Stránka 1 z 1

zpomalené win10, procesor na 100 %

Napsal: 01 zář 2018 07:17
od jendaabenda
Ahoj, prosím o kontrolu logu. Ať dělám co dělám, procesor mám na stále na 100 %
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:04:38, on 01.09.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0850)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe
C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
C:\Users\germa\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp17win10.msn.com/?pc=HCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hp17win10.msn.com/?pc=HCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\windows\system32\userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [HPRadioMgr] C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [RtlS5Wake] C:\PROGRA~2\Realtek\PCIEWI~1\RTLS5W~1\RtlS5Wake.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\germa\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\AMD\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - AMD - C:\windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atiesrxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BTDevManager - Realtek Semiconductor Corp. - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Comm Recovery (HP Comm Recover) - HP Inc. - C:\Program Files\HPCommRecovery\HPCommRecovery.exe
O23 - Service: HP JumpStart Bridge (HPJumpStartBridge) - HP Inc. - C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
O23 - Service: HP CASL Framework Service (hpqcaslwmiex) - HP - C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: HPWMISVC - HP Inc. - C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\windows\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10805 bytes

Re: zpomalené win10, procesor na 100 %

Napsal: 01 zář 2018 08:34
od jendaabenda
JEště jeden log:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23.08.2018
Ran by germa (01-09-2018 09:18:34)
Running from C:\Users\germa\Downloads
Windows 10 Home Version 1703 15063.1266 (X64) (2018-07-17 14:16:53)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1894498253-2117363191-260290956-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1894498253-2117363191-260290956-503 - Limited - Disabled)
germa (S-1-5-21-1894498253-2117363191-260290956-1001 - Administrator - Enabled) => C:\Users\germa
Guest (S-1-5-21-1894498253-2117363191-260290956-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20058 - Adobe Systems Incorporated)
Adobe Flash Player 30 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 30.0.0.154 - Adobe Systems Incorporated)
Alcorlink USB Card Reader Driver (HKLM-x32\...\AmUStor) (Version: 20.4.45.34706 - Alcorlink Corp.)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.5.1 - Advanced Micro Devices, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center Next Localization BR (HKLM\...\{787FDFF7-EE83-76B9-C5E9-B0E10B487FFB}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{A1F7029B-189A-D46A-05D4-C7EBBB1F009F}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{F7F3376A-35BD-22F5-E8FE-31F0124465F1}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{B71E0D12-088D-91B2-249F-1E2D27BF3F03}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{142FA9FE-83E3-1B87-320E-73D450083C4F}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{7C350240-B882-6665-F318-6BACDFCB39AD}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{51AB5F9E-A0D9-866F-BC7D-908B7B64C544}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{BD19E4B4-7D20-1A01-7A97-7B3398ED7216}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{92784795-5410-1BAE-2DE8-B08AA939EDAE}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{791052C7-675B-F84F-B654-716718FB3CFB}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{2803AC43-60F9-9CD6-295F-589B2EE3FED8}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{2E9B61E0-C645-8992-135F-48BDB6EB7410}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{4F572E63-3C9C-C309-BA75-C113278C152D}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{DD81C958-D07B-3FDC-FA0F-70EF7C1FD641}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{B3909DD8-3560-DB7D-3FA2-59A407B18E69}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{230DFB28-7B17-F3DB-E0E9-CFAF5AF437D4}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{2817064F-C179-02E5-F752-DABB0A89A04E}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{09D14252-3239-939C-5C48-D70150DB919B}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{DCBBB6E6-6732-BD8C-35B1-B0037C9C3CCF}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{272DB21B-7B02-66F4-B01E-8533A8133EAA}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{365F3DEF-FB25-048C-3E9B-439C764E470B}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{72D3A484-0DD7-024C-1327-084B934F764B}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{EEAECCBD-772A-0533-1555-738F32309006}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{09D7E2A9-3FC2-60DF-52BB-59C174690395}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{16FA2442-3C6F-6F23-C472-A02F7DD5DD83}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{45A5F779-B1EF-B1A7-D0F3-A659066C19D8}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{CF22635E-0FB3-2ACC-9205-A341951E01FB}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{3F817498-6A80-AD5D-F843-909F992DC1C1}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{D63D8B64-86AC-D7C9-D5FD-AFF67F7A08AA}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{202B9923-287A-2E78-05C5-B772C851EB97}) (Version: 2017.0216.111.2109 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{8A1C1036-95EA-6FD4-1358-D22577B597C9}) (Version: 2017.0319.1455.26818 - Advanced Micro Devices, Inc.) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
CyberLink Power Media Player 14 (HKLM-x32\...\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}) (Version: 14.0.6.7428 - CyberLink Corp.)
Dropbox 25 GB (HKLM-x32\...\{84D8451D-2ED6-3A59-ABA5-2A447F7C6310}) (Version: 4.1.2.0 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.127.1 - Dropbox, Inc.) Hidden
ELAN Touchpad 18.2.8.1_X64_WHQL (HKLM\...\Elantech) (Version: 18.2.8.1 - ELAN Microelectronic Corp.)
Energy Star (HKLM\...\{5CB22648-35F8-41BC-9C35-1E41FE6E12A5}) (Version: 1.1.1 - HP Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 68.0.3440.106 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
HP Audio Switch (HKLM-x32\...\{BC852AA8-58F6-4F07-ACB1-7377E52CA4F3}) (Version: 1.0.150.0 - HP Inc.)
HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.9.0 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\...\{54da9769-2364-4bd3-8139-6400500778b3}) (Version: 5.3.22034 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\...\{EB0912FF-C311-4E0F-A6B1-420FDD3C295E}) (Version: 1.3.0.407 - HP Inc.)
HP JumpStart Launch (HKLM-x32\...\{81CA40FD-E11B-4DC1-AE33-A71EB044B8B7}) (Version: 1.1.275.0 - HP Inc.)
HP Support Assistant (HKLM-x32\...\{4780AF24-213D-4187-86F2-0014A6D6077B}) (Version: 8.6.18.11 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\...\{83D9E6C0-5F20-49B4-9ACF-80A24A1A045D}) (Version: 12.9.24.3 - HP Inc.)
HP System Event Utility (HKLM-x32\...\{5D308D1F-E37B-431A-8D35-67D16287467D}) (Version: 1.4.28 - HP Inc.)
HP Wireless Button Driver (HKLM-x32\...\{099DAD2B-56C5-4919-9F82-418C2A018CAE}) (Version: 1.1.18.1 - HP)
Microsoft Office 365 ProPlus - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.10325.20118 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1894498253-2117363191-260290956-1001\...\OneDriveSetup.exe) (Version: 18.131.0701.0007 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\...\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123 (HKLM-x32\...\{206898cc-4b41-4d98-ac28-9f9ae57f91fe}) (Version: 14.0.24123.0 - Microsoft Corporation)
MV2Player (remove only) (HKLM-x32\...\MV2Player) (Version: - )
OEM Application Profile (HKLM-x32\...\{B4B7FD8F-06FC-E277-4F29-8F75F8281D8F}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10325.20118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10325.20118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10325.20118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.10325.20118 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 1.0.0.88 - REALTEK Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.23.1003.2017 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8437 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.113 - REALTEK Semiconductor Corp.)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{A6F2ADC4-12C4-41E8-B90B-3BE018F5787C}) (Version: 2.48.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - )
WinRAR 5.60 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
XnView 2.45 (HKLM-x32\...\XnView_is1) (Version: 2.45 - Gougelet Pierre-e)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1-x32: [IXnView] -> {A5D35F9F-6A11-4EAA-B70B-7BB6FE32663A} => C:\Program Files (x86)\XnView\ShellEx\XnViewShellExt.dll [2015-02-19] ()
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (Alexander Roshal)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-05-16] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {05FC1E3D-37B0-4856-A3CD-90192ED47C74} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-08-09] (Microsoft Corporation)
Task: {0C969EF0-7062-48B4-9C9C-0859F402001A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-08-18] (Microsoft Corporation)
Task: {0EAFDBFE-165E-4D1C-88CC-A0C29F4E525B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-08-18] (Microsoft Corporation)
Task: {0F20BF54-0E3A-4906-8E98-61622C9155B0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-01] (Microsoft Corporation)
Task: {188961AA-B7EB-4855-87D6-F748FF66EE89} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-08-18] (Microsoft Corporation)
Task: {1B5888F1-97B8-4603-991F-CB7D2E1EC672} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-17] (Google Inc.)
Task: {28E3AEBD-1BA8-47CC-8A48-8DFDF0DB518F} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2016-11-28] (DropboxOEM)
Task: {3E83C0ED-19D8-44C5-856E-AAB30D1817E3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {420898C0-CCFA-4B4C-95F2-6E64ECB53B87} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {46B3E6AC-73AE-41E4-92F6-88DBE8E3616E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {53E1FFCE-E674-4C1F-B545-BA2B97E5DE44} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_154_pepper.exe [2018-08-19] (Adobe Systems Incorporated)
Task: {56F5C501-527C-4D65-91D8-E7BF332FC087} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [2017-02-01] ()
Task: {577D6DEC-C7B2-4AD6-8DDA-8B0310238E72} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-08-18] (Microsoft Corporation)
Task: {6C5AE035-184D-4303-811C-CEB671A66ACD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {70A3571B-3A43-4E23-A0B0-0169A0C16B9E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-17] (Google Inc.)
Task: {71739926-DDC6-4482-A499-E1CD7E883AC0} - System32\Tasks\HPCeeScheduleForgerma => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-05-12] (HP Development Company, L.P.)
Task: {733B316D-5007-483F-B9C1-3CB53C5DD09D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-08-18] (Microsoft Corporation)
Task: {7786A666-3BFE-4588-9EEA-791405F6B61F} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-05-16] (Advanced Micro Devices, Inc.)
Task: {7963516E-5BF3-4EFE-8B22-C60BDF1D8FA0} - System32\Tasks\RtHDVBg_Session => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2018-05-11] (Realtek Semiconductor)
Task: {82B7E292-16B1-4D8E-84A5-77FBEF025935} - System32\Tasks\Microsoft\Windows\rempl\shell-maintenance => C:\Program Files\rempl\remsh.exe
Task: {82E10585-1E3A-4A39-AD1B-04A5A1DA9932} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-06-27] (HP Inc.)
Task: {82F9E497-57DF-4E64-B9EE-E2F9E503F2D7} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-07-17] (Dropbox, Inc.)
Task: {8936301B-5CF6-4F13-A3E7-3B985A88F4BC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-01] (Microsoft Corporation)
Task: {91BE7635-BA4B-4919-8275-78CEADF8F0BF} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [2018-05-16] (Advanced Micro Devices, Inc.)
Task: {98EBB1C7-C558-4E0D-B399-F6959DEF1CD3} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2018-05-11] (Realtek Semiconductor)
Task: {9E607B82-D6DC-4014-9EAF-7B508F5E30D0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-01] (Microsoft Corporation)
Task: {9E7843CC-B97D-4077-A8F5-2D1E789FC09F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-08-09] (Microsoft Corporation)
Task: {A04F19EB-1C43-471A-977D-A40D182C2D67} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-12-06] (HP Inc.)
Task: {C3ED1C79-6B1F-4630-AF2A-5D7B02F66A26} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-08-18] (Microsoft Corporation)
Task: {D42EF1B0-B84F-4E8C-BAF9-DAE9B791915C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {D6448604-5C59-41D8-A370-0C7955ADF115} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-07-17] (Dropbox, Inc.)
Task: {E5CCFC1A-0DE1-480A-8B80-93C3D7305A58} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {EEAC6F6A-B654-4EB0-B5C4-E8A62361A15E} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [2017-02-02] (HP Inc.)
Task: {EFEDB1D6-F5AA-41E6-8B33-7D12614E01AA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated)
Task: {F41BCCDC-6216-4289-A139-FB31F1E9B187} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-08-01] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForgerma.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-02-01 11:50 - 2017-02-01 11:50 - 000459264 _____ () C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe
2017-03-18 22:58 - 2017-03-18 22:58 - 000138000 _____ () C:\windows\SYSTEM32\inputhost.dll
2017-05-15 04:29 - 2018-08-01 07:37 - 008952496 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1029\GrooveIntlResource.dll
2018-07-18 04:05 - 2018-07-18 04:05 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-07-18 04:05 - 2018-07-18 04:05 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-07-18 04:05 - 2018-07-18 04:05 - 022373888 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-07-18 04:05 - 2018-07-18 04:05 - 002610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll
2018-07-18 04:05 - 2018-07-18 04:05 - 000653824 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-04-24 22:12 - 2018-04-24 22:12 - 000015360 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-04-24 22:12 - 2018-04-24 22:12 - 002519040 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-05-16 14:29 - 2018-05-16 14:29 - 000017408 _____ () C:\Program Files\AMD\ATI.ACE\a4\AS4.NativeProxy.dll
2018-05-16 15:19 - 2018-05-16 15:19 - 000155016 _____ () C:\Program Files\AMD\ATI.ACE\A4\AdaptiveSleepService.exe
2018-08-01 07:05 - 2018-08-01 07:06 - 000199168 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11807.1001.13.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll
2018-08-01 07:05 - 2018-08-01 07:06 - 002447072 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11807.1001.13.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-08-01 07:05 - 2018-08-01 07:06 - 007814144 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11807.1001.13.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2018-08-10 16:52 - 2018-08-08 02:41 - 004855640 _____ () C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\libglesv2.dll
2018-08-10 16:52 - 2018-08-08 02:41 - 000115544 _____ () C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\libegl.dll
2018-08-27 23:17 - 2018-08-27 23:17 - 000156672 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\BRIDGECommon\579c6797ba35c1954b97f798d87e1aa0\BRIDGECommon.ni.dll
2018-08-28 01:39 - 2018-08-28 01:39 - 000329728 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\CleanStartController\e43176b005dfa7386f9e81c0203014f9\CleanStartController.ni.dll
2018-08-28 01:39 - 2018-08-28 01:39 - 000116736 _____ () C:\windows\assembly\NativeImages_v4.0.30319_32\BridgeExtension\a02a66fce77002601f0dd9d6a014238e\BridgeExtension.ni.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1894498253-2117363191-260290956-1001\...\sharepoint.com -> hxxps://rwe-files.sharepoint.com

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2017-03-18 23:01 - 000000824 _____ C:\windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1894498253-2117363191-260290956-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\HP Backgrounds\backgroundDefault.jpg
DNS Servers: 213.46.172.36 - 213.46.172.37
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKU\S-1-5-21-1894498253-2117363191-260290956-1001\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{E91A77E6-189E-43EB-B29F-63371059DBAD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{590F82B2-E002-40F8-B708-8D02BAE740BD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B0AEABFD-7098-4045-B8E9-EAC8E3815A8E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D0BC557A-0208-404E-B198-83295219417D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CC1ECB75-2372-48E4-9A44-1BFE363FE07F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD.exe
FirewallRules: [{0C7F10B3-9CFC-48A3-A910-3095846F280C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Kernel\DMS\CLMSServerPDVD14.exe
FirewallRules: [{0A760450-554A-46CE-8926-85C5D7F3C683}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe
FirewallRules: [{7C0FB0B8-B0E2-4268-BC1C-ED5617F6AB63}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVDMovie.exe
FirewallRules: [{DB34BF4C-7963-4AC4-A30C-9BFC7DEE2301}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{CFB95944-49F4-4BEC-A8B8-8252829828C8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{89E16AB8-DE1F-4C10-9896-F45A2459E02C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{AEADD29A-0DD4-4ABE-AACC-76A5E3C97F8C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A812DC9D-C1EF-4AB6-84A8-EDC43A82F507}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{0D9F746A-FF26-4DCA-8796-E965CD030958}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

10-08-2018 07:52:41 Windows Update
18-08-2018 18:33:40 Windows Update
28-08-2018 01:53:56 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/01/2018 09:10:55 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:56 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:55 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:54 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:51 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:49 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:47 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/01/2018 08:35:39 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LAPTOP-F2ORDJBC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147024629. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.


System errors:
=============
Error: (09/01/2018 09:10:55 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-F2ORDJBC)
Description: Nelze spustit server DCOM: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppX360dyffbd5crx5cph6sy881bkkccrbr0.mca jako Není k dispozici/Není k dispozici. Došlo k chybě:
267
při provádění příkazu:
"C:\windows\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca

Error: (09/01/2018 09:00:49 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/01/2018 08:36:24 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server Microsoft.Bluetooth.Profiles.Gatt.Interface.GattServerRegistrar se v daném časovém limitu neregistroval u služby DCOM.

Error: (09/01/2018 08:35:56 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-F2ORDJBC)
Description: Nelze spustit server DCOM: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXjytc7c0yvwb8n3cw0r82k4364sd1s7bv.mca jako Není k dispozici/Není k dispozici. Došlo k chybě:
267
při provádění příkazu:
"C:\windows\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca

Error: (09/01/2018 08:35:55 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-F2ORDJBC)
Description: Nelze spustit server DCOM: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca jako Není k dispozici/Není k dispozici. Došlo k chybě:
267
při provádění příkazu:
"C:\windows\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca

Error: (09/01/2018 08:35:54 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-F2ORDJBC)
Description: Nelze spustit server DCOM: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI jako Není k dispozici/Není k dispozici. Došlo k chybě:
267
při provádění příkazu:
"C:\windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca

Error: (09/01/2018 08:35:51 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-F2ORDJBC)
Description: Nelze spustit server DCOM: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI jako Není k dispozici/Není k dispozici. Došlo k chybě:
267
při provádění příkazu:
"C:\windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca

Error: (09/01/2018 08:35:49 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-F2ORDJBC)
Description: Nelze spustit server DCOM: Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI jako Není k dispozici/Není k dispozici. Došlo k chybě:
267
při provádění příkazu:
"C:\windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca


Windows Defender:
===================================
Date: 2018-08-27 23:34:54.874
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {84ECCD44-3303-424B-87F2-61E6B7A473BE}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-10 16:59:48.055
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {A070EC66-64FD-41F2-996F-08FB68E8C6F6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-10 10:11:28.631
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FECCFC8E-C03C-4F85-BF31-2BDB1A3FEA55}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-07-29 08:46:18.149
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {255CD666-F5EF-4E14-912B-54EB5A604023}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-07-26 18:26:25.877
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {CAE89EE3-24D3-41DE-8510-25E5F2C39788}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-27 18:51:39.845
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu:
Zdroj aktualizace: Uživatel
Typ podpisu:
Typ aktualizace:
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu:
Kód chyby: 0x80070652
Popis chyby :Momentálně je spuštěna jiná instalace. Před spuštěním nové instalace nejdříve dokončete spuštěnou instalaci.

Date: 2018-08-27 18:42:06.199
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1791.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80070643
Popis chyby :Při instalaci došlo k závažné chybě.

Date: 2018-08-27 18:40:48.052
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.275.79.0
Předchozí verze podpisu: 1.273.1791.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antispywarový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15100.1
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

Date: 2018-08-27 18:40:48.051
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 1.275.79.0
Předchozí verze podpisu: 1.273.1791.0
Zdroj aktualizace: Uživatel
Typ podpisu: Antivirový program
Typ aktualizace: Delta
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 1.1.15100.1
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80070666
Popis chyby :Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.

Date: 2018-08-18 18:00:22.114
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1167.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80240022
Popis chyby :V daném programu nelze zkontrolovat aktualizace definic.

CodeIntegrity:
===================================

Date: 2018-09-01 09:17:51.434
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 09:17:51.424
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 09:17:50.850
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 09:17:50.843
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 09:15:56.914
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 09:15:56.896
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 08:45:50.395
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-01 07:43:10.362
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info ===========================

Processor: AMD E2-9000e RADEON R2, 4 COMPUTE CORES 2C+2G
Percentage of memory in use: 54%
Total physical RAM: 3977.44 MB
Available physical RAM: 1819.66 MB
Total Virtual: 5897.44 MB
Available Virtual: 2881.08 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:223.22 GB) (Free:169.19 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:14.02 GB) (Free:1.69 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{06471cf0-2615-4fd8-b883-291388507d23}\ (Windows RE tools) (Fixed) (Total:0.96 GB) (Free:0.57 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: EDED45A4)

Partition: GPT.

==================== End of Addition.txt ============================

Re: zpomalené win10, procesor na 100 %

Napsal: 01 zář 2018 10:13
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: zpomalené win10, procesor na 100 %

Napsal: 02 zář 2018 18:27
od jendaabenda
# -------------------------------
# Malwarebytes AdwCleaner 7.2.3.0
# -------------------------------
# Build: 08-30-2018
# Database: 2018-09-01.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-02-2018
# Duration: 00:00:02
# OS: Windows 10 Home
# Cleaned: 1
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Users\germa\AppData\Roaming\WinThruster

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1297 octets] - [02/09/2018 19:22:38]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: zpomalené win10, procesor na 100 %

Napsal: 02 zář 2018 19:16
od Rudy

Re: zpomalené win10, procesor na 100 %

Napsal: 05 zář 2018 10:58
od jendaabenda
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01.09.2018 03
Ran by germa (administrator) on LAPTOP-F2ORDJBC (05-09-2018 11:46:07)
Running from C:\Users\germa\Downloads
Loaded Profiles: germa (Available Profiles: germa)
Platform: Windows 10 Home Version 1703 15063.1266 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
() C:\Program Files\AMD\ATI.ACE\a4\AdaptiveSleepService.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(Realtek) C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
(HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\LockAppHost.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\b408aeaa92b8d6de04ea8845ffbf6d03\WindowsUpdateBox.exe
(Microsoft Corporation) C:\$WINDOWS.~BT\Sources\SetupHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3349728 2017-05-08] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9274312 2018-05-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Session] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1505736 2018-05-11] (Realtek Semiconductor)
HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [324488 2016-08-02] (HP)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [709152 2018-03-22] (HP Inc.)
HKLM-x32\...\Run: [RtlS5Wake] => C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe [2097600 2018-02-23] (Realtek)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{1128892f-6ea7-4d5c-8ed0-699ea15e29ef}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{6509596d-3fb8-48b0-bd53-7fe68584d901}: [DhcpNameServer] 40.23.1.12
Tcpip\..\Interfaces\{737094c3-7117-4ee6-8ec7-473a8d532b6d}: [DhcpNameServer] 213.46.172.36 213.46.172.37

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-1894498253-2117363191-260290956-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-1894498253-2117363191-260290956-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> {EDC3304B-8338-4F39-A818-2688DCA03749} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM-x32 -> {EDC3304B-8338-4F39-A818-2688DCA03749} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKU\S-1-5-21-1894498253-2117363191-260290956-1001 -> {EDC3304B-8338-4F39-A818-2688DCA03749} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-08-18] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-08-01] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-12-06] (HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-08-10] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-08-10] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-12-06] (HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-08-18] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-08-18] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-08-18] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-08-18] (Microsoft Corporation)

FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-08-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-07-17] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-09-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-09-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default [2018-09-05]
CHR Extension: (Prezentace) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-09-03]
CHR Extension: (Dokumenty) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-09-03]
CHR Extension: (Disk Google) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-09-03]
CHR Extension: (YouTube) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-09-03]
CHR Extension: (Tabulky) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-09-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-03]
CHR Extension: (HP Network Check Launcher) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2018-09-03]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-09-03]
CHR Extension: (Gmail) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-09-03]
CHR Extension: (Chrome Media Router) - C:\Users\germa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-03]
CHR HKLM-x32\...\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdaptiveSleepService; C:\Program Files\AMD\ATI.ACE\A4\AdaptiveSleepService.exe [155016 2018-05-16] ()
R2 AMD External Events Utility; C:\windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atiesrxx.exe [481656 2018-05-22] (AMD)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [679400 2018-04-02] (Realtek Semiconductor Corp.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8853984 2018-08-09] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-07-17] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-07-17] (Dropbox, Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144600 2017-05-08] (ELAN Microelectronics Corp.)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1327400 2017-09-05] (HP Inc.)
R2 HPJumpStartBridge; C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [471040 2017-05-23] (HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [265672 2018-05-11] (Realtek Semiconductor)
R2 tbaseprovisioning; C:\windows\SysWOW64\tbaseprovisioning.exe [51224 2017-03-30] (Advanced Micro Devices, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-08-01] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-08-01] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AmdAS4; C:\windows\System32\drivers\AmdAS4.sys [27376 2017-03-30] (Advanced Micro Devices, INC.)
S3 amdkmcsp; C:\windows\system32\DRIVERS\amdkmcsp.sys [100752 2017-03-30] (Advanced Micro Devices, Inc. )
R3 amdkmdag; C:\windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atikmdag.sys [44682104 2018-05-22] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atikmpag.sys [552824 2018-05-22] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\windows\System32\DRIVERS\amdpsp.sys [254864 2017-03-30] (Advanced Micro Devices, Inc. )
S3 AmUStor; C:\windows\system32\drivers\AmUStor.SYS [90560 2017-04-26] (Alcorlink Corp.)
R3 AtiHDAudioService; C:\windows\system32\drivers\AtihdWT6.sys [111080 2018-04-26] (Advanced Micro Devices)
S3 dot4; C:\windows\system32\DRIVERS\Dot4.sys [146856 2015-03-10] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\windows\System32\drivers\Dot4Prt.sys [21928 2015-03-10] (Windows (R) Win 7 DDK provider)
R3 ETDSMBus; C:\windows\System32\drivers\ETDSMBus.sys [32848 2017-05-08] (ELAN Microelectronic Corp.)
S3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [259360 2018-08-19] (Malwarebytes)
R3 rt640x64; C:\windows\System32\drivers\rt640x64.sys [1010656 2017-11-23] (Realtek )
S3 RT8723DE; C:\windows\System32\drivers\rtl8723de.sys [6763672 2017-04-28] (Realtek Semiconductor Corporation )
R3 RtkBtFilter; C:\windows\system32\DRIVERS\RtkBtfilter.sys [758216 2018-04-04] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\drivers\rtwlane.sys [8050000 2018-04-11] (Realtek Semiconductor Corporation )
S3 SDFRd; C:\windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S0 WdBoot; C:\windows\System32\drivers\wd\WdBoot.sys [46584 2018-08-01] (Microsoft Corporation)
R0 WdFilter; C:\windows\System32\drivers\wd\WdFilter.sys [340008 2018-08-01] (Microsoft Corporation)
R3 WdNisDrv; C:\windows\System32\drivers\wd\WdNisDrv.sys [61992 2018-08-01] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\windows\system32\DRIVERS\WirelessButtonDriver64.sys [34944 2018-05-11] (HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-05 11:46 - 2018-09-05 11:47 - 000017276 _____ C:\Users\germa\Downloads\FRST.txt
2018-09-05 11:42 - 2018-09-05 11:46 - 002413056 _____ (Farbar) C:\Users\germa\Downloads\FRST64.exe
2018-09-05 10:00 - 2018-09-05 10:00 - 000000000 ____D C:\Users\germa\AppData\Local\ElevatedDiagnostics
2018-09-03 17:15 - 2018-09-03 17:15 - 000000000 ____D C:\windows\LastGood.Tmp
2018-09-03 17:11 - 2018-09-03 17:11 - 001544192 _____ C:\Users\germa\Downloads\Dot4x64.msi
2018-09-03 17:07 - 2018-09-03 17:07 - 000118030 _____ C:\Users\germa\Documents\USB
2018-09-03 12:47 - 2018-09-03 12:47 - 000002080 _____ C:\Users\Public\Desktop\Google Slides.lnk
2018-09-03 12:47 - 2018-09-03 12:47 - 000002078 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2018-09-03 12:47 - 2018-09-03 12:47 - 000002068 _____ C:\Users\Public\Desktop\Google Docs.lnk
2018-09-03 12:47 - 2018-09-03 12:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2018-09-03 12:47 - 2018-09-03 12:47 - 000000000 ____D C:\Program Files\Google
2018-09-03 12:46 - 2018-09-03 12:46 - 001130840 _____ (Google Inc.) C:\Users\germa\Downloads\installbackupandsync.exe
2018-09-02 20:23 - 2018-09-02 20:23 - 000002340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-09-02 20:23 - 2018-09-02 20:23 - 000002299 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-09-02 20:22 - 2018-09-02 20:22 - 000003472 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-09-02 20:22 - 2018-09-02 20:22 - 000003348 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-09-02 20:18 - 2018-09-02 20:18 - 000000000 _____ C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}
2018-09-02 19:21 - 2018-09-02 19:22 - 000000000 ____D C:\AdwCleaner
2018-09-01 19:18 - 2018-09-01 19:47 - 000000000 ____D C:\bckpphone
2018-09-01 09:18 - 2018-09-01 09:18 - 000045458 _____ C:\Users\germa\Downloads\Addition.txt
2018-09-01 09:16 - 2018-09-05 11:46 - 000000000 ____D C:\FRST
2018-09-01 09:16 - 2018-09-01 09:18 - 000056585 _____ C:\Users\germa\Downloads\FRST_b.txt
2018-08-31 21:19 - 2018-08-31 21:56 - 000036824 _____ C:\Users\germa\Documents\zapasy1819_testovaci.xlsx
2018-08-31 21:19 - 2018-08-27 15:00 - 000006824 _____ C:\Users\germa\Documents\zapasy1819_testovaci.csv
2018-08-31 21:19 - 2018-08-27 14:59 - 000002561 _____ C:\Users\germa\Documents\zapasy1819_MZJU1.csv
2018-08-31 21:19 - 2018-08-27 12:05 - 000014322 _____ C:\Users\germa\Documents\zapasy1819A.xlsx
2018-08-27 18:47 - 2018-08-27 18:47 - 000000000 ____D C:\windows\UpdateAssistant
2018-08-20 22:03 - 2018-08-20 22:03 - 000000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2018-08-19 10:16 - 2018-07-31 08:20 - 000556352 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
2018-08-19 10:16 - 2018-07-31 08:19 - 002211240 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-08-19 10:16 - 2018-07-31 08:19 - 000115096 _____ (Microsoft Corporation) C:\windows\SysWOW64\offlinelsa.dll
2018-08-19 10:16 - 2018-07-31 08:18 - 000059480 _____ (Microsoft Corporation) C:\windows\SysWOW64\wldp.dll
2018-08-19 10:16 - 2018-07-31 08:17 - 006768824 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-08-19 10:16 - 2018-07-31 08:17 - 004673360 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2018-08-19 10:16 - 2018-07-31 08:15 - 000583672 _____ (Microsoft Corporation) C:\windows\SysWOW64\CoreMessaging.dll
2018-08-19 10:16 - 2018-07-31 08:07 - 002950656 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32kfull.sys
2018-08-19 10:16 - 2018-07-31 08:04 - 000025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\odbcconf.dll
2018-08-19 10:16 - 2018-07-31 07:58 - 000506880 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-08-19 10:16 - 2018-07-31 07:58 - 000396800 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-08-19 10:16 - 2018-07-31 07:58 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\cldapi.dll
2018-08-19 10:16 - 2018-07-31 07:57 - 007598592 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2018-08-19 10:16 - 2018-07-31 07:55 - 004034560 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-08-19 10:16 - 2018-07-31 07:54 - 004558848 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbgeng.dll
2018-08-19 10:16 - 2018-07-31 07:51 - 004054528 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2018-08-19 10:16 - 2018-07-31 07:51 - 000089600 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2018-08-19 10:15 - 2018-07-31 08:36 - 000367512 _____ (Microsoft Corporation) C:\windows\SysWOW64\aepic.dll
2018-08-19 10:15 - 2018-07-31 08:25 - 001838120 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-08-19 10:15 - 2018-07-31 08:24 - 002259032 _____ (Microsoft Corporation) C:\windows\SysWOW64\CoreUIComponents.dll
2018-08-19 10:15 - 2018-07-31 08:17 - 020378560 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2018-08-19 10:15 - 2018-07-31 08:07 - 005974016 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2018-08-19 10:15 - 2018-07-31 08:07 - 001449984 _____ (Microsoft Corporation) C:\windows\SysWOW64\GdiPlus.dll
2018-08-19 10:15 - 2018-07-31 08:06 - 000133632 _____ (Microsoft Corporation) C:\windows\SysWOW64\t2embed.dll
2018-08-19 10:15 - 2018-07-31 08:06 - 000097280 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2018-08-19 10:15 - 2018-07-31 08:04 - 000035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\tokenbinding.dll
2018-08-19 10:15 - 2018-07-31 08:03 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\tbauth.dll
2018-08-19 10:15 - 2018-07-31 08:01 - 000742912 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2018-08-19 10:15 - 2018-07-31 08:01 - 000365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msIso.dll
2018-08-19 10:15 - 2018-07-31 08:01 - 000099328 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
2018-08-19 10:15 - 2018-07-31 08:00 - 000932352 _____ (Microsoft Corporation) C:\windows\SysWOW64\GamePanel.exe
2018-08-19 10:15 - 2018-07-31 07:59 - 001248768 _____ (Microsoft Corporation) C:\windows\SysWOW64\AzureSettingSyncProvider.dll
2018-08-19 10:15 - 2018-07-31 07:59 - 000892928 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Cred.dll
2018-08-19 10:15 - 2018-07-31 07:59 - 000586240 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2018-08-19 10:15 - 2018-07-31 07:58 - 000636416 _____ (Microsoft Corporation) C:\windows\SysWOW64\WpcWebFilter.dll
2018-08-19 10:15 - 2018-07-31 07:58 - 000598528 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-08-19 10:15 - 2018-07-31 07:58 - 000563200 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2018-08-19 10:15 - 2018-07-31 07:57 - 000266752 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncryptprov.dll
2018-08-19 10:15 - 2018-07-31 07:56 - 003669504 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DCompiler_47.dll
2018-08-19 10:15 - 2018-07-31 07:55 - 005226496 _____ (Microsoft Corporation) C:\windows\SysWOW64\d2d1.dll
2018-08-19 10:15 - 2018-07-31 07:55 - 001019904 _____ (Microsoft Corporation) C:\windows\SysWOW64\aadtb.dll
2018-08-19 10:15 - 2018-07-31 07:55 - 000813568 _____ (Microsoft Corporation) C:\windows\SysWOW64\TokenBroker.dll
2018-08-19 10:15 - 2018-07-31 07:51 - 000059904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2018-08-19 10:15 - 2018-03-02 15:51 - 000056320 _____ (Microsoft Corporation) C:\windows\system32\fwcfg.dll
2018-08-19 10:15 - 2018-03-02 15:49 - 000501760 _____ (Microsoft Corporation) C:\windows\system32\authfwcfg.dll
2018-08-19 10:15 - 2018-03-02 08:38 - 000017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2018-08-19 10:14 - 2018-07-31 09:01 - 000092456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\scmbus.sys
2018-08-19 10:14 - 2018-07-31 08:58 - 002400664 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-08-19 10:14 - 2018-07-31 08:58 - 000138024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-08-19 10:14 - 2018-07-31 08:56 - 001239448 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2018-08-19 10:14 - 2018-07-31 08:51 - 004709016 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2018-08-19 10:14 - 2018-07-31 08:51 - 000254168 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2018-08-19 10:14 - 2018-07-31 08:51 - 000094616 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2018-08-19 10:14 - 2018-07-31 08:49 - 002672024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2018-08-19 10:14 - 2018-07-31 08:49 - 000387928 _____ (Microsoft Corporation) C:\windows\system32\wmpps.dll
2018-08-19 10:14 - 2018-07-31 08:49 - 000058488 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-08-19 10:14 - 2018-07-31 08:06 - 000037376 _____ (Microsoft Corporation) C:\windows\system32\SEMgrPS.dll
2018-08-19 10:14 - 2018-07-31 08:04 - 000110592 _____ (Microsoft Corporation) C:\windows\system32\Chakradiag.dll
2018-08-19 10:14 - 2018-07-31 08:03 - 000080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakradiag.dll
2018-08-19 10:14 - 2018-07-31 08:02 - 020519936 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll
2018-08-19 10:14 - 2018-07-31 08:01 - 019356672 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-08-19 10:14 - 2018-07-31 08:01 - 008214016 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2018-08-19 10:14 - 2018-07-31 08:01 - 000330240 _____ (Microsoft Corporation) C:\windows\SysWOW64\webplatstorageserver.dll
2018-08-19 10:14 - 2018-07-31 08:00 - 013429248 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2018-08-19 10:14 - 2018-07-31 08:00 - 012263936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2018-08-19 10:14 - 2018-07-31 07:58 - 000553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-08-19 10:14 - 2018-07-31 07:56 - 006258176 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll
2018-08-19 10:14 - 2018-07-31 07:56 - 000658432 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-08-19 10:14 - 2018-07-31 07:55 - 004719616 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-08-19 10:14 - 2018-07-31 07:55 - 003653632 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-08-19 10:14 - 2018-07-31 07:55 - 001886720 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2018-08-19 10:14 - 2018-03-02 15:39 - 000031744 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2018-08-19 10:13 - 2018-07-31 08:57 - 001930344 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-08-19 10:13 - 2018-07-31 08:25 - 001618784 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-08-19 10:13 - 2018-07-31 08:05 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\odbcconf.dll
2018-08-19 10:13 - 2018-07-31 08:02 - 000457728 _____ (Microsoft Corporation) C:\windows\system32\webplatstorageserver.dll
2018-08-19 10:13 - 2018-07-31 08:00 - 023703040 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-08-19 10:13 - 2018-07-31 08:00 - 000692736 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-08-19 10:13 - 2018-07-31 07:59 - 000582144 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-08-19 10:13 - 2018-07-31 07:57 - 000755712 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-08-19 10:13 - 2018-07-31 07:56 - 008167424 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll
2018-08-19 10:12 - 2018-07-31 09:01 - 002868632 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2018-08-19 10:12 - 2018-07-31 09:01 - 001200936 _____ (Microsoft Corporation) C:\windows\system32\hvix64.exe
2018-08-19 10:12 - 2018-07-31 09:01 - 001039280 _____ (Microsoft Corporation) C:\windows\system32\hvax64.exe
2018-08-19 10:12 - 2018-07-31 09:01 - 000968488 _____ (Microsoft Corporation) C:\windows\system32\hvloader.efi
2018-08-19 10:12 - 2018-07-31 09:01 - 000823216 _____ (Microsoft Corporation) C:\windows\system32\hvloader.exe
2018-08-19 10:12 - 2018-07-31 09:01 - 000546088 _____ (Microsoft Corporation) C:\windows\system32\securekernel.exe
2018-08-19 10:12 - 2018-07-31 09:01 - 000077208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hvservice.sys
2018-08-19 10:12 - 2018-07-31 09:00 - 001067544 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-08-19 10:12 - 2018-07-31 09:00 - 000901392 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2018-08-19 10:12 - 2018-07-31 08:58 - 008321432 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-08-19 10:12 - 2018-07-31 08:58 - 001399640 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-08-19 10:12 - 2018-07-31 08:58 - 001189056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2018-08-19 10:12 - 2018-07-31 08:57 - 002971848 _____ (Microsoft Corporation) C:\windows\system32\CoreUIComponents.dll
2018-08-19 10:12 - 2018-07-31 08:57 - 000115496 _____ (Microsoft Corporation) C:\windows\system32\kdnet.dll
2018-08-19 10:12 - 2018-07-31 08:56 - 000923592 _____ (Microsoft Corporation) C:\windows\system32\CoreMessaging.dll
2018-08-19 10:12 - 2018-07-31 08:56 - 000172328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-08-19 10:12 - 2018-07-31 08:54 - 001019288 _____ (Microsoft Corporation) C:\windows\system32\SecConfig.efi
2018-08-19 10:12 - 2018-07-31 08:53 - 002695224 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-08-19 10:12 - 2018-07-31 08:53 - 002442672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2018-08-19 10:12 - 2018-07-31 08:53 - 000652296 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
2018-08-19 10:12 - 2018-07-31 08:52 - 000872472 _____ (Microsoft Corporation) C:\windows\system32\ClipSVC.dll
2018-08-19 10:12 - 2018-07-31 08:52 - 000645128 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2018-08-19 10:12 - 2018-07-31 08:52 - 000129832 _____ (Microsoft Corporation) C:\windows\system32\offlinelsa.dll
2018-08-19 10:12 - 2018-07-31 08:52 - 000070352 _____ (Microsoft Corporation) C:\windows\system32\wldp.dll
2018-08-19 10:12 - 2018-07-31 08:52 - 000033064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\winhv.sys
2018-08-19 10:12 - 2018-07-31 08:51 - 021359928 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2018-08-19 10:12 - 2018-07-31 08:51 - 007909936 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Protection.PlayReady.dll
2018-08-19 10:12 - 2018-07-31 08:49 - 001103792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2018-08-19 10:12 - 2018-07-31 08:22 - 023684096 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll
2018-08-19 10:12 - 2018-07-31 08:08 - 003666432 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys
2018-08-19 10:12 - 2018-07-31 08:07 - 000584192 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIRibbonRes.dll
2018-08-19 10:12 - 2018-07-31 08:07 - 000584192 _____ (Microsoft Corporation) C:\windows\system32\UIRibbonRes.dll
2018-08-19 10:12 - 2018-07-31 08:07 - 000175616 _____ (Microsoft Corporation) C:\windows\system32\t2embed.dll
2018-08-19 10:12 - 2018-07-31 08:07 - 000123392 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2018-08-19 10:12 - 2018-07-31 08:07 - 000055296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\winhvr.sys
2018-08-19 10:12 - 2018-07-31 08:03 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-08-19 10:12 - 2018-07-31 08:02 - 000099328 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2018-08-19 10:12 - 2018-07-31 08:00 - 001051136 _____ (Microsoft Corporation) C:\windows\system32\nettrace.dll
2018-08-19 10:12 - 2018-07-31 07:59 - 000488960 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-08-19 10:12 - 2018-07-31 07:58 - 000315904 _____ (Microsoft Corporation) C:\windows\system32\ncryptprov.dll
2018-08-19 10:12 - 2018-07-31 07:57 - 005892608 _____ (Microsoft Corporation) C:\windows\system32\d2d1.dll
2018-08-19 10:12 - 2018-07-31 07:57 - 004398080 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_47.dll
2018-08-19 10:12 - 2018-07-31 07:56 - 004481024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-08-19 10:12 - 2018-07-31 07:56 - 002053120 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys
2018-08-19 10:12 - 2018-07-31 07:55 - 002007040 _____ (Microsoft Corporation) C:\windows\system32\LocationFramework.dll
2018-08-19 10:12 - 2018-07-31 07:54 - 005557760 _____ (Microsoft Corporation) C:\windows\system32\dbgeng.dll
2018-08-19 10:12 - 2018-07-31 07:53 - 000079360 _____ (Microsoft Corporation) C:\windows\system32\LocationFrameworkInternalPS.dll
2018-08-19 10:12 - 2018-07-31 07:51 - 004050432 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2018-08-19 10:12 - 2018-07-31 07:50 - 000029696 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2018-08-19 10:12 - 2018-07-28 16:57 - 000125015 ____R C:\windows\system32\CaptureCountdown.hcp
2018-08-19 10:12 - 2018-07-28 16:57 - 000017806 ____R C:\windows\system32\CaptureToast.hcp
2018-08-19 10:12 - 2018-07-28 16:56 - 000119017 ____R C:\windows\system32\CaptureBrackets.hcp
2018-08-19 10:12 - 2018-03-18 23:15 - 003996160 _____ (Microsoft Corporation) C:\windows\system32\UIRibbon.dll
2018-08-19 10:12 - 2018-03-18 23:09 - 003466240 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIRibbon.dll
2018-08-19 10:11 - 2018-07-31 14:39 - 001161216 ____R (Microsoft Corporation) C:\windows\system32\Windows.Mirage.Internal.Capture.UX.dll
2018-08-19 10:11 - 2018-07-31 09:04 - 000144792 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2018-08-19 10:11 - 2018-07-31 09:03 - 001612072 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2018-08-19 10:11 - 2018-07-31 09:03 - 000309656 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2018-08-19 10:11 - 2018-07-31 09:03 - 000071464 _____ (Microsoft Corporation) C:\windows\system32\win32appinventorycsp.dll
2018-08-19 10:11 - 2018-07-31 09:02 - 000793896 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2018-08-19 10:11 - 2018-07-31 09:02 - 000612272 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2018-08-19 10:11 - 2018-07-31 09:02 - 000453416 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2018-08-19 10:11 - 2018-07-31 09:02 - 000035224 _____ (Microsoft Corporation) C:\windows\system32\DeviceCensus.exe
2018-08-19 10:11 - 2018-07-31 09:01 - 000689560 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2018-08-19 10:11 - 2018-07-31 09:01 - 000482088 _____ (Microsoft Corporation) C:\windows\system32\dcntel.dll
2018-08-19 10:11 - 2018-07-31 09:01 - 000445848 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2018-08-19 10:11 - 2018-07-31 09:01 - 000060312 _____ (Microsoft Corporation) C:\windows\system32\hvhostsvc.dll
2018-08-19 10:11 - 2018-07-31 08:55 - 000529704 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2018-08-19 10:11 - 2018-07-31 08:53 - 005478112 _____ (Microsoft Corporation) C:\windows\system32\OneCoreUAPCommonProxyStub.dll
2018-08-19 10:11 - 2018-07-31 08:08 - 001640448 _____ (Microsoft Corporation) C:\windows\system32\GdiPlus.dll
2018-08-19 10:11 - 2018-07-31 08:06 - 007346176 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2018-08-19 10:11 - 2018-07-31 08:05 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\tokenbinding.dll
2018-08-19 10:11 - 2018-07-31 08:04 - 000499712 _____ (Microsoft Corporation) C:\windows\system32\nltest.exe
2018-08-19 10:11 - 2018-07-31 08:04 - 000036864 _____ (Microsoft Corporation) C:\windows\system32\tbauth.dll
2018-08-19 10:11 - 2018-07-31 08:03 - 000354816 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.BioFeedback.dll
2018-08-19 10:11 - 2018-07-31 08:02 - 000434176 _____ (Microsoft Corporation) C:\windows\system32\msIso.dll
2018-08-19 10:11 - 2018-07-31 08:01 - 000527872 _____ (Microsoft Corporation) C:\windows\system32\aadcloudap.dll
2018-08-19 10:11 - 2018-07-31 08:01 - 000427008 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.LockScreen.dll
2018-08-19 10:11 - 2018-07-31 08:00 - 001878016 _____ (Microsoft Corporation) C:\windows\system32\AzureSettingSyncProvider.dll
2018-08-19 10:11 - 2018-07-31 08:00 - 001433600 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Cred.dll
2018-08-19 10:11 - 2018-07-31 08:00 - 000925696 _____ (Microsoft Corporation) C:\windows\system32\WpcWebFilter.dll
2018-08-19 10:11 - 2018-07-31 08:00 - 000833024 _____ (Microsoft Corporation) C:\windows\system32\Windows.Security.Authentication.Web.Core.dll
2018-08-19 10:11 - 2018-07-31 08:00 - 000691712 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2018-08-19 10:11 - 2018-07-31 07:59 - 001260544 _____ (Microsoft Corporation) C:\windows\system32\GamePanel.exe
2018-08-19 10:11 - 2018-07-31 07:58 - 000056832 _____ (Microsoft Corporation) C:\windows\system32\cldapi.dll
2018-08-19 10:11 - 2018-07-31 07:57 - 001736704 _____ (Microsoft Corporation) C:\windows\system32\wevtsvc.dll
2018-08-19 10:11 - 2018-07-31 07:56 - 002625024 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Logon.dll
2018-08-19 10:11 - 2018-07-31 07:56 - 001293312 _____ (Microsoft Corporation) C:\windows\system32\aadtb.dll
2018-08-19 10:11 - 2018-07-31 07:56 - 001071104 _____ (Microsoft Corporation) C:\windows\system32\TokenBroker.dll
2018-08-19 10:11 - 2018-07-31 07:51 - 000066048 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2018-08-19 10:11 - 2018-07-31 07:49 - 000045568 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2018-08-19 10:11 - 2018-07-31 07:49 - 000012800 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2018-08-18 19:57 - 2018-09-04 08:21 - 000007594 _____ C:\Users\germa\AppData\Local\Resmon.ResmonCfg
2018-08-18 19:19 - 2018-08-18 19:19 - 000000000 ____D C:\Users\germa\AppData\Local\mbam
2018-08-18 19:18 - 2018-08-19 10:45 - 000259360 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-08-18 19:17 - 2018-08-18 19:17 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-08-18 19:17 - 2018-08-18 19:17 - 000000000 ____D C:\Program Files\Malwarebytes
2018-08-18 19:16 - 2018-08-18 19:17 - 082335352 _____ (Malwarebytes ) C:\Users\germa\Downloads\mb3-setup-consumer-3.5.1.2522-1.0.421-1.0.6385.exe
2018-08-18 18:59 - 2018-08-18 18:59 - 000000000 ____D C:\windows\Firmware
2018-08-18 18:18 - 2018-08-18 18:18 - 000002526 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-08-18 18:18 - 2018-08-18 18:18 - 000002525 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive pro firmy.lnk
2018-08-18 18:18 - 2018-08-18 18:18 - 000002485 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy.lnk
2018-08-18 18:18 - 2018-08-18 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2018-08-11 11:06 - 2018-09-03 06:13 - 000000000 ____D C:\Users\germa\AppData\Roaming\XnView
2018-08-11 11:06 - 2018-08-11 11:06 - 000000955 _____ C:\Users\germa\Desktop\XnView.lnk
2018-08-11 11:05 - 2018-08-11 11:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
2018-08-11 11:05 - 2018-08-11 11:06 - 000000000 ____D C:\Program Files (x86)\XnView
2018-08-11 10:45 - 2018-08-11 10:45 - 020346760 _____ (Gougelet Pierre-e ) C:\Users\germa\Downloads\XnView-win-full.exe
2018-08-11 10:24 - 2007-04-01 14:39 - 000005097 _____ C:\Users\germa\Documents\nemec1.ged
2018-08-11 10:24 - 2007-04-01 13:53 - 000003502 _____ C:\Users\germa\Documents\22.ged
2018-08-11 10:24 - 2007-04-01 13:44 - 000003534 _____ C:\Users\germa\Documents\nemec.ged
2018-08-11 10:23 - 2007-04-01 14:40 - 000005105 _____ C:\Users\germa\Documents\Nemec_aktualni.ged
2018-08-10 17:11 - 2018-08-10 17:11 - 000003222 _____ C:\windows\System32\Tasks\RtHDVBg_Session
2018-08-10 17:09 - 2018-08-10 17:09 - 000003194 _____ C:\windows\System32\Tasks\RTKCPL
2018-08-10 17:08 - 2018-05-11 01:52 - 072520680 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RCoRes64.dat
2018-08-10 17:08 - 2018-05-11 01:52 - 018223906 _____ C:\windows\system32\Drivers\RTAIODAT.DAT
2018-08-10 17:08 - 2018-05-11 01:52 - 003691368 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RltkAPO64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 003677128 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTSnMg64.cpl
2018-08-10 17:08 - 2018-05-11 01:52 - 003452120 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkApi64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 003417976 _____ (DTS, Inc.) C:\windows\system32\slcnt64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 003215184 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtPgEx64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 003128776 _____ (DTS, Inc.) C:\windows\system32\sltech64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 002930624 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RCoInstII64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001618216 _____ (Conexant Systems Inc.) C:\windows\system32\CX64APO.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001537504 _____ (Conexant Systems Inc.) C:\windows\system32\CX64Proxy.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001435104 _____ (Synopsys, Inc.) C:\windows\system32\SRRPTR64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001366904 _____ (Sound Research, Corp.) C:\windows\system32\SECOMN64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001353288 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTCOM64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001300664 _____ (Sound Research, Corp.) C:\windows\system32\SEHDHF64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001229088 _____ (Sound Research, Corp.) C:\windows\system32\SEAPO64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001157216 _____ (Sound Research, Corp.) C:\windows\system32\SEHDRA64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001045880 _____ (Sound Research, Corp.) C:\windows\SysWOW64\SECOMN32.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 001007344 _____ (Sound Research, Corp.) C:\windows\SysWOW64\SEHDHF32.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000994648 _____ (DTS, Inc.) C:\windows\system32\sl3apo64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000692128 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtDataProc64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000541080 _____ (SRS Labs, Inc.) C:\windows\system32\SRSTSX64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000507144 _____ (Conexant Systems, Inc.) C:\windows\system32\CAF64APO2.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000467120 _____ (Synopsys, Inc.) C:\windows\system32\SRAPO64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000392840 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEP64A.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000381376 _____ (Synopsys, Inc.) C:\windows\system32\SRCOM64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000343672 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtlCPAPI64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000341112 _____ (Synopsys, Inc.) C:\windows\SysWOW64\SRCOM.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000341112 _____ (Synopsys, Inc.) C:\windows\system32\SRCOM.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000327240 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DHT64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000327240 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DAA64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000266520 _____ (TODO: <Company name>) C:\windows\system32\slprp64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000220352 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEED64A.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000192944 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCfg64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000174904 _____ (SRS Labs, Inc.) C:\windows\system32\SRSWOW64.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000123768 _____ (Conexant System, Inc.) C:\windows\system32\Caf64api.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000122280 _____ (Real Sound Lab SIA) C:\windows\system32\CONEQMSAPOGUILibrary.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000116504 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEL64A.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000093872 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEG64A.dll
2018-08-10 17:08 - 2018-05-11 01:52 - 000004204 _____ C:\windows\system32\cxapo.prop
2018-08-10 16:52 - 2018-08-10 17:11 - 000002063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Control.lnk
2018-08-10 16:52 - 2018-08-10 17:09 - 000000000 ____D C:\windows\SysWOW64\RTCOM
2018-08-10 16:52 - 2018-08-10 16:52 - 000000000 ____D C:\ProgramData\SoundResearch
2018-08-10 16:39 - 2018-08-10 16:39 - 000000000 ____D C:\Users\germa\AppData\LocalLow\Adobe
2018-08-10 16:39 - 2018-08-10 16:39 - 000000000 ____D C:\Users\germa\AppData\Local\CEF
2018-08-10 16:38 - 2018-08-10 16:44 - 000112195 _____ C:\Users\germa\Documents\Soustředění - seznam busy.pdf
2018-08-10 16:25 - 2018-08-10 16:43 - 000004562 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2018-08-10 16:24 - 2018-08-18 18:38 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-08-10 16:24 - 2018-08-10 16:24 - 000002091 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2018-08-10 16:22 - 2018-08-10 16:22 - 000000000 ____D C:\Program Files (x86)\Adobe
2018-08-10 16:19 - 2018-08-10 16:40 - 000000000 ____D C:\ProgramData\Adobe
2018-08-10 16:11 - 2018-08-10 16:47 - 000057916 _____ C:\Users\germa\Documents\2018 - Přihláška na soustředění HBC Hostivař (Odpovědi).xlsx
2018-08-10 16:11 - 2018-08-10 16:45 - 000242356 _____ C:\Users\germa\Documents\Seznamy soustředění HBC Hostivař 2018 (1).pdf
2018-08-10 10:47 - 2018-04-03 23:12 - 000057924 _____ C:\windows\rtl8723d_mp_chip_bt40_fw_asic_rom_patch_new.dll
2018-08-10 10:47 - 2018-04-03 23:12 - 000050888 _____ C:\windows\rtl8723b_mp_chip_bt40_fw_asic_rom_patch_new.dll
2018-08-10 10:47 - 2018-04-03 23:12 - 000050836 _____ C:\windows\rtl8723b_mp_chip_bt40_fw_asic_rom_patch_new_s1.dll
2018-08-10 10:47 - 2018-04-03 23:12 - 000049424 _____ C:\windows\rtl8822b_mp_chip_bt40_fw_asic_rom_patch_new.dll
2018-08-10 10:47 - 2018-04-03 23:12 - 000044660 _____ C:\windows\rtl8821c_mp_chip_bt40_fw_asic_rom_patch_new.dll
2018-08-10 10:30 - 2018-08-10 10:30 - 000000000 ____D C:\Users\germa\AppData\Roaming\HP Active Health
2018-08-10 07:55 - 2018-05-17 10:52 - 000023024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Luadgmgt.dll
2018-08-09 07:26 - 2018-08-09 07:26 - 000000000 ____D C:\6749525315573233238
2018-08-08 20:33 - 2018-08-08 20:33 - 000003160 _____ C:\windows\System32\Tasks\StartCN
2018-08-08 20:33 - 2018-08-08 20:33 - 000003074 _____ C:\windows\System32\Tasks\StartDVR
2018-08-08 20:33 - 2018-08-08 20:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2018-08-08 20:33 - 2018-08-08 20:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\##ID_STRING16##
2018-08-08 20:33 - 2018-08-08 20:33 - 000000000 ____D C:\Program Files (x86)\AMD
2018-08-08 20:31 - 2018-08-08 20:31 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
2018-08-08 20:21 - 2018-08-08 20:21 - 000000000 ____D C:\Users\germa\AppData\Roaming\ATI
2018-08-08 20:21 - 2018-08-08 20:21 - 000000000 ____D C:\Users\germa\AppData\Local\ATI
2018-08-08 20:21 - 2018-08-08 20:21 - 000000000 ____D C:\ProgramData\ATI
2018-08-08 20:20 - 2018-08-08 20:20 - 000000000 ____D C:\Users\germa\AppData\Local\RadeonInstaller

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-05 11:38 - 2017-03-18 06:46 - 000000000 ____D C:\windows\Panther
2018-09-05 11:02 - 2017-03-18 05:52 - 000000000 ____D C:\windows\system32\SleepStudy
2018-09-05 09:17 - 2017-05-15 13:14 - 001216284 _____ C:\windows\system32\perfh005.dat
2018-09-05 09:17 - 2017-05-15 13:14 - 000295434 _____ C:\windows\system32\perfc005.dat
2018-09-05 09:17 - 2017-04-01 07:38 - 002768646 _____ C:\windows\system32\PerfStringBackup.INI
2018-09-05 09:11 - 2017-03-18 13:40 - 000786432 _____ C:\windows\system32\config\BBI
2018-09-05 09:11 - 2017-03-18 05:52 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-09-05 09:10 - 2017-09-22 08:53 - 000065536 _____ C:\windows\psp_storage.bin
2018-09-03 17:19 - 2017-03-18 23:01 - 000000000 ____D C:\windows\INF
2018-09-03 17:15 - 2017-05-15 04:18 - 000000000 ____D C:\Program Files (x86)\HP
2018-09-03 13:01 - 2018-07-26 20:33 - 000000364 _____ C:\windows\Tasks\HPCeeScheduleForgerma.job
2018-09-03 12:47 - 2018-07-17 18:56 - 000000000 ____D C:\Users\germa\AppData\Local\Google
2018-09-03 12:34 - 2018-07-26 20:33 - 000003256 _____ C:\windows\System32\Tasks\HPCeeScheduleForgerma
2018-09-03 10:38 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-09-03 10:38 - 2017-03-18 23:03 - 000000000 ____D C:\windows\AppReadiness
2018-09-03 06:14 - 2018-07-17 21:38 - 000000000 ____D C:\windows\system32\Drivers\wd
2018-09-03 06:14 - 2017-03-18 23:03 - 000000000 ____D C:\windows\system32\WinBioPlugIns
2018-09-03 06:11 - 2018-07-17 18:35 - 000000000 ____D C:\Users\germa\AppData\Local\VirtualStore
2018-09-03 06:11 - 2017-03-18 23:03 - 000000000 ____D C:\windows\SystemApps
2018-09-02 20:22 - 2018-07-17 18:56 - 000000000 ____D C:\Program Files (x86)\Google
2018-09-02 20:15 - 2018-07-17 18:31 - 000000000 ____D C:\Users\germa
2018-09-02 20:14 - 2017-05-15 04:25 - 000000948 _____ C:\windows\Tasks\DropboxUpdateTaskMachineUA.job
2018-09-02 20:14 - 2017-05-15 04:25 - 000000944 _____ C:\windows\Tasks\DropboxUpdateTaskMachineCore.job
2018-08-23 22:58 - 2017-05-15 04:25 - 000004008 _____ C:\windows\System32\Tasks\DropboxUpdateTaskMachineUA
2018-08-23 22:58 - 2017-05-15 04:25 - 000003776 _____ C:\windows\System32\Tasks\DropboxUpdateTaskMachineCore
2018-08-20 19:16 - 2018-07-17 18:46 - 000003376 _____ C:\windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1894498253-2117363191-260290956-1001
2018-08-20 19:16 - 2018-07-17 18:39 - 000002394 _____ C:\Users\germa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-08-20 19:16 - 2018-07-17 18:39 - 000000000 ___RD C:\Users\germa\OneDrive
2018-08-19 12:13 - 2017-03-18 05:53 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-08-19 11:17 - 2017-03-18 23:03 - 000000000 ____D C:\windows\rescache
2018-08-19 11:02 - 2017-03-18 22:51 - 000000000 ____D C:\windows\CbsTemp
2018-08-19 10:44 - 2017-03-18 05:52 - 000454416 _____ C:\windows\system32\FNTCACHE.DAT
2018-08-19 10:42 - 2017-03-19 04:32 - 000000000 ____D C:\windows\HoloShell
2018-08-19 10:42 - 2017-03-18 23:03 - 000000000 ___SD C:\windows\SysWOW64\F12
2018-08-19 10:42 - 2017-03-18 23:03 - 000000000 ___SD C:\windows\system32\F12
2018-08-19 10:42 - 2017-03-18 23:03 - 000000000 ___SD C:\windows\system32\DiagSvcs
2018-08-19 10:42 - 2017-03-18 23:03 - 000000000 ____D C:\windows\ShellExperiences
2018-08-19 10:42 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-08-19 10:42 - 2017-03-18 23:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-08-19 09:58 - 2018-07-17 19:13 - 000004666 _____ C:\windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-08-19 09:58 - 2018-07-17 19:11 - 000000000 ____D C:\Users\germa\AppData\Local\Adobe
2018-08-19 09:57 - 2017-03-18 23:03 - 000000000 ____D C:\windows\SysWOW64\Macromed
2018-08-19 09:57 - 2017-03-18 23:03 - 000000000 ____D C:\windows\system32\Macromed
2018-08-18 19:03 - 2018-07-17 22:08 - 000000000 ____D C:\Program Files\rempl
2018-08-18 18:59 - 2018-07-17 22:06 - 000000000 ____D C:\windows\system32\MRT
2018-08-18 18:35 - 2018-07-17 22:05 - 137343192 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-08-18 18:21 - 2017-03-19 04:31 - 009261568 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2018-08-18 18:21 - 2017-03-19 04:31 - 009261568 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2018-08-18 18:19 - 2017-03-18 23:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-08-18 18:18 - 2017-05-15 04:28 - 000002520 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-08-18 18:18 - 2017-05-15 04:28 - 000002497 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-08-18 18:18 - 2017-05-15 04:28 - 000002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-08-18 18:18 - 2017-05-15 04:28 - 000002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-08-18 18:18 - 2017-05-15 04:28 - 000002418 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-08-18 18:18 - 2017-05-15 04:28 - 000002414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-08-18 18:16 - 2017-05-15 04:26 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-08-18 18:12 - 2018-07-19 08:12 - 000000000 ____D C:\ProgramData\AMD
2018-08-10 17:11 - 2017-09-22 08:50 - 000000000 ___HD C:\Program Files (x86)\Temp
2018-08-10 17:09 - 2017-09-22 08:51 - 003280227 _____ C:\windows\system32\Drivers\rtkhdasetting.zip
2018-08-10 17:08 - 2017-05-15 04:20 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-08-10 16:39 - 2018-07-17 18:35 - 000000000 ____D C:\Users\germa\AppData\Roaming\Adobe
2018-08-10 16:15 - 2018-07-17 18:35 - 000000000 ____D C:\Users\germa\AppData\Local\Packages
2018-08-10 16:15 - 2018-07-17 18:34 - 000000000 ____D C:\Users\germa\AppData\Local\ConnectedDevicesPlatform
2018-08-10 16:06 - 2017-09-22 08:50 - 000000000 ____D C:\Program Files (x86)\Realtek
2018-08-10 11:07 - 2017-05-15 12:55 - 000000000 ____D C:\SWSetup
2018-08-10 10:46 - 2017-09-22 08:57 - 000000000 ____D C:\ProgramData\Realtek
2018-08-10 10:33 - 2017-09-22 08:54 - 000000740 _____ C:\windows\HPSetLog.txt
2018-08-10 10:30 - 2017-05-15 04:25 - 000000000 ____D C:\Program Files\HPCommRecovery
2018-08-09 07:26 - 2018-07-17 18:35 - 000000000 ____D C:\Users\germa\AppData\Local\AMD
2018-08-09 07:23 - 2018-07-17 18:57 - 000000000 ____D C:\Users\germa\AppData\LocalLow\AMD
2018-08-08 20:33 - 2018-07-17 21:53 - 000000000 ____D C:\AMD
2018-08-08 20:33 - 2017-09-22 08:51 - 000000000 ____D C:\Program Files\AMD
2018-08-08 20:28 - 2017-09-22 08:52 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-08-08 20:26 - 2017-05-15 04:15 - 000000000 ____D C:\ProgramData\Package Cache
2018-08-08 19:44 - 2017-09-22 10:17 - 000000000 ____D C:\windows\HP
2018-08-08 19:22 - 2017-05-15 12:56 - 000014848 _____ (Hewlett-Packard) C:\windows\HPCUST2.exe

==================== Files in the root of some directories =======

2018-07-27 00:10 - 2018-07-27 00:13 - 000006144 _____ () C:\Users\germa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-08-18 19:57 - 2018-09-04 08:21 - 000007594 _____ () C:\Users\germa\AppData\Local\Resmon.ResmonCfg
2018-09-02 20:18 - 2018-09-02 20:18 - 000000000 _____ () C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-09-03 10:41

==================== End of FRST.txt ============================

Re: zpomalené win10, procesor na 100 %

Napsal: 05 zář 2018 11:53
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
C:\windows\LastGood.Tmp
C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}
C:\Program Files (x86)\Temp
C:\Users\germa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}

EmptyTemp:
End
Uložte do C:\Users\germa\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: zpomalené win10, procesor na 100 %

Napsal: 05 zář 2018 14:10
od jendaabenda
Fix result of Farbar Recovery Scan Tool (x64) Version: 01.09.2018 03
Ran by germa (05-09-2018 14:56:13) Run:1
Running from C:\Users\germa\Downloads
Loaded Profiles: germa (Available Profiles: germa)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
C:\windows\LastGood.Tmp
C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}
C:\Program Files (x86)\Temp
C:\Users\germa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}

EmptyTemp:
End
*****************

Processes closed successfully.
C:\windows\LastGood.Tmp => moved successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946} => moved successfully
C:\Program Files (x86)\Temp => moved successfully
C:\Users\germa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
"C:\Users\germa\AppData\Local\{C305E1E1-9898-4EE4-A06F-679DFABBA946}" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 41525596 B
Java, Flash, Steam htmlcache => 717 B
Windows/system/drivers => 1574781 B
Edge => 9781683 B
Chrome => 716644623 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 128 B
LocalService => 6496 B
NetworkService => 121576 B
germa => 275104928 B

RecycleBin => 0 B
EmptyTemp: => 1003.9 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 14:58:39 ====

Re: zpomalené win10, procesor na 100 %

Napsal: 05 zář 2018 16:37
od Rudy
Smazáno. Nastala nějaká změna?

Re: zpomalené win10, procesor na 100 %

Napsal: 05 zář 2018 17:40
od jendaabenda
Vypadá to pozitivně. Říkal jsem si, že tam bude ještě pár schovaných servis na vypnutí.
Dekuji za pomoc

Re: zpomalené win10, procesor na 100 %

Napsal: 05 zář 2018 17:54
od Rudy
Rádo se stalo! :)