prosím o kontrolu logu
Napsal: 22 říj 2018 14:23
Zdravím, posílám log z FRST. Při zapnutí stolního PC se mi mění čas i datum. Prý to může být baterka na desce, ale pro jistotu zasílám scan. Děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10.10.2018
Ran by Šáfa (administrator) on ŠÁFA-PC (22-10-2018 14:49:43)
Running from C:\Users\Šáfa\Desktop
Loaded Profiles: Šáfa (Available Profiles: Šáfa)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCService.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\Monitor.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files\AMD\ATI.ACE\Core-Static\MOM.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(BitTorrent Inc.) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Windows\System32\Codecs\TrayMenu.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(BitTorrent Inc.) C:\Users\Šáfa\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe
(BitTorrent Inc.) C:\Users\Šáfa\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe
(Fuzhou Xianzhi Ruishi Information Technology Co.,Ltd) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Fuzhou Xianzhi Ruishi Information Technology Co.,Ltd) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
(Advanced Micro Devices Inc.) C:\Program Files\AMD\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\SpeedFan\speedfan.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Codec Settings UAC Manager] => C:\Windows\system32\Codecs\CodecUACManager.exe [68992 2017-01-09] ()
HKLM\...\Run: [StartCCC] => C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe [748744 2015-07-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [297592 2018-03-04] (ESET)
HKLM\...\Run: [Family Tree Builder Update] => C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [14517936 2016-07-03] (MyHeritage)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-09-09] (AVAST Software)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [3880640 2017-08-14] (Disc Soft Ltd)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [Advanced SystemCare Ultimate] => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [3703568 2018-08-15] (IObit)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [uTorrent] => C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe [1984184 2018-06-22] (BitTorrent Inc.)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7347928 2017-02-08] (Piriform Ltd)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\MountPoints2: H - H:\SETUP.EXE
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\MountPoints2: {a48d2319-a834-11e7-a944-001d60a5c02a} - G:\SETUP.EXE
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\MountPoints2: {a48d231d-a834-11e7-a944-001d60a5c02a} - H:\SETUP.EXE
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2017-08-20]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\System32\Codecs\TrayMenu.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SpeedFan.lnk [2017-09-18]
ShortcutTarget: SpeedFan.lnk -> C:\Program Files\SpeedFan\speedfan.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E1E2B149-F77E-4E59-B357-9D1334912906}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{FE849000-500A-4145-A97A-0D2228DA8136}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3680866379-1800367177-3165316198-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10438__180128__yaie&p={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll [2018-01-31] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-31] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
FireFox:
========
FF Plugin: @EDVR/WebClient -> C:\windows\system32\WebClient\npwebclient.dll [2014-10-30] ( )
FF Plugin: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-31] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-31] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)
Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.google.co.in/"
CHR Profile: C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default [2018-10-22]
CHR Extension: (Prezentace) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15]
CHR Extension: (Dokumenty) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15]
CHR Extension: (Disk Google) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-20]
CHR Extension: (Zhasnout světla) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2018-09-22]
CHR Extension: (Celá obrazovka Flash) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdldlonfinlckniaobgoadifkdldhhf [2017-10-03]
CHR Extension: (YouTube) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (Adobe Acrobat) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-12-03]
CHR Extension: (Tabulky) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-15]
CHR Extension: (Dokumenty Google offline) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (AdBlock) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-10-18]
CHR Extension: (Komponenta pro aplikaci SERVIS 24) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gincjcoomijeeoddomaaimknmflggfnb [2018-09-29]
CHR Extension: (Avast Online Security) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-09-26]
CHR Extension: (Looper for YouTube) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg [2018-08-01]
CHR Extension: (Open in VLC media player) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihpiinojhnfhpdmmacgmpoonphhimkaj [2018-10-05]
CHR Extension: (DjVu Viewer Extension) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghccooedabolhnplggblcggcbplekbk [2017-10-03]
CHR Extension: (Tlačítko Google Scholar) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldipcbpaocekfooobnbcddclnhejkcpn [2017-10-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Gmail) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-20]
CHR Extension: (Chrome Media Router) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-20]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
===================== Drivers (Whitelisted) ======================
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-10-22 14:49 - 2018-10-22 14:51 - 000013531 _____ C:\Users\Šáfa\Desktop\FRST.txt
2018-10-22 14:49 - 2018-10-22 14:49 - 000000000 ____D C:\FRST
2018-10-22 14:40 - 2018-10-22 14:41 - 001774592 _____ (Farbar) C:\Users\Šáfa\Desktop\FRST.exe
2018-10-17 19:55 - 2018-10-17 19:55 - 000008224 _____ C:\Users\Šáfa\Downloads\cc_20181017_195503.reg
2018-10-10 21:56 - 2018-09-19 10:08 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll
2018-10-10 21:56 - 2018-09-18 20:10 - 000348976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-10-10 21:56 - 2018-09-18 06:33 - 020278784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-10-10 21:56 - 2018-09-18 06:31 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-10-10 21:56 - 2018-09-18 06:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-10-10 21:56 - 2018-09-18 06:21 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-10-10 21:56 - 2018-09-18 06:21 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-10-10 21:56 - 2018-09-18 06:20 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-10-10 21:56 - 2018-09-18 06:20 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-10-10 21:56 - 2018-09-18 06:19 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-10-10 21:56 - 2018-09-18 06:18 - 002295808 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-10-10 21:56 - 2018-09-18 06:15 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-10-10 21:56 - 2018-09-18 06:15 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-10-10 21:56 - 2018-09-18 06:14 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-10-10 21:56 - 2018-09-18 06:13 - 000662016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-10-10 21:56 - 2018-09-18 06:13 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-10-10 21:56 - 2018-09-18 06:13 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-10-10 21:56 - 2018-09-18 06:12 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-10-10 21:56 - 2018-09-18 06:09 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-10-10 21:56 - 2018-09-18 06:06 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-10-10 21:56 - 2018-09-18 06:03 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-10-10 21:56 - 2018-09-18 06:02 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-10-10 21:56 - 2018-09-18 06:02 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-10-10 21:56 - 2018-09-18 06:00 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-10-10 21:56 - 2018-09-18 05:59 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-10-10 21:56 - 2018-09-18 05:58 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-10-10 21:56 - 2018-09-18 05:57 - 004494848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-10-10 21:56 - 2018-09-18 05:57 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-10-10 21:56 - 2018-09-18 05:53 - 013679616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-10-10 21:56 - 2018-09-18 05:52 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-10-10 21:56 - 2018-09-18 05:51 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-10-10 21:56 - 2018-09-18 05:51 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-10-10 21:56 - 2018-09-18 05:50 - 002059776 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-10-10 21:56 - 2018-09-18 05:50 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-10-10 21:56 - 2018-09-18 05:37 - 004037632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-10-10 21:56 - 2018-09-18 05:34 - 001330176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-10-10 21:56 - 2018-09-18 05:31 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-10-10 21:56 - 2018-09-11 20:23 - 002404864 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-10-10 21:56 - 2018-09-11 20:20 - 000126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-10-10 21:56 - 2018-09-11 20:20 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 004054216 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-10-10 21:56 - 2018-09-09 02:46 - 003959496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-10-10 21:56 - 2018-09-09 02:46 - 001310488 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 001214152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000730824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000219336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000189640 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 000189640 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 000137928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000136392 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 000067272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-10-10 21:56 - 2018-09-09 02:44 - 002755584 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 001391104 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-10-10 21:56 - 2018-09-09 02:18 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-10-10 21:56 - 2018-09-09 02:18 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-10-10 21:56 - 2018-09-09 02:18 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-10-10 21:56 - 2018-09-09 02:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-10-10 21:56 - 2018-09-09 02:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-10-10 21:56 - 2018-09-09 02:16 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-10-10 21:56 - 2018-09-09 02:15 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-10-10 21:56 - 2018-09-09 02:13 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-10-10 21:56 - 2018-09-09 02:12 - 000055296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\viac7.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-10-10 21:56 - 2018-09-09 02:12 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-10-10 21:56 - 2018-09-09 02:12 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-10-10 21:56 - 2018-08-28 08:09 - 012574208 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2018-10-10 21:56 - 2018-08-28 08:09 - 011411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-10-10 21:56 - 2018-08-28 07:52 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2018-10-10 21:56 - 2018-08-28 07:52 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2018-10-10 21:56 - 2018-08-28 07:52 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2018-10-10 21:56 - 2018-08-16 04:14 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2018-10-10 21:56 - 2018-08-13 23:48 - 000940784 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2018-10-10 21:56 - 2018-08-13 17:41 - 000527872 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2018-10-10 21:56 - 2018-08-12 22:17 - 000122536 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-10-10 21:56 - 2018-08-12 22:13 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-10-10 21:56 - 2018-08-08 17:40 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-10-10 21:56 - 2018-08-08 17:40 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2098-10-22 03:48 - 2017-08-20 20:01 - 000000000 ____D C:\Program Files\SpeedFan
2098-10-22 03:40 - 2018-05-09 14:20 - 000000000 ____D C:\Users\Šáfa\AppData\LocalLow\uTorrent
2098-10-22 03:40 - 2017-08-19 21:08 - 000000000 ____D C:\ProgramData\ProductData
2098-10-22 03:38 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2052-10-16 21:14 - 2018-01-29 13:47 - 000002311 _____ C:\Users\Public\Desktop\Advanced SystemCare Ultimate 11.lnk
2018-10-22 14:51 - 2017-08-19 21:05 - 000000000 ____D C:\Users\Šáfa\AppData\Roaming\uTorrent
2018-10-22 14:51 - 2009-07-14 06:34 - 000014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-10-22 14:51 - 2009-07-14 06:34 - 000014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-10-21 20:20 - 2017-09-02 14:49 - 000000000 ____D C:\Users\Šáfa\AppData\Roaming\vlc
2018-10-18 01:48 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2018-10-15 23:48 - 2018-07-04 17:53 - 000479504 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-10-13 11:17 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache
2018-10-11 10:35 - 2017-08-20 19:48 - 000486108 _____ C:\Windows\system32\perfh014.dat
2018-10-11 10:35 - 2017-08-20 19:48 - 000095062 _____ C:\Windows\system32\perfc014.dat
2018-10-11 10:35 - 2017-08-20 19:44 - 000688802 _____ C:\Windows\system32\perfh007.dat
2018-10-11 10:35 - 2017-08-20 19:44 - 000148774 _____ C:\Windows\system32\perfc007.dat
2018-10-11 10:35 - 2017-08-18 20:00 - 002999612 _____ C:\Windows\system32\PerfStringBackup.INI
2018-10-11 10:35 - 2009-07-14 10:44 - 000668542 _____ C:\Windows\system32\perfh005.dat
2018-10-11 10:35 - 2009-07-14 10:44 - 000141202 _____ C:\Windows\system32\perfc005.dat
2018-10-11 10:27 - 2009-07-14 06:33 - 000423840 _____ C:\Windows\system32\FNTCACHE.DAT
2018-10-11 00:54 - 2017-08-20 19:24 - 000000000 ____D C:\Windows\system32\MRT
2018-10-11 00:50 - 2017-08-20 19:23 - 133674168 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-10-10 22:00 - 2018-01-19 19:12 - 000000000 ____D C:\Users\Šáfa\Desktop\Studium
2018-10-09 23:04 - 2017-12-31 13:07 - 000000000 ____D C:\Users\Šáfa\AppData\Roaming\AirDroid
2018-10-09 22:45 - 2017-12-31 13:06 - 000001913 _____ C:\Users\Public\Desktop\AirDroid.lnk
2018-10-09 12:12 - 2017-11-21 17:56 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-10-05 23:07 - 2018-09-21 21:54 - 000000000 ____D C:\Users\Šáfa\AppData\Local\ThisSideUp
2018-10-02 18:23 - 2017-11-21 17:57 - 000000000 ____D C:\Users\Šáfa\AppData\LocalLow\Adobe
Some files in TEMP:
====================
2017-08-20 20:04 - 2098-10-22 03:48 - 000192512 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfamcc00001.dll
2018-09-20 23:06 - 2098-10-22 03:48 - 000158720 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfareca00001.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-10-18 19:54
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10.10.2018
Ran by Šáfa (22-10-2018 14:52:16)
Running from C:\Users\Šáfa\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2017-08-18 17:55:41)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3680866379-1800367177-3165316198-500 - Administrator - Disabled)
Guest (S-1-5-21-3680866379-1800367177-3165316198-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3680866379-1800367177-3165316198-1002 - Limited - Enabled)
Šáfa (S-1-5-21-3680866379-1800367177-3165316198-1000 - Administrator - Enabled) => C:\Users\Šáfa
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Advanced SystemCare Ultimate (Disabled - Out of date) {91A1210C-78DD-A71C-E865-63DB27C767EE}
AV: ESET NOD32 Antivirus (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: ESET NOD32 Antivirus (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\uTorrent) (Version: 3.5.3.44494 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.008.20074 - Adobe Systems Incorporated)
Adobe Flash Player 27 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Advanced SystemCare Ultimate 11 (HKLM\...\Advanced SystemCare Ultimate_is1) (Version: 11.2.0 - IObit)
AirDroid 3.6.0.0 (HKLM\...\AirDroid) (Version: 3.6.0.0 - Sand Studio)
AMD Catalyst Install Manager (HKLM\...\{6649FF3E-5231-B481-3376-8108FDF1EAD3}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apowersoft Phone Manager verze 2.8.9 (HKLM\...\{4A00E3C4-2D0F-4AE7-9F2A-74870BE09EF8}_is1) (Version: 2.8.9 - APOWERSOFT LIMITED)
Atheros Communications Inc.(R) L1 Gigabit Ethernet Driver (HKLM\...\{6E19F210-3813-4002-B561-94D66AA182B6}) (Version: 2.4.7.29 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 18.6.2349 - AVAST Software)
Brother's Keeper 6.2 (HKLM\...\Brother's Keeper 6.2) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform)
CPUID CPU-Z 1.80 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) <==== ATTENTION
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.6.0.0283 - Disc Soft Ltd)
DjVu Viewer version 1.0 (HKLM\...\{3A959BCB-643A-462F-A692-5B7FE4CE35AC}_is1) (Version: 1.0 - djvuviewer.com)
D-Link DWA-131 - V5.04b03 (HKLM\...\{B7C11488-750D-4E48-A9A4-7207A335984D}) (Version: 5.00.0000 - D-Link)
ESET NOD32 Antivirus (HKLM\...\{DA272F71-1048-429B-B4F8-EC7AE64DF265}) (Version: 10.1.219.1 - ESET, spol. s r.o.)
Google Chrome (HKLM\...\Google Chrome) (Version: 69.0.3497.100 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM\...\{520F0634-40C0-453F-8C84-4EFAE89989A8}) (Version: 19.60.0 - Intel Corporation)
Java 8 Update 161 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (norsk språkpakke) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1044) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
MoboPlay for iOS (HKLM\...\iMoboPlay) (Version: 3.0.6.339 - Xianzhi)
MyHeritage Family Tree Builder (HKLM\...\Family Tree Builder) (Version: 8.0.0.8296 - MyHeritage.com)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM\...\{90160000-001F-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM\...\{90160000-001F-041B-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
OpenAL (HKLM\...\OpenAL) (Version: - )
PlaysTV (HKLM\...\PlaysTV) (Version: 1.27.5-r125535-release - Plays.tv, LLC)
PokerStars.cz (HKLM\...\PokerStars.cz) (Version: - PokerStars.cz)
Raptr (HKLM\...\Raptr) (Version: 5.2.10-r123135-release - Raptr, Inc)
SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - )
Super Mp3 Download (HKLM\...\SuperMp3Download) (Version: 5.0.4.8 - )
TNod User & Password Finder (HKLM\...\TNod) (Version: 1.6.1.0 - Tukero[X]Team)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.8 - VideoLAN)
Web Companion (HKLM\...\{b9462242-e767-4601-93ed-3fdb40dba4ee}) (Version: 4.0.1780.3335 - Lavasoft)
WebClient (HKLM\...\WebClient) (Version: - )
Windows 7 Codec Pack 4.1.7 (HKLM\...\Windows 7 - Codec Pack) (Version: 4.1.7 - Windows 7 Codec Pack)
WinRAR 5.50 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll [2017-11-06] (IObit)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-03-04] (ESET)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll [2017-11-06] (IObit)
ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-03-04] (ESET)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll [2017-11-06] (IObit)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\ATI.ACE\Core-Static\atiacmxx.dll [2015-07-15] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-03-04] (ESET)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {10FFF174-D986-46F0-B84D-A286E19B27FF} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-09-16] (AVAST Software)
Task: {12B2C551-A568-4646-9937-652F3A2507AE} - System32\Tasks\ASCU_ASCTray_Auto => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2018-08-15] (IObit)
Task: {31FFA406-59EF-4C98-B283-53B7DF3A58DD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-08-20] (Google Inc.)
Task: {500F9538-ADA6-4F2D-8B95-8CF5A98991E6} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation)
Task: {50F715FF-65FD-40F8-BB29-9A610FF0B9D8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
Task: {6651A83C-C3A8-44C4-AB7E-76D2742D76E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-08-20] (Google Inc.)
Task: {6747B6EF-F493-457B-9E69-FC852312D927} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-09-09] (AVAST Software)
Task: {705C825C-7BD1-4494-AC9F-D5AD2A07943F} - System32\Tasks\{61EDCE40-776C-4E71-B92A-00D8117873DA} => C:\Windows\system32\pcalua.exe -a "D:\Programy\ovladače REALTEK\nové\WDM_R248.exe" -d "D:\Programy\ovladače REALTEK\nové"
Task: {73456731-A096-42A1-BA86-F7D1697B443A} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation)
Task: {80A10EF0-99BE-44ED-A3AC-59DCD7551DEF} - System32\Tasks\ASCU11_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare Ultimate\Monitor.exe [2018-03-28] (IObit)
Task: {92DD3AB5-A5B3-4725-8047-43BEE0441FDB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3680866379-1800367177-3165316198-1000
Task: {9E06C6FE-1457-428B-9423-9E1E66E52C7E} - System32\Tasks\ASCU11_SkipUac_Šáfa => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASC.exe [2018-08-23] (IObit)
Task: {AF9FEEE6-2507-403D-9989-125E040D8978} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)
Task: {ED2DDC6E-879D-4445-94C1-DF62FD8EAB6C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
Task: {FDACCCD0-4AE4-457F-B3F7-8193EB0BF761} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-08] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-09-09 11:33 - 2018-09-09 11:33 - 000575704 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-10-21 18:08 - 2018-10-21 18:08 - 005678224 _____ () C:\Program Files\AVAST Software\Avast\defs\18102102\algo.dll
2018-09-09 11:36 - 2018-09-09 11:36 - 000896216 _____ () C:\Program Files\AVAST Software\Avast\anen.dll
2018-09-09 11:33 - 2018-09-09 11:33 - 000541400 _____ () C:\Program Files\AVAST Software\Avast\gui_cache.dll
2018-09-09 11:33 - 2018-09-09 11:33 - 000151768 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll
2018-09-09 11:33 - 2018-09-09 11:33 - 000986840 _____ () C:\Program Files\AVAST Software\Avast\shepherdsync.dll
2018-05-02 14:33 - 2017-08-04 13:44 - 000082720 _____ () C:\Program Files\IObit\Advanced SystemCare Ultimate\GetProcessDLL.dll
2018-09-09 11:36 - 2018-09-09 11:36 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-08-16 02:15 - 2016-08-16 02:15 - 000897224 _____ () C:\Windows\System32\Codecs\TrayMenu.exe
2013-02-17 19:35 - 2012-12-21 20:33 - 000020288 _____ () C:\Program Files\CCleaner\branding.dll
2017-02-08 04:52 - 2017-02-08 04:52 - 000065536 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000220176 _____ () C:\Program Files\Xianzhi\Service\Utility.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000070672 _____ () C:\Program Files\Xianzhi\Service\AutoStatistic.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000250384 _____ () C:\Program Files\Xianzhi\Service\Singleton.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000262160 _____ () C:\Program Files\Xianzhi\Service\AINTERFACE.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000886288 _____ () C:\Program Files\Xianzhi\Service\NetInterface.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 003011088 _____ () C:\Program Files\Xianzhi\Service\FUMODL.dll
2016-06-29 20:01 - 2016-06-29 20:01 - 008166536 _____ () C:\Program Files\SpeedFan\speedfan.exe
2018-09-20 23:06 - 2098-10-22 03:48 - 000158720 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfareca00001.dll
2017-08-20 20:04 - 2098-10-22 03:48 - 000192512 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfamcc00001.dll
2018-09-19 23:51 - 2018-09-15 10:48 - 004317528 _____ () C:\Program Files\Google\Chrome\Application\69.0.3497.100\libglesv2.dll
2018-09-19 23:51 - 2018-09-15 10:48 - 000096600 _____ () C:\Program Files\Google\Chrome\Application\69.0.3497.100\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:04 - 2018-10-14 22:34 - 000000825 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Šáfa\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{B8D42AEC-7EFA-4CE4-B282-1116E134B6FC}] => (Allow) C:\Program Files\D-Link\DWA-131 revE\IHV\RTLDHCP.exe
FirewallRules: [{A41A91CD-E2C7-4A34-B037-52DAA603BCFB}] => (Allow) C:\Program Files\D-Link\DWA-131 revE\IHV\PortableWiFi.exe
FirewallRules: [{481311B2-2A7B-4B73-A833-1143A8CEDDDB}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{99E816D9-4C80-4B59-9245-ACBECD49781B}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe
FirewallRules: [{687E5111-C8E9-4A1D-85F0-C52F93810D9F}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe
FirewallRules: [{20527A9A-0FB7-4593-A102-3D2C3244C132}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{CE8A82FB-1996-4992-980D-1EA98F181457}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{CE125627-50E8-4E67-BC42-F799795F04E7}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{5223EC30-E84B-436D-A4BF-F9BE1CCB2256}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{8090831E-FFD5-48E6-A292-F51049D02EBA}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{2E0E273E-B68B-4413-8B5C-4E303DD3733B}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{BDE22887-B5DA-4CD6-9A4C-EEEAA69472FE}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{985153DD-F759-4D73-A260-459D903A46E1}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{EB6ACA6A-6240-417D-83B8-408A8C3EAC71}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{2B5AEE82-4558-4DCF-A63A-46C2F28DBAC1}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{55B6188E-316F-4918-B7CF-CF7AB82046F2}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{B103C80F-C91B-4DDF-80AB-D9FC120F4467}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{17B9D460-C6AC-41EB-A88E-4375A3F47860}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{A7CDAB9A-4F66-4599-B3C6-6AF85D9E610C}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{DEBB4134-EC86-4103-A4E9-20ADC98BCC5D}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{A8F904EE-7C5A-4619-8FB7-1E6A93105F4D}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{9BB2BE16-9EC1-4E43-AC43-F84E78E33154}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
FirewallRules: [{312DD44B-B8AF-4847-A79F-922DC9F1EE74}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
FirewallRules: [{D73C5F07-B333-46F4-B47D-42E4266461EA}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
FirewallRules: [{000C1D6F-5B1E-49FB-8806-C6B8C740B124}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
FirewallRules: [TCP Query User{94AFB6D0-7A70-4755-A4BC-526D984D8BC6}C:\program files\xianzhi\service\xianzhideviceproxy.exe] => (Block) C:\program files\xianzhi\service\xianzhideviceproxy.exe
FirewallRules: [UDP Query User{A74AA96B-DA42-4AFA-8675-3EFF66FB2EBD}C:\program files\xianzhi\service\xianzhideviceproxy.exe] => (Block) C:\program files\xianzhi\service\xianzhideviceproxy.exe
FirewallRules: [TCP Query User{7BF7D336-A738-4FD1-B227-B43BB3DC2355}C:\program files\airdroid\airdroid.exe] => (Allow) C:\program files\airdroid\airdroid.exe
FirewallRules: [UDP Query User{FE4E3AEC-C74F-4FC1-9A06-CEFC67BEB5BB}C:\program files\airdroid\airdroid.exe] => (Allow) C:\program files\airdroid\airdroid.exe
FirewallRules: [TCP Query User{BE4AD12D-C2AA-49A5-8F30-4D5FE155E929}C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe] => (Allow) C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe
FirewallRules: [UDP Query User{E46EC591-DB33-4F52-916B-AB8F9D10D3D3}C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe] => (Allow) C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe
FirewallRules: [{CEB393A4-7F67-4868-BF53-D5C24F362659}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{C7C1B11F-F1A6-425F-BA26-BF0A4FC9166F}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{753AB5B9-7AFB-405F-8FF9-671F669DAA33}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{E8B1C74C-F1D2-420E-B0DC-E57D16F165D4}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{EB79862E-9C10-4271-B57C-279ED7B9AF97}] => (Allow) C:\Program Files\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{492081D2-089D-4DE7-AA92-B65E3408451F}] => (Allow) C:\Program Files\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [TCP Query User{8B4F475C-C5A8-425F-A90B-739EF9C0E70B}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{8F1A484D-D46A-4988-8691-2B53864C7BBF}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [{8D07AAA4-7468-41ED-BED3-30D218CA5C70}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5415F9E1-ED3E-4A54-9C7E-8F693FAC7B61}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{070F3C69-FE05-4AC4-8B2A-F434BF46CF55}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{464C180B-C4EA-4CF6-B13D-CA2D83256F60}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E00A75EC-30EC-47F6-A7FA-901E1968060E}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{CC3DF070-74B0-4126-9177-824C58862FF8}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C57A1731-6EFB-4186-9ABD-4C0A09F40C4A}] => (Allow) C:\Program Files\IObit\Advanced SystemCare Ultimate\AutoUpdate.exe
FirewallRules: [{D53DEE86-A24C-4CF1-9489-60CD505643B4}] => (Allow) C:\Program Files\IObit\Advanced SystemCare Ultimate\AutoUpdate.exe
FirewallRules: [{DDD41FAC-04F1-4140-993F-547D5B7E7AFB}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{027A0382-896A-4737-B519-6C31D742B84B}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{C8A86F4D-795F-42EF-BAF0-0E7B288422B4}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
21-10-2018 12:53:46 Windows Update
==================== Faulty Device Manager Devices =============
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Standardní klávesnice PS/2
Description: Standardní klávesnice PS/2
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní klávesnice)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/22/2018 02:33:38 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/21/2018 10:20:33 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/19/2018 03:27:06 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/18/2018 06:24:33 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/17/2018 07:55:03 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/14/2018 04:22:06 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/05/2018 11:07:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Vžum.exe, verze: 1.0.6123.42412, časové razítko: 0x57f6c339
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.24168, časové razítko: 0x5b1aa77b
Kód výjimky: 0xe0434352
Posun chyby: 0x0000845d
ID chybujícího procesu: 0x19ac
Čas spuštění chybující aplikace: 0x01d45cef67f54aa2
Cesta k chybující aplikaci: C:\Users\Šáfa\Desktop\Studium\Vžum.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: b5a60f9f-c8e2-11e8-8838-001d60a5c02a
Error: (10/05/2018 11:07:45 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Vžum.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.FileNotFoundException
na Vžum_Reloaded.FileDownloader.ZískejURL(System.String ByRef, System.String ByRef)
na Vžum_Reloaded.FileDownloader.Vlákno()
na System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
na System.Threading.ThreadHelper.ThreadStart()
System errors:
=============
Error: (10/22/2098 03:48:46 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:48:46 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Error: (10/22/2098 03:48:17 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:48:17 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Error: (10/22/2098 03:47:58 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:47:58 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Error: (10/22/2098 03:47:39 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:47:39 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Windows Defender:
===================================
Date: 2018-07-04 17:54:25.892
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci.
Nová verze podpisu:1.271.442.0
Předchozí verze podpisu:1.269.1075.0
Zdroj aktualizace:Uživatel
Typ podpisu:Antispywarový program
Typ aktualizace:Delta
Uživatel:NT AUTHORITY\SYSTEM
Aktuální verze modulu:1.1.15000.2
Předchozí verze modulu:1.1.14901.4
Kód chyby:0x80070666
Popis chyby:Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.
Date: 2018-07-04 17:54:25.891
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci modulu
Nová verze modulu:1.1.15000.2
Předchozí verze modulu:1.1.14901.4
Zdroj aktualizace:Uživatel
Uživatel:NT AUTHORITY\SYSTEM
Kód chyby:0x80070666
Popis chyby:Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz
Percentage of memory in use: 80%
Total physical RAM: 2047.12 MB
Available physical RAM: 403.3 MB
Total Virtual: 4094.23 MB
Available Virtual: 1767.54 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:48.83 GB) (Free:10 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:184.05 GB) (Free:17.66 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 051A0519)
Partition 1: (Active) - (Size=48.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=184 GB) - (Type=0F Extended)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10.10.2018
Ran by Šáfa (administrator) on ŠÁFA-PC (22-10-2018 14:49:43)
Running from C:\Users\Šáfa\Desktop
Loaded Profiles: Šáfa (Available Profiles: Šáfa)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCService.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare Ultimate\Monitor.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files\AMD\ATI.ACE\Core-Static\MOM.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(BitTorrent Inc.) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Windows\System32\Codecs\TrayMenu.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(BitTorrent Inc.) C:\Users\Šáfa\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe
(BitTorrent Inc.) C:\Users\Šáfa\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe
(Fuzhou Xianzhi Ruishi Information Technology Co.,Ltd) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Fuzhou Xianzhi Ruishi Information Technology Co.,Ltd) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
(Advanced Micro Devices Inc.) C:\Program Files\AMD\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\SpeedFan\speedfan.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Codec Settings UAC Manager] => C:\Windows\system32\Codecs\CodecUACManager.exe [68992 2017-01-09] ()
HKLM\...\Run: [StartCCC] => C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe [748744 2015-07-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [297592 2018-03-04] (ESET)
HKLM\...\Run: [Family Tree Builder Update] => C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [14517936 2016-07-03] (MyHeritage)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-09-09] (AVAST Software)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [3880640 2017-08-14] (Disc Soft Ltd)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [Advanced SystemCare Ultimate] => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [3703568 2018-08-15] (IObit)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [uTorrent] => C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe [1984184 2018-06-22] (BitTorrent Inc.)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7347928 2017-02-08] (Piriform Ltd)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\MountPoints2: H - H:\SETUP.EXE
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\MountPoints2: {a48d2319-a834-11e7-a944-001d60a5c02a} - G:\SETUP.EXE
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\MountPoints2: {a48d231d-a834-11e7-a944-001d60a5c02a} - H:\SETUP.EXE
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2017-08-20]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\System32\Codecs\TrayMenu.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SpeedFan.lnk [2017-09-18]
ShortcutTarget: SpeedFan.lnk -> C:\Program Files\SpeedFan\speedfan.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E1E2B149-F77E-4E59-B357-9D1334912906}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{FE849000-500A-4145-A97A-0D2228DA8136}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3680866379-1800367177-3165316198-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10438__180128__yaie&p={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_161\bin\ssv.dll [2018-01-31] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-31] (Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation)
FireFox:
========
FF Plugin: @EDVR/WebClient -> C:\windows\system32\WebClient\npwebclient.dll [2014-10-30] ( )
FF Plugin: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-31] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-31] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)
Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.google.co.in/"
CHR Profile: C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default [2018-10-22]
CHR Extension: (Prezentace) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15]
CHR Extension: (Dokumenty) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15]
CHR Extension: (Disk Google) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-20]
CHR Extension: (Zhasnout světla) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2018-09-22]
CHR Extension: (Celá obrazovka Flash) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdldlonfinlckniaobgoadifkdldhhf [2017-10-03]
CHR Extension: (YouTube) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (Adobe Acrobat) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-12-03]
CHR Extension: (Tabulky) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-15]
CHR Extension: (Dokumenty Google offline) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (AdBlock) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-10-18]
CHR Extension: (Komponenta pro aplikaci SERVIS 24) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gincjcoomijeeoddomaaimknmflggfnb [2018-09-29]
CHR Extension: (Avast Online Security) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-09-26]
CHR Extension: (Looper for YouTube) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg [2018-08-01]
CHR Extension: (Open in VLC media player) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihpiinojhnfhpdmmacgmpoonphhimkaj [2018-10-05]
CHR Extension: (DjVu Viewer Extension) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jghccooedabolhnplggblcggcbplekbk [2017-10-03]
CHR Extension: (Tlačítko Google Scholar) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldipcbpaocekfooobnbcddclnhejkcpn [2017-10-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Gmail) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-20]
CHR Extension: (Chrome Media Router) - C:\Users\Šáfa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-20]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
===================== Drivers (Whitelisted) ======================
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-10-22 14:49 - 2018-10-22 14:51 - 000013531 _____ C:\Users\Šáfa\Desktop\FRST.txt
2018-10-22 14:49 - 2018-10-22 14:49 - 000000000 ____D C:\FRST
2018-10-22 14:40 - 2018-10-22 14:41 - 001774592 _____ (Farbar) C:\Users\Šáfa\Desktop\FRST.exe
2018-10-17 19:55 - 2018-10-17 19:55 - 000008224 _____ C:\Users\Šáfa\Downloads\cc_20181017_195503.reg
2018-10-10 21:56 - 2018-09-19 10:08 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll
2018-10-10 21:56 - 2018-09-18 20:10 - 000348976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-10-10 21:56 - 2018-09-18 06:33 - 020278784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-10-10 21:56 - 2018-09-18 06:31 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-10-10 21:56 - 2018-09-18 06:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-10-10 21:56 - 2018-09-18 06:21 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-10-10 21:56 - 2018-09-18 06:21 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-10-10 21:56 - 2018-09-18 06:20 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-10-10 21:56 - 2018-09-18 06:20 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-10-10 21:56 - 2018-09-18 06:19 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-10-10 21:56 - 2018-09-18 06:18 - 002295808 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-10-10 21:56 - 2018-09-18 06:15 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-10-10 21:56 - 2018-09-18 06:15 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-10-10 21:56 - 2018-09-18 06:14 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-10-10 21:56 - 2018-09-18 06:13 - 000662016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-10-10 21:56 - 2018-09-18 06:13 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-10-10 21:56 - 2018-09-18 06:13 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-10-10 21:56 - 2018-09-18 06:12 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-10-10 21:56 - 2018-09-18 06:09 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-10-10 21:56 - 2018-09-18 06:06 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-10-10 21:56 - 2018-09-18 06:03 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-10-10 21:56 - 2018-09-18 06:02 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-10-10 21:56 - 2018-09-18 06:02 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-10-10 21:56 - 2018-09-18 06:00 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-10-10 21:56 - 2018-09-18 05:59 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-10-10 21:56 - 2018-09-18 05:58 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-10-10 21:56 - 2018-09-18 05:57 - 004494848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-10-10 21:56 - 2018-09-18 05:57 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-10-10 21:56 - 2018-09-18 05:53 - 013679616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-10-10 21:56 - 2018-09-18 05:52 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-10-10 21:56 - 2018-09-18 05:51 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-10-10 21:56 - 2018-09-18 05:51 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-10-10 21:56 - 2018-09-18 05:50 - 002059776 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-10-10 21:56 - 2018-09-18 05:50 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-10-10 21:56 - 2018-09-18 05:37 - 004037632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-10-10 21:56 - 2018-09-18 05:34 - 001330176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-10-10 21:56 - 2018-09-18 05:31 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-10-10 21:56 - 2018-09-11 20:23 - 002404864 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-10-10 21:56 - 2018-09-11 20:20 - 000126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-10-10 21:56 - 2018-09-11 20:20 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 004054216 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-10-10 21:56 - 2018-09-09 02:46 - 003959496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-10-10 21:56 - 2018-09-09 02:46 - 001310488 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 001214152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000730824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000219336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000189640 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 000189640 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 000137928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-10-10 21:56 - 2018-09-09 02:46 - 000136392 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-10-10 21:56 - 2018-09-09 02:46 - 000067272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-10-10 21:56 - 2018-09-09 02:44 - 002755584 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-10-10 21:56 - 2018-09-09 02:44 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 001391104 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-10-10 21:56 - 2018-09-09 02:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-10-10 21:56 - 2018-09-09 02:42 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-10-10 21:56 - 2018-09-09 02:18 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-10-10 21:56 - 2018-09-09 02:18 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-10-10 21:56 - 2018-09-09 02:18 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-10-10 21:56 - 2018-09-09 02:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-10-10 21:56 - 2018-09-09 02:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-10-10 21:56 - 2018-09-09 02:16 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-10-10 21:56 - 2018-09-09 02:15 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-10-10 21:56 - 2018-09-09 02:13 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-10-10 21:56 - 2018-09-09 02:12 - 000055296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\viac7.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2018-10-10 21:56 - 2018-09-09 02:12 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-10-10 21:56 - 2018-09-09 02:12 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-10-10 21:56 - 2018-09-09 02:12 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-10-10 21:56 - 2018-08-28 08:09 - 012574208 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2018-10-10 21:56 - 2018-08-28 08:09 - 011411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-10-10 21:56 - 2018-08-28 07:52 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2018-10-10 21:56 - 2018-08-28 07:52 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2018-10-10 21:56 - 2018-08-28 07:52 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2018-10-10 21:56 - 2018-08-16 04:14 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2018-10-10 21:56 - 2018-08-13 23:48 - 000940784 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2018-10-10 21:56 - 2018-08-13 17:41 - 000527872 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2018-10-10 21:56 - 2018-08-12 22:17 - 000122536 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-10-10 21:56 - 2018-08-12 22:13 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-10-10 21:56 - 2018-08-08 17:40 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-10-10 21:56 - 2018-08-08 17:40 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2098-10-22 03:48 - 2017-08-20 20:01 - 000000000 ____D C:\Program Files\SpeedFan
2098-10-22 03:40 - 2018-05-09 14:20 - 000000000 ____D C:\Users\Šáfa\AppData\LocalLow\uTorrent
2098-10-22 03:40 - 2017-08-19 21:08 - 000000000 ____D C:\ProgramData\ProductData
2098-10-22 03:38 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2052-10-16 21:14 - 2018-01-29 13:47 - 000002311 _____ C:\Users\Public\Desktop\Advanced SystemCare Ultimate 11.lnk
2018-10-22 14:51 - 2017-08-19 21:05 - 000000000 ____D C:\Users\Šáfa\AppData\Roaming\uTorrent
2018-10-22 14:51 - 2009-07-14 06:34 - 000014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-10-22 14:51 - 2009-07-14 06:34 - 000014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-10-21 20:20 - 2017-09-02 14:49 - 000000000 ____D C:\Users\Šáfa\AppData\Roaming\vlc
2018-10-18 01:48 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf
2018-10-15 23:48 - 2018-07-04 17:53 - 000479504 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-10-13 11:17 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\rescache
2018-10-11 10:35 - 2017-08-20 19:48 - 000486108 _____ C:\Windows\system32\perfh014.dat
2018-10-11 10:35 - 2017-08-20 19:48 - 000095062 _____ C:\Windows\system32\perfc014.dat
2018-10-11 10:35 - 2017-08-20 19:44 - 000688802 _____ C:\Windows\system32\perfh007.dat
2018-10-11 10:35 - 2017-08-20 19:44 - 000148774 _____ C:\Windows\system32\perfc007.dat
2018-10-11 10:35 - 2017-08-18 20:00 - 002999612 _____ C:\Windows\system32\PerfStringBackup.INI
2018-10-11 10:35 - 2009-07-14 10:44 - 000668542 _____ C:\Windows\system32\perfh005.dat
2018-10-11 10:35 - 2009-07-14 10:44 - 000141202 _____ C:\Windows\system32\perfc005.dat
2018-10-11 10:27 - 2009-07-14 06:33 - 000423840 _____ C:\Windows\system32\FNTCACHE.DAT
2018-10-11 00:54 - 2017-08-20 19:24 - 000000000 ____D C:\Windows\system32\MRT
2018-10-11 00:50 - 2017-08-20 19:23 - 133674168 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-10-10 22:00 - 2018-01-19 19:12 - 000000000 ____D C:\Users\Šáfa\Desktop\Studium
2018-10-09 23:04 - 2017-12-31 13:07 - 000000000 ____D C:\Users\Šáfa\AppData\Roaming\AirDroid
2018-10-09 22:45 - 2017-12-31 13:06 - 000001913 _____ C:\Users\Public\Desktop\AirDroid.lnk
2018-10-09 12:12 - 2017-11-21 17:56 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-10-05 23:07 - 2018-09-21 21:54 - 000000000 ____D C:\Users\Šáfa\AppData\Local\ThisSideUp
2018-10-02 18:23 - 2017-11-21 17:57 - 000000000 ____D C:\Users\Šáfa\AppData\LocalLow\Adobe
Some files in TEMP:
====================
2017-08-20 20:04 - 2098-10-22 03:48 - 000192512 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfamcc00001.dll
2018-09-20 23:06 - 2098-10-22 03:48 - 000158720 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfareca00001.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-10-18 19:54
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10.10.2018
Ran by Šáfa (22-10-2018 14:52:16)
Running from C:\Users\Šáfa\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2017-08-18 17:55:41)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3680866379-1800367177-3165316198-500 - Administrator - Disabled)
Guest (S-1-5-21-3680866379-1800367177-3165316198-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3680866379-1800367177-3165316198-1002 - Limited - Enabled)
Šáfa (S-1-5-21-3680866379-1800367177-3165316198-1000 - Administrator - Enabled) => C:\Users\Šáfa
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Advanced SystemCare Ultimate (Disabled - Out of date) {91A1210C-78DD-A71C-E865-63DB27C767EE}
AV: ESET NOD32 Antivirus (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: ESET NOD32 Antivirus (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\uTorrent) (Version: 3.5.3.44494 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.008.20074 - Adobe Systems Incorporated)
Adobe Flash Player 27 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Advanced SystemCare Ultimate 11 (HKLM\...\Advanced SystemCare Ultimate_is1) (Version: 11.2.0 - IObit)
AirDroid 3.6.0.0 (HKLM\...\AirDroid) (Version: 3.6.0.0 - Sand Studio)
AMD Catalyst Install Manager (HKLM\...\{6649FF3E-5231-B481-3376-8108FDF1EAD3}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apowersoft Phone Manager verze 2.8.9 (HKLM\...\{4A00E3C4-2D0F-4AE7-9F2A-74870BE09EF8}_is1) (Version: 2.8.9 - APOWERSOFT LIMITED)
Atheros Communications Inc.(R) L1 Gigabit Ethernet Driver (HKLM\...\{6E19F210-3813-4002-B561-94D66AA182B6}) (Version: 2.4.7.29 - Atheros Communications Inc.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 18.6.2349 - AVAST Software)
Brother's Keeper 6.2 (HKLM\...\Brother's Keeper 6.2) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform)
CPUID CPU-Z 1.80 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) <==== ATTENTION
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.6.0.0283 - Disc Soft Ltd)
DjVu Viewer version 1.0 (HKLM\...\{3A959BCB-643A-462F-A692-5B7FE4CE35AC}_is1) (Version: 1.0 - djvuviewer.com)
D-Link DWA-131 - V5.04b03 (HKLM\...\{B7C11488-750D-4E48-A9A4-7207A335984D}) (Version: 5.00.0000 - D-Link)
ESET NOD32 Antivirus (HKLM\...\{DA272F71-1048-429B-B4F8-EC7AE64DF265}) (Version: 10.1.219.1 - ESET, spol. s r.o.)
Google Chrome (HKLM\...\Google Chrome) (Version: 69.0.3497.100 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM\...\{520F0634-40C0-453F-8C84-4EFAE89989A8}) (Version: 19.60.0 - Intel Corporation)
Java 8 Update 161 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (norsk språkpakke) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1044) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
MoboPlay for iOS (HKLM\...\iMoboPlay) (Version: 3.0.6.339 - Xianzhi)
MyHeritage Family Tree Builder (HKLM\...\Family Tree Builder) (Version: 8.0.0.8296 - MyHeritage.com)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM\...\{90160000-001F-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM\...\{90160000-001F-041B-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
OpenAL (HKLM\...\OpenAL) (Version: - )
PlaysTV (HKLM\...\PlaysTV) (Version: 1.27.5-r125535-release - Plays.tv, LLC)
PokerStars.cz (HKLM\...\PokerStars.cz) (Version: - PokerStars.cz)
Raptr (HKLM\...\Raptr) (Version: 5.2.10-r123135-release - Raptr, Inc)
SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - )
Super Mp3 Download (HKLM\...\SuperMp3Download) (Version: 5.0.4.8 - )
TNod User & Password Finder (HKLM\...\TNod) (Version: 1.6.1.0 - Tukero[X]Team)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.8 - VideoLAN)
Web Companion (HKLM\...\{b9462242-e767-4601-93ed-3fdb40dba4ee}) (Version: 4.0.1780.3335 - Lavasoft)
WebClient (HKLM\...\WebClient) (Version: - )
Windows 7 Codec Pack 4.1.7 (HKLM\...\Windows 7 - Codec Pack) (Version: 4.1.7 - Windows 7 Codec Pack)
WinRAR 5.50 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll [2017-11-06] (IObit)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-03-04] (ESET)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll [2017-11-06] (IObit)
ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-03-04] (ESET)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll [2017-11-06] (IObit)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\ATI.ACE\Core-Static\atiacmxx.dll [2015-07-15] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-09-09] (AVAST Software)
ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-03-04] (ESET)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {10FFF174-D986-46F0-B84D-A286E19B27FF} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-09-16] (AVAST Software)
Task: {12B2C551-A568-4646-9937-652F3A2507AE} - System32\Tasks\ASCU_ASCTray_Auto => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2018-08-15] (IObit)
Task: {31FFA406-59EF-4C98-B283-53B7DF3A58DD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-08-20] (Google Inc.)
Task: {500F9538-ADA6-4F2D-8B95-8CF5A98991E6} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation)
Task: {50F715FF-65FD-40F8-BB29-9A610FF0B9D8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
Task: {6651A83C-C3A8-44C4-AB7E-76D2742D76E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2017-08-20] (Google Inc.)
Task: {6747B6EF-F493-457B-9E69-FC852312D927} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-09-09] (AVAST Software)
Task: {705C825C-7BD1-4494-AC9F-D5AD2A07943F} - System32\Tasks\{61EDCE40-776C-4E71-B92A-00D8117873DA} => C:\Windows\system32\pcalua.exe -a "D:\Programy\ovladače REALTEK\nové\WDM_R248.exe" -d "D:\Programy\ovladače REALTEK\nové"
Task: {73456731-A096-42A1-BA86-F7D1697B443A} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation)
Task: {80A10EF0-99BE-44ED-A3AC-59DCD7551DEF} - System32\Tasks\ASCU11_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare Ultimate\Monitor.exe [2018-03-28] (IObit)
Task: {92DD3AB5-A5B3-4725-8047-43BEE0441FDB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3680866379-1800367177-3165316198-1000
Task: {9E06C6FE-1457-428B-9423-9E1E66E52C7E} - System32\Tasks\ASCU11_SkipUac_Šáfa => C:\Program Files\IObit\Advanced SystemCare Ultimate\ASC.exe [2018-08-23] (IObit)
Task: {AF9FEEE6-2507-403D-9989-125E040D8978} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)
Task: {ED2DDC6E-879D-4445-94C1-DF62FD8EAB6C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
Task: {FDACCCD0-4AE4-457F-B3F7-8193EB0BF761} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-08] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-09-09 11:33 - 2018-09-09 11:33 - 000575704 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-10-21 18:08 - 2018-10-21 18:08 - 005678224 _____ () C:\Program Files\AVAST Software\Avast\defs\18102102\algo.dll
2018-09-09 11:36 - 2018-09-09 11:36 - 000896216 _____ () C:\Program Files\AVAST Software\Avast\anen.dll
2018-09-09 11:33 - 2018-09-09 11:33 - 000541400 _____ () C:\Program Files\AVAST Software\Avast\gui_cache.dll
2018-09-09 11:33 - 2018-09-09 11:33 - 000151768 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll
2018-09-09 11:33 - 2018-09-09 11:33 - 000986840 _____ () C:\Program Files\AVAST Software\Avast\shepherdsync.dll
2018-05-02 14:33 - 2017-08-04 13:44 - 000082720 _____ () C:\Program Files\IObit\Advanced SystemCare Ultimate\GetProcessDLL.dll
2018-09-09 11:36 - 2018-09-09 11:36 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-08-16 02:15 - 2016-08-16 02:15 - 000897224 _____ () C:\Windows\System32\Codecs\TrayMenu.exe
2013-02-17 19:35 - 2012-12-21 20:33 - 000020288 _____ () C:\Program Files\CCleaner\branding.dll
2017-02-08 04:52 - 2017-02-08 04:52 - 000065536 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000220176 _____ () C:\Program Files\Xianzhi\Service\Utility.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000070672 _____ () C:\Program Files\Xianzhi\Service\AutoStatistic.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000250384 _____ () C:\Program Files\Xianzhi\Service\Singleton.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000262160 _____ () C:\Program Files\Xianzhi\Service\AINTERFACE.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 000886288 _____ () C:\Program Files\Xianzhi\Service\NetInterface.dll
2017-10-03 15:37 - 2017-10-18 08:18 - 003011088 _____ () C:\Program Files\Xianzhi\Service\FUMODL.dll
2016-06-29 20:01 - 2016-06-29 20:01 - 008166536 _____ () C:\Program Files\SpeedFan\speedfan.exe
2018-09-20 23:06 - 2098-10-22 03:48 - 000158720 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfareca00001.dll
2017-08-20 20:04 - 2098-10-22 03:48 - 000192512 _____ () C:\Users\Šáfa\AppData\Local\Temp\sfamcc00001.dll
2018-09-19 23:51 - 2018-09-15 10:48 - 004317528 _____ () C:\Program Files\Google\Chrome\Application\69.0.3497.100\libglesv2.dll
2018-09-19 23:51 - 2018-09-15 10:48 - 000096600 _____ () C:\Program Files\Google\Chrome\Application\69.0.3497.100\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:04 - 2018-10-14 22:34 - 000000825 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3680866379-1800367177-3165316198-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Šáfa\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{B8D42AEC-7EFA-4CE4-B282-1116E134B6FC}] => (Allow) C:\Program Files\D-Link\DWA-131 revE\IHV\RTLDHCP.exe
FirewallRules: [{A41A91CD-E2C7-4A34-B037-52DAA603BCFB}] => (Allow) C:\Program Files\D-Link\DWA-131 revE\IHV\PortableWiFi.exe
FirewallRules: [{481311B2-2A7B-4B73-A833-1143A8CEDDDB}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{99E816D9-4C80-4B59-9245-ACBECD49781B}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe
FirewallRules: [{687E5111-C8E9-4A1D-85F0-C52F93810D9F}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe
FirewallRules: [{20527A9A-0FB7-4593-A102-3D2C3244C132}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{CE8A82FB-1996-4992-980D-1EA98F181457}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{CE125627-50E8-4E67-BC42-F799795F04E7}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{5223EC30-E84B-436D-A4BF-F9BE1CCB2256}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceProxy.exe
FirewallRules: [{8090831E-FFD5-48E6-A292-F51049D02EBA}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{2E0E273E-B68B-4413-8B5C-4E303DD3733B}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{BDE22887-B5DA-4CD6-9A4C-EEEAA69472FE}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{985153DD-F759-4D73-A260-459D903A46E1}] => (Allow) C:\Program Files\Xianzhi\Service\XianzhiDeviceService.exe
FirewallRules: [{EB6ACA6A-6240-417D-83B8-408A8C3EAC71}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{2B5AEE82-4558-4DCF-A63A-46C2F28DBAC1}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{55B6188E-316F-4918-B7CF-CF7AB82046F2}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{B103C80F-C91B-4DDF-80AB-D9FC120F4467}] => (Allow) C:\Program Files\ExtendRes\ExtendRes.exe
FirewallRules: [{17B9D460-C6AC-41EB-A88E-4375A3F47860}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{A7CDAB9A-4F66-4599-B3C6-6AF85D9E610C}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{DEBB4134-EC86-4103-A4E9-20ADC98BCC5D}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{A8F904EE-7C5A-4619-8FB7-1E6A93105F4D}] => (Allow) C:\Program Files\Xianzhi\iMoboPlay\iMoboPlay.exe
FirewallRules: [{9BB2BE16-9EC1-4E43-AC43-F84E78E33154}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
FirewallRules: [{312DD44B-B8AF-4847-A79F-922DC9F1EE74}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
FirewallRules: [{D73C5F07-B333-46F4-B47D-42E4266461EA}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
FirewallRules: [{000C1D6F-5B1E-49FB-8806-C6B8C740B124}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
FirewallRules: [TCP Query User{94AFB6D0-7A70-4755-A4BC-526D984D8BC6}C:\program files\xianzhi\service\xianzhideviceproxy.exe] => (Block) C:\program files\xianzhi\service\xianzhideviceproxy.exe
FirewallRules: [UDP Query User{A74AA96B-DA42-4AFA-8675-3EFF66FB2EBD}C:\program files\xianzhi\service\xianzhideviceproxy.exe] => (Block) C:\program files\xianzhi\service\xianzhideviceproxy.exe
FirewallRules: [TCP Query User{7BF7D336-A738-4FD1-B227-B43BB3DC2355}C:\program files\airdroid\airdroid.exe] => (Allow) C:\program files\airdroid\airdroid.exe
FirewallRules: [UDP Query User{FE4E3AEC-C74F-4FC1-9A06-CEFC67BEB5BB}C:\program files\airdroid\airdroid.exe] => (Allow) C:\program files\airdroid\airdroid.exe
FirewallRules: [TCP Query User{BE4AD12D-C2AA-49A5-8F30-4D5FE155E929}C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe] => (Allow) C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe
FirewallRules: [UDP Query User{E46EC591-DB33-4F52-916B-AB8F9D10D3D3}C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe] => (Allow) C:\program files\apowersoft\apowersoft phone manager\apowersoft phone manager.exe
FirewallRules: [{CEB393A4-7F67-4868-BF53-D5C24F362659}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{C7C1B11F-F1A6-425F-BA26-BF0A4FC9166F}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{753AB5B9-7AFB-405F-8FF9-671F669DAA33}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{E8B1C74C-F1D2-420E-B0DC-E57D16F165D4}] => (Allow) C:\Program Files\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{EB79862E-9C10-4271-B57C-279ED7B9AF97}] => (Allow) C:\Program Files\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{492081D2-089D-4DE7-AA92-B65E3408451F}] => (Allow) C:\Program Files\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [TCP Query User{8B4F475C-C5A8-425F-A90B-739EF9C0E70B}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{8F1A484D-D46A-4988-8691-2B53864C7BBF}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [{8D07AAA4-7468-41ED-BED3-30D218CA5C70}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5415F9E1-ED3E-4A54-9C7E-8F693FAC7B61}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{070F3C69-FE05-4AC4-8B2A-F434BF46CF55}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{464C180B-C4EA-4CF6-B13D-CA2D83256F60}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E00A75EC-30EC-47F6-A7FA-901E1968060E}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{CC3DF070-74B0-4126-9177-824C58862FF8}] => (Allow) C:\Users\Šáfa\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C57A1731-6EFB-4186-9ABD-4C0A09F40C4A}] => (Allow) C:\Program Files\IObit\Advanced SystemCare Ultimate\AutoUpdate.exe
FirewallRules: [{D53DEE86-A24C-4CF1-9489-60CD505643B4}] => (Allow) C:\Program Files\IObit\Advanced SystemCare Ultimate\AutoUpdate.exe
FirewallRules: [{DDD41FAC-04F1-4140-993F-547D5B7E7AFB}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{027A0382-896A-4737-B519-6C31D742B84B}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{C8A86F4D-795F-42EF-BAF0-0E7B288422B4}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
21-10-2018 12:53:46 Windows Update
==================== Faulty Device Manager Devices =============
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Standardní klávesnice PS/2
Description: Standardní klávesnice PS/2
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní klávesnice)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Periferní zařízení Bluetooth
Description: Periferní zařízení Bluetooth
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/22/2018 02:33:38 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/21/2018 10:20:33 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/19/2018 03:27:06 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/18/2018 06:24:33 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/17/2018 07:55:03 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/14/2018 04:22:06 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (10/05/2018 11:07:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Vžum.exe, verze: 1.0.6123.42412, časové razítko: 0x57f6c339
Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.24168, časové razítko: 0x5b1aa77b
Kód výjimky: 0xe0434352
Posun chyby: 0x0000845d
ID chybujícího procesu: 0x19ac
Čas spuštění chybující aplikace: 0x01d45cef67f54aa2
Cesta k chybující aplikaci: C:\Users\Šáfa\Desktop\Studium\Vžum.exe
Cesta k chybujícímu modulu: C:\Windows\system32\KERNELBASE.dll
ID zprávy: b5a60f9f-c8e2-11e8-8838-001d60a5c02a
Error: (10/05/2018 11:07:45 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Vžum.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.FileNotFoundException
na Vžum_Reloaded.FileDownloader.ZískejURL(System.String ByRef, System.String ByRef)
na Vžum_Reloaded.FileDownloader.Vlákno()
na System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
na System.Threading.ThreadHelper.ThreadStart()
System errors:
=============
Error: (10/22/2098 03:48:46 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:48:46 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Error: (10/22/2098 03:48:17 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:48:17 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Error: (10/22/2098 03:47:58 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:47:58 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Error: (10/22/2098 03:47:39 AM) (Source: Schannel) (EventID: 4113) (User: NT AUTHORITY)
Description: Certifikátu přijatému ze vzdáleného serveru vypršela platnost. Požadavek na připojení SSL nebyl úspěšný. Připojená data obsahují certifikát serveru.
Error: (10/22/2098 03:47:39 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Byla vygenerována následující výstraha o závažné chybě: 45. Stav interní chyby: 552
Windows Defender:
===================================
Date: 2018-07-04 17:54:25.892
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci.
Nová verze podpisu:1.271.442.0
Předchozí verze podpisu:1.269.1075.0
Zdroj aktualizace:Uživatel
Typ podpisu:Antispywarový program
Typ aktualizace:Delta
Uživatel:NT AUTHORITY\SYSTEM
Aktuální verze modulu:1.1.15000.2
Předchozí verze modulu:1.1.14901.4
Kód chyby:0x80070666
Popis chyby:Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.
Date: 2018-07-04 17:54:25.891
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci modulu
Nová verze modulu:1.1.15000.2
Předchozí verze modulu:1.1.14901.4
Zdroj aktualizace:Uživatel
Uživatel:NT AUTHORITY\SYSTEM
Kód chyby:0x80070666
Popis chyby:Již je nainstalována jiná verze tohoto produktu. Instalaci této verze nelze dokončit. Chcete-li znovu nakonfigurovat nebo odebrat existující verzi produktu, použijte ovládací panel Přidat nebo odebrat programy.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz
Percentage of memory in use: 80%
Total physical RAM: 2047.12 MB
Available physical RAM: 403.3 MB
Total Virtual: 4094.23 MB
Available Virtual: 1767.54 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:48.83 GB) (Free:10 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:184.05 GB) (Free:17.66 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 051A0519)
Partition 1: (Active) - (Size=48.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=184 GB) - (Type=0F Extended)
==================== End of Addition.txt ============================