Stránka 1 z 1

Prosím o kontrolu. Děkuji

Napsal: 22 zář 2018 10:58
od vrchlab
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.09.2018
Ran by petr.kopecny (administrator) on INVESTICE02 (22-09-2018 11:49:06)
Running from C:\Users\petr.kopecny.MSQUATRO\Downloads
Loaded Profiles: petr.kopecny (Available Profiles: petr.kopecny & petr.kopecny & Administrator & DefaultAppPool)
Platform: Windows 10 Pro Version 1803 17134.285 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(ESET) C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [415128 2016-07-11] ()
HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184632 2013-11-14] (Motorola Solutions, Inc.)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-08] (Acer Incorporated)
HKLM\...\Run: [ALU] => C:\Program Files\Acer\Acer Updater\ALU.exe [2379056 2017-04-21] (Acer Incorporated)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3237808 2018-01-09] (Dominik Reichl)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\RunOnce: [Uninstall 18.131.0701.0007\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Microsoft\OneDrive\18.131.0701.0007\amd64"
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\RunOnce: [Uninstall 18.131.0701.0007] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Microsoft\OneDrive\18.131.0701.0007"
Startup: C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Poslat do aplikace OneNote.lnk [2018-02-16]
ShortcutTarget: Poslat do aplikace OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1F160B83-A94E-4E9D-8350-E9581BEB162E}: [DhcpNameServer] 192.168.1.22 192.168.1.5
Tcpip\..\Interfaces\{25cfe3ba-35be-4348-922b-92cd6f407bd2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6195e00b-5162-47c6-9fde-413d8051bdac}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://msq.msquatro.cz/
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://obchod.msquatro.cz/
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-09-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-07-23] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-07-23] (Oracle Corporation)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxps://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1474031863011
DPF: HKLM-x32 {F680B28A-3AEE-4C88-93ED-45AE9215C128} hxxps://adisepo.mfcr.cz/adistc/adis/idpr_pub/xspa/bin/cryptsignx.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\Mozilla\Firefox\Profiles\h2eaaugm.default [2018-09-22]
FF Homepage: Mozilla\Firefox\Profiles\h2eaaugm.default -> about:home
FF Session Restore: Mozilla\Firefox\Profiles\h2eaaugm.default -> is enabled.
FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-11] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-11] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-07-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-07-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-09-11] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default [2018-09-22]
CHR Extension: (Slides) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-03]
CHR Extension: (Docs) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-03]
CHR Extension: (Google Drive) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-03]
CHR Extension: (YouTube) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-03]
CHR Extension: (Sheets) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-03]
CHR Extension: (Google Docs Offline) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-03]
CHR Extension: (Gmail) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-03]
CHR Extension: (Chrome Media Router) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-03]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9658664 2018-09-08] (Microsoft Corporation)
R2 EraAgentSvc; C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe [1605832 2015-08-22] (ESET)
S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin Ltd. or its subsidiaries)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [184064 2016-12-12] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [370064 2016-07-11] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [445696 2014-03-12] (Acer Incorporate)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-07-31] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-07-31] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230656 2016-12-12] (Intel Corporation)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
S3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
R3 Microsoft_Bluetooth_AvrcpTransport; C:\WINDOWS\system32\DRIVERS\Microsoft.Bluetooth.AvrcpTransport.sys [46592 2018-04-12] (Microsoft Corporation)
R1 MpKsl64ce7b34; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6FD79C18-F713-4C5F-B026-C300B5443110}\MpKsl64ce7b34.sys [58120 2018-09-22] (Microsoft Corporation)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2018-04-12] (Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [751632 2016-08-30] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-01-24] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46584 2018-07-31] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-07-31] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-07-31] (Microsoft Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-22 11:49 - 2018-09-22 11:50 - 000017840 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST.txt
2018-09-22 11:45 - 2018-09-22 11:49 - 000000000 ____D C:\FRST
2018-09-22 11:44 - 2018-09-22 11:44 - 002413568 _____ (Farbar) C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST64.exe
2018-09-22 11:13 - 2018-09-22 11:13 - 016796856 _____ (Piriform Ltd) C:\Users\petr.kopecny.MSQUATRO\Downloads\ccsetup547.exe
2018-09-22 11:13 - 2018-09-22 11:13 - 016796856 _____ (Piriform Ltd) C:\Users\petr.kopecny.MSQUATRO\Downloads\ccsetup547(1).exe
2018-09-19 20:22 - 2018-09-19 20:22 - 000000000 ___HD C:\OneDriveTemp
2018-09-19 19:34 - 2018-09-19 19:34 - 000002563 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002557 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002534 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002529 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2018-09-12 21:53 - 2018-08-31 09:43 - 001524152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2018-09-12 21:53 - 2018-08-31 09:42 - 001636232 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-09-12 21:53 - 2018-08-31 09:24 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2018-09-12 21:53 - 2018-08-31 09:23 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-09-12 21:53 - 2018-08-31 09:23 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2018-09-12 21:53 - 2018-08-31 09:22 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-09-12 21:53 - 2018-08-31 09:22 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-09-12 21:53 - 2018-08-31 08:55 - 001455960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-09-12 21:53 - 2018-08-31 08:53 - 001327504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2018-09-12 21:53 - 2018-08-31 08:36 - 001469952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-09-12 21:53 - 2018-08-31 05:44 - 001222440 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-09-12 21:53 - 2018-08-31 05:44 - 001030952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-09-12 21:53 - 2018-08-31 05:43 - 002719216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-09-12 21:53 - 2018-08-31 05:43 - 000722880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 009090016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-09-12 21:53 - 2018-08-31 05:42 - 007520064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 007436192 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 002824672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-09-12 21:53 - 2018-08-31 05:42 - 002461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 001767064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 001458552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-09-12 21:53 - 2018-08-31 05:42 - 001258352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-09-12 21:53 - 2018-08-31 05:42 - 001142000 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-09-12 21:53 - 2018-08-31 05:42 - 001097720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 000632296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpx.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 006570040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 006043680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 001989496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 001514352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 001129728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 000453104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpx.dll
2018-09-12 21:53 - 2018-08-31 05:26 - 025847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-09-12 21:53 - 2018-08-31 05:21 - 022008320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-09-12 21:53 - 2018-08-31 05:20 - 022715904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-09-12 21:53 - 2018-08-31 05:18 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-09-12 21:53 - 2018-08-31 05:16 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-09-12 21:53 - 2018-08-31 05:16 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-09-12 21:53 - 2018-08-31 05:16 - 004382720 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 007577088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 004866560 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-09-12 21:53 - 2018-08-31 05:14 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-09-12 21:53 - 2018-08-31 05:14 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-09-12 21:53 - 2018-08-31 05:13 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-09-12 21:53 - 2018-08-31 05:11 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-09-12 21:53 - 2018-08-31 05:11 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-09-12 21:53 - 2018-08-31 05:11 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-09-12 21:53 - 2018-08-31 05:11 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-09-12 21:53 - 2018-08-31 05:11 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 005777920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 003711488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 001375744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-09-12 21:53 - 2018-08-31 05:09 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2018-09-12 21:53 - 2018-08-31 05:07 - 001627648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-09-12 21:53 - 2018-08-28 09:17 - 023862784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-09-12 21:53 - 2018-08-28 08:48 - 001274368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-09-12 21:53 - 2018-08-28 08:45 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2018-09-12 21:53 - 2018-08-09 11:37 - 002267944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2018-09-12 21:53 - 2018-08-09 11:32 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-09-12 21:53 - 2018-08-09 11:31 - 001617728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2018-09-12 21:53 - 2018-08-09 11:16 - 004491264 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-09-12 21:53 - 2018-08-09 11:14 - 012709376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-09-12 21:53 - 2018-08-09 11:13 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-09-12 21:53 - 2018-08-09 11:12 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-09-12 21:53 - 2018-08-09 11:11 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-09-12 21:53 - 2018-08-09 11:11 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-09-12 21:53 - 2018-08-09 11:11 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-09-12 21:53 - 2018-08-09 11:10 - 001557504 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2018-09-12 21:53 - 2018-08-09 10:38 - 001538976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2018-09-12 21:53 - 2018-08-09 10:24 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-09-12 21:53 - 2018-08-09 10:23 - 003397632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-09-12 21:53 - 2018-08-09 10:21 - 002894848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-09-12 21:53 - 2018-08-09 10:20 - 002401792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-09-12 21:53 - 2018-08-09 07:02 - 001035144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-09-12 21:53 - 2018-08-09 07:01 - 000777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2018-09-12 21:53 - 2018-08-09 06:54 - 001019016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-09-12 21:53 - 2018-08-09 06:53 - 002765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-09-12 21:53 - 2018-08-09 06:53 - 001947720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-09-12 21:53 - 2018-08-09 06:53 - 000932136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-09-12 21:53 - 2018-08-09 06:53 - 000482480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-09-12 21:53 - 2018-08-09 06:30 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-09-12 21:53 - 2018-08-09 06:29 - 002253584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-09-12 21:53 - 2018-08-09 06:29 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-09-12 21:53 - 2018-08-09 06:29 - 001174552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-09-12 21:53 - 2018-08-09 06:28 - 003395072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-09-12 21:53 - 2018-08-09 06:28 - 001589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2018-09-12 21:53 - 2018-08-09 06:25 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-09-12 21:53 - 2018-08-09 06:25 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-09-12 21:53 - 2018-08-09 06:24 - 002368512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 003148288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 002904064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-09-12 21:53 - 2018-08-09 06:22 - 004615680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-09-12 21:53 - 2018-08-09 06:22 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-09-12 21:53 - 2018-08-09 06:21 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-09-12 21:53 - 2018-08-09 06:13 - 001189376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2018-09-12 21:53 - 2018-08-09 06:11 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-09-12 21:53 - 2018-08-09 06:10 - 002893824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2018-09-12 21:53 - 2018-08-09 06:10 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-09-12 21:53 - 2018-08-09 06:09 - 004191232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-09-12 21:52 - 2018-08-31 09:46 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-09-12 21:52 - 2018-08-31 09:45 - 000348328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-09-12 21:52 - 2018-08-31 09:27 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2018-09-12 21:52 - 2018-08-31 09:27 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2018-09-12 21:52 - 2018-08-31 09:26 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
2018-09-12 21:52 - 2018-08-31 09:25 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll
2018-09-12 21:52 - 2018-08-31 09:25 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2018-09-12 21:52 - 2018-08-31 09:24 - 000482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2018-09-12 21:52 - 2018-08-31 09:24 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-09-12 21:52 - 2018-08-31 08:41 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2018-09-12 21:52 - 2018-08-31 08:41 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2018-09-12 21:52 - 2018-08-31 08:40 - 000216576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll
2018-09-12 21:52 - 2018-08-31 08:37 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-09-12 21:52 - 2018-08-31 08:37 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2018-09-12 21:52 - 2018-08-31 08:37 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-09-12 21:52 - 2018-08-31 05:50 - 000273720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-09-12 21:52 - 2018-08-31 05:50 - 000270648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-09-12 21:52 - 2018-08-31 05:44 - 001064744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-09-12 21:52 - 2018-08-31 05:44 - 000568600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-09-12 21:52 - 2018-08-31 05:44 - 000136488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-09-12 21:52 - 2018-08-31 05:44 - 000076256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-09-12 21:52 - 2018-08-31 05:42 - 000983080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-09-12 21:52 - 2018-08-31 05:42 - 000885928 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-09-12 21:52 - 2018-08-31 05:42 - 000604640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-09-12 21:52 - 2018-08-31 05:42 - 000527328 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-09-12 21:52 - 2018-08-31 05:42 - 000494472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2018-09-12 21:52 - 2018-08-31 05:42 - 000155112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2018-09-12 21:52 - 2018-08-31 05:28 - 000568568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-09-12 21:52 - 2018-08-31 05:28 - 000134936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2018-09-12 21:52 - 2018-08-31 05:17 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-09-12 21:52 - 2018-08-31 05:17 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\netevent.dll
2018-09-12 21:52 - 2018-08-31 05:15 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2018-09-12 21:52 - 2018-08-31 05:15 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-09-12 21:52 - 2018-08-31 05:14 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-09-12 21:52 - 2018-08-31 05:14 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-09-12 21:52 - 2018-08-31 05:14 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-09-12 21:52 - 2018-08-31 05:13 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-09-12 21:52 - 2018-08-31 05:13 - 000402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-09-12 21:52 - 2018-08-31 05:12 - 000736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-09-12 21:52 - 2018-08-31 05:12 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netevent.dll
2018-09-12 21:52 - 2018-08-31 05:11 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-09-12 21:52 - 2018-08-31 05:11 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-09-12 21:52 - 2018-08-31 05:10 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2018-09-12 21:52 - 2018-08-31 05:09 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-09-12 21:52 - 2018-08-31 05:08 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-09-12 21:52 - 2018-08-31 05:07 - 000856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2018-09-12 21:52 - 2018-08-31 05:07 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2018-09-12 21:52 - 2018-08-31 05:06 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2018-09-12 21:52 - 2018-08-31 03:57 - 000001308 _____ C:\WINDOWS\system32\tcbres.wim
2018-09-12 21:52 - 2018-08-28 08:56 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-09-12 21:52 - 2018-08-28 08:49 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-09-12 21:52 - 2018-08-28 07:51 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-09-12 21:52 - 2018-08-14 04:14 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2018-09-12 21:52 - 2018-08-14 04:14 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-09-12 21:52 - 2018-08-09 11:31 - 000766872 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-09-12 21:52 - 2018-08-09 11:31 - 000253544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2018-09-12 21:52 - 2018-08-09 11:31 - 000236624 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2018-09-12 21:52 - 2018-08-09 11:17 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-09-12 21:52 - 2018-08-09 11:14 - 000466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2018-09-12 21:52 - 2018-08-09 11:14 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollUI.dll
2018-09-12 21:52 - 2018-08-09 11:14 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdeploy.dll
2018-09-12 21:52 - 2018-08-09 11:13 - 000521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2018-09-12 21:52 - 2018-08-09 11:13 - 000517120 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe
2018-09-12 21:52 - 2018-08-09 11:13 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsExt.dll
2018-09-12 21:52 - 2018-08-09 11:12 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-09-12 21:52 - 2018-08-09 11:12 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-09-12 21:52 - 2018-08-09 11:11 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-09-12 21:52 - 2018-08-09 11:11 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2018-09-12 21:52 - 2018-08-09 11:10 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2018-09-12 21:52 - 2018-08-09 11:10 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-09-12 21:52 - 2018-08-09 11:09 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput8.dll
2018-09-12 21:52 - 2018-08-09 11:09 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput.dll
2018-09-12 21:52 - 2018-08-09 11:09 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-09-12 21:52 - 2018-08-09 11:09 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageInspector.exe
2018-09-12 21:52 - 2018-08-09 10:36 - 000660896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-09-12 21:52 - 2018-08-09 10:36 - 000221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2018-09-12 21:52 - 2018-08-09 10:24 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdeploy.dll
2018-09-12 21:52 - 2018-08-09 10:23 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-09-12 21:52 - 2018-08-09 10:23 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollUI.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2018-09-12 21:52 - 2018-08-09 10:21 - 002016768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-09-12 21:52 - 2018-08-09 10:21 - 001274368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2018-09-12 21:52 - 2018-08-09 10:21 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-09-12 21:52 - 2018-08-09 10:20 - 000423424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2018-09-12 21:52 - 2018-08-09 10:20 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput8.dll
2018-09-12 21:52 - 2018-08-09 10:20 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput.dll
2018-09-12 21:52 - 2018-08-09 10:19 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-09-12 21:52 - 2018-08-09 06:55 - 000230304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2018-09-12 21:52 - 2018-08-09 06:54 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-09-12 21:52 - 2018-08-09 06:54 - 000375704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-09-12 21:52 - 2018-08-09 06:54 - 000203568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2018-09-12 21:52 - 2018-08-09 06:54 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-09-12 21:52 - 2018-08-09 06:53 - 001026456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-09-12 21:52 - 2018-08-09 06:53 - 000714792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-09-12 21:52 - 2018-08-09 06:53 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-09-12 21:52 - 2018-08-09 06:53 - 000125600 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptxml.dll
2018-09-12 21:52 - 2018-08-09 06:30 - 000183992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2018-09-12 21:52 - 2018-08-09 06:29 - 000581696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2018-09-12 21:52 - 2018-08-09 06:29 - 000099208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptxml.dll
2018-09-12 21:52 - 2018-08-09 06:27 - 000428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-09-12 21:52 - 2018-08-09 06:27 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\eShims.dll
2018-09-12 21:52 - 2018-08-09 06:27 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2018-09-12 21:52 - 2018-08-09 06:26 - 000990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2018-09-12 21:52 - 2018-08-09 06:26 - 000572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2018-09-12 21:52 - 2018-08-09 06:26 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2018-09-12 21:52 - 2018-08-09 06:26 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-09-12 21:52 - 2018-08-09 06:26 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsAuth.dll
2018-09-12 21:52 - 2018-08-09 06:26 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsCfg.dll
2018-09-12 21:52 - 2018-08-09 06:26 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000797184 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2018-09-12 21:52 - 2018-08-09 06:24 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-09-12 21:52 - 2018-08-09 06:22 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-09-12 21:52 - 2018-08-09 06:22 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2018-09-12 21:52 - 2018-08-09 06:13 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2018-09-12 21:52 - 2018-08-09 06:12 - 000652288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsAuth.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsCfg.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2018-09-12 21:52 - 2018-08-09 06:10 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-09-12 21:52 - 2018-08-09 06:09 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-09-12 21:52 - 2018-08-09 06:08 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2018-09-12 21:52 - 2018-08-09 05:08 - 000806416 _____ C:\WINDOWS\SysWOW64\locale.nls
2018-09-12 21:52 - 2018-08-09 05:08 - 000806416 _____ C:\WINDOWS\system32\locale.nls
2018-09-02 12:32 - 2018-09-02 20:28 - 4243487457 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\53 - Ve stínu (1953).mkv
2018-08-27 23:26 - 2018-08-27 23:26 - 000675984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000457512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000386712 _____ (Microsoft Corporation) C:\WINDOWS\system32\vccorlib140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000343192 _____ (Microsoft Corporation) C:\WINDOWS\system32\concrt140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000274072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vccorlib140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000248624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\concrt140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000089248 _____ (Microsoft Corporation) C:\WINDOWS\system32\vcruntime140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000087352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vcruntime140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000031896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140_1.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000028472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140_1.dll
2018-08-23 22:10 - 2018-09-05 01:04 - 000835144 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-08-23 22:10 - 2018-09-05 01:04 - 000179808 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-22 11:16 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2018-09-22 11:14 - 2018-05-22 22:23 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-09-22 11:14 - 2017-05-31 10:15 - 000000867 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-09-22 11:08 - 2014-12-10 11:36 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\Documents\Soubory aplikace Outlook
2018-09-22 10:52 - 2018-05-22 21:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-09-22 10:52 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-09-22 10:52 - 2014-08-05 22:01 - 000000000 ____D C:\Users\petr.kopecny\Documents\Soubory aplikace Outlook
2018-09-21 23:14 - 2018-04-12 01:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-09-21 23:14 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-09-21 21:09 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-09-20 20:37 - 2017-12-17 15:14 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Packages
2018-09-19 20:22 - 2018-05-22 22:23 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2852774663-3114243248-3625044681-2121
2018-09-19 20:22 - 2018-05-22 21:54 - 000002484 _____ C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-09-19 20:22 - 2014-12-12 00:10 - 000000000 ___RD C:\Users\petr.kopecny.MSQUATRO\OneDrive
2018-09-19 19:32 - 2014-05-23 11:48 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-09-18 23:09 - 2018-05-22 22:23 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-09-13 06:27 - 2016-11-18 07:50 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\AppData\LocalLow\Mozilla
2018-09-13 06:26 - 2017-04-20 14:00 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-09-13 06:26 - 2016-09-10 01:50 - 000000000 __SHD C:\Users\petr.kopecny\IntelGraphicsProfiles
2018-09-12 23:11 - 2018-05-22 21:49 - 001956628 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-09-12 23:11 - 2018-04-12 17:51 - 000809600 _____ C:\WINDOWS\system32\perfh005.dat
2018-09-12 23:11 - 2018-04-12 17:51 - 000186808 _____ C:\WINDOWS\system32\perfc005.dat
2018-09-12 23:06 - 2018-05-22 21:44 - 000280608 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-09-12 23:05 - 2018-05-22 22:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-09-12 23:05 - 2018-04-11 23:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-09-12 23:05 - 2016-12-14 10:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-09-12 23:05 - 2014-07-30 08:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-09-12 23:03 - 2018-04-12 17:52 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-09-12 23:03 - 2018-04-11 23:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-09-11 19:57 - 2014-08-06 11:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-09-11 19:54 - 2014-08-06 11:07 - 139184408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-09-11 19:28 - 2018-05-22 22:23 - 000004654 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-09-11 19:28 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-09-11 19:28 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-09-11 19:28 - 2017-05-31 10:15 - 000000000 ____D C:\Program Files\CCleaner
2018-09-10 06:37 - 2015-01-05 23:21 - 000005976 _____ C:\WINDOWS\wininit.ini
2018-09-10 06:36 - 2014-07-30 08:28 - 000001167 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-09-01 13:15 - 2015-03-19 16:53 - 000000000 ____D C:\QPlán
2018-09-01 13:14 - 2015-04-01 08:40 - 000000679 _____ C:\Users\petr.kopecny.MSQUATRO\Desktop\QKalkulátor.lnk
2018-09-01 13:14 - 2015-04-01 08:40 - 000000625 _____ C:\Users\petr.kopecny.MSQUATRO\Desktop\QPlán Výstupy.lnk
2018-09-01 13:12 - 2015-04-01 08:42 - 000000654 _____ C:\Users\petr.kopecny.MSQUATRO\Desktop\QRenta.lnk
2018-08-31 21:59 - 2015-02-15 20:39 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\vlc
2018-08-23 22:23 - 2016-07-11 18:07 - 000000000 ___RD C:\Users\petr.kopecny.MSQUATRO\3D Objects
2018-08-23 22:23 - 2016-07-11 14:53 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-08-23 22:23 - 2014-10-24 09:02 - 000000000 ___RD C:\Users\petr.kopecny.MSQUATRO\Virtual Machines
2018-08-23 22:06 - 2018-04-12 17:53 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ___SD C:\WINDOWS\system32\UNP
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-08-23 22:06 - 2018-04-12 01:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-22 21:44

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.09.2018
Ran by petr.kopecny (22-09-2018 11:51:26)
Running from C:\Users\petr.kopecny.MSQUATRO\Downloads
Windows 10 Pro Version 1803 17134.285 (X64) (2018-05-22 20:24:51)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3251029710-3280901918-1644894361-500 - Administrator - Enabled) => C:\Users\Administrator.INVESTICE02
DefaultAccount (S-1-5-21-3251029710-3280901918-1644894361-503 - Limited - Disabled)
Guest (S-1-5-21-3251029710-3280901918-1644894361-501 - Limited - Disabled)
petr.kopecny (S-1-5-21-3251029710-3280901918-1644894361-1000 - Limited - Enabled) => C:\Users\petr.kopecny
WDAGUtilityAccount (S-1-5-21-3251029710-3280901918-1644894361-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.01.3509 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{F0D9378C-CFA3-4503-A562-5350BE6E05C2}) (Version: 7.00.3004 - Acer Incorporated)
Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3504 - Acer Incorporated)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20058 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Advanced Office Password Recovery (remove only) (HKLM-x32\...\Advanced Office Password Recovery) (Version: 4.11 - Elcomsoft Co.Ltd.)
ANT Drivers Installer x64 (HKLM\...\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
calibre 64bit (HKLM\...\{1428EEEC-F3E9-407A-A60E-2E51CF66ED80}) (Version: 2.20.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 5.47 - Piriform)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3323.57 - CyberLink Corp.)
ČSOBP Kalkulátory 1.15.3.x (OED B) (HKLM-x32\...\Kalkulátory_is1) (Version: - )
Elevated Installer (HKLM-x32\...\{1052502B-4C91-43F9-B160-AE39ED57C9F0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
ESET Remote Administrator Agent (HKLM\...\{7AC14666-285C-4019-9351-AD4E2F4BA9E8}) (Version: 6.2.171.0 - ESET, spol. s r.o.)
Evernote v. 4.5.2 (HKLM-x32\...\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
FileZilla Client 3.26.1 (HKLM-x32\...\FileZilla Client) (Version: 3.26.1 - Tim Kosse)
FormApps Signing Extension (HKLM-x32\...\{ACA43D91-8B42-4D42-8C8B-A893BD6AA40D}) (Version: 2.8.2.28 - Software602 a.s.)
Garmin Express (HKLM-x32\...\{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\...\{DA9C865D-6762-4931-8588-0B13B7A0796B}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin USB Drivers (HKLM\...\{DC7720F2-98BE-41C1-B0A8-E391362E86B8}) (Version: 2.3.1.1 - Garmin Ltd or its subsidiaries)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3503 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4248 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1412.3) (HKLM\...\{302600C1-6BDF-4FD1-1401-148929CC1385}) (Version: 17.0.1401.0428 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.3.34 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{6e8d4676-a513-4f5b-9b52-6deb7bdc94f0}) (Version: 16.8.0 - Intel Corporation)
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
KeePass Password Safe 2.38 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.38 - Dominik Reichl)
Kuki (HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\Kuki) (Version: 20160616.000 - SMART Comp. a.s.)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft Office 2016 pro podnikatele - cs-cz (HKLM\...\HomeBusinessRetail - cs-cz) (Version: 16.0.10730.20102 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\OneDriveSetup.exe) (Version: 18.151.0729.0012 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 62.0 (x64 cs) (HKLM\...\Mozilla Firefox 62.0 (x64 cs)) (Version: 62.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 62.0.0.6816 - Mozilla)
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}) (Version: 12.5.00500 - Nero AG)
O2 (HKLM-x32\...\O2CZ) (Version: - O2)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PČS SmartClient (HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\ee485056d1c5a354) (Version: 2.2.8.24 - Pojišťovna České spořitelny)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0003 - Nero AG) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.78.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7209 - Realtek Semiconductor Corp.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.)
Skype verze 8.13 (HKLM-x32\...\Skype_is1) (Version: 8.13 - Skype Technologies S.A.)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.12 - Ghisler Software GmbH)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-06-10] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-06-10] (Alexander Roshal)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-07-11] (Intel Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-06-10] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-06-10] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {015FEE6B-965F-4CD2-8D54-8F425E13F54D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {039317C3-146E-40BB-9635-07EBD1657403} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {04634AFA-C48D-4F13-A1C5-A03F66B6C94E} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {138F9DCF-575E-4F4A-B58F-760204D81E6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {1BFA2634-20F0-40CF-B108-C99C0C1AB5AC} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-03-12] (Acer Incorporate)
Task: {1C0CC246-0F7B-46F0-B6EF-847CDC2848B4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {20BAB122-249D-4F89-B985-9FFA5CBD1F09} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {21294EFE-623A-4DF3-866B-AB883704667E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {25D44F0D-249A-4FD8-87E5-002E2804186D} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {295EA083-66D7-49D6-BB91-8ABC0FFC4EDA} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {2A9887B0-F37D-4169-B88B-F0CF987853AB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {32873E4B-628A-4731-8527-B6C34805477F} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\WINDOWS\system32\gpupdate.exe [2018-04-12] (Microsoft Corporation)
Task: {402C796C-7342-40FC-8D40-244949C94D87} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {403E734B-F397-4C6E-805C-58D16E0C25CA} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {41E007FB-A00C-43FD-BF53-580A3DA6B3E6} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {422E12A4-7128-487A-BE42-F2DB5810E137} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {44434647-BA48-4F05-9C1D-01246DB75BCC} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {48AC3E3F-35AD-4C3A-B0CA-F73E8C854A5C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {52785BBD-BB16-4287-9123-D416EEE62326} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56871B82-CAA9-4BB0-90F2-CC6C0BB3DC0F} - System32\Tasks\{6FE0153C-5C4A-4821-8638-5CD756409D8B} => C:\Windows\system32\pcalua.exe -a C:\Users\petr.kopecny.MSQUATRO\Downloads\KoopP7BNExtern.exe -d C:\Users\petr.kopecny.MSQUATRO\Downloads
Task: {59A94ED6-A2B5-4525-BDFC-FCC35954AC0F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {5C4570FD-DD48-4821-B08A-A33FFBB5F2B5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-09-15] (Microsoft Corporation)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {6773438D-19A4-4E83-B04A-608D098E91E0} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\WINDOWS\system32\gpupdate.exe [2018-04-12] (Microsoft Corporation)
Task: {69324F4E-685E-43EF-8E72-403647B180A5} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6A43A726-D725-47B4-AE94-0882FFD4E5CA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {72D71E87-6364-46AF-AD63-2734F87D019B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-19] (Piriform Ltd)
Task: {74D513B1-DA52-43F5-8FD1-9887A14935A0} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-09-15] (Microsoft Corporation)
Task: {75BB1E3B-DBFB-47B8-8CD6-365045949546} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {75D3F1B8-218E-4817-9E08-9F783F91729C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7625E195-A9D6-4E83-9441-CB904B76AE7F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {828573E3-F205-4843-A269-F01A049297FD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {866D66DE-DEEE-4951-8E16-A46EC0A4684B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {8B88A449-0B19-477C-8375-FE02786F91C5} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8BC8E22E-BEC5-4A35-81E5-07197B80BAB2} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8C1889CA-61FD-4206-B50B-894714D7DF77} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-03-28] ()
Task: {931D79A4-19CF-4E24-BD45-3468DE8250A8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {97239DF1-B99C-46EB-9A0F-E34AA94B3708} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {9BB095E2-7966-405C-A930-9331F75F1014} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-09-15] (Microsoft Corporation)
Task: {A510561A-1539-4499-81AC-954DF6864D7F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)
Task: {A7392A3C-C9EC-4959-B2C4-D4B605897024} - System32\Tasks\Teamviewer-QS-updater-xrkj2nv => C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe [2016-08-08] (TeamViewer GmbH)
Task: {A9C557FD-1811-4B24-9950-F3943EC9B0F9} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {AB6833A8-94D3-4F3F-A8F4-EF9865CA2AAE} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {B435ECFE-52DE-4BEA-87F8-33D389547425} - System32\Tasks\{5E5C22A3-BEA3-4932-9987-890CA37850FD} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Elcomsoft\AOPR\Uninstall.exe" -d "C:\Program Files (x86)\Elcomsoft\AOPR"
Task: {B8024CF1-C859-471C-AEAE-0055C760664A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {B9F686E8-5867-4A30-9CE9-8AF85556457C} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {C0EEB21F-ECAE-42A6-8820-F00BFD7CBC91} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {C33A9601-DEAC-45A4-AAF8-C3CE16BFE6BC} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C713EDFE-D0AB-409A-9239-EFFC7E47341C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C938D901-1632-467B-BB60-61ED890A6122} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D17C4A63-6A08-4185-8BBD-50D1B8A915A7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-09-08] (Microsoft Corporation)
Task: {D2751475-CD5B-403A-9FF0-543996CEEB23} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D3F1192E-D509-42B7-859F-00F4619501E3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-19] (Piriform Ltd)
Task: {D7A54453-B098-45CB-AA38-B297FBA0E646} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DC84F3B1-35C3-4FEE-8772-A260FFF98292} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-09-08] (Microsoft Corporation)
Task: {DEC12249-4054-4FA7-B934-B36AC89950A6} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2016-06-08] (Acer Incorporated)
Task: {DFCDD285-43D2-43EB-B027-30768703D420} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E193A597-44F7-47AA-A062-1BF0EFD066B6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E9C30631-96C0-4CB8-BE63-99FBFA80557C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {EB2A50C8-21DF-485A-A240-4DBB9693A141} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EC349F5A-6FE3-4382-BDC0-7CCADE35D05B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {F7581B14-6699-43B3-91CC-DD34E0306439} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {FBE193BD-A0C8-4F51-A3FD-5C36E028747A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Teamviewer-QS-updater-xrkj2nv.job => C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe*--configuration xrkj2nv --cqsupdate --drepetr.kop

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2016-07-11 15:03 - 2016-07-11 15:03 - 000415128 _____ () C:\WINDOWS\system32\igfxTray.exe
2018-09-12 21:53 - 2018-08-31 05:12 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-07-11 19:18 - 2017-07-11 19:18 - 000076456 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2014-05-23 11:21 - 2013-10-01 11:09 - 000078880 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2018-07-10 23:02 - 2018-06-15 06:41 - 005471232 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
2018-07-10 23:01 - 2018-06-15 06:36 - 000047616 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll
2018-07-10 23:02 - 2018-06-15 06:40 - 005082112 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll
2014-05-23 11:25 - 2013-12-10 01:27 - 001242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-03-16 08:19 - 2018-09-11 19:42 - 001075168 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Acer01.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^Users^petr.kopecny.MSQUATRO^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kooperativa - PDF Server.lnk => C:\Windows\pss\Kooperativa - PDF Server.lnk.Startup
MSCONFIG\startupfolder: C:^Users^petr.kopecny.MSQUATRO^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Odeslat do OneNote.lnk => C:\Windows\pss\Odeslat do OneNote.lnk.Startup

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{C9193898-5D55-4C01-AB94-129626D63521}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [{FBDB37F3-B689-40C9-9F79-82BB705640F3}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [UDP Query User{801B6D7E-2715-40BC-8CAB-7C76B89FCD05}C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe] => (Allow) C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [TCP Query User{AEF556E6-98F8-4344-8FC1-0F7C9179B428}C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe] => (Allow) C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [UDP Query User{755FA9D9-52C6-4EA5-B23F-02979A8CC426}C:\program files (x86)\microsoft\skype for desktop\skype.exe] => (Allow) C:\program files (x86)\microsoft\skype for desktop\skype.exe
FirewallRules: [TCP Query User{8DA7CF1C-7557-4B0F-B471-439AE2FC4D47}C:\program files (x86)\microsoft\skype for desktop\skype.exe] => (Allow) C:\program files (x86)\microsoft\skype for desktop\skype.exe
FirewallRules: [{31657A2C-B62F-44CE-88FA-1343EA1E07D8}] => (Allow) C:\Program Files (x86)\Kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [{AB658FAC-1FB0-4AE4-BAD8-F711CEA78110}] => (Allow) C:\Program Files (x86)\Kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [{277AA902-9724-4E1C-B026-73784E3D7CFE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{8385934A-2944-435A-BE0D-2BB6D96CC4A5}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{D978E42D-B862-44C7-A005-852FB786B34C}] => (Allow) C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{D613EF0B-7927-4C80-A726-51A39DB71DCE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ACEEFEA9-0683-4711-8FE3-098466D9A6B4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{67555717-3B9E-45C5-B45D-B89595F0D2CD}C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe] => (Allow) C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe
FirewallRules: [TCP Query User{882C0982-5BB0-4A73-AE1A-0E7650278DF1}C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe] => (Allow) C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe
FirewallRules: [UDP Query User{4715F08E-6A40-4A1A-AD83-246F90D546DC}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{90151E1E-3BB3-49F1-8A92-BA6AB61CBD8B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0F068683-70CF-48B6-88A9-8074D3A4C744}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{E5BF5977-7A39-4E1D-84E4-C2CF2ED4A2C0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{48F004E7-DAB2-4457-BE05-82C3F7251471}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C32B8EB3-31F6-4F3F-9298-392F3E11A988}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C0A21420-40A6-4BF1-BF2D-D0EB6AFE4E57}] => (Allow) C:\Users\petr.kopecny\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{B4393C7F-03B6-4BD8-AD25-B0A7EB1CCEA7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{2775DAFA-19ED-4FD4-A72D-A4983C61ED9E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{7975B085-C2C0-4BA9-A85B-212E7DF7F161}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{2E63D987-7B7B-4F68-8436-5F84FF2AC0AD}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{5AE65038-5AC0-44C3-9A95-4CF94941E26C}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{5C953BFC-E3F3-49A2-9156-019D99F0869D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{B57A5547-ACC2-4A61-B134-E95B51232DE8}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{15B71BD7-D2F8-46B5-B1CE-1965F6074A5B}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe

==================== Restore Points =========================

12-09-2018 22:10:16 Instalační služba modulů systému Windows
13-09-2018 23:07:10 Instalační služba modulů systému Windows
15-09-2018 11:06:54 Instalační služba modulů systému Windows
16-09-2018 19:06:08 Instalační služba modulů systému Windows
17-09-2018 21:06:40 Instalační služba modulů systému Windows
18-09-2018 23:06:24 Instalační služba modulů systému Windows
20-09-2018 21:06:08 Instalační služba modulů systému Windows
21-09-2018 21:08:18 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/22/2018 10:56:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: esu.exe, verze: 1.0.0.0, časové razítko: 0x58dac8d5
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17134.165, časové razítko: 0xfa43f4b2
Kód výjimky: 0xe0434352
Posun chyby: 0x0010ddc2
ID chybujícího procesu: 0x1d74
Čas spuštění chybující aplikace: 0x01d45252129d58e4
Cesta k chybující aplikaci: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 0d7a11b0-a03c-4bba-ad9d-9f644318c364
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/22/2018 10:56:04 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: esu.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.FileNotFoundException
na Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61.MoveNext()
na System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](<UpdateDatacenterOverridesAsync>d__61 ByRef)
na Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean)
na Garmin.Omt.Service.Shared.Overrides..cctor()

Informace o výjimce: System.TypeInitializationException
na Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl()
na Garmin.Omt.Express.SelfUpdater.Program.RealMain()
na Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (09/21/2018 06:48:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: esu.exe, verze: 1.0.0.0, časové razítko: 0x58dac8d5
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17134.165, časové razítko: 0xfa43f4b2
Kód výjimky: 0xe0434352
Posun chyby: 0x0010ddc2
ID chybujícího procesu: 0x1b04
Čas spuštění chybující aplikace: 0x01d451cad807969f
Cesta k chybující aplikaci: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 1e96ffa1-fb34-440a-aea2-ef74cdd4e1d2
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/21/2018 06:48:07 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: esu.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.FileNotFoundException
na Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61.MoveNext()
na System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](<UpdateDatacenterOverridesAsync>d__61 ByRef)
na Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean)
na Garmin.Omt.Service.Shared.Overrides..cctor()

Informace o výjimce: System.TypeInitializationException
na Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl()
na Garmin.Omt.Express.SelfUpdater.Program.RealMain()
na Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (09/20/2018 07:24:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: esu.exe, verze: 1.0.0.0, časové razítko: 0x58dac8d5
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17134.165, časové razítko: 0xfa43f4b2
Kód výjimky: 0xe0434352
Posun chyby: 0x0010ddc2
ID chybujícího procesu: 0x17d4
Čas spuštění chybující aplikace: 0x01d45106baaafcf6
Cesta k chybující aplikaci: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 875cdf1b-00f6-472a-b12c-1a4e47a56429
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/20/2018 07:24:14 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: esu.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.FileNotFoundException
na Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61.MoveNext()
na System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+<UpdateDatacenterOverridesAsync>d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](<UpdateDatacenterOverridesAsync>d__61 ByRef)
na Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean)
na Garmin.Omt.Service.Shared.Overrides..cctor()

Informace o výjimce: System.TypeInitializationException
na Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl()
na Garmin.Omt.Express.SelfUpdater.Program.RealMain()
na Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (09/19/2018 07:34:49 PM) (Source: Outlook) (EventID: 35) (User: )
Description: Nelze určit, zda se zásobník nachází v oboru procházení (chyba=0x8007045b).

Error: (09/19/2018 07:34:49 PM) (Source: Outlook) (EventID: 34) (User: )
Description: Nepodařilo se získat správce oboru procházení. Chyba=0x8007045b.


System errors:
=============
Error: (09/22/2018 11:26:03 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/22/2018 10:55:58 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: MSQUATRO)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/22/2018 10:55:48 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/22/2018 10:55:43 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: MSQUATRO)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/22/2018 10:55:43 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/22/2018 10:52:44 AM) (Source: NETLOGON) (EventID: 5719) (User: )
Description: Tento počítač nemohl nastavit zabezpečenou relaci s řadičem
domény v doméně MSQUATRO z následujícího důvodu:
Nemůžeme vás přihlásit s těmito přihlašovacími údaji, protože vaše doména není k dispozici. Ujistěte se, že je vaše zařízení připojeno k vaší podnikové síti, a zkuste to znovu. Pokud jste se na tomto zařízení dříve přihlásili s jinými přihlašovacími údaji, můžete se přihlásit s jejich pomocí.


To může vést k potížím při ověřování. Přesvědčte se, zda je tento
počítač připojen k síti. Pokud potíže trvají,
obraťte se na správce domény.



DALŠÍ INFORMACE

Pokud je tento počítač řadičem domény pro určenou doménu,
nastaví zabezpečenou relaci s emulátorem primárního řadiče domény v určené
doméně. V opačném případě tento počítač nastaví zabezpečenou relaci s libovolným řadičem domény
v určené doméně.

Error: (09/22/2018 01:36:03 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/22/2018 01:07:59 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: MSQUATRO)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.


Windows Defender:
===================================
Date: 2018-08-21 10:47:03.468
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {E2EFFFC1-B137-4882-BABA-AF71F2D1F8C6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-08 22:27:32.185
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {1812355A-3A7E-42CB-8F81-C95FBAD2518E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-07-06 11:12:10.651
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {DA53A880-CE39-4976-A861-9E6BF8AFB0ED}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-06-12 21:17:10.358
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {E09FB522-45C3-4347-AC08-181A9D094848}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-06-12 21:10:24.618
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {408C9A52-F9D5-4124-B0D6-E7D77E0B2C56}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-22 18:39:34.682
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1826.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80240016
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-08-22 10:05:37.049
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1749.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-08-21 10:19:54.505
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1749.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-08-20 09:48:41.555
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1702.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.

Date: 2018-08-20 09:48:41.554
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1702.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz
Percentage of memory in use: 80%
Total physical RAM: 3987.27 MB
Available physical RAM: 778.43 MB
Total Virtual: 8835.74 MB
Available Virtual: 1771.82 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:218.85 GB) (Free:130.21 GB) NTFS
Drive d: (DATA) (Fixed) (Total:218.85 GB) (Free:59.05 GB) NTFS

\\?\Volume{c62f4623-e44c-4170-be50-a3004eeaebf8}\ (Recovery) (Fixed) (Total:0.59 GB) (Free:0.31 GB) NTFS
\\?\Volume{01973d99-228c-44b8-98df-789accaa4bb2}\ (Push Button Reset) (Fixed) (Total:27.06 GB) (Free:2.62 GB) NTFS
\\?\Volume{225254fe-4c05-40b0-85e1-cc0906d9a1d8}\ (ESP) (Fixed) (Total:0.29 GB) (Free:0.24 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: A7C0CE7C)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Prosím o kontrolu. Děkuji

Napsal: 23 zář 2018 02:27
od Conder
Ahoj :)

:arrow: Su tam nejake zbytky po McAfee, ten si odinstaloval?

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
  • Nechaj zaskrtnute vsetky nalezy
  • Klikni na Cisteni a opravy (Clean and Repair) a potvrd restart PC teraz
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah sem skopiruj

Re: Prosím o kontrolu. Děkuji

Napsal: 23 zář 2018 09:30
od vrchlab
Ahoj,
McAfee by doufám měl být odinstalován. Požadovaný log přikládám:


# -------------------------------
# Malwarebytes AdwCleaner 7.2.3.1
# -------------------------------
# Build: 09-03-2018
# Database: (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-23-2018
# Duration: 00:00:04
# OS: Windows 10 Pro
# Cleaned: 1
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1340 octets] - [23/09/2018 09:47:24]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Prosím o kontrolu. Děkuji

Napsal: 23 zář 2018 21:34
od Conder
:arrow: Poprosim o obidva nove logy z FRST.

Re: Prosím o kontrolu. Děkuji

Napsal: 23 zář 2018 22:35
od vrchlab
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23.09.2018
Ran by petr.kopecny (administrator) on INVESTICE02 (23-09-2018 23:25:56)
Running from C:\Users\petr.kopecny.MSQUATRO\Downloads
Loaded Profiles: petr.kopecny (Available Profiles: petr.kopecny & petr.kopecny & Administrator & DefaultAppPool)
Platform: Windows 10 Pro Version 1803 17134.285 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(ESET) C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1807.18075-0\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\internet explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [415128 2016-07-11] ()
HKLM\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184632 2013-11-14] (Motorola Solutions, Inc.)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-08] (Acer Incorporated)
HKLM\...\Run: [ALU] => C:\Program Files\Acer\Acer Updater\ALU.exe [2379056 2017-04-21] (Acer Incorporated)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3237808 2018-01-09] (Dominik Reichl)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries)
Startup: C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Poslat do aplikace OneNote.lnk [2018-02-16]
ShortcutTarget: Poslat do aplikace OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1F160B83-A94E-4E9D-8350-E9581BEB162E}: [DhcpNameServer] 192.168.1.22 192.168.1.5
Tcpip\..\Interfaces\{25cfe3ba-35be-4348-922b-92cd6f407bd2}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6195e00b-5162-47c6-9fde-413d8051bdac}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://msq.msquatro.cz/
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://obchod.msquatro.cz/
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-09-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-07-23] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-07-23] (Oracle Corporation)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxps://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1474031863011
DPF: HKLM-x32 {F680B28A-3AEE-4C88-93ED-45AE9215C128} hxxps://adisepo.mfcr.cz/adistc/adis/idpr_pub/xspa/bin/cryptsignx.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-09-11] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\Mozilla\Firefox\Profiles\h2eaaugm.default [2018-09-23]
FF Homepage: Mozilla\Firefox\Profiles\h2eaaugm.default -> about:home
FF Session Restore: Mozilla\Firefox\Profiles\h2eaaugm.default -> is enabled.
FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-11] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-11] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-07-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-07-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-09-11] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default [2018-09-22]
CHR Extension: (Slides) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-03]
CHR Extension: (Docs) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-03]
CHR Extension: (Google Drive) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-03]
CHR Extension: (YouTube) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-03]
CHR Extension: (Sheets) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-03]
CHR Extension: (Google Docs Offline) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-03]
CHR Extension: (Gmail) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-03]
CHR Extension: (Chrome Media Router) - C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-03]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9658664 2018-09-08] (Microsoft Corporation)
R2 EraAgentSvc; C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe [1605832 2015-08-22] (ESET)
S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin Ltd. or its subsidiaries)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [184064 2016-12-12] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [370064 2016-07-11] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [445696 2014-03-12] (Acer Incorporate)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\NisSrv.exe [3905952 2018-07-31] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MsMpEng.exe [110944 2018-07-31] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230656 2016-12-12] (Intel Corporation)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
S3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
R3 Microsoft_Bluetooth_AvrcpTransport; C:\WINDOWS\system32\DRIVERS\Microsoft.Bluetooth.AvrcpTransport.sys [46592 2018-04-12] (Microsoft Corporation)
R1 MpKsle221ebf7; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59CD83D7-DD8B-4260-96B6-22BA61CDFED1}\MpKsle221ebf7.sys [58120 2018-09-23] (Microsoft Corporation)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2018-04-12] (Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [751632 2016-08-30] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-01-24] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46584 2018-07-31] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-07-31] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-07-31] (Microsoft Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-23 23:28 - 2018-09-23 23:28 - 008961654 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\20150514 0320 - Kino Barrandov - Emanuela_ Soukromá sbírka (5) ; emmanuelle vs. dracula.mkv.part
2018-09-23 23:28 - 2018-09-23 23:28 - 000000000 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\20150514 0320 - Kino Barrandov - Emanuela_ Soukromá sbírka (5) ; emmanuelle vs. dracula.mkv
2018-09-23 23:25 - 2018-09-23 23:25 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST-OlderVersion
2018-09-23 09:44 - 2018-09-23 10:18 - 000000000 ____D C:\AdwCleaner
2018-09-23 09:44 - 2018-09-23 09:44 - 007571152 _____ (Malwarebytes) C:\Users\petr.kopecny.MSQUATRO\Downloads\adwcleaner_7.2.3.1.exe
2018-09-22 11:51 - 2018-09-22 11:52 - 000047528 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\Addition.txt
2018-09-22 11:49 - 2018-09-23 23:27 - 000017210 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST.txt
2018-09-22 11:45 - 2018-09-23 23:25 - 000000000 ____D C:\FRST
2018-09-22 11:44 - 2018-09-23 23:25 - 002414080 _____ (Farbar) C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST64.exe
2018-09-22 11:13 - 2018-09-22 11:13 - 016796856 _____ (Piriform Ltd) C:\Users\petr.kopecny.MSQUATRO\Downloads\ccsetup547.exe
2018-09-22 11:13 - 2018-09-22 11:13 - 016796856 _____ (Piriform Ltd) C:\Users\petr.kopecny.MSQUATRO\Downloads\ccsetup547(1).exe
2018-09-19 20:22 - 2018-09-19 20:22 - 000000000 ___HD C:\OneDriveTemp
2018-09-19 19:34 - 2018-09-19 19:34 - 000002563 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002557 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002534 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002529 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-09-19 19:34 - 2018-09-19 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office
2018-09-12 21:53 - 2018-08-31 09:43 - 001524152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2018-09-12 21:53 - 2018-08-31 09:42 - 001636232 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-09-12 21:53 - 2018-08-31 09:24 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2018-09-12 21:53 - 2018-08-31 09:23 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-09-12 21:53 - 2018-08-31 09:23 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2018-09-12 21:53 - 2018-08-31 09:22 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-09-12 21:53 - 2018-08-31 09:22 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-09-12 21:53 - 2018-08-31 08:55 - 001455960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-09-12 21:53 - 2018-08-31 08:53 - 001327504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2018-09-12 21:53 - 2018-08-31 08:36 - 001469952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-09-12 21:53 - 2018-08-31 05:44 - 001222440 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-09-12 21:53 - 2018-08-31 05:44 - 001030952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-09-12 21:53 - 2018-08-31 05:43 - 002719216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-09-12 21:53 - 2018-08-31 05:43 - 000722880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 009090016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-09-12 21:53 - 2018-08-31 05:42 - 007520064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 007436192 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 002824672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-09-12 21:53 - 2018-08-31 05:42 - 002461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 001767064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 001458552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-09-12 21:53 - 2018-08-31 05:42 - 001258352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-09-12 21:53 - 2018-08-31 05:42 - 001142000 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-09-12 21:53 - 2018-08-31 05:42 - 001097720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-09-12 21:53 - 2018-08-31 05:42 - 000632296 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpx.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 006570040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 006043680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 001989496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 001514352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 001129728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-09-12 21:53 - 2018-08-31 05:28 - 000453104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpx.dll
2018-09-12 21:53 - 2018-08-31 05:26 - 025847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-09-12 21:53 - 2018-08-31 05:21 - 022008320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-09-12 21:53 - 2018-08-31 05:20 - 022715904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-09-12 21:53 - 2018-08-31 05:18 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-09-12 21:53 - 2018-08-31 05:16 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-09-12 21:53 - 2018-08-31 05:16 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-09-12 21:53 - 2018-08-31 05:16 - 004382720 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 007577088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 004866560 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-09-12 21:53 - 2018-08-31 05:15 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-09-12 21:53 - 2018-08-31 05:14 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-09-12 21:53 - 2018-08-31 05:14 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-09-12 21:53 - 2018-08-31 05:13 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-09-12 21:53 - 2018-08-31 05:11 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-09-12 21:53 - 2018-08-31 05:11 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-09-12 21:53 - 2018-08-31 05:11 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-09-12 21:53 - 2018-08-31 05:11 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-09-12 21:53 - 2018-08-31 05:11 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 005777920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 003711488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 001375744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-09-12 21:53 - 2018-08-31 05:10 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-09-12 21:53 - 2018-08-31 05:09 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2018-09-12 21:53 - 2018-08-31 05:07 - 001627648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-09-12 21:53 - 2018-08-28 09:17 - 023862784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-09-12 21:53 - 2018-08-28 08:48 - 001274368 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-09-12 21:53 - 2018-08-28 08:45 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2018-09-12 21:53 - 2018-08-09 11:37 - 002267944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2018-09-12 21:53 - 2018-08-09 11:32 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-09-12 21:53 - 2018-08-09 11:31 - 001617728 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2018-09-12 21:53 - 2018-08-09 11:16 - 004491264 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-09-12 21:53 - 2018-08-09 11:14 - 012709376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-09-12 21:53 - 2018-08-09 11:13 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-09-12 21:53 - 2018-08-09 11:12 - 001787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-09-12 21:53 - 2018-08-09 11:11 - 003652608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-09-12 21:53 - 2018-08-09 11:11 - 002051584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-09-12 21:53 - 2018-08-09 11:11 - 001004032 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-09-12 21:53 - 2018-08-09 11:10 - 001557504 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2018-09-12 21:53 - 2018-08-09 10:38 - 001538976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2018-09-12 21:53 - 2018-08-09 10:24 - 011901952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-09-12 21:53 - 2018-08-09 10:23 - 003397632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-09-12 21:53 - 2018-08-09 10:21 - 002894848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-09-12 21:53 - 2018-08-09 10:20 - 002401792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-09-12 21:53 - 2018-08-09 07:02 - 001035144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-09-12 21:53 - 2018-08-09 07:01 - 000777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2018-09-12 21:53 - 2018-08-09 06:54 - 001019016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-09-12 21:53 - 2018-08-09 06:53 - 002765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-09-12 21:53 - 2018-08-09 06:53 - 001947720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-09-12 21:53 - 2018-08-09 06:53 - 000932136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-09-12 21:53 - 2018-08-09 06:53 - 000482480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-09-12 21:53 - 2018-08-09 06:30 - 000829856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-09-12 21:53 - 2018-08-09 06:29 - 002253584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-09-12 21:53 - 2018-08-09 06:29 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-09-12 21:53 - 2018-08-09 06:29 - 001174552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-09-12 21:53 - 2018-08-09 06:28 - 003395072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-09-12 21:53 - 2018-08-09 06:28 - 001589248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2018-09-12 21:53 - 2018-08-09 06:25 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-09-12 21:53 - 2018-08-09 06:25 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-09-12 21:53 - 2018-08-09 06:24 - 002368512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 003148288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 002904064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-09-12 21:53 - 2018-08-09 06:23 - 000916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-09-12 21:53 - 2018-08-09 06:22 - 004615680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-09-12 21:53 - 2018-08-09 06:22 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-09-12 21:53 - 2018-08-09 06:21 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-09-12 21:53 - 2018-08-09 06:13 - 001189376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2018-09-12 21:53 - 2018-08-09 06:11 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-09-12 21:53 - 2018-08-09 06:10 - 002893824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2018-09-12 21:53 - 2018-08-09 06:10 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-09-12 21:53 - 2018-08-09 06:09 - 004191232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-09-12 21:52 - 2018-08-31 09:46 - 000542504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-09-12 21:52 - 2018-08-31 09:45 - 000348328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-09-12 21:52 - 2018-08-31 09:27 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2018-09-12 21:52 - 2018-08-31 09:27 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2018-09-12 21:52 - 2018-08-31 09:26 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bowser.sys
2018-09-12 21:52 - 2018-08-31 09:25 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\spp.dll
2018-09-12 21:52 - 2018-08-31 09:25 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe
2018-09-12 21:52 - 2018-08-31 09:24 - 000482304 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2018-09-12 21:52 - 2018-08-31 09:24 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-09-12 21:52 - 2018-08-31 08:41 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2018-09-12 21:52 - 2018-08-31 08:41 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2018-09-12 21:52 - 2018-08-31 08:40 - 000216576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spp.dll
2018-09-12 21:52 - 2018-08-31 08:37 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-09-12 21:52 - 2018-08-31 08:37 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2018-09-12 21:52 - 2018-08-31 08:37 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-09-12 21:52 - 2018-08-31 05:50 - 000273720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-09-12 21:52 - 2018-08-31 05:50 - 000270648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-09-12 21:52 - 2018-08-31 05:44 - 001064744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-09-12 21:52 - 2018-08-31 05:44 - 000568600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-09-12 21:52 - 2018-08-31 05:44 - 000136488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-09-12 21:52 - 2018-08-31 05:44 - 000076256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-09-12 21:52 - 2018-08-31 05:42 - 000983080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-09-12 21:52 - 2018-08-31 05:42 - 000885928 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-09-12 21:52 - 2018-08-31 05:42 - 000604640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-09-12 21:52 - 2018-08-31 05:42 - 000527328 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-09-12 21:52 - 2018-08-31 05:42 - 000494472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2018-09-12 21:52 - 2018-08-31 05:42 - 000155112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2018-09-12 21:52 - 2018-08-31 05:28 - 000568568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-09-12 21:52 - 2018-08-31 05:28 - 000134936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2018-09-12 21:52 - 2018-08-31 05:17 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-09-12 21:52 - 2018-08-31 05:17 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\netevent.dll
2018-09-12 21:52 - 2018-08-31 05:15 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2018-09-12 21:52 - 2018-08-31 05:15 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-09-12 21:52 - 2018-08-31 05:14 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-09-12 21:52 - 2018-08-31 05:14 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-09-12 21:52 - 2018-08-31 05:14 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-09-12 21:52 - 2018-08-31 05:13 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-09-12 21:52 - 2018-08-31 05:13 - 000402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-09-12 21:52 - 2018-08-31 05:12 - 000736256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-09-12 21:52 - 2018-08-31 05:12 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netevent.dll
2018-09-12 21:52 - 2018-08-31 05:11 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-09-12 21:52 - 2018-08-31 05:11 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-09-12 21:52 - 2018-08-31 05:10 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-09-12 21:52 - 2018-08-31 05:10 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2018-09-12 21:52 - 2018-08-31 05:09 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-09-12 21:52 - 2018-08-31 05:08 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-09-12 21:52 - 2018-08-31 05:07 - 000856064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2018-09-12 21:52 - 2018-08-31 05:07 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2018-09-12 21:52 - 2018-08-31 05:06 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2018-09-12 21:52 - 2018-08-31 03:57 - 000001308 _____ C:\WINDOWS\system32\tcbres.wim
2018-09-12 21:52 - 2018-08-28 08:56 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-09-12 21:52 - 2018-08-28 08:49 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-09-12 21:52 - 2018-08-28 07:51 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-09-12 21:52 - 2018-08-14 04:14 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2018-09-12 21:52 - 2018-08-14 04:14 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-09-12 21:52 - 2018-08-09 11:31 - 000766872 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-09-12 21:52 - 2018-08-09 11:31 - 000253544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2018-09-12 21:52 - 2018-08-09 11:31 - 000236624 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2018-09-12 21:52 - 2018-08-09 11:17 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-09-12 21:52 - 2018-08-09 11:14 - 000466944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2018-09-12 21:52 - 2018-08-09 11:14 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollUI.dll
2018-09-12 21:52 - 2018-08-09 11:14 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdeploy.dll
2018-09-12 21:52 - 2018-08-09 11:13 - 000521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2018-09-12 21:52 - 2018-08-09 11:13 - 000517120 _____ (Microsoft Corporation) C:\WINDOWS\system32\certreq.exe
2018-09-12 21:52 - 2018-08-09 11:13 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsExt.dll
2018-09-12 21:52 - 2018-08-09 11:12 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-09-12 21:52 - 2018-08-09 11:12 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-09-12 21:52 - 2018-08-09 11:11 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-09-12 21:52 - 2018-08-09 11:11 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2018-09-12 21:52 - 2018-08-09 11:10 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2018-09-12 21:52 - 2018-08-09 11:10 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-09-12 21:52 - 2018-08-09 11:09 - 000217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput8.dll
2018-09-12 21:52 - 2018-08-09 11:09 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dinput.dll
2018-09-12 21:52 - 2018-08-09 11:09 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-09-12 21:52 - 2018-08-09 11:09 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageInspector.exe
2018-09-12 21:52 - 2018-08-09 10:36 - 000660896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-09-12 21:52 - 2018-08-09 10:36 - 000221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2018-09-12 21:52 - 2018-08-09 10:24 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdeploy.dll
2018-09-12 21:52 - 2018-08-09 10:23 - 001308160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-09-12 21:52 - 2018-08-09 10:23 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollUI.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-09-12 21:52 - 2018-08-09 10:22 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2018-09-12 21:52 - 2018-08-09 10:21 - 002016768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-09-12 21:52 - 2018-08-09 10:21 - 001274368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2018-09-12 21:52 - 2018-08-09 10:21 - 000775168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-09-12 21:52 - 2018-08-09 10:20 - 000423424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2018-09-12 21:52 - 2018-08-09 10:20 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput8.dll
2018-09-12 21:52 - 2018-08-09 10:20 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dinput.dll
2018-09-12 21:52 - 2018-08-09 10:19 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-09-12 21:52 - 2018-08-09 06:55 - 000230304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2018-09-12 21:52 - 2018-08-09 06:54 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-09-12 21:52 - 2018-08-09 06:54 - 000375704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-09-12 21:52 - 2018-08-09 06:54 - 000203568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2018-09-12 21:52 - 2018-08-09 06:54 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-09-12 21:52 - 2018-08-09 06:53 - 001026456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-09-12 21:52 - 2018-08-09 06:53 - 000714792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-09-12 21:52 - 2018-08-09 06:53 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-09-12 21:52 - 2018-08-09 06:53 - 000125600 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptxml.dll
2018-09-12 21:52 - 2018-08-09 06:30 - 000183992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2018-09-12 21:52 - 2018-08-09 06:29 - 000581696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2018-09-12 21:52 - 2018-08-09 06:29 - 000099208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptxml.dll
2018-09-12 21:52 - 2018-08-09 06:27 - 000428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-09-12 21:52 - 2018-08-09 06:27 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\eShims.dll
2018-09-12 21:52 - 2018-08-09 06:27 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2018-09-12 21:52 - 2018-08-09 06:26 - 000990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2018-09-12 21:52 - 2018-08-09 06:26 - 000572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2018-09-12 21:52 - 2018-08-09 06:26 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2018-09-12 21:52 - 2018-08-09 06:26 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-09-12 21:52 - 2018-08-09 06:26 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsAuth.dll
2018-09-12 21:52 - 2018-08-09 06:26 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TtlsCfg.dll
2018-09-12 21:52 - 2018-08-09 06:26 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000797184 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2018-09-12 21:52 - 2018-08-09 06:25 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2018-09-12 21:52 - 2018-08-09 06:24 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-09-12 21:52 - 2018-08-09 06:22 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-09-12 21:52 - 2018-08-09 06:22 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\GlobCollationHost.dll
2018-09-12 21:52 - 2018-08-09 06:13 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2018-09-12 21:52 - 2018-08-09 06:12 - 000652288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsAuth.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TtlsCfg.dll
2018-09-12 21:52 - 2018-08-09 06:11 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2018-09-12 21:52 - 2018-08-09 06:10 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-09-12 21:52 - 2018-08-09 06:09 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-09-12 21:52 - 2018-08-09 06:08 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GlobCollationHost.dll
2018-09-12 21:52 - 2018-08-09 05:08 - 000806416 _____ C:\WINDOWS\SysWOW64\locale.nls
2018-09-12 21:52 - 2018-08-09 05:08 - 000806416 _____ C:\WINDOWS\system32\locale.nls
2018-09-02 12:32 - 2018-09-02 20:28 - 4243487457 _____ C:\Users\petr.kopecny.MSQUATRO\Downloads\53 - Ve stínu (1953).mkv
2018-08-27 23:26 - 2018-08-27 23:26 - 000675984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000457512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000386712 _____ (Microsoft Corporation) C:\WINDOWS\system32\vccorlib140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000343192 _____ (Microsoft Corporation) C:\WINDOWS\system32\concrt140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000274072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vccorlib140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000248624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\concrt140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000089248 _____ (Microsoft Corporation) C:\WINDOWS\system32\vcruntime140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000087352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vcruntime140.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000031896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140_1.dll
2018-08-27 23:26 - 2018-08-27 23:26 - 000028472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140_1.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-09-23 23:27 - 2014-12-10 11:36 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\Documents\Soubory aplikace Outlook
2018-09-23 23:25 - 2015-02-15 20:39 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\vlc
2018-09-23 23:23 - 2014-08-05 22:01 - 000000000 ____D C:\Users\petr.kopecny\Documents\Soubory aplikace Outlook
2018-09-23 23:19 - 2018-05-22 21:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-09-23 22:19 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-09-23 10:27 - 2018-05-22 21:49 - 001956628 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-09-23 10:27 - 2018-04-12 17:51 - 000809600 _____ C:\WINDOWS\system32\perfh005.dat
2018-09-23 10:27 - 2018-04-12 17:51 - 000186808 _____ C:\WINDOWS\system32\perfc005.dat
2018-09-23 10:27 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2018-09-23 10:23 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-09-23 10:23 - 2016-11-18 07:50 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\AppData\LocalLow\Mozilla
2018-09-23 10:22 - 2014-12-12 00:10 - 000000000 ___RD C:\Users\petr.kopecny.MSQUATRO\OneDrive
2018-09-23 10:21 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-09-23 10:21 - 2017-04-20 14:00 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-09-23 10:21 - 2016-09-10 01:50 - 000000000 __SHD C:\Users\petr.kopecny\IntelGraphicsProfiles
2018-09-23 10:19 - 2018-05-22 22:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-09-23 10:19 - 2018-04-11 23:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-09-23 10:19 - 2016-12-14 10:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-09-23 10:19 - 2014-07-30 08:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-09-23 09:45 - 2015-01-05 23:21 - 000006056 _____ C:\WINDOWS\wininit.ini
2018-09-23 09:45 - 2014-07-30 08:28 - 000001167 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-09-23 09:43 - 2018-05-22 22:23 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-09-23 09:43 - 2015-07-15 09:16 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-09-22 11:14 - 2018-05-22 22:23 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-09-22 11:14 - 2017-05-31 10:15 - 000000867 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-09-21 23:14 - 2018-04-12 01:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-09-20 20:37 - 2017-12-17 15:14 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Packages
2018-09-19 20:22 - 2018-05-22 22:23 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2852774663-3114243248-3625044681-2121
2018-09-19 20:22 - 2018-05-22 21:54 - 000002484 _____ C:\Users\petr.kopecny.MSQUATRO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-09-19 19:32 - 2014-05-23 11:48 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-09-12 23:06 - 2018-05-22 21:44 - 000280608 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-09-12 23:03 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-09-12 23:03 - 2018-04-11 23:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-09-11 19:57 - 2014-08-06 11:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-09-11 19:54 - 2014-08-06 11:07 - 139184408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-09-11 19:28 - 2018-05-22 22:23 - 000004654 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-09-11 19:28 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-09-11 19:28 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-09-11 19:28 - 2017-05-31 10:15 - 000000000 ____D C:\Program Files\CCleaner
2018-09-05 01:04 - 2018-08-23 22:10 - 000835144 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-09-05 01:04 - 2018-08-23 22:10 - 000179808 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-09-01 13:15 - 2015-03-19 16:53 - 000000000 ____D C:\QPlán
2018-09-01 13:14 - 2015-04-01 08:40 - 000000679 _____ C:\Users\petr.kopecny.MSQUATRO\Desktop\QKalkulátor.lnk
2018-09-01 13:14 - 2015-04-01 08:40 - 000000625 _____ C:\Users\petr.kopecny.MSQUATRO\Desktop\QPlán Výstupy.lnk
2018-09-01 13:12 - 2015-04-01 08:42 - 000000654 _____ C:\Users\petr.kopecny.MSQUATRO\Desktop\QRenta.lnk

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-22 21:44

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23.09.2018
Ran by petr.kopecny (23-09-2018 23:29:17)
Running from C:\Users\petr.kopecny.MSQUATRO\Downloads
Windows 10 Pro Version 1803 17134.285 (X64) (2018-05-22 20:24:51)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3251029710-3280901918-1644894361-500 - Administrator - Enabled) => C:\Users\Administrator.INVESTICE02
DefaultAccount (S-1-5-21-3251029710-3280901918-1644894361-503 - Limited - Disabled)
Guest (S-1-5-21-3251029710-3280901918-1644894361-501 - Limited - Disabled)
petr.kopecny (S-1-5-21-3251029710-3280901918-1644894361-1000 - Limited - Enabled) => C:\Users\petr.kopecny
WDAGUtilityAccount (S-1-5-21-3251029710-3280901918-1644894361-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.01.3509 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{F0D9378C-CFA3-4503-A562-5350BE6E05C2}) (Version: 7.00.3004 - Acer Incorporated)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20063 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Advanced Office Password Recovery (remove only) (HKLM-x32\...\Advanced Office Password Recovery) (Version: 4.11 - Elcomsoft Co.Ltd.)
ANT Drivers Installer x64 (HKLM\...\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
calibre 64bit (HKLM\...\{1428EEEC-F3E9-407A-A60E-2E51CF66ED80}) (Version: 2.20.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 5.47 - Piriform)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3323.57 - CyberLink Corp.)
ČSOBP Kalkulátory 1.15.3.x (OED B) (HKLM-x32\...\Kalkulátory_is1) (Version: - )
Elevated Installer (HKLM-x32\...\{1052502B-4C91-43F9-B160-AE39ED57C9F0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
ESET Remote Administrator Agent (HKLM\...\{7AC14666-285C-4019-9351-AD4E2F4BA9E8}) (Version: 6.2.171.0 - ESET, spol. s r.o.)
Evernote v. 4.5.2 (HKLM-x32\...\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
FileZilla Client 3.26.1 (HKLM-x32\...\FileZilla Client) (Version: 3.26.1 - Tim Kosse)
FormApps Signing Extension (HKLM-x32\...\{ACA43D91-8B42-4D42-8C8B-A893BD6AA40D}) (Version: 2.8.2.28 - Software602 a.s.)
Garmin Express (HKLM-x32\...\{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\...\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\...\{DA9C865D-6762-4931-8588-0B13B7A0796B}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin USB Drivers (HKLM\...\{DC7720F2-98BE-41C1-B0A8-E391362E86B8}) (Version: 2.3.1.1 - Garmin Ltd or its subsidiaries)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3503 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4248 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1412.3) (HKLM\...\{302600C1-6BDF-4FD1-1401-148929CC1385}) (Version: 17.0.1401.0428 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.3.34 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{6e8d4676-a513-4f5b-9b52-6deb7bdc94f0}) (Version: 16.8.0 - Intel Corporation)
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
KeePass Password Safe 2.38 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.38 - Dominik Reichl)
Kuki (HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\Kuki) (Version: 20160616.000 - SMART Comp. a.s.)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft Office 2016 pro podnikatele - cs-cz (HKLM\...\HomeBusinessRetail - cs-cz) (Version: 16.0.10730.20102 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\OneDriveSetup.exe) (Version: 18.151.0729.0012 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 62.0.2 (x64 cs) (HKLM\...\Mozilla Firefox 62.0.2 (x64 cs)) (Version: 62.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 62.0.2.6837 - Mozilla)
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}) (Version: 12.5.00500 - Nero AG)
O2 (HKLM-x32\...\O2CZ) (Version: - O2)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0405-0000-0000000FF1CE}) (Version: 16.0.10730.20102 - Microsoft Corporation) Hidden
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
PČS SmartClient (HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\...\ee485056d1c5a354) (Version: 2.2.8.24 - Pojišťovna České spořitelny)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0003 - Nero AG) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.78.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7209 - Realtek Semiconductor Corp.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.)
Skype verze 8.13 (HKLM-x32\...\Skype_is1) (Version: 8.13 - Skype Technologies S.A.)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.12 - Ghisler Software GmbH)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-06-10] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-06-10] (Alexander Roshal)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-07-11] (Intel Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-06-10] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-06-10] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {015FEE6B-965F-4CD2-8D54-8F425E13F54D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {039317C3-146E-40BB-9635-07EBD1657403} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {04634AFA-C48D-4F13-A1C5-A03F66B6C94E} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {138F9DCF-575E-4F4A-B58F-760204D81E6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {1BFA2634-20F0-40CF-B108-C99C0C1AB5AC} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-03-12] (Acer Incorporate)
Task: {1C0CC246-0F7B-46F0-B6EF-847CDC2848B4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {20BAB122-249D-4F89-B985-9FFA5CBD1F09} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {21294EFE-623A-4DF3-866B-AB883704667E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {25D44F0D-249A-4FD8-87E5-002E2804186D} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {295EA083-66D7-49D6-BB91-8ABC0FFC4EDA} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {2A9887B0-F37D-4169-B88B-F0CF987853AB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {32873E4B-628A-4731-8527-B6C34805477F} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\WINDOWS\system32\gpupdate.exe [2018-04-12] (Microsoft Corporation)
Task: {402C796C-7342-40FC-8D40-244949C94D87} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {403E734B-F397-4C6E-805C-58D16E0C25CA} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {41E007FB-A00C-43FD-BF53-580A3DA6B3E6} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {422E12A4-7128-487A-BE42-F2DB5810E137} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {44434647-BA48-4F05-9C1D-01246DB75BCC} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {48AC3E3F-35AD-4C3A-B0CA-F73E8C854A5C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {52785BBD-BB16-4287-9123-D416EEE62326} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56871B82-CAA9-4BB0-90F2-CC6C0BB3DC0F} - System32\Tasks\{6FE0153C-5C4A-4821-8638-5CD756409D8B} => C:\Windows\system32\pcalua.exe -a C:\Users\petr.kopecny.MSQUATRO\Downloads\KoopP7BNExtern.exe -d C:\Users\petr.kopecny.MSQUATRO\Downloads
Task: {59A94ED6-A2B5-4525-BDFC-FCC35954AC0F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {5C4570FD-DD48-4821-B08A-A33FFBB5F2B5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-09-15] (Microsoft Corporation)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {6773438D-19A4-4E83-B04A-608D098E91E0} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\WINDOWS\system32\gpupdate.exe [2018-04-12] (Microsoft Corporation)
Task: {69324F4E-685E-43EF-8E72-403647B180A5} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6A43A726-D725-47B4-AE94-0882FFD4E5CA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {72D71E87-6364-46AF-AD63-2734F87D019B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-19] (Piriform Ltd)
Task: {74D513B1-DA52-43F5-8FD1-9887A14935A0} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-09-15] (Microsoft Corporation)
Task: {75BB1E3B-DBFB-47B8-8CD6-365045949546} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {75D3F1B8-218E-4817-9E08-9F783F91729C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7625E195-A9D6-4E83-9441-CB904B76AE7F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {828573E3-F205-4843-A269-F01A049297FD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {866D66DE-DEEE-4951-8E16-A46EC0A4684B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {8B88A449-0B19-477C-8375-FE02786F91C5} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8BC8E22E-BEC5-4A35-81E5-07197B80BAB2} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8C1889CA-61FD-4206-B50B-894714D7DF77} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-03-28] ()
Task: {931D79A4-19CF-4E24-BD45-3468DE8250A8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {97239DF1-B99C-46EB-9A0F-E34AA94B3708} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {9BB095E2-7966-405C-A930-9331F75F1014} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-09-15] (Microsoft Corporation)
Task: {A7392A3C-C9EC-4959-B2C4-D4B605897024} - System32\Tasks\Teamviewer-QS-updater-xrkj2nv => C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe [2016-08-08] (TeamViewer GmbH)
Task: {A9C557FD-1811-4B24-9950-F3943EC9B0F9} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {AB6833A8-94D3-4F3F-A8F4-EF9865CA2AAE} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {B435ECFE-52DE-4BEA-87F8-33D389547425} - System32\Tasks\{5E5C22A3-BEA3-4932-9987-890CA37850FD} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Elcomsoft\AOPR\Uninstall.exe" -d "C:\Program Files (x86)\Elcomsoft\AOPR"
Task: {B8024CF1-C859-471C-AEAE-0055C760664A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {B9F686E8-5867-4A30-9CE9-8AF85556457C} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {C0EEB21F-ECAE-42A6-8820-F00BFD7CBC91} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {C33A9601-DEAC-45A4-AAF8-C3CE16BFE6BC} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C713EDFE-D0AB-409A-9239-EFFC7E47341C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C938D901-1632-467B-BB60-61ED890A6122} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D17C4A63-6A08-4185-8BBD-50D1B8A915A7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-09-08] (Microsoft Corporation)
Task: {D2751475-CD5B-403A-9FF0-543996CEEB23} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D3F1192E-D509-42B7-859F-00F4619501E3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-19] (Piriform Ltd)
Task: {D7A54453-B098-45CB-AA38-B297FBA0E646} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DC84F3B1-35C3-4FEE-8772-A260FFF98292} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-09-08] (Microsoft Corporation)
Task: {DEC12249-4054-4FA7-B934-B36AC89950A6} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2016-06-08] (Acer Incorporated)
Task: {DFCDD285-43D2-43EB-B027-30768703D420} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E193A597-44F7-47AA-A062-1BF0EFD066B6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E7B2E99A-1530-4B2E-ABCF-CFA4ACB7B9AD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)
Task: {E9C30631-96C0-4CB8-BE63-99FBFA80557C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {EB2A50C8-21DF-485A-A240-4DBB9693A141} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EC349F5A-6FE3-4382-BDC0-7CCADE35D05B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-07-31] (Microsoft Corporation)
Task: {F7581B14-6699-43B3-91CC-DD34E0306439} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {FBE193BD-A0C8-4F51-A3FD-5C36E028747A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Teamviewer-QS-updater-xrkj2nv.job => C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe*--configuration xrkj2nv --cqsupdate --drepetr.kop

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2016-07-11 15:03 - 2016-07-11 15:03 - 000415128 _____ () C:\WINDOWS\system32\igfxTray.exe
2018-09-12 21:53 - 2018-08-31 05:12 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-07-11 19:18 - 2017-07-11 19:18 - 000076456 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2014-05-23 11:21 - 2013-10-01 11:09 - 000078880 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2014-05-23 11:25 - 2013-12-10 01:27 - 001242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-03-16 08:17 - 2018-09-11 19:47 - 000166992 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\JitV.dll
2016-03-16 08:19 - 2018-09-11 19:42 - 001075168 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000143296 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 002631616 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000554944 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000041920 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000039872 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000086464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll
2015-04-13 15:56 - 2015-04-13 15:56 - 000070675 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 002158528 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000114112 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000245184 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000089536 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libvdr_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000055744 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000072128 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000593344 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000771520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000131520 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000052672 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\librar_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000023488 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000145856 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 001566656 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000332736 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 001264064 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libwin_msg_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000069568 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll
2015-04-13 15:57 - 2015-04-13 15:57 - 000242112 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000048576 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libwin_hotkeys_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 012001728 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000046528 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000261056 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libjpeg_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000027072 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000304576 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 001291200 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000754624 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000344512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000036800 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000052160 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsubstx3g_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000456128 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000035776 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000157632 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 001549248 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000356288 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000028096 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000031680 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000363456 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll
2015-04-13 16:00 - 2015-04-13 16:00 - 000121792 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdvbsub_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 013522368 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000022464 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000027072 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 001504704 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000772544 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000038848 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_sse2_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000030144 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_mmx_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000702400 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libswscale_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000036800 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_sse2_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000125376 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_sse2_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000064448 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_mmx_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000028608 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_mmx_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000027584 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000024512 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000030656 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000027584 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000029120 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000037312 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll
2015-04-13 15:58 - 2015-04-13 15:58 - 000024000 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000023488 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll
2015-04-13 15:59 - 2015-04-13 15:59 - 000022976 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Acer01.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

MSCONFIG\startupfolder: C:^Users^petr.kopecny.MSQUATRO^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kooperativa - PDF Server.lnk => C:\Windows\pss\Kooperativa - PDF Server.lnk.Startup
MSCONFIG\startupfolder: C:^Users^petr.kopecny.MSQUATRO^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Odeslat do OneNote.lnk => C:\Windows\pss\Odeslat do OneNote.lnk.Startup

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{C9193898-5D55-4C01-AB94-129626D63521}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [{FBDB37F3-B689-40C9-9F79-82BB705640F3}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
FirewallRules: [UDP Query User{801B6D7E-2715-40BC-8CAB-7C76B89FCD05}C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe] => (Allow) C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [TCP Query User{AEF556E6-98F8-4344-8FC1-0F7C9179B428}C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe] => (Allow) C:\program files (x86)\kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [UDP Query User{755FA9D9-52C6-4EA5-B23F-02979A8CC426}C:\program files (x86)\microsoft\skype for desktop\skype.exe] => (Allow) C:\program files (x86)\microsoft\skype for desktop\skype.exe
FirewallRules: [TCP Query User{8DA7CF1C-7557-4B0F-B471-439AE2FC4D47}C:\program files (x86)\microsoft\skype for desktop\skype.exe] => (Allow) C:\program files (x86)\microsoft\skype for desktop\skype.exe
FirewallRules: [{31657A2C-B62F-44CE-88FA-1343EA1E07D8}] => (Allow) C:\Program Files (x86)\Kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [{AB658FAC-1FB0-4AE4-BAD8-F711CEA78110}] => (Allow) C:\Program Files (x86)\Kuki\addons\skin.netboxkuki\proxies\proxy2.exe
FirewallRules: [{277AA902-9724-4E1C-B026-73784E3D7CFE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{8385934A-2944-435A-BE0D-2BB6D96CC4A5}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{D978E42D-B862-44C7-A005-852FB786B34C}] => (Allow) C:\Users\petr.kopecny.MSQUATRO\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{D613EF0B-7927-4C80-A726-51A39DB71DCE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ACEEFEA9-0683-4711-8FE3-098466D9A6B4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{67555717-3B9E-45C5-B45D-B89595F0D2CD}C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe] => (Allow) C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe
FirewallRules: [TCP Query User{882C0982-5BB0-4A73-AE1A-0E7650278DF1}C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe] => (Allow) C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe
FirewallRules: [UDP Query User{4715F08E-6A40-4A1A-AD83-246F90D546DC}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{90151E1E-3BB3-49F1-8A92-BA6AB61CBD8B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0F068683-70CF-48B6-88A9-8074D3A4C744}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{E5BF5977-7A39-4E1D-84E4-C2CF2ED4A2C0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{48F004E7-DAB2-4457-BE05-82C3F7251471}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C32B8EB3-31F6-4F3F-9298-392F3E11A988}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C0A21420-40A6-4BF1-BF2D-D0EB6AFE4E57}] => (Allow) C:\Users\petr.kopecny\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{B4393C7F-03B6-4BD8-AD25-B0A7EB1CCEA7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{2775DAFA-19ED-4FD4-A72D-A4983C61ED9E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{7975B085-C2C0-4BA9-A85B-212E7DF7F161}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{2E63D987-7B7B-4F68-8436-5F84FF2AC0AD}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{5AE65038-5AC0-44C3-9A95-4CF94941E26C}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{5C953BFC-E3F3-49A2-9156-019D99F0869D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{B57A5547-ACC2-4A61-B134-E95B51232DE8}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{15B71BD7-D2F8-46B5-B1CE-1965F6074A5B}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe

==================== Restore Points =========================

13-09-2018 23:07:10 Instalační služba modulů systému Windows
15-09-2018 11:06:54 Instalační služba modulů systému Windows
16-09-2018 19:06:08 Instalační služba modulů systému Windows
17-09-2018 21:06:40 Instalační služba modulů systému Windows
18-09-2018 23:06:24 Instalační služba modulů systému Windows
20-09-2018 21:06:08 Instalační služba modulů systému Windows
21-09-2018 21:08:18 Instalační služba modulů systému Windows
23-09-2018 10:20:31 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=43, ID autora=9, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=25, ID autora=9, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=17, ID autora=9, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=23, ID autora=8086, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=21, ID autora=8086, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=18, ID autora=8086, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=43, ID autora=9, ID dodavatele=0, typ dodavatele=0

Error: (09/23/2018 10:19:54 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Přeskočení: Ověření Eap method DLL path se nezdařilo. Chyba: ID typu=25, ID autora=9, ID dodavatele=0, typ dodavatele=0


System errors:
=============
Error: (09/23/2018 10:46:18 PM) (Source: NETLOGON) (EventID: 5719) (User: )
Description: Tento počítač nemohl nastavit zabezpečenou relaci s řadičem
domény v doméně MSQUATRO z následujícího důvodu:
Nemůžeme vás přihlásit s těmito přihlašovacími údaji, protože vaše doména není k dispozici. Ujistěte se, že je vaše zařízení připojeno k vaší podnikové síti, a zkuste to znovu. Pokud jste se na tomto zařízení dříve přihlásili s jinými přihlašovacími údaji, můžete se přihlásit s jejich pomocí.


To může vést k potížím při ověřování. Přesvědčte se, zda je tento
počítač připojen k síti. Pokud potíže trvají,
obraťte se na správce domény.



DALŠÍ INFORMACE

Pokud je tento počítač řadičem domény pro určenou doménu,
nastaví zabezpečenou relaci s emulátorem primárního řadiče domény v určené
doméně. V opačném případě tento počítač nastaví zabezpečenou relaci s libovolným řadičem domény
v určené doméně.

Error: (09/23/2018 10:30:52 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: MSQUATRO)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/23/2018 09:55:52 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/23/2018 08:47:51 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: MSQUATRO)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/23/2018 08:17:52 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/23/2018 07:04:51 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: MSQUATRO)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.

Error: (09/23/2018 06:46:17 PM) (Source: NETLOGON) (EventID: 5719) (User: )
Description: Tento počítač nemohl nastavit zabezpečenou relaci s řadičem
domény v doméně MSQUATRO z následujícího důvodu:
Nemůžeme vás přihlásit s těmito přihlašovacími údaji, protože vaše doména není k dispozici. Ujistěte se, že je vaše zařízení připojeno k vaší podnikové síti, a zkuste to znovu. Pokud jste se na tomto zařízení dříve přihlásili s jinými přihlašovacími údaji, můžete se přihlásit s jejich pomocí.


To může vést k potížím při ověřování. Přesvědčte se, zda je tento
počítač připojen k síti. Pokud potíže trvají,
obraťte se na správce domény.



DALŠÍ INFORMACE

Pokud je tento počítač řadičem domény pro určenou doménu,
nastaví zabezpečenou relaci s emulátorem primárního řadiče domény v určené
doméně. V opačném případě tento počítač nastaví zabezpečenou relaci s libovolným řadičem domény
v určené doméně.

Error: (09/23/2018 06:39:51 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: Zpracování zásad skupiny selhalo v důsledku toho, že se nebylo v síti možné připojit k řadiči domény. Může se jednat o přechodný stav. Po připojení počítače k řadiči domény a úspěšném zpracování zásad skupiny bude odeslána zpráva o úspěšném provedení těchto akcí. Pokud se tato zpráva nezobrazí během několika hodin, obraťte se na správce.


Windows Defender:
===================================
Date: 2018-09-23 11:11:20.264
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {B80BCF00-4AAB-4B87-8281-4FFB44641A66}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-21 10:47:03.468
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {E2EFFFC1-B137-4882-BABA-AF71F2D1F8C6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-08 22:27:32.185
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {1812355A-3A7E-42CB-8F81-C95FBAD2518E}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-07-06 11:12:10.651
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {DA53A880-CE39-4976-A861-9E6BF8AFB0ED}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-08-22 18:39:34.682
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1826.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80240016
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-08-22 10:05:37.049
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1749.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-08-21 10:19:54.505
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1749.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-08-20 09:48:41.555
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1702.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.

Date: 2018-08-20 09:48:41.554
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.273.1702.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15100.1
Kód chyby: 0x80072ee7
Popis chyby :Nelze rozpoznat název nebo adresu serveru.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz
Percentage of memory in use: 76%
Total physical RAM: 3987.27 MB
Available physical RAM: 935.71 MB
Total Virtual: 8083.27 MB
Available Virtual: 3712.37 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:218.85 GB) (Free:131.43 GB) NTFS
Drive d: (DATA) (Fixed) (Total:218.85 GB) (Free:59.05 GB) NTFS

\\?\Volume{c62f4623-e44c-4170-be50-a3004eeaebf8}\ (Recovery) (Fixed) (Total:0.59 GB) (Free:0.31 GB) NTFS
\\?\Volume{01973d99-228c-44b8-98df-789accaa4bb2}\ (Push Button Reset) (Fixed) (Total:27.06 GB) (Free:2.62 GB) NTFS
\\?\Volume{225254fe-4c05-40b0-85e1-cc0906d9a1d8}\ (ESP) (Fixed) (Total:0.29 GB) (Free:0.24 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: A7C0CE7C)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Prosím o kontrolu. Děkuji

Napsal: 24 zář 2018 22:02
od Conder
:arrow: Precisti to najprv McAfee odinstalatorom: http://download.mcafee.com/products/lic ... s/MCPR.exe

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
    File: C:\Program Files\Intel\iCLS Client\HeciServer.exe
    File: C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe
    Folder: C:\QPlán
    
    HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
    FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 => not found
    FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird => not found
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
    S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
    S3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
    R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
    R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
    R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
    R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
    U3 idsvc; no ImagePath
    2018-09-23 23:25 - 2018-09-23 23:25 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST-OlderVersion
    ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
    Task: {20BAB122-249D-4F89-B985-9FFA5CBD1F09} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
    Task: {295EA083-66D7-49D6-BB91-8ABC0FFC4EDA} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
    Task: {2A9887B0-F37D-4169-B88B-F0CF987853AB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
    Task: {41E007FB-A00C-43FD-BF53-580A3DA6B3E6} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    Task: {48AC3E3F-35AD-4C3A-B0CA-F73E8C854A5C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {56871B82-CAA9-4BB0-90F2-CC6C0BB3DC0F} - System32\Tasks\{6FE0153C-5C4A-4821-8638-5CD756409D8B} => C:\Windows\system32\pcalua.exe -a C:\Users\petr.kopecny.MSQUATRO\Downloads\KoopP7BNExtern.exe -d C:\Users\petr.kopecny.MSQUATRO\Downloads
    Task: {59A94ED6-A2B5-4525-BDFC-FCC35954AC0F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {6A43A726-D725-47B4-AE94-0882FFD4E5CA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {828573E3-F205-4843-A269-F01A049297FD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {8B88A449-0B19-477C-8375-FE02786F91C5} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
    Task: {97239DF1-B99C-46EB-9A0F-E34AA94B3708} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {B9F686E8-5867-4A30-9CE9-8AF85556457C} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
    Task: {C33A9601-DEAC-45A4-AAF8-C3CE16BFE6BC} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {C713EDFE-D0AB-409A-9239-EFFC7E47341C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {DFCDD285-43D2-43EB-B027-30768703D420} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {E9C30631-96C0-4CB8-BE63-99FBFA80557C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {F7581B14-6699-43B3-91CC-DD34E0306439} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {FBE193BD-A0C8-4F51-A3FD-5C36E028747A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
    
    C:\Program Files\Common Files\McAfee
    C:\Windows\system32\mfevtps.exe
    C:\WINDOWS\System32\drivers\cfwids.sys
    C:\WINDOWS\System32\drivers\mfeapfk.sys
    C:\WINDOWS\System32\drivers\mfeavfk.sys
    C:\WINDOWS\System32\drivers\mfefirek.sys
    C:\WINDOWS\System32\drivers\mfehidk.sys
    C:\WINDOWS\System32\drivers\mfewfpk.sys
    
    Hosts:
    EmptyTemp:
    End
  • Klikni na Subor a potom na Ulozit
  • Vpravo dole vyber kodovanie Unicode
  • Subor uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj

Re: Prosím o kontrolu. Děkuji

Napsal: 26 zář 2018 21:16
od vrchlab
1. pročištěno
2. log

Fix result of Farbar Recovery Scan Tool (x64) Version: 23.09.2018
Ran by petr.kopecny (26-09-2018 22:00:26) Run:1
Running from C:\Users\petr.kopecny.MSQUATRO\Desktop
Loaded Profiles: petr.kopecny (Available Profiles: petr.kopecny & petr.kopecny & Administrator & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
File: C:\Program Files\Intel\iCLS Client\HeciServer.exe
File: C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe
Folder: C:\QPlán

HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
FF HKLM-x32\...\Firefox\Extensions: [{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}] - C:\Program Files\Acer ProShield\FFExt20 => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Endpoint Antivirus\Mozilla Thunderbird => not found
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
S3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
U3 idsvc; no ImagePath
2018-09-23 23:25 - 2018-09-23 23:25 - 000000000 ____D C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST-OlderVersion
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {20BAB122-249D-4F89-B985-9FFA5CBD1F09} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {295EA083-66D7-49D6-BB91-8ABC0FFC4EDA} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {2A9887B0-F37D-4169-B88B-F0CF987853AB} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {41E007FB-A00C-43FD-BF53-580A3DA6B3E6} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {48AC3E3F-35AD-4C3A-B0CA-F73E8C854A5C} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {56871B82-CAA9-4BB0-90F2-CC6C0BB3DC0F} - System32\Tasks\{6FE0153C-5C4A-4821-8638-5CD756409D8B} => C:\Windows\system32\pcalua.exe -a C:\Users\petr.kopecny.MSQUATRO\Downloads\KoopP7BNExtern.exe -d C:\Users\petr.kopecny.MSQUATRO\Downloads
Task: {59A94ED6-A2B5-4525-BDFC-FCC35954AC0F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {6A43A726-D725-47B4-AE94-0882FFD4E5CA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {828573E3-F205-4843-A269-F01A049297FD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {8B88A449-0B19-477C-8375-FE02786F91C5} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {97239DF1-B99C-46EB-9A0F-E34AA94B3708} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {B9F686E8-5867-4A30-9CE9-8AF85556457C} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION
Task: {C33A9601-DEAC-45A4-AAF8-C3CE16BFE6BC} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {C713EDFE-D0AB-409A-9239-EFFC7E47341C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {DFCDD285-43D2-43EB-B027-30768703D420} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E9C30631-96C0-4CB8-BE63-99FBFA80557C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {F7581B14-6699-43B3-91CC-DD34E0306439} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {FBE193BD-A0C8-4F51-A3FD-5C36E028747A} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION

C:\Program Files\Common Files\McAfee
C:\Windows\system32\mfevtps.exe
C:\WINDOWS\System32\drivers\cfwids.sys
C:\WINDOWS\System32\drivers\mfeapfk.sys
C:\WINDOWS\System32\drivers\mfeavfk.sys
C:\WINDOWS\System32\drivers\mfefirek.sys
C:\WINDOWS\System32\drivers\mfehidk.sys
C:\WINDOWS\System32\drivers\mfewfpk.sys

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.

========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========



Count : 3108
Average :
Sum : 5975942699
Maximum :
Minimum :
Property : Length




========= End of Powershell: =========


========================= File: C:\Program Files\Intel\iCLS Client\HeciServer.exe ========================

C:\Program Files\Intel\iCLS Client\HeciServer.exe
File not signed
MD5: DAE6C3099D291EED8922A65C29ABCF52
Creation and modification date: 2013-08-27 23:32 - 2013-08-27 23:32
Size: 000747520
Attributes: ----A
Company Name: Intel(R) Corporation
Internal Name: HeciServer
Original Name: HeciServer.exe
Product: Intel(R) Capability Licensing Service Interface
Description: Intel(R) Capability Licensing Service Interface
File Version: 1.31.8.1 sys_sysscbld
Product Version: 1,31,8,1
Copyright: (C) Copyright Intel(R) Corporation
VirusTotal: https://www.virustotal.com/file/ad0a932 ... 537898756/

====== End of File: ======


========================= File: C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe ========================

C:\Users\petr.kopecny.MSQUATRO\AppData\Local\TeamViewer\CustomConfigs\xrkj2nv\TeamViewer.exe
File is digitally signed
MD5: E72DA04872CD4CD3109B30C383CDC932
Creation and modification date: 2016-06-21 15:25 - 2016-08-08 23:28
Size: 019293456
Attributes: ----A
Company Name: TeamViewer GmbH
Internal Name: TeamViewer
Original Name: TeamViewer.exe
Product: TeamViewer
Description: TeamViewer 11
File Version: 11.0.64630.0
Product Version: 11.0
Copyright: TeamViewer GmbH
VirusTotal: https://www.virustotal.com/file/5368dfb ... 512561668/

====== End of File: ======


========================= Folder: C:\QPlán ========================

2016-02-12 16:01 - 2016-02-12 16:01 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QHypoinvest_02-2016.xlsm
2016-05-15 23:57 - 2016-05-15 23:57 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QHypoinvest_05-2016.xlsm
2016-01-08 16:28 - 2016-01-08 16:28 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_01-2016.xlsm
2017-01-12 23:51 - 2017-01-12 23:51 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_01-2017.xlsm
2016-02-09 13:38 - 2016-02-09 13:38 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_02-2016.xlsm
2016-06-03 10:15 - 2016-06-03 10:15 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_06-2016.xlsm
2016-06-28 22:44 - 2016-06-28 22:44 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_07-2016.xlsm
2016-11-08 17:33 - 2016-11-08 17:33 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_11-2016.xlsm
2015-12-03 11:17 - 2015-12-03 11:17 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QKalkulátor_12-2015.xlsm
2016-02-12 15:24 - 2016-02-12 15:24 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QRenta_02-2016.xlsm
2017-03-21 22:44 - 2017-03-21 22:44 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QRenta_03-2017.xlsm
2016-06-11 01:45 - 2016-06-11 01:45 - 000000165 ___AH [B7E339F5507511FCAE26B1F25C064F71] () C:\QPlán\~$QRenta_07-2016.xlsm
2015-04-22 15:49 - 2015-04-24 16:50 - 000414183 ____A [8D401486BDED94C2A1E9FD044F890AAF] () C:\QPlán\HYP vs PI.pdf
2015-03-19 16:48 - 2018-03-31 15:01 - 000020732 ____A [C5BC66785232BA4DB19C21C4F2326BC0] () C:\QPlán\klient.xlsx
2015-05-20 14:16 - 2017-04-28 15:40 - 000014336 ____A [53BF326D62E715B22E689F1D596D1361] () C:\QPlán\poradce.xlsx
2018-07-01 23:01 - 2018-07-01 23:00 - 001227599 ____A [5ED913249F7C45C631D28B37B38FBA67] () C:\QPlán\QHypoinvest_3Q2018.xlsm
2018-07-01 23:06 - 2018-09-01 13:07 - 001898516 ____A [DF2E69EE204C8EC88EFDC130669E17B9] () C:\QPlán\QKalkulátor_3Q2018.xlsm
2018-07-01 23:13 - 2018-09-01 13:08 - 002392317 ____A [3794226D44178588E44DDD52319FABCD] () C:\QPlán\QRenta_3Q2018.xlsm
2018-07-01 23:25 - 2018-07-01 23:24 - 000431983 ____A [1BE264CD6004910787DF524D5440A65A] () C:\QPlán\QŽivot_3Q2018.xlsm
2016-05-11 15:17 - 2016-05-18 14:02 - 000241990 ____A [1D2165B6B4770FE94BFD55890CA01887] () C:\QPlán\Tipy na nastavení produktů na tvorbu rezerv.pdf
2015-03-19 16:53 - 2015-03-19 16:45 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\Databáze klientů
2016-05-18 23:05 - 2016-05-18 23:05 - 000019968 ____A [A53B732ACA080139BD7D8BE543AF521A] () C:\QPlán\Databáze klientů\Bláhová_Dana_1986_04_13.xlsx
2015-06-15 11:57 - 2015-06-22 15:55 - 000019456 ____A [DEA8D064B474C4AB0613AB71F3B9448D] () C:\QPlán\Databáze klientů\Budín_Jiří_1960_01_08.xlsx
2015-06-15 11:57 - 2015-06-16 13:46 - 000019456 ____A [38841AD97147B1ADE34EFCF409F7B968] () C:\QPlán\Databáze klientů\Budínová_Stanislava_1960_02_21.xlsx
2015-06-14 19:01 - 2015-06-14 19:01 - 000019456 ____A [E0DD664D6FA25987098504FDAFC4CB0D] () C:\QPlán\Databáze klientů\Čech_Pavel_1986_03_15.xlsx
2015-05-21 11:45 - 2015-05-21 11:45 - 000012871 ____A [96A1AE8249B9997E16C08442B1BA369D] () C:\QPlán\Databáze klientů\Čermák_Čestmír_1974_04_08.xlsx
2016-05-18 23:17 - 2016-05-18 23:17 - 000019968 ____A [000B172EDC145B5CE6DC035EDB1734C0] () C:\QPlán\Databáze klientů\Dlouhý_David_1975_01_24.xlsx
2017-12-17 13:02 - 2017-12-17 13:06 - 000021504 ____A [BC5A9F651B3ABCA53C08A0DDB371B468] () C:\QPlán\Databáze klientů\Hak_Petr_1980_11_15.xlsx
2017-02-22 02:44 - 2018-03-28 01:18 - 000020480 ____A [76868C74FB6A8686272D0708CF5A2665] () C:\QPlán\Databáze klientů\Hašek_Jan_1985_04_25.xlsx
2015-03-19 17:22 - 2015-03-16 15:26 - 000012728 ____A [5D3F790AD272FAF1384713D9FCC8BC11] () C:\QPlán\Databáze klientů\Hemala_Jan_1986_10_17.xlsx
2017-06-01 09:56 - 2017-06-01 10:11 - 000020480 ____A [CBB481AE96A07EB8B533EEE8DBB02043] () C:\QPlán\Databáze klientů\Hencová_Daniela_1990_07_15.xlsx
2015-04-02 13:12 - 2015-05-20 14:25 - 000019456 ____A [0E08E62C2628FDBFC50B979FC6E38985] () C:\QPlán\Databáze klientů\Hora_Jan_1988_08_15.xlsx
2015-03-19 17:22 - 2015-03-19 17:23 - 000012864 ____A [991FAFE647EDC71F004CBF87EB5DFF9C] () C:\QPlán\Databáze klientů\Horák_Jan_1990_06_17.xlsx
2017-02-22 00:52 - 2017-02-24 15:53 - 000020480 ____A [3D0E3209D3770E9CF710F7B14802E9B4] () C:\QPlán\Databáze klientů\Horešovský_David_1984_09_15.xlsx
2017-02-22 01:05 - 2017-02-22 04:00 - 000020480 ____A [1CD0D9BD9955F1ACEEF6764247D1F9DA] () C:\QPlán\Databáze klientů\Hus_David_1988_08_14.xlsx
2016-06-11 15:50 - 2017-11-23 12:33 - 000021504 ____A [190DB72EA1DCEB47E3C203EE72411BD1] () C:\QPlán\Databáze klientů\Chloupek_Oktavián_1976_12_05.xlsx
2015-03-19 17:22 - 2015-03-18 13:26 - 000012724 ____A [905723526B27B5106B4A1294507B2472] () C:\QPlán\Databáze klientů\Jarý_Petr_1990_07_15.xlsx
2015-05-20 13:54 - 2015-05-20 13:54 - 000019456 ____A [6B10FEFBCB80C0431925BE18E8ABA342] () C:\QPlán\Databáze klientů\Ječný_Libor_1982_04_13.xlsx
2018-03-31 15:21 - 2018-03-31 15:39 - 000020992 ____A [C3F654380739D00F7B73038125A7139F] () C:\QPlán\Databáze klientů\Kovář_Jan_1990_03_25.xlsx
2015-03-19 17:22 - 2017-01-01 19:38 - 000020480 ____A [9D0CC59E13E415F923FBB6279849AF4F] () C:\QPlán\Databáze klientů\Malý_David_1985_12_12.xlsx
2017-02-22 17:23 - 2017-02-22 17:23 - 000020480 ____A [298982467A43DB5E6CECCAB7029151B2] () C:\QPlán\Databáze klientů\Mařák_David_1985_08_15.xlsx
2015-03-19 17:22 - 2015-03-09 13:32 - 000012659 ____A [F6B657D1C1DC594735DE756E80511C1C] () C:\QPlán\Databáze klientů\Mašek_Jan_1990_06_15.xlsx
2015-03-19 17:22 - 2015-06-14 18:51 - 000019456 ____A [5863168A6BA92F219A906C4E1D2696A9] () C:\QPlán\Databáze klientů\Neuwirth_Michal_1988_07_15.xlsx
2017-11-22 12:58 - 2017-12-08 00:32 - 000021504 ____A [0AAE4FCB738429E5060AB24F83C0B274] () C:\QPlán\Databáze klientů\Nováček_Jan_1990_08_17.xlsx
2017-12-07 21:44 - 2017-12-08 00:32 - 000021504 ____A [048EAC0B3432E1CA1D95843EBE27FC72] () C:\QPlán\Databáze klientů\Nováčková_Lenka_1992_11_02.xlsx
2015-03-20 12:45 - 2015-03-20 12:48 - 000012761 ____A [AA9435794DC08A26726753EAD83209D6] () C:\QPlán\Databáze klientů\Novák_Jan_1980_07_15.xlsx
2015-03-19 17:22 - 2015-03-18 18:07 - 000012807 ____A [EF381AE0AF324E6A0A7C870D9A264FE6] () C:\QPlán\Databáze klientů\Novák_Pavel_1990_05_15.xlsx
2015-03-19 17:22 - 2016-04-11 13:58 - 000019968 ____A [FDFE7011F400539F52A2BCEFAAE57CD6] () C:\QPlán\Databáze klientů\Novotná_Jana_1980_01_01.xlsx
2015-05-06 10:48 - 2015-05-20 13:50 - 000019456 ____A [DAD439520E4A54D975E44D20AE9CB8BB] () C:\QPlán\Databáze klientů\Novotná_Pavla_1980_01_01.xlsx
2015-03-23 00:14 - 2015-10-30 16:27 - 000019456 ____A [144DE381CBA72BA0EE04A68CA8F15F6B] () C:\QPlán\Databáze klientů\Novotný_David_1989_08_14.xlsx
2016-05-17 10:20 - 2016-05-17 10:20 - 000019968 ____A [B6377C36B5C51350D4C964C719AE771F] () C:\QPlán\Databáze klientů\Příklad_Druhý_1986_04_13.xlsx
2016-05-16 16:21 - 2016-05-16 17:11 - 000019968 ____A [01863A915DFBD208B95F06DC922A1AB0] () C:\QPlán\Databáze klientů\Příklad_První_1980_08_15.xlsx
2016-05-16 17:19 - 2016-05-16 23:56 - 000019968 ____A [833FD3C9D51467EF42D8D183148C548B] () C:\QPlán\Databáze klientů\Příklad_První_1981_04_15.xlsx
2016-05-17 11:19 - 2016-05-17 11:19 - 000019968 ____A [DC2F8FC1F7A0EDD8271F10B49A28DAFB] () C:\QPlán\Databáze klientů\Příklad_Třetí_1975_01_24.xlsx
2017-01-01 21:23 - 2017-01-01 21:41 - 000019968 ____A [9B7ACC1F6D7F51333C6AC8479B1A7FE4] () C:\QPlán\Databáze klientů\Rys_Roman_1982_08_15.xlsx
2015-05-20 11:52 - 2015-06-14 19:19 - 000019456 ____A [199FB6E45A5FB191AE68DEFB61CEF450] () C:\QPlán\Databáze klientů\Skála_Michal_1985_12_17.xlsx
2015-03-19 17:22 - 2015-03-09 13:07 - 000012662 ____A [1BDCFD0A31636374F776B95C2DAACCBE] () C:\QPlán\Databáze klientů\Sládek_Dušan_1980_04_04.xlsx
2017-11-14 02:14 - 2017-11-14 02:14 - 000020480 ____A [B82167113CB8FDC553A959B8B450E7B9] () C:\QPlán\Databáze klientů\Svátek_Michal_1982_06_15.xlsx
2016-04-11 11:30 - 2016-04-11 11:30 - 000019968 ____A [C5F5BB38C07041FB5456FCEEDB0B74F2] () C:\QPlán\Databáze klientů\Vzorková_Jana_1975_01_24.xlsx
2016-01-28 21:41 - 2016-01-28 21:41 - 000019456 ____A [927167E31F16AB4EC2D903171BECED78] () C:\QPlán\Databáze klientů\Zatloukalová_Zuzana_1959_04_29.xlsx
2017-02-22 00:58 - 2017-02-22 00:58 - 000020480 ____A [3CD5C0A5F3394E6D350FA4DF5939BFAF] () C:\QPlán\Databáze klientů\Závora_Jan_1989_11_17.xlsx
2015-04-22 15:49 - 2015-04-22 15:49 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\QKalkulátor Výstupy pdf
2015-03-19 16:53 - 2015-04-24 19:24 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\QPlán Výstupy
2015-04-20 15:46 - 2015-04-20 15:36 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy
2015-05-19 12:21 - 2015-05-19 12:21 - 000434371 ____A [BF8F0346790DB0D85E66FB0F4F3FE90C] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\_19.5.2015_QHypoinvest_1.pdf
2015-08-26 11:04 - 2015-08-26 11:04 - 000433352 ____A [6A64CA89CEF4B8DD839B242A629C67BF] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\_26.8.2015_QHypoinvest_1.pdf
2015-10-30 16:38 - 2015-10-30 16:38 - 000432142 ____A [D5AD45216DC18F5A0734340089A7C60D] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\_30.10.2015_QHypoinvest_1.pdf
2015-05-19 11:47 - 2015-05-19 11:47 - 000431427 ____A [19F234C170670EBDB14B0E6E2D51DDD5] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\Marek Dobeš_19.5.2015_QHypoinvest_1.pdf
2015-05-19 11:49 - 2015-05-19 11:49 - 000431427 ____A [D3DAC43035281F9168063546B2F19357] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\Marek Dobeš_19.5.2015_QHypoinvest_2.pdf
2015-05-19 10:15 - 2015-05-19 10:15 - 000433721 ____A [D4EE38DDA21A505D2A2C42CFBB385240] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_19.5.2015__1.pdf
2015-05-19 11:42 - 2015-05-19 11:42 - 000431341 ____A [83DDE2C2C313C0FD1E17F240A6183DFA] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_19.5.2015__2.pdf
2015-05-19 11:47 - 2015-05-19 11:47 - 000431427 ____A [DBC92F4F685231D7443F375716E73EA5] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_19.5.2015_Marek Dobeš_2.pdf
2015-05-19 11:48 - 2015-05-19 11:48 - 000431427 ____A [5B745E90DE659ABB3CE2608DEA5C1D84] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_19.5.2015_Marek Dobeš_3.pdf
2015-04-20 15:48 - 2015-04-20 15:48 - 000433441 ____A [46BDAB7A5B4B7421B80C3B5BE7E638E7] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_20.4.2015__1.pdf
2015-04-20 15:49 - 2015-04-20 15:49 - 000433441 ____A [B843A81085E3A6E5851277F979F25B87] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_20.4.2015__2.pdf
2015-04-20 15:57 - 2015-04-20 15:57 - 000434153 ____A [741499EEAA48575B5B5967089199B51E] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_20.4.2015_Dan Hušek_1.pdf
2015-04-20 15:49 - 2015-04-20 15:49 - 000433517 ____A [6B7DB4AEF0BCC74DCDC5D77A0D1B4D85] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_20.4.2015_Jan Novák_1.pdf
2015-04-21 10:10 - 2015-04-21 10:10 - 000434091 ____A [B619F6A09DD8796F4E952E610DA20108] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_21.4.2015__1.pdf
2015-04-23 13:01 - 2015-04-23 13:01 - 000416869 ____A [62095146A6DBB17173489C5278D89E9F] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_23.4.2015__1.pdf
2015-04-24 17:38 - 2015-04-24 17:38 - 000414981 ____A [9B1BC6146244E5B8B6563FB5D6B4C257] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_24.4.2015__1.pdf
2015-04-24 17:49 - 2015-04-24 17:49 - 000414980 ____A [37AB03A35D15308311CAAC5BF7F8328C] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_24.4.2015__2.pdf
2015-04-24 17:58 - 2015-04-24 17:58 - 000416315 ____A [6302A1D9ABC637331BFA62B7469D97E5] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_24.4.2015__3.pdf
2015-04-24 19:27 - 2015-04-24 19:27 - 000415868 ____A [1167D0549CA2585E01F5255A2D9ECA20] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_24.4.2015__4.pdf
2015-04-24 19:30 - 2015-04-24 19:30 - 000415026 ____A [203940874E3DED5F7FAE89AD225C02D2] () C:\QPlán\QPlán Výstupy\QHypoinvest Výstupy\QHypoinvest_Výstup_24.4.2015__5.pdf
2015-03-19 16:53 - 2015-03-19 16:47 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy
2016-03-10 22:18 - 2016-03-10 22:18 - 000457969 ____A [EFB63207AA12313E4BE2724CD004DC07] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_10.3.2016_J&T LIFE_1.pdf
2016-03-10 16:22 - 2016-03-10 16:22 - 000462644 ____A [D59E7BB80369A32F76BE39622FB26DEC] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_10.3.2016_PIP_1.pdf
2016-03-10 21:44 - 2016-03-10 21:44 - 000462701 ____A [17238D2A95F3E77EB730EA8680E97A00] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_10.3.2016_PIP_2.pdf
2016-12-11 21:06 - 2016-12-11 21:06 - 000775776 ____A [1BA0705937E247E1DE12157F79F8E4B6] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_11.12.2016_DoZlata_1.pdf
2016-05-11 11:37 - 2016-05-11 11:37 - 000358838 ____A [1DA6E864FE8F51FFCB4D6ED2F2111162] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_11.5.2016_Srovnání_1.pdf
2015-06-12 11:34 - 2015-06-12 11:34 - 000539581 ____A [7841AC53DF30EBC2A2FD8DF47C5AA831] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_12.6.2015_J&T LIFE_1.pdf
2017-11-13 09:58 - 2017-11-13 09:58 - 000782929 ____A [C997862F5BC03E478D6D9AD358CE9897] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_13.11.2017_DoZlata_1.pdf
2017-06-14 11:34 - 2017-06-14 11:34 - 000683596 ____A [3BC7CFF247CE288E2EC6CB22EBEFE8EE] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_14.6.2017_DoZlata_1.pdf
2015-05-16 13:51 - 2015-05-16 13:51 - 000267547 ____A [141E82C9D3C1E3120030FBFEAAF4B1FC] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_DPS_1.pdf
2015-05-16 13:33 - 2015-05-16 13:33 - 000517024 ____A [E9F3EA8BA7A2053A2AFE7A49740D2A5E] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_FMK_1.pdf
2015-05-16 13:37 - 2015-05-16 13:37 - 000463468 ____A [49B4B100E0BB421AF49CE96497644470] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_HI_1.pdf
2015-05-16 13:38 - 2015-05-16 13:38 - 000531284 ____A [452E50AA41C2609A87679DCDA94EDA62] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_HI_2.pdf
2015-05-16 13:39 - 2015-05-16 13:39 - 000531284 ____A [82D410528CA15E9929343D9565ECFEBF] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_HI_3.pdf
2015-05-16 13:42 - 2015-05-16 13:42 - 000532852 ____A [3A4C16367E27907148647D511C365422] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_PI_1.pdf
2015-05-16 13:52 - 2015-05-16 13:52 - 000263591 ____A [ED9EC49DC06B5F6584E11E3D32C2A14A] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_SS_1.pdf
2015-05-16 13:53 - 2015-05-16 13:53 - 000263591 ____A [6841D4F27681466C23DF11FFF8EBD547] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_SS_2.pdf
2015-05-16 14:26 - 2015-05-16 14:26 - 000258459 ____A [1E2FB6B8D818542D98B35F04BD0A206F] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_SÚ_1.pdf
2015-05-16 13:56 - 2015-05-16 13:56 - 000255737 ____A [BCCDD5F2D9D2AB6AAEE31D609FE77F69] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_16.5.2015_TV_1.pdf
2016-12-19 16:08 - 2016-12-19 16:08 - 000514395 ____A [187B02CEC7770238F94EA5650350BCAB] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_19.12.2016_Srovnání_1.pdf
2016-12-19 17:39 - 2016-12-19 17:39 - 000513645 ____A [1117C8524B87AA2FECC6D2D254454081] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_19.12.2016_Srovnání_2.pdf
2017-01-02 16:31 - 2017-01-02 16:31 - 000682206 ____A [E9F4C549A9D4EC7C4AAC17E340C57F7B] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_2.1.2017_DoZlata_1.pdf
2017-01-02 23:27 - 2017-01-02 23:27 - 000679909 ____A [CA9A6B9EE46C482DD034F9D86AC7D0C8] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_2.1.2017_DoZlata_2.pdf
2016-12-21 16:10 - 2016-12-21 16:10 - 000774168 ____A [7464005CEAD1B988F488E825A60A10C3] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_21.12.2016_DoZlata_1.pdf
2015-05-22 15:10 - 2015-05-22 15:10 - 000532816 ____A [491ECC4727D31B7C3D62738BCC9894B0] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_22.5.2015_PI_1.pdf
2015-05-22 15:11 - 2015-05-22 15:11 - 000532816 ____A [C854FD06AAFF79F4BE1857C59BBAD48F] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_22.5.2015_PI_2.pdf
2015-03-31 13:48 - 2015-03-31 13:48 - 000534697 ____A [558AAEADBEBDF1B7F1F3645027DDC9A3] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_31.3.2015_FMK_1.pdf
2015-03-31 13:54 - 2015-03-31 13:54 - 000534463 ____A [CFAEE5B94602175BEA4BB6A916D9541E] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_31.3.2015_HI_1.pdf
2015-03-31 13:55 - 2015-03-31 13:55 - 000553214 ____A [058012B5EDD2DA6BA569314C9B5D58D3] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_31.3.2015_HI_2.pdf
2015-03-31 13:59 - 2015-03-31 13:59 - 000536132 ____A [1899B72D686FB551D0194B50F331800B] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_31.3.2015_TCF_1.pdf
2017-01-04 21:21 - 2017-01-04 21:21 - 000679748 ____A [23775D04D1E3F18D691EF612F24B8D22] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_4.1.2017_DoZlata_1.pdf
2017-01-04 21:23 - 2017-01-04 21:23 - 000679754 ____A [37B185BD20438D10385E77A7EC502182] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_4.1.2017_DoZlata_2.pdf
2017-01-04 21:23 - 2017-01-04 21:23 - 000679881 ____A [FF28E5CC064F885590E5EFBCD4E68D45] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_4.1.2017_DoZlata_3.pdf
2017-01-04 22:06 - 2017-01-04 22:06 - 000680139 ____A [7AD214596684975B19D3563B192E7571] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_4.1.2017_DoZlata_4.pdf
2015-05-06 12:10 - 2015-05-06 12:10 - 000493040 ____A [F10C4AC38C82DEC492C12AF33A3EA876] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_6.5.2015_FMK_1.pdf
2015-09-06 11:22 - 2015-09-06 11:22 - 000356283 ____A [C64F3C51FF5E2C75C3F9DCEC2BAF1E82] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_6.9.2015_JI_1.pdf
2015-09-06 11:22 - 2015-09-06 11:22 - 000357175 ____A [55C972AC64F14079F104F46AD56A45C6] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_6.9.2015_JI_2.pdf
2015-09-06 11:24 - 2015-09-06 11:24 - 000357173 ____A [FCB30B41CBB0B745BAE4071093E7F33C] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_6.9.2015_JI_3.pdf
2015-09-06 15:07 - 2015-09-06 15:07 - 000276803 ____A [0BFB5A86F8EF3A9A96DF7DA4AEC2D42B] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_6.9.2015_JI_4.pdf
2015-09-06 16:20 - 2015-09-06 16:20 - 000277096 ____A [0C17D6115954B6A3F660EE39C296CD44] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_6.9.2015_JI_5.pdf
2015-09-09 09:14 - 2015-09-09 09:14 - 000265831 ____A [F819B8DF7210A52BC41B58D60B634E2D] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\_9.9.2015_COMBI_1.pdf
2015-03-20 12:40 - 2015-03-20 12:40 - 000353975 ____A [658058EB4B4050D67C503B92BFF5F26E] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\David Horák_20.3.2015_Srovnání_1.pdf
2015-03-19 21:24 - 2015-03-14 21:47 - 000376850 ____A [EBE26AB32CE5880F306BF48B3848ECB4] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\DPS_14.3.2015_Jan Horák_1.pdf
2015-03-19 21:24 - 2015-03-18 14:51 - 000267330 ____A [183BA2C3E509D7B6F3D1E962A3FDEB70] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\DPS_18.3.2015__1.pdf
2015-03-19 21:24 - 2015-03-18 17:45 - 000269755 ____A [AC50CF84029BA1751699FD3415815764] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\DPS_18.3.2015__2.pdf
2015-03-19 21:24 - 2015-03-14 20:45 - 000555925 ____A [DB90D83AA112C293CD526C73007FE2A4] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\FMK_14.3.2015_Jan Horák_1.pdf
2015-03-19 21:24 - 2015-03-14 21:22 - 000538295 ____A [3ED8E9DE62CE9BB54665A120B64D966E] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\FMK_14.3.2015_Jan Horák_2.pdf
2017-06-01 12:08 - 2017-06-01 12:08 - 000786328 ____A [20DA7E14E201A5620A9FB107DFDB9798] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\František Vomáčka_1.6.2017_HI_1.pdf
2015-03-19 21:24 - 2015-03-14 21:29 - 000554928 ____A [4C31169477A977FCDB20C676AFF1BBDD] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\HI_14.3.2015_Jan Horák_1.pdf
2016-03-21 11:52 - 2016-03-21 11:52 - 000458953 ____A [8C20931B937F0B985BA5ABF45CFF7ABD] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Jana McSweeney_21.3.2016_PIP_1.pdf
2016-03-21 11:52 - 2016-03-21 11:52 - 000459286 ____A [17FE853827940392076FFDE4EF01DE7B] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Jana McSweeney_21.3.2016_PIP_2.pdf
2017-11-14 02:50 - 2017-11-14 02:50 - 000781705 ____A [CA9395890D1B88553157E20B6EABDD9C] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Michal Svátek_14.11.2017_HI_1.pdf
2016-06-11 16:50 - 2016-06-11 16:50 - 000550494 ____A [174BBC9F9A37C191ED8195349366CFB7] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Oktavián Chloupek_11.6.2016_HI_1.pdf
2015-03-19 21:24 - 2015-03-15 21:42 - 000355700 ____A [6C1AEDBB7A37137B907D0118AEB17545] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Srovnání_15.3.2015_Jan Horák_1.pdf
2015-03-19 21:24 - 2015-03-15 21:44 - 000355147 ____A [5B364146FA677426C96E7FF2FB032C1F] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Srovnání_15.3.2015_Jan Horák_2.pdf
2015-03-19 21:24 - 2015-03-15 21:49 - 000355321 ____A [FB626E0144BE8EDD74AD17ACFE8004D4] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\Srovnání_15.3.2015_Jan Horák_3.pdf
2015-03-19 21:24 - 2015-03-15 20:53 - 000263990 ____A [25A71420ABA6CC2E09D9E41AFFBEBE57] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\SS_15.3.2015_Jan Horák_1.pdf
2015-03-19 21:24 - 2015-03-15 21:15 - 000269318 ____A [A319CA31C3C594F028A34E53EFE361E3] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\SU_15.3.2015_Jan Horák_1.pdf
2015-03-19 21:24 - 2015-03-14 20:37 - 000537395 ____A [3A9989FF16D3E59B4D2CFF981071CCF3] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\TCF_14.3.2015__1.pdf
2015-03-19 21:24 - 2015-03-14 20:40 - 000537768 ____A [810E3FBA7FB291983AC8DD11387AC22F] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\TCF_14.3.2015_Jan Horák_1.pdf
2015-03-19 21:24 - 2015-03-14 20:41 - 000537764 ____A [58E982FEECA708A64E817A818933F8E8] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\TCF_14.3.2015_Jan Horák_2.pdf
2015-03-19 21:24 - 2015-03-15 20:58 - 000258057 ____A [E39DFB58234E42F5CB4D250DADECB87E] () C:\QPlán\QPlán Výstupy\QKalkulátor Výstupy\TV_15.3.2015_Jan Horák_1.pdf
2015-03-19 16:53 - 2015-03-19 16:46 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\QPlán Výstupy\QRenta Výstupy
2015-10-30 16:12 - 2015-10-30 16:12 - 000443269 ____A [A6E01C981249C18F238FC947D9007982] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budín_Jiří_1960_01_08_QRenta_1.pdf
2016-03-24 14:17 - 2016-03-24 14:17 - 000470527 ____A [70487FCE033300FE00C9F2DCE03A7DA4] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budín_Jiří_1960_01_08_QRenta_2.pdf
2016-03-24 14:29 - 2016-03-24 14:29 - 000473178 ____A [3BE270B7985779D6C13CA10413A7EF88] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budín_Jiří_1960_01_08_QRenta_3.pdf
2016-03-24 14:38 - 2016-03-24 14:38 - 000470802 ____A [ED5F1144B51B9A7F5E2792D24688065F] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budín_Jiří_1960_01_08_QRenta_4.pdf
2015-09-26 16:03 - 2015-09-26 16:03 - 000445869 ____A [AAE3C20A5E2C4D1916D4C5E9BC06BDAE] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budínová_Stanislava_1960_02_21_QRenta_1.pdf
2016-02-29 00:13 - 2016-02-29 00:13 - 000453925 ____A [A0445C426AA0432CDBAE29BB8C038889] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budínová_Stanislava_1960_02_21_QRenta_2.pdf
2016-02-29 00:15 - 2016-02-29 00:15 - 000453925 ____A [81A7885D46B891194BBD14C0C9D95BAB] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budínová_Stanislava_1960_02_21_QRenta_3.pdf
2016-02-29 00:30 - 2016-02-29 00:30 - 000453925 ____A [69814FF93435E3495F2607000CBACF61] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budínová_Stanislava_1960_02_21_QRenta_4.pdf
2016-02-29 00:33 - 2016-02-29 00:33 - 000453925 ____A [7BE4F1FAE3C176D12CDC3E0FEAB74935] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Budínová_Stanislava_1960_02_21_QRenta_5.pdf
2016-06-09 22:11 - 2016-06-09 22:11 - 000512925 ____A [9068A5037548FBEBC8067FBAA70BDBFD] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\fd_sdsd_1965_07_01_QRenta_1.pdf
2016-06-09 22:11 - 2016-06-09 22:11 - 000513201 ____A [582D295DFA1A7C2514C6678A70B74794] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\fd_sdsd_1965_07_01_QRenta_2.pdf
2017-12-17 13:03 - 2017-12-17 13:03 - 000712815 ____A [104DB9D8CCC154E8708B48E77C01824B] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hak_Petr_1980_11_15_QRenta_1.pdf
2015-03-30 15:42 - 2015-03-30 15:42 - 000442984 ____A [73C2BDA1F1ED7351D6C21A50257E44EB] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_1.pdf
2015-03-30 22:15 - 2015-03-30 22:15 - 000442801 ____A [B0281E4028612326A18B3790819A2659] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_2.pdf
2015-03-30 22:49 - 2015-03-30 22:49 - 000445187 ____A [F58F7037436CFC602F1AD82B7A9588D4] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_3.pdf
2015-03-31 00:01 - 2015-03-31 00:01 - 000445181 ____A [398117D65E1CB6BCFAC6D4DF9F628568] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_4.pdf
2015-03-31 00:02 - 2015-03-31 00:02 - 000445180 ____A [2B8497E631A5A8ED870FCACEEEAF26B1] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_5.pdf
2015-03-31 13:16 - 2015-03-31 13:16 - 000444205 ____A [0403AA6B7323B792FB7CAA177C89BB6B] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_6.pdf
2015-03-31 13:38 - 2015-03-31 13:38 - 000444205 ____A [76431236D54E54EC8AD613D1E6DB8ED0] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hemala_Jan_1986_10_17_Výstup_7.pdf
2017-06-01 10:32 - 2017-06-01 10:32 - 000715040 ____A [8C6513EF43E84EBBFDA47DBEF92221A0] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hencová_Daniela_1990_07_15_QRenta_1.pdf
2016-06-09 21:51 - 2016-06-09 21:51 - 000513189 ____A [1774F78FF81EBCF9A78E19C82954DB6C] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hora_Jan_1966_07_12_QRenta_1.pdf
2016-06-09 21:52 - 2016-06-09 21:52 - 000513188 ____A [E3B1AA927C3574C50EADE56C09A46BD5] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hora_Jan_1966_07_12_QRenta_2.pdf
2016-06-09 21:54 - 2016-06-09 21:54 - 000471836 ____A [E48FEAEC1DE7CE028F4007A3359EA509] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hora_Jan_1966_07_12_QRenta_3.pdf
2016-06-09 21:55 - 2016-06-09 21:55 - 000471832 ____A [A2C2786A8EAA7CB81016CA53E939DDA1] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Hora_Jan_1966_07_12_QRenta_4.pdf
2016-02-29 00:04 - 2016-02-29 00:04 - 000453842 ____A [8982ED35919CE28A1A72D0F6FA559520] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_1.pdf
2016-02-29 00:06 - 2016-02-29 00:06 - 000453842 ____A [5F0D91D147AA384D79E142C50E2E0714] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_2.pdf
2016-02-29 00:06 - 2016-02-29 00:06 - 000453842 ____A [F4DDFA5BD47CF8E5CCADA6973D06CAA3] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_3.pdf
2016-02-29 00:09 - 2016-02-29 00:09 - 000454206 ____A [AA4479D02D524CB27BE2A489ED065466] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_4.pdf
2016-02-29 00:12 - 2016-02-29 00:12 - 000454206 ____A [B3381489B9991D17A993EF4344749013] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_5.pdf
2016-02-29 00:14 - 2016-02-29 00:14 - 000454209 ____A [AA83F8FD92D0D2DF079F7BF907A3FCC9] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_6.pdf
2016-06-10 17:09 - 2016-06-10 17:09 - 000515171 ____A [2A31ED3E618026AD7FFB68AC2E240DD9] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_7.pdf
2016-06-10 17:10 - 2016-06-10 17:10 - 000515173 ____A [FEB154D9D38AA4D36AA77D0DF1B51C4A] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_QRenta_8.pdf
2015-03-26 17:07 - 2015-03-26 17:07 - 000443784 ____A [C59FF95B4B39F1824E8D97DA1C00C4EB] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_Výstup_1.pdf
2015-03-26 17:08 - 2015-03-26 17:08 - 000443785 ____A [4E186585139DBDC934364CD37E52186F] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_Výstup_2.pdf
2015-03-27 16:39 - 2015-03-27 16:39 - 000443775 ____A [7648A4E843EAE8C6DD38CA37FB9CB829] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_Výstup_3.pdf
2015-03-30 02:56 - 2015-03-30 02:56 - 000443511 ____A [4BB61B3A8D6A8663E75F5FAA1DC4BD35] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_Výstup_4.pdf
2015-03-30 02:56 - 2015-03-30 02:56 - 000443511 ____A [550729AC2C7C3D7F804925A0E583731E] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Horák_Jan_1990_06_17_Výstup_5.pdf
2015-03-31 00:39 - 2015-03-31 00:39 - 000444920 ____A [87C16FA88408ECF2AE9637C959E75DE4] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Jarý_Petr_1990_07_15_Výstup_1.pdf
2018-03-31 15:45 - 2018-03-31 15:45 - 000315997 ____A [EE58085F20EE58EF21D18F568B2DAA18] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Kovář_Jan_1990_03_25_QRenta_1.pdf
2018-03-31 14:35 - 2018-03-31 14:35 - 000315936 ____A [CC5368B7EBA89BA1FAB5812BBD58BCD6] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Kovář_Jan_1990_08_07_QRenta_1.pdf
2017-01-01 18:41 - 2017-01-01 18:41 - 000709514 ____A [D4E1DDA7D8FE769238D30CD4997296B2] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Kula_Jan_1974_09_22_QRenta_1.pdf
2016-02-29 00:29 - 2016-02-29 00:29 - 000454595 ____A [25ED99D14F4DA2B5E71B5DAC673EB369] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_1.pdf
2016-04-12 11:57 - 2016-04-12 11:57 - 000472392 ____A [CB6BD3507A712AC5E466809BAFB995D7] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_10.pdf
2016-09-01 00:22 - 2016-09-01 00:22 - 000591920 ____A [8F59E78D40B2B5516D924C6D31E27E49] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_11.pdf
2017-01-01 19:18 - 2017-01-01 19:18 - 000709764 ____A [74F840AB3FF917E594636268B9BAC540] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_12.pdf
2016-02-29 00:32 - 2016-02-29 00:32 - 000454599 ____A [D2FB52A3B2B99FF342B6F48277902A34] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_2.pdf
2016-02-29 00:45 - 2016-02-29 00:45 - 000454597 ____A [41E5389F5AB43B4C550E0BB55C238CF9] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_3.pdf
2016-03-09 17:30 - 2016-03-09 17:30 - 000454694 ____A [AE0C69DE50DCCBD606D36849A9C4AB6F] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_4.pdf
2016-03-16 18:02 - 2016-03-16 18:02 - 000471874 ____A [2EBB9C313A6E167E48043E424874B144] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_5.pdf
2016-03-24 14:39 - 2016-03-24 14:39 - 000471880 ____A [B67A51169688C1E35474954B02854AA7] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_6.pdf
2016-03-24 14:40 - 2016-03-24 14:40 - 000471883 ____A [257F182B14100E7B9115DA0A274CAD2E] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_7.pdf
2016-04-07 22:07 - 2016-04-07 22:07 - 000472373 ____A [A7BCAE608B11C084B69862EBD0908CF8] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_8.pdf
2016-04-12 11:38 - 2016-04-12 11:38 - 000472393 ____A [7F7534BAABB9532ABE9D63C0583A5EC2] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Malý_David_1985_12_12_QRenta_9.pdf
2015-10-30 16:20 - 2015-10-30 16:20 - 000442891 ____A [99F1CD8CA3B3A33A2A37659CD7F7F411] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novák_Jan_1980_07_15_QRenta_1.pdf
2016-04-12 11:34 - 2016-04-12 11:34 - 000471808 ____A [ED3E8F985A3195B63CB885369C4D86EB] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotná_Jana_1980_01_01_QRenta_1.pdf
2015-05-20 14:31 - 2015-05-20 14:31 - 000445877 ____A [1BF75B24F8B776BB74241C7686869CA2] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotná_Pavla_1980_01_01_QRenta_1.pdf
2015-05-20 14:31 - 2015-05-20 14:31 - 000445762 ____A [8B6E05110C2D5C9DF38FD58E7EC6D225] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotná_Pavla_1980_01_01_QRenta_2.pdf
2015-05-06 11:28 - 2015-05-06 11:28 - 000424676 ____A [8F76CA3D505527AF217FDAAAB8D018C1] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotná_Pavla_1980_01_01_Výstup_1.pdf
2015-05-20 13:59 - 2015-05-20 13:59 - 000445049 ____A [01A521F1F74226C499A6D8C95282E78D] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotná_Pavla_1980_01_01_Výstup_2.pdf
2015-05-20 14:00 - 2015-05-20 14:00 - 000444940 ____A [E93127E902F6B90304C269A96765B18B] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotná_Pavla_1980_01_01_Výstup_3.pdf
2015-10-30 16:27 - 2015-10-30 16:27 - 000443234 ____A [F0C1EE6592A134248021B1FE62D01ADD] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotný_David_1989_08_14_QRenta_1.pdf
2015-03-23 00:29 - 2015-03-23 00:29 - 000458733 ____A [BA12096083CD59E0AD8D8568FC8956CF] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotný_David_1989_08_14_Výstup_1.pdf
2015-03-23 00:30 - 2015-03-23 00:30 - 000458733 ____A [FCE237428C3F251A4E22CD3F456D6092] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotný_David_1989_08_14_Výstup_2.pdf
2015-03-23 00:30 - 2015-03-23 00:30 - 000458733 ____A [E575C7D4872ACE5480337E07A35587B8] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotný_David_1989_08_14_Výstup_3.pdf
2015-03-23 02:34 - 2015-03-23 02:34 - 000443254 ____A [D91DE278131DF4D7A64E33DE66864CE8] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotný_David_1989_08_14_Výstup_4.pdf
2015-03-23 02:35 - 2015-03-23 02:35 - 000443254 ____A [1D5AED55DD1CD946A90504D9A80A26AE] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Novotný_David_1989_08_14_Výstup_5.pdf
2017-01-01 22:06 - 2017-01-01 22:06 - 000709591 ____A [60B850276377F7FB6CC5A166970D9042] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Rys_Roman_1982_08_15_QRenta_1.pdf
2017-01-01 22:13 - 2017-01-01 22:13 - 000709691 ____A [5F5513C05FEC301FC6AC64A50337CD76] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Rys_Roman_1982_08_15_QRenta_2.pdf
2015-06-14 19:17 - 2015-06-14 19:17 - 000445911 ____A [0C4446C4C709A14814C9A5B48B6A2623] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Skála_Michal_1985_12_17_QRenta_1.pdf
2017-11-14 02:14 - 2017-11-14 02:14 - 000711063 ____A [1B41BFC0C45E9E9317867B897A78D758] () C:\QPlán\QPlán Výstupy\QRenta Výstupy\Svátek_Michal_1982_06_15_QRenta_1.pdf
2017-02-22 23:08 - 2015-03-19 16:46 - 000000000 ____D [00000000000000000000000000000000] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy
2017-02-27 17:15 - 2017-02-27 17:15 - 000581498 ____A [E08490D59593810F4587A596701011DD] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Horešovský_David_1984_09_15_QŽivot_1.pdf
2017-03-01 17:38 - 2017-03-01 17:38 - 000581476 ____A [C78A9FA2E059BDB634DA3280D6529B9D] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nohavica_Jarek_1982_08_19_QŽivot_1.pdf
2017-12-21 23:27 - 2017-12-21 23:27 - 000578871 ____A [158FB2525D9C7E1FE99987D75F969C08] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováček_Jan_1990_08_17_QŽivot_1.pdf
2017-12-21 23:28 - 2017-12-21 23:28 - 000578967 ____A [9E9D76AE5215068243D88EA3FE56CAA6] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováček_Jan_1990_08_17_QŽivot_2.pdf
2017-12-21 23:29 - 2017-12-21 23:29 - 000578967 ____A [B5F2999F41352365D6C0E8C641695B8C] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováček_Jan_1990_08_17_QŽivot_3.pdf
2017-12-21 23:24 - 2017-12-21 23:24 - 000584437 ____A [2C173C57DDDC2F0C5CE32539E50D71C3] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováčková_Lenka_1992_11_02_QŽivot_1.pdf
2017-12-21 23:25 - 2017-12-21 23:25 - 000584437 ____A [A93B37E1AB6435AA87FEAE2DBD8B878D] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováčková_Lenka_1992_11_02_QŽivot_2.pdf
2017-12-21 23:25 - 2017-12-21 23:25 - 000584437 ____A [739DF9587473B5EE02BFE205295CCFD2] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováčková_Lenka_1992_11_02_QŽivot_3.pdf
2017-12-21 23:26 - 2017-12-21 23:26 - 000582434 ____A [82D9718F45AB18C5B7BEE6C11D01B991] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Nováčková_Lenka_1992_11_02_QŽivot_4.pdf
2017-02-23 13:28 - 2017-02-23 13:28 - 000582781 ____A [FC80AE022EC81C62B4A271C402C976BF] () C:\QPlán\QPlán Výstupy\QŽivot Výstupy\Vomáčka_František_1972_02_04_QŽivot_1.pdf

====== End of Folder: ======

HKU\S-1-5-21-2852774663-3114243248-3625044681-2121\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
"HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{d4da7309-b89a-45ec-8ebb-cfb2ae13618b}" => removed successfully
"HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com" => removed successfully
mfefire => service not found.
mfevtp => service not found.
cfwids => service not found.
mfeapfk => service not found.
mfeavfk => service not found.
mfefirek => service not found.
mfehidk => service not found.
mfewfpk => service not found.
"HKLM\System\CurrentControlSet\Services\idsvc" => removed successfully
idsvc => service removed successfully
C:\Users\petr.kopecny.MSQUATRO\Downloads\FRST-OlderVersion => moved successfully
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets" => removed successfully
HKLM\Software\Classes\CLSID\{6B9228DA-9C15-419e-856C-19E768A13BDC} => invalid subkey removed.
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{20BAB122-249D-4F89-B985-9FFA5CBD1F09}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20BAB122-249D-4F89-B985-9FFA5CBD1F09}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{295EA083-66D7-49D6-BB91-8ABC0FFC4EDA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{295EA083-66D7-49D6-BB91-8ABC0FFC4EDA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\rundetector" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A9887B0-F37D-4169-B88B-F0CF987853AB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A9887B0-F37D-4169-B88B-F0CF987853AB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41E007FB-A00C-43FD-BF53-580A3DA6B3E6}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41E007FB-A00C-43FD-BF53-580A3DA6B3E6}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{48AC3E3F-35AD-4C3A-B0CA-F73E8C854A5C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{48AC3E3F-35AD-4C3A-B0CA-F73E8C854A5C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{56871B82-CAA9-4BB0-90F2-CC6C0BB3DC0F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56871B82-CAA9-4BB0-90F2-CC6C0BB3DC0F}" => removed successfully
C:\WINDOWS\System32\Tasks\{6FE0153C-5C4A-4821-8638-5CD756409D8B} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6FE0153C-5C4A-4821-8638-5CD756409D8B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{59A94ED6-A2B5-4525-BDFC-FCC35954AC0F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59A94ED6-A2B5-4525-BDFC-FCC35954AC0F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A43A726-D725-47B4-AE94-0882FFD4E5CA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A43A726-D725-47B4-AE94-0882FFD4E5CA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{828573E3-F205-4843-A269-F01A049297FD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{828573E3-F205-4843-A269-F01A049297FD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8B88A449-0B19-477C-8375-FE02786F91C5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B88A449-0B19-477C-8375-FE02786F91C5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{97239DF1-B99C-46EB-9A0F-E34AA94B3708}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97239DF1-B99C-46EB-9A0F-E34AA94B3708}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B9F686E8-5867-4A30-9CE9-8AF85556457C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9F686E8-5867-4A30-9CE9-8AF85556457C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-Weekend" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C33A9601-DEAC-45A4-AAF8-C3CE16BFE6BC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C33A9601-DEAC-45A4-AAF8-C3CE16BFE6BC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C713EDFE-D0AB-409A-9239-EFFC7E47341C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C713EDFE-D0AB-409A-9239-EFFC7E47341C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DFCDD285-43D2-43EB-B027-30768703D420}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFCDD285-43D2-43EB-B027-30768703D420}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E9C30631-96C0-4CB8-BE63-99FBFA80557C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E9C30631-96C0-4CB8-BE63-99FBFA80557C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F7581B14-6699-43B3-91CC-DD34E0306439}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F7581B14-6699-43B3-91CC-DD34E0306439}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FBE193BD-A0C8-4F51-A3FD-5C36E028747A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FBE193BD-A0C8-4F51-A3FD-5C36E028747A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => removed successfully
"C:\Program Files\Common Files\McAfee" => not found
"C:\Windows\system32\mfevtps.exe" => not found
"C:\WINDOWS\System32\drivers\cfwids.sys" => not found
"C:\WINDOWS\System32\drivers\mfeapfk.sys" => not found
"C:\WINDOWS\System32\drivers\mfeavfk.sys" => not found
"C:\WINDOWS\System32\drivers\mfefirek.sys" => not found
"C:\WINDOWS\System32\drivers\mfehidk.sys" => not found
"C:\WINDOWS\System32\drivers\mfewfpk.sys" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 58538829 B
Java, Flash, Steam htmlcache => 1227 B
Windows/system/drivers => 512896 B
Edge => 13211 B
Chrome => 750013 B
Firefox => 1111882638 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6152 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 6152 B
LocalService => 0 B
NetworkService => 11518 B
NetworkService => 0 B
petr.kopecny.MSQUATRO => 18976362 B
administrator => 31232 B
petr.kopecny => 3779623 B
Administrator.INVESTICE02 => 38357 B
DefaultAppPool => 6152 B

RecycleBin => 0 B
EmptyTemp: => 1.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 22:05:32 ====

Re: Prosím o kontrolu. Děkuji

Napsal: 27 zář 2018 21:38
od Conder
:arrow: Vyzera to OK. Su nejake problemy s PC?

:arrow: Plocha ma cca 5 GB. Presun vsetky subory a zlozky z plochy do dokumentov a na ploche nechaj iba odkazy/zastupcov. Prilis velka velkost plochy moze sposobit spomalenie systemu.

Re: Prosím o kontrolu. Děkuji

Napsal: 27 zář 2018 22:01
od vrchlab
Super, děkuju za pomoc. PC šlape v pohodě.

Re: Prosím o kontrolu. Děkuji

Napsal: 27 zář 2018 22:05
od Conder
:arrow: Tak este upraceme po pouzitych nastrojoch: