10 Pro Version 1803 17134.165 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Lenovo.) C:\Windows\System32\LPlatSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
() C:\Program Files (x86)\Lenovo\System Update\SUService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo.) C:\Windows\System32\LPlatSvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiScanner.exe
(Reimage) C:\Program Files\Reimage\Reimage Repair\REI_AVIRA.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [137464 2018-07-02] (Intel)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-1792014199-4145456807-672966040-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18534016 2018-07-20] (Piriform Ltd)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{02483b34-26a8-44a8-8c28-3e6249cda0b4}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{14ca1b2e-0e83-45d8-8e01-3faa303f359f}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{85e240c2-b712-46a0-b2e1-a8a7c1781c47}: [DhcpNameServer] 10.0.0.138
Internet Explorer:
==================
HKU\S-1-5-21-1792014199-4145456807-672966040-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-07-19] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-07-19] (Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-19] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 9mjdcly9.default
FF ProfilePath: C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\9mjdcly9.default [2018-08-12]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-07-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-07-19] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8522928 2018-06-30] (Microsoft Corporation)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23288 2018-07-02] (Intel)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [71408 2018-05-16] (Lenovo Group Limited)
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel Corporation)
R2 LPlatSvc; C:\WINDOWS\system32\LPlatSvc.exe [710144 2016-07-13] (Lenovo.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268968 2017-10-24] ()
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [9037680 2018-04-25] (Reimage®)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [23880 2018-03-26] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [255608 2016-04-21] (Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-08-01] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-08-01] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3758760 2017-10-24] (Intel® Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Huawei; C:\WINDOWS\system32\DRIVERS\ewdcsc.sys [29696 2009-12-15] (Huawei Tech. Co., Ltd.)
S3 hwusbdev; C:\WINDOWS\system32\DRIVERS\ewusbdev.sys [114304 2009-12-15] (Huawei Technologies Co., Ltd.)
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8213328 2018-01-31] (Realtek Semiconductor Corporation )
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
S3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52912 2015-08-07] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46584 2018-08-01] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-08-01] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-08-01] (Microsoft Corporation)
U4 ESRV_SVC_WILLAMETTE; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-08-12 11:45 - 2018-08-12 11:46 - 000011813 _____ C:\Users\Ivana\Downloads\FRST.txt
2018-08-12 11:44 - 2018-08-12 11:45 - 000000000 ____D C:\FRST
2018-08-12 11:41 - 2018-08-12 11:41 - 000000000 _____ C:\Users\Ivana\Downloads\FRSTLauncher.exe
2018-08-12 11:38 - 2018-08-12 11:38 - 002412544 _____ (Farbar) C:\Users\Ivana\Downloads\FRST64.exe
2018-08-10 14:52 - 2018-08-10 14:59 - 000014582 _____ C:\Users\Ivana\Desktop\10.8. 18 Predpremiery_Po cem muzi - IVANA.xlsx
2018-07-30 11:35 - 2018-07-30 15:18 - 000000000 ____D C:\Users\Ivana\Documents\DOKUMENT KUNDERA
2018-07-29 14:32 - 2018-08-12 11:30 - 000000000 ____D C:\ProgramData\Reimage Protector
2018-07-29 14:32 - 2018-07-29 14:32 - 000004352 _____ C:\WINDOWS\System32\Tasks\ReimageUpdater
2018-07-29 14:32 - 2018-07-29 14:32 - 000001886 _____ C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
2018-07-29 14:32 - 2018-07-29 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2018-07-29 14:31 - 2018-07-29 14:33 - 000000150 _____ C:\WINDOWS\Reimage.ini
2018-07-29 14:31 - 2018-07-29 14:33 - 000000000 ____D C:\rei
2018-07-29 14:31 - 2018-07-29 14:32 - 000000000 ____D C:\Program Files\Reimage
2018-07-29 14:29 - 2018-07-29 14:29 - 000605424 _____ (Reimage) C:\Users\Ivana\Downloads\ReimageRepair.exe
2018-07-29 14:14 - 2018-08-12 11:29 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-07-29 14:14 - 2018-07-29 14:14 - 000002870 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-07-29 14:14 - 2018-07-29 14:14 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-07-29 14:14 - 2018-07-29 14:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-07-29 14:14 - 2018-07-29 14:14 - 000000000 ____D C:\Program Files\CCleaner
2018-07-29 14:13 - 2018-07-29 14:13 - 000000000 ____D C:\Program Files\Google
2018-07-29 14:12 - 2018-07-30 10:38 - 000000000 ____D C:\Program Files (x86)\Google
2018-07-29 14:12 - 2018-07-29 14:35 - 000000000 ____D C:\Users\Ivana\AppData\Local\Google
2018-07-29 14:12 - 2018-07-29 14:13 - 007417040 _____ (Malwarebytes) C:\Users\Ivana\Downloads\adwcleaner_7.2.2.exe
2018-07-29 14:11 - 2018-07-29 14:11 - 016625464 _____ (Piriform Ltd) C:\Users\Ivana\Downloads\ccsetup545.exe
2018-07-17 13:37 - 2018-07-17 13:37 - 000017566 _____ C:\Users\Ivana\Desktop\1 Václav Postránecký 5cyklus ze dne 17.7..pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-08-12 11:39 - 2016-08-22 17:38 - 000000000 ____D C:\Users\Ivana\AppData\Local\ClassicShell
2018-08-12 11:34 - 2017-10-26 22:24 - 000000000 ____D C:\Users\Ivana\AppData\LocalLow\Mozilla
2018-08-10 23:46 - 2018-05-24 23:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-08-10 15:24 - 2017-12-26 22:05 - 000000000 ____D C:\Users\Ivana\AppData\Local\Packages
2018-08-10 12:03 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-08-10 10:02 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-08-09 12:33 - 2018-03-23 13:41 - 000002270 _____ C:\Users\Ivana\Desktop\VÁCLAV POSTRÁNECKÝ 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-03-23 13:40 - 000002136 _____ C:\Users\Ivana\Desktop\POLÍVKOVÁ 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-03-23 13:39 - 000002241 _____ C:\Users\Ivana\Desktop\VERONIKA GAJEROVÁ 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002541 _____ C:\Users\Ivana\Desktop\Word 2016.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002518 _____ C:\Users\Ivana\Desktop\PowerPoint 2016.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002513 _____ C:\Users\Ivana\Desktop\Excel 2016.lnk
2018-08-09 12:33 - 2018-02-05 12:16 - 000002439 _____ C:\Users\Ivana\Desktop\Outlook 2016.lnk
2018-08-09 12:33 - 2018-01-05 01:47 - 000002169 _____ C:\Users\Ivana\Desktop\SANDEVA SARA 2018 – zástupce.lnk
2018-08-09 12:33 - 2018-01-02 17:12 - 000002182 _____ C:\Users\Ivana\Desktop\BOUDOVÁ NELA 2018 – zástupce.lnk
2018-08-09 12:33 - 2016-08-23 12:29 - 000001452 _____ C:\Users\Ivana\Desktop\HERCI ZASTUPOVÁNÍ.lnk
2018-08-09 12:33 - 2016-08-22 17:38 - 000001283 _____ C:\Users\Ivana\Desktop\Internet Explorer.lnk
2018-08-08 08:38 - 2018-07-06 20:02 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
2018-08-06 10:46 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-08-06 10:45 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2018-08-01 13:14 - 2018-02-18 00:49 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-07-31 12:01 - 2016-08-22 19:29 - 000000000 ____D C:\Users\Ivana\Documents\CASTING FOTKY VÝBĚR
2018-07-30 12:29 - 2017-01-26 17:00 - 000000000 ____D C:\Users\Ivana\Documents\ČERTOVINA POHÁDKA
2018-07-30 12:11 - 2016-08-22 19:29 - 000000000 ____D C:\Users\Ivana\Documents\HERCI ZASTUPOVÁNÍ
2018-07-30 11:08 - 2016-08-22 19:30 - 000000000 ____D C:\Users\Ivana\Documents\MOJE FOTO
2018-07-29 14:24 - 2018-05-25 00:03 - 001601516 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-07-29 14:24 - 2018-04-12 17:51 - 000681858 _____ C:\WINDOWS\system32\perfh005.dat
2018-07-29 14:24 - 2018-04-12 17:51 - 000136754 _____ C:\WINDOWS\system32\perfc005.dat
2018-07-29 14:17 - 2018-05-25 00:11 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-29 14:17 - 2017-05-30 01:01 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-07-29 14:17 - 2016-08-22 17:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-07-29 14:16 - 2018-04-11 23:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-29 14:10 - 2017-12-31 13:03 - 000000000 ____D C:\Users\Ivana\AppData\Local\ElevatedDiagnostics
2018-07-29 14:02 - 2016-08-22 17:54 - 000001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-07-26 16:44 - 2018-07-06 19:58 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-07-26 13:47 - 2018-05-25 00:11 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1792014199-4145456807-672966040-1001
2018-07-26 13:47 - 2018-05-24 23:51 - 000002387 _____ C:\Users\Ivana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-07-26 13:47 - 2016-08-22 12:26 - 000000000 ___RD C:\Users\Ivana\OneDrive
2018-07-19 16:07 - 2018-02-05 12:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office 2016
2018-07-19 16:07 - 2016-08-22 18:01 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-07-18 12:34 - 2017-05-17 09:54 - 000000000 ____D C:\Users\Ivana\Documents\DOKONALÁ ŽENSKÁ
2018-07-17 13:24 - 2016-11-16 16:54 - 000671206 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2018-07-17 13:23 - 2016-08-22 12:59 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-05-24 23:46
==================== End of FRST.txt ============================