Stránka 1 z 1

Prosím o preventivní kontrolu

Napsal: 04 lis 2018 14:10
od Robotka
Prosím o kontrolu .
Předem děkuji.
log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.10.2018
Ran by Vilem (administrator) on DEDA (04-11-2018 13:57:58)
Running from C:\Users\Vilem\Desktop
Loaded Profiles: Vilem (Available Profiles: Vilem)
Platform: Windows 10 Home Version 1803 17134.345 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(InterVideo Inc.) C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeApp.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Picosmos) C:\Program Files (x86)\PicosmosTools\PicosmosTools.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
() C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdwtxcr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\sznpp_64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Video.UI.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\downloader.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM-x32\...\Run: [UVS11 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [341488 2007-03-03] (InterVideo Digital Technology Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1069296 2018-03-27] ()
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [Picosmos] => C:\Program Files (x86)\PicosmosTools\PicosmosTools.exe [5646152 2016-02-08] (Picosmos)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [LaunchList] => C:\Program Files (x86)\Pinnacle\Studio 11\LaunchList2.exe [145496 2007-03-21] (Pinnacle Systems)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [752736 2012-10-18] (ZONER software)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Vilem\AppData\Roaming\Seznam.cz\szninstall.exe [1069296 2018-03-27] ()
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [109808 2018-03-27] ()
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\RunOnce: [SeznamInstall-uninstall:b1228ad37fd3a6f717a64cc81b4c4600] => C:\Users\Vilem\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe [534528 2018-11-03] () <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.88.1 85.162.162.162 85.162.162.85 1.1.1.1 8.8.4.4 208.67.222.220
Tcpip\..\Interfaces\{15b37f45-28f8-47f9-8cbf-33615db2e61d}: [DhcpNameServer] 192.168.88.1 85.162.162.162 85.162.162.85 1.1.1.1 8.8.4.4 208.67.222.220
Tcpip\..\Interfaces\{70037fd9-b008-4e3b-872c-bf3927b9bd30}: [DhcpNameServer] 192.168.88.1 85.162.162.162 85.162.162.85 1.1.1.1 8.8.4.4 208.67.222.220
Tcpip\..\Interfaces\{734cbd2f-4e07-4c52-9f9e-e0bf268a566f}: [DhcpNameServer] 192.168.88.2

Internet Explorer:
==================
BHO: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-09-30] (Bitdefender)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
BHO-x32: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-09-30] (Bitdefender)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
Toolbar: HKLM - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-09-30] (Bitdefender)
Toolbar: HKLM-x32 - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-09-30] (Bitdefender)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2018-09-30]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2018-02-27] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default [2018-11-04]
CHR Extension: (Plugins) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\chemohaemmfhjpmlgkmkanfpfbkaihop [2017-04-15]
CHR Extension: (Bitdefender Wallet) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl [2018-03-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Chrome Media Router) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-11-01]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [779152 2018-11-01] (Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [779152 2018-11-01] (Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195320 2018-09-30] (Bitdefender)
R2 Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-07-26] ()
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S2 PCLEPCI; C:\WINDOWS\SysWOW64\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1284032 2018-07-31] (Bitdefender)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6634224 2018-02-02] (TeamViewer GmbH)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [112144 2018-11-01] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe [804144 2018-11-01] (Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\NisSrv.exe [3847376 2018-09-30] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MsMpEng.exe [114200 2018-09-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndnetBus; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [29184 2015-05-12] (LG Electronics Inc.)
S3 AndNetDiag; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [30720 2015-05-12] (LG Electronics Inc.)
S3 ANDNetModem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [37376 2015-05-12] (LG Electronics Inc.)
R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUS Corporation)
R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1292296 2018-10-19] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [1723552 2018-05-24] (BitDefender)
R2 BdDci; C:\WINDOWS\System32\DRIVERS\bddci.sys [156912 2018-11-01] (Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [23032 2018-05-24] (Bitdefender)
R0 bdprivmon; C:\WINDOWS\System32\DRIVERS\bdprivmon.sys [45728 2018-10-19] (© Bitdefender SRL)
R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96448 2018-05-24] (BitDefender)
R3 glavcam; C:\WINDOWS\system32\DRIVERS\glavcam.sys [3475456 2015-08-10] (Windows (R) Codename Longhorn DDK provider)
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation)
R0 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [193184 2018-09-30] (BitDefender LLC)
R3 iaioi2c; C:\WINDOWS\System32\drivers\iaioi2ce.sys [67584 2013-11-11] (Intel Corporation)
R0 Ignis; C:\WINDOWS\System32\DRIVERS\ignis.sys [191592 2018-05-24] (Bitdefender)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R0 MBI; C:\WINDOWS\System32\drivers\MBI.sys [29464 2013-10-28] (Intel Corporation)
R3 Microsoft_Bluetooth_AvrcpTransport; C:\WINDOWS\system32\DRIVERS\Microsoft.Bluetooth.AvrcpTransport.sys [46592 2018-04-12] (Microsoft Corporation)
S3 pcouffin; C:\Windows\SysWOW64\Drivers\pcouffin.sys [47360 2016-04-08] (VSO Software) [File not signed]
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Realtek )
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [609576 2018-08-02] (Bitdefender)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46184 2018-09-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [352424 2018-09-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60584 2018-09-30] (Microsoft Corporation)
S3 PCASp60; System32\Drivers\PCASp60.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-04 13:57 - 2018-11-04 14:01 - 000016804 _____ C:\Users\Vilem\Desktop\FRST.txt
2018-11-04 13:55 - 2018-11-04 13:56 - 000000000 ____D C:\FRST
2018-11-04 13:53 - 2018-11-04 13:53 - 002414592 _____ (Farbar) C:\Users\Vilem\Desktop\FRST64.exe
2018-11-03 21:52 - 2018-11-03 21:52 - 000070275 _____ C:\Users\Vilem\Desktop\jak na focení.html
2018-11-03 21:40 - 2018-11-03 21:41 - 014189016 _____ C:\Users\Vilem\Downloads\hddinsp (1).exe
2018-11-03 20:47 - 2018-11-03 20:50 - 000000000 ____D C:\Program Files (x86)32
2018-11-03 20:47 - 2018-11-03 20:47 - 000000000 ____D C:\ProgramData\AltrixSoft
2018-11-03 20:46 - 2018-11-03 20:46 - 014189016 _____ C:\Users\Vilem\Downloads\hddinsp.exe
2018-11-03 17:27 - 2018-11-03 17:27 - 000045469 _____ C:\Users\Vilem\Downloads\repository.kodi-czsk-1.0.2 (2).zip
2018-10-16 18:27 - 2018-10-16 18:27 - 000000746 _____ C:\Users\Vilem\Documents\ObjednávkA 4.psc
2018-10-16 18:27 - 2018-10-16 18:27 - 000000000 ____D C:\Users\Vilem\Documents\ObjednávkA 4-soubory
2018-10-16 18:11 - 2018-10-16 18:11 - 000000736 _____ C:\Users\Vilem\Documents\Objednávka 3.psc
2018-10-16 18:11 - 2018-10-16 18:11 - 000000000 ____D C:\Users\Vilem\Documents\Objednávka 3-soubory
2018-10-16 17:56 - 2018-10-16 17:56 - 000000734 _____ C:\Users\Vilem\Desktop\Objednávka 2.psc
2018-10-16 17:56 - 2018-10-16 17:56 - 000000000 ____D C:\Users\Vilem\Desktop\Objednávka 2-soubory
2018-10-16 17:02 - 2018-10-16 17:02 - 000000781 _____ C:\Users\Vilem\Desktop\Objednávka 1.psc
2018-10-16 17:02 - 2018-10-16 17:02 - 000000000 ____D C:\Users\Vilem\Desktop\Objednávka 1-soubory
2018-10-15 20:10 - 2018-10-16 16:48 - 000121009 _____ C:\Users\Vilem\Documents\dinosauři.pbf
2018-10-15 20:10 - 2018-10-16 16:39 - 000000000 ____D C:\Users\Vilem\Documents\dinosauři-soubory
2018-10-14 09:04 - 2018-10-16 17:43 - 000162101 _____ C:\Users\Vilem\Documents\jaro 2018.pbf
2018-10-14 09:04 - 2018-10-14 16:34 - 000000000 ____D C:\Users\Vilem\Documents\jaro 2018-soubory
2018-10-13 20:59 - 2018-10-13 20:59 - 000000000 ____D C:\Users\Vilem\AppData\Local\HappyFoto DESIGNER
2018-10-13 20:57 - 2018-10-13 20:57 - 000001136 _____ C:\Users\Public\Desktop\HappyFoto DESIGNER.lnk
2018-10-13 20:57 - 2018-10-13 20:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HappyFoto DESIGNER
2018-10-13 20:54 - 2018-10-13 20:57 - 000000000 ____D C:\Program Files (x86)\HappyFoto DESIGNER
2018-10-13 20:54 - 2018-10-13 20:54 - 000000000 ____D C:\ProgramData\HappyFoto DESIGNER
2018-10-13 20:52 - 2018-10-16 18:12 - 000163667 _____ C:\Users\Vilem\Documents\děcka narozeniny2018.pbf
2018-10-13 20:52 - 2018-10-15 20:07 - 000000000 ____D C:\Users\Vilem\Documents\děcka narozeniny2018-soubory
2018-10-13 20:28 - 2018-10-13 20:52 - 348696160 _____ ( ) C:\Users\Vilem\Downloads\HappyFoto-Designer (1).exe
2018-10-13 14:51 - 2018-10-13 14:51 - 000219741 _____ (Irfan Skiljan) C:\Users\Vilem\Downloads\irfanview_lang_czech.exe
2018-10-13 14:49 - 2018-10-13 14:59 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\IrfanView
2018-10-13 14:49 - 2018-10-13 14:59 - 000000000 ____D C:\Program Files\IrfanView
2018-10-13 14:49 - 2018-10-13 14:49 - 003531400 _____ (Irfan Skiljan) C:\Users\Vilem\Downloads\iview451_x64_setup.exe
2018-10-12 20:25 - 2018-10-12 20:25 - 000016657 _____ C:\Users\Vilem\Desktop\priloha1.PDF
2018-10-12 14:32 - 2018-09-21 10:18 - 021386888 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-10-12 14:32 - 2018-09-20 05:29 - 006569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-10-12 14:32 - 2018-09-20 05:09 - 007520096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-10-12 14:32 - 2018-09-20 04:53 - 025851392 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-10-12 14:32 - 2018-09-20 04:46 - 022715392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-10-12 14:31 - 2018-09-21 09:22 - 020381784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-10-12 14:31 - 2018-09-21 05:14 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-10-12 14:31 - 2018-09-21 05:13 - 000480568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-10-12 14:31 - 2018-09-21 05:12 - 001035256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-10-12 14:31 - 2018-09-21 05:11 - 000753056 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-10-12 14:31 - 2018-09-21 05:09 - 004790160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-10-12 14:31 - 2018-09-21 05:09 - 002253696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-10-12 14:31 - 2018-09-21 05:09 - 001427968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 004404720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 002765344 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 001566720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 001456720 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-10-12 14:31 - 2018-09-21 05:08 - 001257864 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-10-12 14:31 - 2018-09-21 05:08 - 001140672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-10-12 14:31 - 2018-09-21 05:08 - 000982600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-10-12 14:31 - 2018-09-21 05:08 - 000261008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-10-12 14:31 - 2018-09-21 05:07 - 000604664 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-10-12 14:31 - 2018-09-21 04:58 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-10-12 14:31 - 2018-09-21 04:57 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-10-12 14:31 - 2018-09-21 04:53 - 001006080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-10-12 14:31 - 2018-09-21 04:43 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-10-12 14:31 - 2018-09-21 04:41 - 003396096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-10-12 14:31 - 2018-09-21 04:40 - 002368000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-10-12 14:31 - 2018-09-21 04:39 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-10-12 14:31 - 2018-09-21 04:39 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-10-12 14:31 - 2018-09-21 04:39 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-10-12 14:31 - 2018-09-21 04:38 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-10-12 14:31 - 2018-09-21 04:38 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-10-12 14:31 - 2018-09-21 04:37 - 002904064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-10-12 14:31 - 2018-09-21 04:37 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-10-12 14:31 - 2018-09-21 04:37 - 001211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-10-12 14:31 - 2018-09-21 04:37 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-10-12 14:31 - 2018-09-21 04:36 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-10-12 14:31 - 2018-09-21 04:36 - 001034240 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-10-12 14:31 - 2018-09-21 04:36 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-10-12 14:31 - 2018-09-20 10:37 - 001634944 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-10-12 14:31 - 2018-09-20 10:23 - 006602240 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-10-12 14:31 - 2018-09-20 10:22 - 013572096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-10-12 14:31 - 2018-09-20 10:19 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-10-12 14:31 - 2018-09-20 10:18 - 003649024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-10-12 14:31 - 2018-09-20 10:17 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-10-12 14:31 - 2018-09-20 10:17 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-10-12 14:31 - 2018-09-20 09:46 - 001454440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-10-12 14:31 - 2018-09-20 09:35 - 005669888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-10-12 14:31 - 2018-09-20 09:34 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-10-12 14:31 - 2018-09-20 09:29 - 002891776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-10-12 14:31 - 2018-09-20 09:29 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-10-12 14:31 - 2018-09-20 05:29 - 006039368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-10-12 14:31 - 2018-09-20 05:29 - 001989232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-10-12 14:31 - 2018-09-20 05:29 - 001513032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2018-10-12 14:31 - 2018-09-20 05:28 - 001129544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-10-12 14:31 - 2018-09-20 05:21 - 022013440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-10-12 14:31 - 2018-09-20 05:17 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-10-12 14:31 - 2018-09-20 05:15 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-10-12 14:31 - 2018-09-20 05:13 - 003711488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-10-12 14:31 - 2018-09-20 05:11 - 005777920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-10-12 14:31 - 2018-09-20 05:11 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-10-12 14:31 - 2018-09-20 05:11 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-10-12 14:31 - 2018-09-20 05:10 - 002719032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-10-12 14:31 - 2018-09-20 05:10 - 001221128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-10-12 14:31 - 2018-09-20 05:10 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-10-12 14:31 - 2018-09-20 05:10 - 000566800 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-10-12 14:31 - 2018-09-20 05:09 - 009089848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-10-12 14:31 - 2018-09-20 05:09 - 007432136 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 002825232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-10-12 14:31 - 2018-09-20 05:09 - 002462888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 002421248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-10-12 14:31 - 2018-09-20 05:09 - 001767096 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 001097744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-10-12 14:31 - 2018-09-20 05:08 - 004191232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-10-12 14:31 - 2018-09-20 05:08 - 001627648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-10-12 14:31 - 2018-09-20 04:44 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-10-12 14:31 - 2018-09-20 04:44 - 004383744 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-10-12 14:31 - 2018-09-20 04:42 - 004866560 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-10-12 14:31 - 2018-09-20 04:42 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-10-12 14:31 - 2018-09-20 04:41 - 007577088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-10-12 14:31 - 2018-09-20 04:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-10-12 14:31 - 2018-09-20 04:41 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-10-12 14:31 - 2018-09-20 04:40 - 003090432 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-10-12 14:31 - 2018-09-20 04:40 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-10-12 14:31 - 2018-09-20 04:38 - 001724416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-10-12 14:31 - 2018-09-20 04:37 - 004615680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-10-12 14:31 - 2018-09-20 04:37 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-10-12 14:31 - 2018-09-20 04:36 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-10-12 14:31 - 2018-09-08 09:12 - 000452112 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 002868536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-10-12 14:31 - 2018-09-08 09:07 - 001610552 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000792376 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000689464 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000612360 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000309560 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000144696 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-10-12 14:31 - 2018-09-08 09:07 - 000069944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-10-12 14:31 - 2018-09-08 09:02 - 000645112 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-10-12 14:31 - 2018-09-08 09:02 - 000540984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-10-12 14:31 - 2018-09-08 08:58 - 001520744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2018-10-12 14:31 - 2018-09-08 08:42 - 000169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2018-10-12 14:31 - 2018-09-08 08:40 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2018-10-12 14:31 - 2018-09-08 08:40 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-10-12 14:31 - 2018-09-08 08:40 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2018-10-12 14:31 - 2018-09-08 08:40 - 000522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2018-10-12 14:31 - 2018-09-08 08:40 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2018-10-12 14:31 - 2018-09-08 08:39 - 002052096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-10-12 14:31 - 2018-09-08 08:39 - 001787904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-10-12 14:31 - 2018-09-08 08:39 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 001288192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 001004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2018-10-12 14:31 - 2018-09-08 08:14 - 001328056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2018-10-12 14:31 - 2018-09-08 08:13 - 000181288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
2018-10-12 14:31 - 2018-09-08 08:02 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
2018-10-12 14:31 - 2018-09-08 08:00 - 000548864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 001530368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2018-10-12 14:31 - 2018-09-08 07:58 - 001308672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-10-12 14:31 - 2018-09-08 07:58 - 000775680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-10-12 14:31 - 2018-09-08 07:57 - 000625664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2018-10-12 14:31 - 2018-09-08 07:57 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2018-10-12 14:31 - 2018-09-08 07:57 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2018-10-12 14:31 - 2018-09-08 05:08 - 000462880 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-10-12 14:31 - 2018-09-08 04:59 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-10-12 14:31 - 2018-09-08 04:59 - 000361544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-10-12 14:31 - 2018-09-08 04:58 - 000744976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-10-12 14:31 - 2018-09-08 04:58 - 000376120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2018-10-12 14:31 - 2018-09-08 04:57 - 002571128 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 001016984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 000930616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-10-12 14:31 - 2018-09-08 04:57 - 000482384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 000368448 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 000267576 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-10-12 14:31 - 2018-09-08 04:51 - 000380728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-10-12 14:31 - 2018-09-08 04:45 - 000286824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-10-12 14:31 - 2018-09-08 04:44 - 001980984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-10-12 14:31 - 2018-09-08 04:44 - 000829752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-10-12 14:31 - 2018-09-08 04:43 - 001174448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-10-12 14:31 - 2018-09-08 04:43 - 000269104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2018-10-12 14:31 - 2018-09-08 04:30 - 003601920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2018-10-12 14:31 - 2018-09-08 04:30 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2018-10-12 14:31 - 2018-09-08 04:29 - 004771840 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-10-12 14:31 - 2018-09-08 04:29 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys
2018-10-12 14:31 - 2018-09-08 04:29 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2018-10-12 14:31 - 2018-09-08 04:29 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000481280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 002328064 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmsipc.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 003553792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcsecproc.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 001457664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 001096704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-10-12 14:31 - 2018-09-08 04:24 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 000845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2018-10-12 14:31 - 2018-09-08 04:23 - 001655296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmsipc.dll
2018-10-12 14:31 - 2018-09-08 04:23 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2018-10-12 14:31 - 2018-09-08 04:22 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-10-12 14:30 - 2018-09-21 10:01 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-10-12 14:30 - 2018-09-21 09:12 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-10-12 14:30 - 2018-09-21 05:09 - 001062920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-10-12 14:30 - 2018-09-21 05:09 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-10-12 14:30 - 2018-09-21 05:08 - 000709936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-10-12 14:30 - 2018-09-21 05:08 - 000170808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-10-12 14:30 - 2018-09-21 04:57 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-10-12 14:30 - 2018-09-21 04:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-10-12 14:30 - 2018-09-21 04:54 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-10-12 14:30 - 2018-09-21 04:42 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-10-12 14:30 - 2018-09-21 04:39 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-10-12 14:30 - 2018-09-21 04:36 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-10-12 14:30 - 2018-09-21 04:36 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-10-12 14:30 - 2018-09-20 10:40 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-10-12 14:30 - 2018-09-20 10:18 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-10-12 14:30 - 2018-09-20 10:17 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2018-10-12 14:30 - 2018-09-20 10:16 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2018-10-12 14:30 - 2018-09-20 09:30 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-10-12 14:30 - 2018-09-20 09:29 - 002824704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2018-10-12 14:30 - 2018-09-20 09:28 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2018-10-12 14:30 - 2018-09-20 07:43 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-10-12 14:30 - 2018-09-20 06:52 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-10-12 14:30 - 2018-09-20 05:29 - 000357056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-10-12 14:30 - 2018-09-20 05:28 - 000581792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2018-10-12 14:30 - 2018-09-20 05:28 - 000567256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-10-12 14:30 - 2018-09-20 05:12 - 000272200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-10-12 14:30 - 2018-09-20 05:12 - 000269128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-10-12 14:30 - 2018-09-20 05:11 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-10-12 14:30 - 2018-09-20 05:11 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2018-10-12 14:30 - 2018-09-20 05:10 - 000500536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-10-12 14:30 - 2018-09-20 05:10 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2018-10-12 14:30 - 2018-09-20 05:10 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-10-12 14:30 - 2018-09-20 05:10 - 000076088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-10-12 14:30 - 2018-09-20 05:09 - 000885952 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-10-12 14:30 - 2018-09-20 05:09 - 000793088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-10-12 14:30 - 2018-09-20 05:09 - 000713472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-10-12 14:30 - 2018-09-20 05:09 - 000412984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-10-12 14:30 - 2018-09-20 04:43 - 000052736 _____ C:\WINDOWS\system32\runexehelper.exe
2018-10-12 14:30 - 2018-09-20 04:42 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2018-10-12 14:30 - 2018-09-20 04:41 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-10-12 14:30 - 2018-09-20 04:41 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-10-12 14:30 - 2018-09-20 04:40 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-10-12 14:30 - 2018-09-20 04:38 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2018-10-12 14:30 - 2018-09-20 03:21 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2018-10-12 14:30 - 2018-09-20 02:28 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2018-10-12 14:30 - 2018-09-08 08:58 - 001639352 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2018-10-12 14:30 - 2018-09-08 08:57 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2018-10-12 14:30 - 2018-09-08 08:44 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2018-10-12 14:30 - 2018-09-08 08:43 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\INETRES.dll
2018-10-12 14:30 - 2018-09-08 08:43 - 000047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardBi.dll
2018-10-12 14:30 - 2018-09-08 08:42 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2018-10-12 14:30 - 2018-09-08 08:42 - 000188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2018-10-12 14:30 - 2018-09-08 08:42 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthci.dll
2018-10-12 14:30 - 2018-09-08 08:41 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-10-12 14:30 - 2018-09-08 08:40 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2018-10-12 14:30 - 2018-09-08 08:39 - 005505024 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2018-10-12 14:30 - 2018-09-08 08:38 - 000986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-10-12 14:30 - 2018-09-08 08:37 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-10-12 14:30 - 2018-09-08 08:16 - 000482080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-10-12 14:30 - 2018-09-08 08:13 - 001626656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2018-10-12 14:30 - 2018-09-08 08:03 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\INETRES.dll
2018-10-12 14:30 - 2018-09-08 08:03 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2018-10-12 14:30 - 2018-09-08 07:58 - 000897536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-10-12 14:30 - 2018-09-08 07:57 - 005391360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2018-10-12 14:30 - 2018-09-08 07:56 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-10-12 14:30 - 2018-09-08 04:58 - 000368440 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2018-10-12 14:30 - 2018-09-08 04:45 - 000295416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2018-10-12 14:30 - 2018-09-08 04:32 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-10-12 14:30 - 2018-09-08 04:31 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-10-12 14:30 - 2018-09-08 04:31 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Proxy.dll
2018-10-12 14:30 - 2018-09-08 04:30 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2018-10-12 14:30 - 2018-09-08 04:30 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2018-10-12 14:30 - 2018-09-08 04:30 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2018-10-12 14:30 - 2018-09-08 04:29 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-10-12 14:30 - 2018-09-08 04:28 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Bluetooth.Proxy.dll
2018-10-12 14:30 - 2018-09-08 04:27 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcfile.dll
2018-10-12 14:30 - 2018-09-08 04:27 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2018-10-12 14:30 - 2018-09-08 04:26 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2018-10-12 14:30 - 2018-09-08 04:26 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-10-12 14:30 - 2018-09-08 04:26 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcfile.dll
2018-10-12 14:30 - 2018-09-08 04:25 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Proximity.dll
2018-10-12 14:30 - 2018-09-08 04:23 - 000807936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc.dll
2018-10-12 14:30 - 2018-09-08 04:23 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Proximity.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-04 14:03 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-11-04 13:52 - 2018-06-30 18:51 - 000004188 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1E81082B-4685-42C7-A11D-8B5C01C32830}
2018-11-04 13:49 - 2018-06-30 18:12 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-11-04 08:23 - 2018-04-11 22:04 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2018-11-03 21:43 - 2015-11-28 22:24 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\Seznam.cz
2018-11-03 21:39 - 2018-06-30 18:35 - 001689050 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-11-03 21:39 - 2018-04-12 16:50 - 000716276 _____ C:\WINDOWS\system32\perfh005.dat
2018-11-03 21:39 - 2018-04-12 16:50 - 000144534 _____ C:\WINDOWS\system32\perfc005.dat
2018-11-03 21:39 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-11-03 21:38 - 2017-08-20 10:42 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2018-11-03 21:36 - 2018-06-30 18:18 - 000000000 ____D C:\Users\Vilem
2018-11-03 21:36 - 2015-08-10 18:24 - 000000000 __SHD C:\Users\Vilem\IntelGraphicsProfiles
2018-11-03 21:35 - 2018-06-30 18:51 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-11-03 20:32 - 2016-06-10 12:26 - 000000000 ____D C:\KMPlayer
2018-11-03 17:32 - 2017-12-28 20:20 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\Kodi
2018-11-03 16:58 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-11-03 16:56 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-11-03 16:55 - 2018-03-04 14:04 - 000007764 _____ C:\bdlog.txt
2018-11-03 08:17 - 2015-08-31 14:42 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-11-02 21:55 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-11-01 21:02 - 2018-09-30 10:23 - 000156912 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2018-10-31 20:33 - 2015-08-24 20:20 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-10-22 20:12 - 2016-01-03 08:42 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-10-22 19:58 - 2018-03-04 13:59 - 000000000 ____D C:\ProgramData\BDLogging
2018-10-21 10:26 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-10-19 19:14 - 2018-03-04 13:58 - 000045728 _____ (© Bitdefender SRL) C:\WINDOWS\system32\Drivers\bdprivmon.sys
2018-10-19 19:07 - 2018-03-04 13:58 - 001292296 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2018-10-16 18:03 - 2018-06-24 20:47 - 000063461 _____ C:\Users\Vilem\Documents\miki a viky.pbf
2018-10-15 22:38 - 2018-07-01 12:35 - 000000000 ____D C:\ProgramData\Packages
2018-10-15 20:10 - 2018-06-30 18:51 - 000003354 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-341233860-2387372215-3518537327-1001
2018-10-15 20:10 - 2018-06-30 18:18 - 000002389 _____ C:\Users\Vilem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-10-15 20:10 - 2015-05-02 19:37 - 000000000 ___RD C:\Users\Vilem\OneDrive
2018-10-13 20:38 - 2017-02-17 20:40 - 000000000 ____D C:\Program Files (x86)\HappyFoto-Designer
2018-10-13 15:03 - 2015-10-28 07:37 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\XnView
2018-10-13 04:40 - 2015-08-10 20:58 - 000000000 ___RD C:\Users\Vilem\3D Objects
2018-10-13 04:40 - 2015-05-03 03:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-10-13 04:38 - 2018-06-30 18:12 - 000446080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2018-10-12 17:54 - 2015-10-03 13:51 - 000000000 ____D C:\Users\Vilem\AppData\LocalLow\Adobe
2018-10-12 15:59 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-10-12 14:50 - 2015-08-23 18:45 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-10-12 14:45 - 2015-08-23 18:45 - 136745976 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Files in the root of some directories =======

2016-04-08 20:24 - 2016-04-08 20:24 - 000099384 _____ () C:\Users\Vilem\AppData\Roaming\ezpinst.exe
2016-11-03 21:44 - 2016-11-03 21:44 - 000099384 _____ () C:\Users\Vilem\AppData\Roaming\inst.exe
2016-04-08 20:24 - 2016-11-03 21:44 - 000007859 _____ () C:\Users\Vilem\AppData\Roaming\pcouffin.cat
2016-04-08 20:24 - 2016-11-03 21:44 - 000001167 _____ () C:\Users\Vilem\AppData\Roaming\pcouffin.inf
2015-11-28 21:17 - 2016-11-03 21:44 - 000000033 _____ () C:\Users\Vilem\AppData\Roaming\pcouffin.log
2016-04-08 20:24 - 2016-11-03 21:44 - 000082816 _____ (VSO Software) C:\Users\Vilem\AppData\Roaming\pcouffin.sys
2016-02-20 20:25 - 2016-02-20 20:28 - 000004608 _____ () C:\Users\Vilem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Files to move or delete:
====================
C:\Users\Vilem\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


Some files in TEMP:
====================
2011-06-24 16:28 - 2011-06-24 16:28 - 000094432 _____ (AltrixSoft) C:\Users\Vilem\AppData\Local\Temp\Utils.dll
2018-11-03 20:48 - 2018-11-03 21:43 - 000534528 _____ () C:\Users\Vilem\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-06-30 18:12

==================== End of FRST.txt ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
Ran by Vilem (04-11-2018 14:04:23)
Running from C:\Users\Vilem\Desktop
Windows 10 Home Version 1803 17134.345 (X64) (2018-06-30 17:53:18)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-341233860-2387372215-3518537327-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-341233860-2387372215-3518537327-503 - Limited - Disabled)
Guest (S-1-5-21-341233860-2387372215-3518537327-501 - Limited - Disabled)
Vilem (S-1-5-21-341233860-2387372215-3518537327-1001 - Administrator - Enabled) => C:\Users\Vilem
WDAGUtilityAccount (S-1-5-21-341233860-2387372215-3518537327-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5}
FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 15.13 (x64) (HKLM\...\7-Zip) (Version: 15.13 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.008.20080 - Adobe Systems Incorporated)
Advanced IP Scanner 2.5 (HKLM-x32\...\{12830D25-D77C-46B1-902E-2CAD8878CE95}) (Version: 2.5.3499 - Famatech)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.18 - ASUS)
ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.7.2 - ASUS)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 21.0.25.59 - Bitdefender)
Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 22.0.19.242 - Bitdefender)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.69.1079 - AB Team, d.o.o.)
CDSM Designer (HKLM-x32\...\CDSM_CDSM Designer) (Version: - )
ConvertXtoDVD 2.0.9 (HKLM-x32\...\{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1) (Version: 2.0.9 - VSO-Software SARL)
DVDFab Platinum 3.0.8.6 (HKLM-x32\...\DVDFab Platinum_is1) (Version: - Fengtao Software Inc.)
Epson Easy Photo Print 2 (HKLM-x32\...\{07AA1C7F-E8CA-4FDC-B975-BC9EBC22B6DE}) (Version: 2.7.0.0 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
FastStone Image Viewer 5.5 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.5 - FastStone Soft)
FormatFactory 3.8.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.8.0.0 - Free Time)
FOTOKNIHY (HKLM-x32\...\FOTOKNIHY_FOTOKNIHY) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 70.0.3538.77 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
HappyFoto DESIGNER 5.6 (HKLM-x32\...\HappyFoto-Designer_is1) (Version: - )
HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
InterVideo DeviceService (HKLM-x32\...\{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}) (Version: 1.0.0 - InterVideo)
KB4023057 (HKLM\...\{264FDD69-C4DF-476F-B1B8-7DCEE4AF839B}) (Version: 2.4.0.0 - Microsoft Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.0.8.1 - PandoraTV)
Kodi (HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Kodi) (Version: - XBMC-Foundation)
LAV Filters 0.55.3 (HKLM-x32\...\lavfilters_is1) (Version: 0.55.3 - Hendrik Leppkes)
Lenovo EasyCamera (HKLM-x32\...\{E8266049-8C7B-4A09-9E11-8BD100E0076A}) (Version: 8.0.1.2368 - GenesysLogic)
LG Mobile Drivers (HKLM-x32\...\{D8D0327A-72B4-4C79-9883-1B6B6C20ED2B}) (Version: 4.0.3 - LG Electronics)
LibreOffice 5.0.4.2 (HKLM-x32\...\{14B5DDCF-61C4-4F1E-A621-844685D60B5A}) (Version: 5.0.4.2 - The Document Foundation)
Microsoft OneDrive (HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\OneDriveSetup.exe) (Version: 18.172.0826.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Multiecuscan (HKLM-x32\...\{803D46C0-7CE0-4F62-B85F-E32EA0C56747}) (Version: 2.2 - FES Soft Ltd.)
Ovladače videa společnosti Pinnacle (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems)
paint.net (HKLM\...\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}) (Version: 4.0.9 - dotPDN LLC)
Pdf2Jpg version 1.2 (HKLM-x32\...\{533D415A-4151-4AC5-858E-4068524C8051}_is1) (Version: 1.2 - Office Necessities inc.)
PicosmosTools 1.4.0.0 (HKLM-x32\...\PicosmosTools) (Version: 1.4.0.0 - Free Time)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}) (Version: 2.00.088 - )
Pinnacle Studio 14 (HKLM-x32\...\{AADD1C8F-D59F-4D55-A726-768C71A205A8}) (Version: 14.0.0.7255 - Pinnacle Systems)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7514 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\SeznamInstall) (Version: 2.1.32 - Seznam.cz)
Studio 11 (HKLM-x32\...\{110B1ADF-2EAE-4E8F-B501-D2A1E6D8ED9D}) (Version: 11.0 - Pinnacle Systems)
Studio 11 (HKLM-x32\...\{2F952048-3220-4AC7-A206-D01EFC774BB2}) (Version: 11.0.0.0 - Pinnacle Systems) Hidden
Super DVD Ripper (remove only) (HKLM-x32\...\x2VCD) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.93450 - TeamViewer)
Ulead VideoStudio 11 (HKLM-x32\...\InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}) (Version: 11.0.0.0000 - InterVideo Digital Technology Corporation)
Video to Video (HKLM-x32\...\{7F95A744-78DA-4AED-A8F0-A0AF330B8411}_is1) (Version: - Media Converters)
VideoStudio (HKLM-x32\...\{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}) (Version: 11.0.0.0000 - InterVideo Digital Technology Corporation) Hidden
VSO ConvertXToDVD 6 (HKLM-x32\...\{8FC36FA6-C508-44FB-B137-1CB46D8258B2}_is1) (Version: 6.0.0.71 - VSO Software)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
XnView 2.34 (HKLM-x32\...\XnView_is1) (Version: 2.34 - Gougelet Pierre-e)
XviD MPEG-4 Video Codec (HKLM-x32\...\xvid) (Version: - XviD Development Team)
Yahoo! Desktop Login (HKLM-x32\...\{F9AEEC34-CF00-4CBD-9E36-DF9DC4002685}) (Version: 1.00.0001 - Pinnacle Systems) Hidden
Zoner Photo Studio 15 - Obálky a šablony (HKLM\...\ZonerPhotoStudio15_Templates_CZ_is1) (Version: 15.0.1.1 - ZONER software)
Zoner Photo Studio 15 (HKLM\...\ZonerPhotoStudio15_CZ_is1) (Version: 15.0.1.3 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-341233860-2387372215-3518537327-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers2-x32: [Ulead UDF Driver] -> {DBD8E168-244D-448C-9922-25508950D1DC} => C:\Program Files (x86)\Common Files\Ulead Systems\DVD\USIShex.dll [2007-03-03] (Ulead Systems, Inc.)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {050EED22-E9CB-409E-B513-8BAB80E601E4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {24709E92-C601-4229-A88B-A0204885780F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2018-10-12] (Microsoft Corporation)
Task: {2F0BBCA7-1AD0-4D17-9603-A1ABCD83B168} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-13] (Realtek Semiconductor)
Task: {459FBC32-99B5-4C54-B16F-B3BDAE46EB28} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {45CF7F9E-DCEA-44A0-9CDF-910C4F67F333} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-07-31] (Bitdefender)
Task: {4AC6203E-0DF0-4CE4-AD18-2F94BF0A59ED} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {5C58ED13-3DF4-4C48-918E-DCAC8B8D726C} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2017-03-09] (AsusTek)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {C451479F-BB05-4E44-A32B-446A60591D15} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-13] (Realtek Semiconductor)
Task: {D1061EE3-7FFB-4180-812C-5CBEA277678D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {FAA6D6A1-F189-444D-B6B9-BDE68E301384} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [2018-11-01] (Bitdefender)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Vilem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Multiecuscan\Multiecuscan Web Site.lnk -> hxxp://www.multiecuscan.net

==================== Loaded Modules (Whitelisted) ==============

2018-09-24 13:49 - 2018-09-24 13:49 - 000994752 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttpbr.mdl
2018-09-24 13:49 - 2018-09-24 13:49 - 000544880 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttpdsp.mdl
2018-09-24 13:49 - 2018-09-24 13:49 - 003240080 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttpph.mdl
2018-09-24 13:49 - 2018-09-24 13:49 - 001530368 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttprbl.mdl
2017-07-26 08:58 - 2017-07-26 08:58 - 000192200 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-11-03 20:48 - 2017-11-13 15:46 - 000092368 _____ () C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\21981libfoxloader-x64.dll
2018-10-12 14:31 - 2018-09-20 04:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-10-15 22:36 - 2018-10-15 22:37 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\ChakraBridge.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000019456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeProxiesAndStubs.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 010978304 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\LibWrapper.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 002810368 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\skypert.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000685056 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000183808 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
2018-11-03 20:48 - 2017-11-13 15:38 - 000506064 _____ () C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
2018-11-03 20:48 - 2017-02-08 12:39 - 000080576 _____ () C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
2018-10-31 20:33 - 2018-10-23 22:24 - 005020504 _____ () C:\Program Files (x86)\Google\Chrome\Application\70.0.3538.77\libglesv2.dll
2018-10-31 20:33 - 2018-10-23 22:24 - 000116056 _____ () C:\Program Files (x86)\Google\Chrome\Application\70.0.3538.77\libegl.dll
2018-11-03 20:48 - 2018-11-03 21:38 - 000860400 ____T () C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\sznpp_64.exe
2018-10-27 09:36 - 2018-10-27 09:37 - 035118592 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-10-27 09:36 - 2018-10-27 09:37 - 000290816 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-10-27 09:36 - 2018-10-27 09:37 - 005987328 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-09-26 21:06 - 2017-09-26 21:07 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-10-27 09:36 - 2018-10-27 09:37 - 009064448 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\EntPlat.dll
2018-09-29 08:03 - 2018-09-29 08:06 - 000479232 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-09-29 08:03 - 2018-09-29 08:06 - 069128192 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-10-05 18:37 - 2017-10-05 18:39 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-09-29 08:03 - 2018-09-29 08:06 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-09-01 09:46 - 2018-09-01 09:48 - 003699200 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-05-04 03:52 - 2018-05-04 03:54 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll
2018-09-01 09:46 - 2018-09-01 09:48 - 000035328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-04-05 19:37 - 2018-04-05 19:41 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-08-21 16:49 - 2018-08-21 16:51 - 002280960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\opencv_core320.dll
2018-08-21 16:49 - 2018-08-21 16:51 - 002480640 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\opencv_imgproc320.dll
2018-09-29 08:03 - 2018-09-29 08:06 - 014171648 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-09-01 09:46 - 2018-09-01 09:48 - 003544576 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-09-29 08:03 - 2018-09-29 08:06 - 002866176 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-09-01 09:46 - 2018-09-01 09:48 - 000973312 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-07-28 16:39 - 2018-07-28 16:40 - 004584960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-11-03 20:48 - 2017-11-13 15:49 - 000085200 _____ () C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\21978libfoxloader.dll
2016-02-07 04:06 - 2016-02-07 04:06 - 003182080 _____ () C:\Program Files (x86)\PicosmosTools\FFImage.dll
2018-11-03 20:48 - 2018-02-21 10:36 - 000869584 _____ () C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\lightspeed.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\WINDOWS\system32\AERTAC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\AERTAR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPD64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPO64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPONS64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSLFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSLimiterDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSNeoPCDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSSymmetryDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PGFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PLFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PREC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\FMAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\igfxCoIn_v4252.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KAAPORT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO20.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO30.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioEQ64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxVolumeSDAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEA64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RCoInstII64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RltkAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RP3DAA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RP3DHT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtCRX64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RtDataProc64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkApi64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkCfg64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkCoLDR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtlCPAPI64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtPgEx64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTSnMg64.cpl:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFNHK64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFSS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSHP64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSTSH64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSTSX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSWOW64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tadefxapo.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tadefxapo264.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tepeqapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tosade.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\glprop.ax:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\gluninstall.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RsCRIcon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SFCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\glavcam.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\RTKVHD64.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\RtsBaStor.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Desktop\0631f272458601909cfdcaf416b11b64_b.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\2014-patrovy-sedlova-strecha-dus.xls:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (1).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (10).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (11).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (2).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (3).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (4).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (5).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (6).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (7).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (8).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (9).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923.csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_rc2.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\mont_navod_plast_zlab_5360944.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\nova_78_38_2m_garaz_33718.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Nový+objekt+-+Dokument+aplikace+Microsoft+Word.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (3).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (4).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (3).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (4).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (5).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_25840.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_26496.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS2.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS4.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\script.module.stream.resolver-1.6.32.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tb_free.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_613900002411.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (3).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (4).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TOPS4.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-master.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-old-master.zip:$CmdZnID [26]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys => ""="Driver"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-08-23 18:26 - 2018-11-04 13:52 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-341233860-2387372215-3518537327-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Vilem\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\asus.jpg
DNS Servers: 192.168.88.1 - 85.162.162.162
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{DEA3B2F4-018E-4A58-9CEF-6F56B769702A}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe
FirewallRules: [{6CD0E4B2-C063-480B-81A1-15E01001B6F6}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe
FirewallRules: [{CA0C52EB-68CC-4CBE-9AF2-4E3BF9835CDB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{03A55787-F0A1-4797-88E5-9386276EC7F8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{9B3F2063-BA19-4489-A0D9-25E1FBA456FB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{AF0964AB-F8E3-40EE-828D-382E70B538B9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [UDP Query User{855D51EC-4483-4D53-8B9F-25AB59DE07C3}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [TCP Query User{0EED3124-A357-4A63-931B-27F0139799FA}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{0A850433-2D85-43E3-990E-C7B582D6C55E}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [TCP Query User{7B5BDBFB-2B22-4FBD-A954-9D0DED2402A2}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{C2B0D30A-2312-456E-ABE4-B83538724EAD}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{4D98E928-F7C6-4EC8-9067-D379924C4E67}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{79A5F907-0204-4F90-98A9-335F8F8E2F23}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{B4737BBD-BA34-4D14-B683-0D0311C12227}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{AB503824-2478-4380-859E-DFC7ABA04FC0}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{3480BACB-58D0-413A-B04D-7132885A4D18}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

19-10-2018 19:09:36 Naplánovaný kontrolní bod
02-11-2018 23:06:45 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/02/2018 03:50:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: kodi.exe, verze: 17.6.0.0, časové razítko: 0x5a2d50f5
Název chybujícího modulu: kodi.exe, verze: 17.6.0.0, časové razítko: 0x5a2d50f5
Kód výjimky: 0xc0000005
Posun chyby: 0x001c975a
ID chybujícího procesu: 0x15b0
Čas spuštění chybující aplikace: 0x01d472b547a41e1e
Cesta k chybující aplikaci: C:\Program Files (x86)\Kodi\kodi.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Kodi\kodi.exe
ID zprávy: 802f5152-7181-401a-adec-939019ca563d
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (10/22/2018 08:10:41 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (10/22/2018 08:10:41 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {95CABCC9-BC57-4C12-B8DF-BA193232AA01} byla odmítnuta.

Error: (10/16/2018 12:36:28 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SkypeApp.exe verze 8.32.0.55 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 3e88

Čas spuštění: 01d464cf610655de

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.32.55.0_x64__kzf8qxf38zg5c\SkypeApp.exe

ID hlášení: 7c9dacf5-686e-4d36-b780-0ca53e99a78f

Úplný název balíčku s chybou: Microsoft.SkypeApp_14.32.55.0_x64__kzf8qxf38zg5c

ID aplikace související s balíčkem s chybou: App

Error: (10/15/2018 08:10:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: backgroundTaskHost.exe, verze: 10.0.17134.1, časové razítko: 0xcb43d9c5
Název chybujícího modulu: combase.dll, verze: 10.0.17134.112, časové razítko: 0xfad18dc5
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000421cc
ID chybujícího procesu: 0x1b00
Čas spuštění chybující aplikace: 0x01d46456274c7627
Cesta k chybující aplikaci: C:\WINDOWS\system32\backgroundTaskHost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\combase.dll
ID zprávy: 0259c443-de31-4585-8c56-9c3042bb4b61
Úplný název chybujícího balíčku: Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy
ID aplikace související s chybujícím balíčkem: App

Error: (10/13/2018 08:59:51 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
Spouštění asynchronní operace

Kontext:
Aktuální stav: DoSnapshotSet

Error: (10/13/2018 03:01:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program xnview.exe verze 2.34.0.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 1f40

Čas spuštění: 01d462fd1496d3a2

Čas ukončení: 25

Cesta k aplikaci: C:\Program Files (x86)\XnView\xnview.exe

ID hlášení: 470db75d-36cb-4ecb-97dc-638f4f4e2eab

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (10/12/2018 08:55:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: kodi.exe, verze: 17.6.0.0, časové razítko: 0x5a2d50f5
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.17134.254, časové razítko: 0x92f5b34a
Kód výjimky: 0xc0000409
Posun chyby: 0x000a24fb
ID chybujícího procesu: 0x3030
Čas spuštění chybující aplikace: 0x01d4626582849306
Cesta k chybující aplikaci: C:\Program Files (x86)\Kodi\kodi.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID zprávy: 202d5820-7b30-4349-94b8-5340b33ad9cc
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (11/04/2018 01:51:04 PM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
a APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:46:33 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:44:30 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:34:30 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:26:23 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:24:55 AM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
a APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:24:53 AM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
a APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/04/2018 08:24:52 AM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
a APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2018-10-06 08:26:40.282
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FB9B08F4-7D45-4AF9-B7B8-267EEFB19DB3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-03 21:03:44.193
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {F49D8E54-A33B-48E5-A89C-13874BE43B4C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-02 20:10:29.674
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {B8FB8C5D-E144-4114-913E-9E38EE3FC6E5}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-02 16:34:16.512
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {D5EB768D-DEEB-4BA9-98CA-FA83C82D8424}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-02 11:51:50.824
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Windows Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x80004005
Popis chyby: Nespecifikovaná chyba
Důvod: Ovladač filtru přeskočil prohledávání položek a je v režimu průchodu. Příčinou může být nízký stav prostředků.

CodeIntegrity:
===================================

Date: 2018-11-03 21:35:13.820
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-11-03 16:57:44.988
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-10-22 21:08:05.407
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-10-22 20:58:37.052
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\vsservp.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-10-13 05:37:27.888
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\vsservp.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-30 17:22:39.789
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.1809.2-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\win32kbase.sys that did not meet the Microsoft signing level requirements.

Date: 2018-09-30 17:06:02.625
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\win32kbase.sys that did not meet the Microsoft signing level requirements.

Date: 2018-09-30 16:57:06.228
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\vsservp.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU N3540 @ 2.16GHz
Percentage of memory in use: 77%
Total physical RAM: 3982.55 MB
Available physical RAM: 885.86 MB
Total Virtual: 6346.21 MB
Available Virtual: 1908.62 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:93.46 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Data) (Fixed) (Total:258.35 GB) (Free:40.69 GB) NTFS

\\?\Volume{f3a1877d-0eb1-4eab-bb8c-50dcd183886f}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.59 GB) NTFS
\\?\Volume{a36cb6bd-1001-49e2-b7eb-6618d67926af}\ (Restore) (Fixed) (Total:20.01 GB) (Free:9.18 GB) NTFS
\\?\Volume{8e42827b-8a41-41ec-8b3a-a7a7e706d199}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 285C82C9)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Prosím o preventivní kontrolu

Napsal: 04 lis 2018 23:18
od Conder
Ahoj :)

:arrow: Ak nepouzivas, odporucam odinstalovat Seznam Software (Seznam Listicka).

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
  • Nechaj zaskrtnute vsetky nalezy
  • Klikni na Cisteni a opravy (Clean and Repair) a potvrd restart PC teraz
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah sem skopiruj

Re: Prosím o preventivní kontrolu

Napsal: 05 lis 2018 20:20
od Robotka
zde jsou dva logy:
skenovat:
log

# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build: 09-25-2018
# Database: 2018-10-31.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 11-05-2018
# Duration: 00:00:32
# OS: Windows 10 Home
# Scanned: 32026
# Detected: 12


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Booking C:\Users\Vilem\AppData\Roaming\Booking_helper
PUP.Optional.Legacy C:\Users\Vilem\AppData\Roaming\GoldenGate

***** [ Files ] *****

PUP.Optional.Legacy C:\Users\Vilem\AppData\Local\Temp\Utils.dll

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Conduit HKCU\Software\Conduit
PUP.Optional.InstallCore HKCU\Software\csastats
PUP.Optional.Legacy HKCU\Software\GoldenGate
PUP.Optional.Legacy HKCU\Software\DriverTuner_Init
PUP.Optional.Legacy HKCU\Software\DriverTuner
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
PUP.Optional.ProductSetup.A HKCU\Software\PRODUCTSETUP

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########


vyčistit
log:

# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build: 09-25-2018
# Database: 2018-10-31.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 11-05-2018
# Duration: 00:00:07
# OS: Windows 10 Home
# Cleaned: 12
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Users\Vilem\AppData\Roaming\Booking_helper
Deleted C:\Users\Vilem\AppData\Roaming\GoldenGate

***** [ Files ] *****

Deleted C:\Users\Vilem\AppData\Local\Temp\Utils.dll

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\Conduit
Deleted HKCU\Software\csastats
Deleted HKCU\Software\GoldenGate
Deleted HKCU\Software\DriverTuner_Init
Deleted HKCU\Software\DriverTuner
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
Deleted HKCU\Software\PRODUCTSETUP

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2076 octets] - [05/11/2018 20:10:38]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Prosím o preventivní kontrolu

Napsal: 05 lis 2018 20:58
od Conder
:arrow: OK, poprosim o obidva nove logy z FRST.

Re: Prosím o preventivní kontrolu

Napsal: 05 lis 2018 21:53
od Robotka
ok. Tady jsou:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.10.2018
Ran by Vilem (administrator) on DEDA (05-11-2018 21:35:28)
Running from C:\Users\Vilem\Desktop
Loaded Profiles: Vilem (Available Profiles: Vilem)
Platform: Windows 10 Home Version 1803 17134.345 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(InterVideo Inc.) C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Bitdefender) C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe
(Picosmos) C:\Program Files (x86)\PicosmosTools\PicosmosTools.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Security\bdwtxcr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM-x32\...\Run: [UVS11 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [341488 2007-03-03] (InterVideo Digital Technology Corporation)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [Picosmos] => C:\Program Files (x86)\PicosmosTools\PicosmosTools.exe [5646152 2016-02-08] (Picosmos)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [LaunchList] => C:\Program Files (x86)\Pinnacle\Studio 11\LaunchList2.exe [145496 2007-03-21] (Pinnacle Systems)
HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE [752736 2012-10-18] (ZONER software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.88.1 85.162.162.162 85.162.162.85 1.1.1.1 8.8.4.4 208.67.222.220
Tcpip\..\Interfaces\{15b37f45-28f8-47f9-8cbf-33615db2e61d}: [DhcpNameServer] 192.168.88.1 85.162.162.162 85.162.162.85 1.1.1.1 8.8.4.4 208.67.222.220
Tcpip\..\Interfaces\{70037fd9-b008-4e3b-872c-bf3927b9bd30}: [DhcpNameServer] 192.168.88.1 85.162.162.162 85.162.162.85 1.1.1.1 8.8.4.4 208.67.222.220
Tcpip\..\Interfaces\{734cbd2f-4e07-4c52-9f9e-e0bf268a566f}: [DhcpNameServer] 192.168.88.2

Internet Explorer:
==================
BHO: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-09-30] (Bitdefender)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
BHO-x32: Bitdefender - Portmonka -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-09-30] (Bitdefender)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31] (Seiko Epson Corporation)
Toolbar: HKLM - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\pmbxie.dll [2018-09-30] (Bitdefender)
Toolbar: HKLM-x32 - Bitdefender - Portmonka - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender Security\Antispam32\pmbxie.dll [2018-09-30] (Bitdefender)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi [2018-09-30]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext [2018-02-27] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [bdwtwe@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdwteff.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender Security\bdtbext
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default [2018-11-05]
CHR Extension: (Plugins) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\chemohaemmfhjpmlgkmkanfpfbkaihop [2017-04-15]
CHR Extension: (Bitdefender Wallet) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\gannpgaobkkhmpomoijebaigcapoeebl [2018-03-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-05]
CHR Extension: (Chrome Media Router) - C:\Users\Vilem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-11-01]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 BDAuxSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [779152 2018-11-01] (Bitdefender)
R2 BDProtSrv; C:\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe [779152 2018-11-01] (Bitdefender)
R2 bdredline; C:\Program Files\Common Files\Bitdefender\SetupInformation\Bitdefender RedLine\bdredline.exe [2195320 2018-09-30] (Bitdefender)
R2 Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-07-26] ()
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S2 PCLEPCI; C:\WINDOWS\SysWOW64\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1284032 2018-07-31] (Bitdefender)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6634224 2018-02-02] (TeamViewer GmbH)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender Security\updatesrv.exe [112144 2018-11-01] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender Security\vsserv.exe [804144 2018-11-01] (Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\NisSrv.exe [3847376 2018-09-30] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MsMpEng.exe [114200 2018-09-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndnetBus; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [29184 2015-05-12] (LG Electronics Inc.)
S3 AndNetDiag; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [30720 2015-05-12] (LG Electronics Inc.)
S3 ANDNetModem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [37376 2015-05-12] (LG Electronics Inc.)
R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUS Corporation)
R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [1292296 2018-10-19] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [1723552 2018-05-24] (BitDefender)
R2 BdDci; C:\WINDOWS\System32\DRIVERS\bddci.sys [156912 2018-11-01] (Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [23032 2018-05-24] (Bitdefender)
R0 bdprivmon; C:\WINDOWS\System32\DRIVERS\bdprivmon.sys [45728 2018-10-19] (© Bitdefender SRL)
R1 BDVEDISK; C:\WINDOWS\system32\DRIVERS\bdvedisk.sys [96448 2018-05-24] (BitDefender)
R3 glavcam; C:\WINDOWS\system32\DRIVERS\glavcam.sys [3475456 2015-08-10] (Windows (R) Codename Longhorn DDK provider)
R3 GPIO; C:\WINDOWS\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation)
R0 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [193184 2018-09-30] (BitDefender LLC)
R3 iaioi2c; C:\WINDOWS\System32\drivers\iaioi2ce.sys [67584 2013-11-11] (Intel Corporation)
R0 Ignis; C:\WINDOWS\System32\DRIVERS\ignis.sys [191592 2018-05-24] (Bitdefender)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R0 MBI; C:\WINDOWS\System32\drivers\MBI.sys [29464 2013-10-28] (Intel Corporation)
R3 Microsoft_Bluetooth_AvrcpTransport; C:\WINDOWS\system32\DRIVERS\Microsoft.Bluetooth.AvrcpTransport.sys [46592 2018-04-12] (Microsoft Corporation)
S3 pcouffin; C:\Windows\SysWOW64\Drivers\pcouffin.sys [47360 2016-04-08] (VSO Software) [File not signed]
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Realtek )
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [609576 2018-08-02] (Bitdefender)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46184 2018-09-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [352424 2018-09-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60584 2018-09-30] (Microsoft Corporation)
S3 PCASp60; System32\Drivers\PCASp60.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-05 20:06 - 2018-11-05 20:06 - 004110280 _____ C:\Users\Vilem\Downloads\adwcleaner_6.047.exe
2018-11-05 20:02 - 2018-11-05 20:02 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Downloads\adwcleaner_7.2.4.0 (5).exe
2018-11-05 19:40 - 2018-11-05 19:40 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Downloads\adwcleaner_7.2.4.0 (4).exe
2018-11-05 19:38 - 2018-11-05 19:38 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Downloads\adwcleaner_7.2.4.0 (3).exe
2018-11-05 19:32 - 2018-11-05 19:32 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Downloads\adwcleaner_7.2.4.0 (2).exe
2018-11-05 19:32 - 2018-11-05 19:32 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Downloads\adwcleaner_7.2.4.0 (1).exe
2018-11-05 19:31 - 2018-11-05 19:31 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Downloads\adwcleaner_7.2.4.0.exe
2018-11-05 19:12 - 2018-11-05 19:12 - 007592144 _____ (Malwarebytes) C:\Users\Vilem\Desktop\adwcleaner_7.2.4.0.exe
2018-11-04 14:04 - 2018-11-04 14:06 - 000050547 _____ C:\Users\Vilem\Desktop\Addition.txt
2018-11-04 13:57 - 2018-11-05 21:36 - 000014586 _____ C:\Users\Vilem\Desktop\FRST.txt
2018-11-04 13:55 - 2018-11-05 21:35 - 000000000 ____D C:\FRST
2018-11-04 13:53 - 2018-11-04 13:53 - 002414592 _____ (Farbar) C:\Users\Vilem\Desktop\FRST64.exe
2018-11-03 21:52 - 2018-11-03 21:52 - 000070275 _____ C:\Users\Vilem\Desktop\jak na focení.html
2018-11-03 21:40 - 2018-11-03 21:41 - 014189016 _____ C:\Users\Vilem\Downloads\hddinsp (1).exe
2018-11-03 20:47 - 2018-11-03 20:50 - 000000000 ____D C:\Program Files (x86)32
2018-11-03 20:47 - 2018-11-03 20:47 - 000000000 ____D C:\ProgramData\AltrixSoft
2018-11-03 20:46 - 2018-11-03 20:46 - 014189016 _____ C:\Users\Vilem\Downloads\hddinsp.exe
2018-11-03 17:27 - 2018-11-03 17:27 - 000045469 _____ C:\Users\Vilem\Downloads\repository.kodi-czsk-1.0.2 (2).zip
2018-10-16 18:27 - 2018-10-16 18:27 - 000000746 _____ C:\Users\Vilem\Documents\ObjednávkA 4.psc
2018-10-16 18:27 - 2018-10-16 18:27 - 000000000 ____D C:\Users\Vilem\Documents\ObjednávkA 4-soubory
2018-10-16 18:11 - 2018-10-16 18:11 - 000000736 _____ C:\Users\Vilem\Documents\Objednávka 3.psc
2018-10-16 18:11 - 2018-10-16 18:11 - 000000000 ____D C:\Users\Vilem\Documents\Objednávka 3-soubory
2018-10-16 17:56 - 2018-10-16 17:56 - 000000734 _____ C:\Users\Vilem\Desktop\Objednávka 2.psc
2018-10-16 17:56 - 2018-10-16 17:56 - 000000000 ____D C:\Users\Vilem\Desktop\Objednávka 2-soubory
2018-10-16 17:02 - 2018-10-16 17:02 - 000000781 _____ C:\Users\Vilem\Desktop\Objednávka 1.psc
2018-10-16 17:02 - 2018-10-16 17:02 - 000000000 ____D C:\Users\Vilem\Desktop\Objednávka 1-soubory
2018-10-15 20:10 - 2018-10-16 16:48 - 000121009 _____ C:\Users\Vilem\Documents\dinosauři.pbf
2018-10-15 20:10 - 2018-10-16 16:39 - 000000000 ____D C:\Users\Vilem\Documents\dinosauři-soubory
2018-10-14 09:04 - 2018-10-16 17:43 - 000162101 _____ C:\Users\Vilem\Documents\jaro 2018.pbf
2018-10-14 09:04 - 2018-10-14 16:34 - 000000000 ____D C:\Users\Vilem\Documents\jaro 2018-soubory
2018-10-13 20:59 - 2018-10-13 20:59 - 000000000 ____D C:\Users\Vilem\AppData\Local\HappyFoto DESIGNER
2018-10-13 20:57 - 2018-10-13 20:57 - 000001136 _____ C:\Users\Public\Desktop\HappyFoto DESIGNER.lnk
2018-10-13 20:57 - 2018-10-13 20:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HappyFoto DESIGNER
2018-10-13 20:54 - 2018-10-13 20:57 - 000000000 ____D C:\Program Files (x86)\HappyFoto DESIGNER
2018-10-13 20:54 - 2018-10-13 20:54 - 000000000 ____D C:\ProgramData\HappyFoto DESIGNER
2018-10-13 20:52 - 2018-10-16 18:12 - 000163667 _____ C:\Users\Vilem\Documents\děcka narozeniny2018.pbf
2018-10-13 20:52 - 2018-10-15 20:07 - 000000000 ____D C:\Users\Vilem\Documents\děcka narozeniny2018-soubory
2018-10-13 20:28 - 2018-10-13 20:52 - 348696160 _____ ( ) C:\Users\Vilem\Downloads\HappyFoto-Designer (1).exe
2018-10-13 14:51 - 2018-10-13 14:51 - 000219741 _____ (Irfan Skiljan) C:\Users\Vilem\Downloads\irfanview_lang_czech.exe
2018-10-13 14:49 - 2018-10-13 14:59 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\IrfanView
2018-10-13 14:49 - 2018-10-13 14:59 - 000000000 ____D C:\Program Files\IrfanView
2018-10-13 14:49 - 2018-10-13 14:49 - 003531400 _____ (Irfan Skiljan) C:\Users\Vilem\Downloads\iview451_x64_setup.exe
2018-10-12 20:25 - 2018-10-12 20:25 - 000016657 _____ C:\Users\Vilem\Desktop\priloha1.PDF
2018-10-12 14:32 - 2018-09-21 10:18 - 021386888 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-10-12 14:32 - 2018-09-20 05:29 - 006569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-10-12 14:32 - 2018-09-20 05:09 - 007520096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-10-12 14:32 - 2018-09-20 04:53 - 025851392 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-10-12 14:32 - 2018-09-20 04:46 - 022715392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-10-12 14:31 - 2018-09-21 09:22 - 020381784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-10-12 14:31 - 2018-09-21 05:14 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2018-10-12 14:31 - 2018-09-21 05:13 - 000480568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-10-12 14:31 - 2018-09-21 05:12 - 001035256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-10-12 14:31 - 2018-09-21 05:11 - 000753056 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2018-10-12 14:31 - 2018-09-21 05:09 - 004790160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-10-12 14:31 - 2018-09-21 05:09 - 002253696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-10-12 14:31 - 2018-09-21 05:09 - 001427968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 004404720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 002765344 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 001566720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-10-12 14:31 - 2018-09-21 05:08 - 001456720 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-10-12 14:31 - 2018-09-21 05:08 - 001257864 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-10-12 14:31 - 2018-09-21 05:08 - 001140672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-10-12 14:31 - 2018-09-21 05:08 - 000982600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-10-12 14:31 - 2018-09-21 05:08 - 000261008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-10-12 14:31 - 2018-09-21 05:07 - 000604664 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-10-12 14:31 - 2018-09-21 04:58 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-10-12 14:31 - 2018-09-21 04:57 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-10-12 14:31 - 2018-09-21 04:53 - 001006080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-10-12 14:31 - 2018-09-21 04:43 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-10-12 14:31 - 2018-09-21 04:41 - 003396096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-10-12 14:31 - 2018-09-21 04:40 - 002368000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-10-12 14:31 - 2018-09-21 04:39 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-10-12 14:31 - 2018-09-21 04:39 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-10-12 14:31 - 2018-09-21 04:39 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-10-12 14:31 - 2018-09-21 04:38 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-10-12 14:31 - 2018-09-21 04:38 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-10-12 14:31 - 2018-09-21 04:37 - 002904064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-10-12 14:31 - 2018-09-21 04:37 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-10-12 14:31 - 2018-09-21 04:37 - 001211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-10-12 14:31 - 2018-09-21 04:37 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-10-12 14:31 - 2018-09-21 04:36 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-10-12 14:31 - 2018-09-21 04:36 - 001034240 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-10-12 14:31 - 2018-09-21 04:36 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-10-12 14:31 - 2018-09-20 10:37 - 001634944 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-10-12 14:31 - 2018-09-20 10:23 - 006602240 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-10-12 14:31 - 2018-09-20 10:22 - 013572096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-10-12 14:31 - 2018-09-20 10:19 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-10-12 14:31 - 2018-09-20 10:18 - 003649024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-10-12 14:31 - 2018-09-20 10:17 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-10-12 14:31 - 2018-09-20 10:17 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-10-12 14:31 - 2018-09-20 09:46 - 001454440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-10-12 14:31 - 2018-09-20 09:35 - 005669888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-10-12 14:31 - 2018-09-20 09:34 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-10-12 14:31 - 2018-09-20 09:29 - 002891776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-10-12 14:31 - 2018-09-20 09:29 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-10-12 14:31 - 2018-09-20 05:29 - 006039368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-10-12 14:31 - 2018-09-20 05:29 - 001989232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-10-12 14:31 - 2018-09-20 05:29 - 001513032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2018-10-12 14:31 - 2018-09-20 05:28 - 001129544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-10-12 14:31 - 2018-09-20 05:21 - 022013440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-10-12 14:31 - 2018-09-20 05:17 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-10-12 14:31 - 2018-09-20 05:15 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-10-12 14:31 - 2018-09-20 05:13 - 003711488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-10-12 14:31 - 2018-09-20 05:11 - 005777920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-10-12 14:31 - 2018-09-20 05:11 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-10-12 14:31 - 2018-09-20 05:11 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-10-12 14:31 - 2018-09-20 05:10 - 002719032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-10-12 14:31 - 2018-09-20 05:10 - 001221128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-10-12 14:31 - 2018-09-20 05:10 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-10-12 14:31 - 2018-09-20 05:10 - 000566800 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-10-12 14:31 - 2018-09-20 05:09 - 009089848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-10-12 14:31 - 2018-09-20 05:09 - 007432136 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 002825232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-10-12 14:31 - 2018-09-20 05:09 - 002462888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 002421248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-10-12 14:31 - 2018-09-20 05:09 - 001767096 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-10-12 14:31 - 2018-09-20 05:09 - 001097744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-10-12 14:31 - 2018-09-20 05:08 - 004191232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-10-12 14:31 - 2018-09-20 05:08 - 001627648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-10-12 14:31 - 2018-09-20 04:44 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-10-12 14:31 - 2018-09-20 04:44 - 004383744 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-10-12 14:31 - 2018-09-20 04:42 - 004866560 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-10-12 14:31 - 2018-09-20 04:42 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-10-12 14:31 - 2018-09-20 04:41 - 007577088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-10-12 14:31 - 2018-09-20 04:41 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2018-10-12 14:31 - 2018-09-20 04:41 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-10-12 14:31 - 2018-09-20 04:40 - 003090432 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-10-12 14:31 - 2018-09-20 04:40 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-10-12 14:31 - 2018-09-20 04:38 - 001724416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-10-12 14:31 - 2018-09-20 04:37 - 004615680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-10-12 14:31 - 2018-09-20 04:37 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-10-12 14:31 - 2018-09-20 04:36 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-10-12 14:31 - 2018-09-08 09:12 - 000452112 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 002868536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-10-12 14:31 - 2018-09-08 09:07 - 001610552 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000792376 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000689464 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000612360 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000309560 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-10-12 14:31 - 2018-09-08 09:07 - 000144696 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-10-12 14:31 - 2018-09-08 09:07 - 000069944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-10-12 14:31 - 2018-09-08 09:02 - 000645112 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-10-12 14:31 - 2018-09-08 09:02 - 000540984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-10-12 14:31 - 2018-09-08 08:58 - 001520744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2018-10-12 14:31 - 2018-09-08 08:42 - 000169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2018-10-12 14:31 - 2018-09-08 08:40 - 001724928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2018-10-12 14:31 - 2018-09-08 08:40 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-10-12 14:31 - 2018-09-08 08:40 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2018-10-12 14:31 - 2018-09-08 08:40 - 000522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2018-10-12 14:31 - 2018-09-08 08:40 - 000249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2018-10-12 14:31 - 2018-09-08 08:39 - 002052096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2018-10-12 14:31 - 2018-09-08 08:39 - 001787904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2018-10-12 14:31 - 2018-09-08 08:39 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 001288192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 001004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2018-10-12 14:31 - 2018-09-08 08:38 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2018-10-12 14:31 - 2018-09-08 08:14 - 001328056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2018-10-12 14:31 - 2018-09-08 08:13 - 000181288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
2018-10-12 14:31 - 2018-09-08 08:02 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
2018-10-12 14:31 - 2018-09-08 08:00 - 000548864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 001530368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 001452544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2018-10-12 14:31 - 2018-09-08 07:59 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2018-10-12 14:31 - 2018-09-08 07:58 - 001308672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2018-10-12 14:31 - 2018-09-08 07:58 - 000775680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2018-10-12 14:31 - 2018-09-08 07:57 - 000625664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2018-10-12 14:31 - 2018-09-08 07:57 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2018-10-12 14:31 - 2018-09-08 07:57 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2018-10-12 14:31 - 2018-09-08 05:08 - 000462880 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-10-12 14:31 - 2018-09-08 04:59 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-10-12 14:31 - 2018-09-08 04:59 - 000361544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-10-12 14:31 - 2018-09-08 04:58 - 000744976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-10-12 14:31 - 2018-09-08 04:58 - 000376120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2018-10-12 14:31 - 2018-09-08 04:57 - 002571128 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 001016984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 000930616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2018-10-12 14:31 - 2018-09-08 04:57 - 000482384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 000368448 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2018-10-12 14:31 - 2018-09-08 04:57 - 000267576 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-10-12 14:31 - 2018-09-08 04:51 - 000380728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-10-12 14:31 - 2018-09-08 04:45 - 000286824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-10-12 14:31 - 2018-09-08 04:44 - 001980984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-10-12 14:31 - 2018-09-08 04:44 - 000829752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2018-10-12 14:31 - 2018-09-08 04:43 - 001174448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2018-10-12 14:31 - 2018-09-08 04:43 - 000269104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2018-10-12 14:31 - 2018-09-08 04:30 - 003601920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2018-10-12 14:31 - 2018-09-08 04:30 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2018-10-12 14:31 - 2018-09-08 04:29 - 004771840 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-10-12 14:31 - 2018-09-08 04:29 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys
2018-10-12 14:31 - 2018-09-08 04:29 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2018-10-12 14:31 - 2018-09-08 04:29 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000481280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-10-12 14:31 - 2018-09-08 04:28 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-10-12 14:31 - 2018-09-08 04:27 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 002328064 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmsipc.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000784896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-10-12 14:31 - 2018-09-08 04:26 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 003553792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcsecproc.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-10-12 14:31 - 2018-09-08 04:25 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 001457664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 001096704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-10-12 14:31 - 2018-09-08 04:24 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 000845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2018-10-12 14:31 - 2018-09-08 04:24 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2018-10-12 14:31 - 2018-09-08 04:23 - 001655296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmsipc.dll
2018-10-12 14:31 - 2018-09-08 04:23 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2018-10-12 14:31 - 2018-09-08 04:22 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2018-10-12 14:30 - 2018-09-21 10:01 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-10-12 14:30 - 2018-09-21 09:12 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-10-12 14:30 - 2018-09-21 05:09 - 001062920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-10-12 14:30 - 2018-09-21 05:09 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-10-12 14:30 - 2018-09-21 05:08 - 000709936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-10-12 14:30 - 2018-09-21 05:08 - 000170808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-10-12 14:30 - 2018-09-21 04:57 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-10-12 14:30 - 2018-09-21 04:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-10-12 14:30 - 2018-09-21 04:54 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-10-12 14:30 - 2018-09-21 04:42 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-10-12 14:30 - 2018-09-21 04:39 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-10-12 14:30 - 2018-09-21 04:36 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-10-12 14:30 - 2018-09-21 04:36 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-10-12 14:30 - 2018-09-20 10:40 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2018-10-12 14:30 - 2018-09-20 10:18 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-10-12 14:30 - 2018-09-20 10:17 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2018-10-12 14:30 - 2018-09-20 10:16 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2018-10-12 14:30 - 2018-09-20 09:30 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-10-12 14:30 - 2018-09-20 09:29 - 002824704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2018-10-12 14:30 - 2018-09-20 09:28 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2018-10-12 14:30 - 2018-09-20 07:43 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-10-12 14:30 - 2018-09-20 06:52 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-10-12 14:30 - 2018-09-20 05:29 - 000357056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-10-12 14:30 - 2018-09-20 05:28 - 000581792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2018-10-12 14:30 - 2018-09-20 05:28 - 000567256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-10-12 14:30 - 2018-09-20 05:12 - 000272200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-10-12 14:30 - 2018-09-20 05:12 - 000269128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-10-12 14:30 - 2018-09-20 05:11 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-10-12 14:30 - 2018-09-20 05:11 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2018-10-12 14:30 - 2018-09-20 05:10 - 000500536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-10-12 14:30 - 2018-09-20 05:10 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2018-10-12 14:30 - 2018-09-20 05:10 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-10-12 14:30 - 2018-09-20 05:10 - 000076088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-10-12 14:30 - 2018-09-20 05:09 - 000885952 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-10-12 14:30 - 2018-09-20 05:09 - 000793088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-10-12 14:30 - 2018-09-20 05:09 - 000713472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-10-12 14:30 - 2018-09-20 05:09 - 000412984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-10-12 14:30 - 2018-09-20 04:43 - 000052736 _____ C:\WINDOWS\system32\runexehelper.exe
2018-10-12 14:30 - 2018-09-20 04:42 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2018-10-12 14:30 - 2018-09-20 04:41 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2018-10-12 14:30 - 2018-09-20 04:41 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-10-12 14:30 - 2018-09-20 04:40 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-10-12 14:30 - 2018-09-20 04:38 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2018-10-12 14:30 - 2018-09-20 03:21 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2018-10-12 14:30 - 2018-09-20 02:28 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2018-10-12 14:30 - 2018-09-08 08:58 - 001639352 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2018-10-12 14:30 - 2018-09-08 08:57 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2018-10-12 14:30 - 2018-09-08 08:44 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2018-10-12 14:30 - 2018-09-08 08:43 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\INETRES.dll
2018-10-12 14:30 - 2018-09-08 08:43 - 000047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardBi.dll
2018-10-12 14:30 - 2018-09-08 08:42 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2018-10-12 14:30 - 2018-09-08 08:42 - 000188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2018-10-12 14:30 - 2018-09-08 08:42 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthci.dll
2018-10-12 14:30 - 2018-09-08 08:41 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-10-12 14:30 - 2018-09-08 08:40 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2018-10-12 14:30 - 2018-09-08 08:39 - 005505024 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2018-10-12 14:30 - 2018-09-08 08:38 - 000986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-10-12 14:30 - 2018-09-08 08:37 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2018-10-12 14:30 - 2018-09-08 08:16 - 000482080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-10-12 14:30 - 2018-09-08 08:13 - 001626656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2018-10-12 14:30 - 2018-09-08 08:03 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\INETRES.dll
2018-10-12 14:30 - 2018-09-08 08:03 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2018-10-12 14:30 - 2018-09-08 07:58 - 000897536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-10-12 14:30 - 2018-09-08 07:57 - 005391360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2018-10-12 14:30 - 2018-09-08 07:56 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2018-10-12 14:30 - 2018-09-08 04:58 - 000368440 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2018-10-12 14:30 - 2018-09-08 04:45 - 000295416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2018-10-12 14:30 - 2018-09-08 04:32 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-10-12 14:30 - 2018-09-08 04:31 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-10-12 14:30 - 2018-09-08 04:31 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Proxy.dll
2018-10-12 14:30 - 2018-09-08 04:30 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2018-10-12 14:30 - 2018-09-08 04:30 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2018-10-12 14:30 - 2018-09-08 04:30 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2018-10-12 14:30 - 2018-09-08 04:29 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-10-12 14:30 - 2018-09-08 04:28 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Bluetooth.Proxy.dll
2018-10-12 14:30 - 2018-09-08 04:27 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winipcfile.dll
2018-10-12 14:30 - 2018-09-08 04:27 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2018-10-12 14:30 - 2018-09-08 04:26 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2018-10-12 14:30 - 2018-09-08 04:26 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-10-12 14:30 - 2018-09-08 04:26 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcfile.dll
2018-10-12 14:30 - 2018-09-08 04:25 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Proximity.dll
2018-10-12 14:30 - 2018-09-08 04:23 - 000807936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winipcsecproc.dll
2018-10-12 14:30 - 2018-09-08 04:23 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Proximity.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-05 21:36 - 2018-06-30 18:51 - 000004188 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1E81082B-4685-42C7-A11D-8B5C01C32830}
2018-11-05 21:33 - 2018-06-30 18:12 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-11-05 21:33 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-11-05 20:19 - 2018-06-30 18:35 - 001689050 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-11-05 20:19 - 2018-04-12 16:50 - 000716276 _____ C:\WINDOWS\system32\perfh005.dat
2018-11-05 20:19 - 2018-04-12 16:50 - 000144534 _____ C:\WINDOWS\system32\perfc005.dat
2018-11-05 20:19 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-11-05 20:15 - 2017-08-20 10:42 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2018-11-05 20:13 - 2015-08-10 18:24 - 000000000 __SHD C:\Users\Vilem\IntelGraphicsProfiles
2018-11-05 20:12 - 2018-06-30 18:51 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-11-05 20:11 - 2018-06-30 18:18 - 000000000 ____D C:\Users\Vilem
2018-11-05 20:11 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-11-05 20:11 - 2018-03-04 14:04 - 000008194 _____ C:\bdlog.txt
2018-11-05 20:10 - 2015-12-05 12:36 - 000000000 ____D C:\AdwCleaner
2018-11-05 19:12 - 2015-11-28 22:24 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\Seznam.cz
2018-11-05 19:11 - 2015-11-28 22:25 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
2018-11-04 14:51 - 2017-12-28 20:20 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\Kodi
2018-11-04 08:23 - 2018-04-11 22:04 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2018-11-03 20:32 - 2016-06-10 12:26 - 000000000 ____D C:\KMPlayer
2018-11-03 16:58 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-11-03 08:17 - 2015-08-31 14:42 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-11-02 21:55 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-11-01 21:02 - 2018-09-30 10:23 - 000156912 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2018-10-31 20:33 - 2015-08-24 20:20 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-10-22 20:12 - 2016-01-03 08:42 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-10-22 19:58 - 2018-03-04 13:59 - 000000000 ____D C:\ProgramData\BDLogging
2018-10-21 10:26 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-10-19 19:14 - 2018-03-04 13:58 - 000045728 _____ (© Bitdefender SRL) C:\WINDOWS\system32\Drivers\bdprivmon.sys
2018-10-19 19:07 - 2018-03-04 13:58 - 001292296 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2018-10-16 18:03 - 2018-06-24 20:47 - 000063461 _____ C:\Users\Vilem\Documents\miki a viky.pbf
2018-10-15 22:38 - 2018-07-01 12:35 - 000000000 ____D C:\ProgramData\Packages
2018-10-15 20:10 - 2018-06-30 18:51 - 000003354 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-341233860-2387372215-3518537327-1001
2018-10-15 20:10 - 2018-06-30 18:18 - 000002389 _____ C:\Users\Vilem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-10-15 20:10 - 2015-05-02 19:37 - 000000000 ___RD C:\Users\Vilem\OneDrive
2018-10-13 20:38 - 2017-02-17 20:40 - 000000000 ____D C:\Program Files (x86)\HappyFoto-Designer
2018-10-13 15:03 - 2015-10-28 07:37 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\XnView
2018-10-13 04:40 - 2015-08-10 20:58 - 000000000 ___RD C:\Users\Vilem\3D Objects
2018-10-13 04:40 - 2015-05-03 03:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-10-13 04:38 - 2018-06-30 18:12 - 000446080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-10-12 21:21 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2018-10-12 17:54 - 2015-10-03 13:51 - 000000000 ____D C:\Users\Vilem\AppData\LocalLow\Adobe
2018-10-12 15:59 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-10-12 14:50 - 2015-08-23 18:45 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-10-12 14:45 - 2015-08-23 18:45 - 136745976 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Files in the root of some directories =======

2016-04-08 20:24 - 2016-04-08 20:24 - 000099384 _____ () C:\Users\Vilem\AppData\Roaming\ezpinst.exe
2016-11-03 21:44 - 2016-11-03 21:44 - 000099384 _____ () C:\Users\Vilem\AppData\Roaming\inst.exe
2016-04-08 20:24 - 2016-11-03 21:44 - 000007859 _____ () C:\Users\Vilem\AppData\Roaming\pcouffin.cat
2016-04-08 20:24 - 2016-11-03 21:44 - 000001167 _____ () C:\Users\Vilem\AppData\Roaming\pcouffin.inf
2015-11-28 21:17 - 2016-11-03 21:44 - 000000033 _____ () C:\Users\Vilem\AppData\Roaming\pcouffin.log
2016-04-08 20:24 - 2016-11-03 21:44 - 000082816 _____ (VSO Software) C:\Users\Vilem\AppData\Roaming\pcouffin.sys
2016-02-20 20:25 - 2016-02-20 20:28 - 000004608 _____ () C:\Users\Vilem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

Some files in TEMP:
====================
2018-11-03 20:48 - 2018-11-05 19:11 - 000534528 _____ () C:\Users\Vilem\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-06-30 18:12

==================== End of FRST.txt ============================




Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
Ran by Vilem (05-11-2018 21:46:12)
Running from C:\Users\Vilem\Desktop
Windows 10 Home Version 1803 17134.345 (X64) (2018-06-30 17:53:18)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-341233860-2387372215-3518537327-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-341233860-2387372215-3518537327-503 - Limited - Disabled)
Guest (S-1-5-21-341233860-2387372215-3518537327-501 - Limited - Disabled)
Vilem (S-1-5-21-341233860-2387372215-3518537327-1001 - Administrator - Enabled) => C:\Users\Vilem
WDAGUtilityAccount (S-1-5-21-341233860-2387372215-3518537327-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5}
FW: Bitdefender Firewall (Enabled) {362C5A58-E860-6396-9204-BEEEF20CA463}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 15.13 (x64) (HKLM\...\7-Zip) (Version: 15.13 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.008.20080 - Adobe Systems Incorporated)
Advanced IP Scanner 2.5 (HKLM-x32\...\{12830D25-D77C-46B1-902E-2CAD8878CE95}) (Version: 2.5.3499 - Famatech)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.18 - ASUS)
ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.7.2 - ASUS)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 21.0.25.59 - Bitdefender)
Bitdefender Internet Security (HKLM\...\Bitdefender) (Version: 22.0.19.242 - Bitdefender)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.69.1079 - AB Team, d.o.o.)
CDSM Designer (HKLM-x32\...\CDSM_CDSM Designer) (Version: - )
ConvertXtoDVD 2.0.9 (HKLM-x32\...\{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1) (Version: 2.0.9 - VSO-Software SARL)
DVDFab Platinum 3.0.8.6 (HKLM-x32\...\DVDFab Platinum_is1) (Version: - Fengtao Software Inc.)
Epson Easy Photo Print 2 (HKLM-x32\...\{07AA1C7F-E8CA-4FDC-B975-BC9EBC22B6DE}) (Version: 2.7.0.0 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
FastStone Image Viewer 5.5 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.5 - FastStone Soft)
FormatFactory 3.8.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.8.0.0 - Free Time)
FOTOKNIHY (HKLM-x32\...\FOTOKNIHY_FOTOKNIHY) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 70.0.3538.77 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
HappyFoto DESIGNER 5.6 (HKLM-x32\...\HappyFoto-Designer_is1) (Version: - )
HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
InterVideo DeviceService (HKLM-x32\...\{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}) (Version: 1.0.0 - InterVideo)
KB4023057 (HKLM\...\{264FDD69-C4DF-476F-B1B8-7DCEE4AF839B}) (Version: 2.4.0.0 - Microsoft Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.0.8.1 - PandoraTV)
Kodi (HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\Kodi) (Version: - XBMC-Foundation)
LAV Filters 0.55.3 (HKLM-x32\...\lavfilters_is1) (Version: 0.55.3 - Hendrik Leppkes)
Lenovo EasyCamera (HKLM-x32\...\{E8266049-8C7B-4A09-9E11-8BD100E0076A}) (Version: 8.0.1.2368 - GenesysLogic)
LG Mobile Drivers (HKLM-x32\...\{D8D0327A-72B4-4C79-9883-1B6B6C20ED2B}) (Version: 4.0.3 - LG Electronics)
LibreOffice 5.0.4.2 (HKLM-x32\...\{14B5DDCF-61C4-4F1E-A621-844685D60B5A}) (Version: 5.0.4.2 - The Document Foundation)
Microsoft OneDrive (HKU\S-1-5-21-341233860-2387372215-3518537327-1001\...\OneDriveSetup.exe) (Version: 18.172.0826.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Multiecuscan (HKLM-x32\...\{803D46C0-7CE0-4F62-B85F-E32EA0C56747}) (Version: 2.2 - FES Soft Ltd.)
Ovladače videa společnosti Pinnacle (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems)
paint.net (HKLM\...\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}) (Version: 4.0.9 - dotPDN LLC)
Pdf2Jpg version 1.2 (HKLM-x32\...\{533D415A-4151-4AC5-858E-4068524C8051}_is1) (Version: 1.2 - Office Necessities inc.)
PicosmosTools 1.4.0.0 (HKLM-x32\...\PicosmosTools) (Version: 1.4.0.0 - Free Time)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}) (Version: 2.00.088 - )
Pinnacle Studio 14 (HKLM-x32\...\{AADD1C8F-D59F-4D55-A726-768C71A205A8}) (Version: 14.0.0.7255 - Pinnacle Systems)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7514 - Realtek Semiconductor Corp.)
Studio 11 (HKLM-x32\...\{110B1ADF-2EAE-4E8F-B501-D2A1E6D8ED9D}) (Version: 11.0 - Pinnacle Systems)
Studio 11 (HKLM-x32\...\{2F952048-3220-4AC7-A206-D01EFC774BB2}) (Version: 11.0.0.0 - Pinnacle Systems) Hidden
Super DVD Ripper (remove only) (HKLM-x32\...\x2VCD) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.93450 - TeamViewer)
Ulead VideoStudio 11 (HKLM-x32\...\InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}) (Version: 11.0.0.0000 - InterVideo Digital Technology Corporation)
Video to Video (HKLM-x32\...\{7F95A744-78DA-4AED-A8F0-A0AF330B8411}_is1) (Version: - Media Converters)
VideoStudio (HKLM-x32\...\{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}) (Version: 11.0.0.0000 - InterVideo Digital Technology Corporation) Hidden
VSO ConvertXToDVD 6 (HKLM-x32\...\{8FC36FA6-C508-44FB-B137-1CB46D8258B2}_is1) (Version: 6.0.0.71 - VSO Software)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
XnView 2.34 (HKLM-x32\...\XnView_is1) (Version: 2.34 - Gougelet Pierre-e)
XviD MPEG-4 Video Codec (HKLM-x32\...\xvid) (Version: - XviD Development Team)
Yahoo! Desktop Login (HKLM-x32\...\{F9AEEC34-CF00-4CBD-9E36-DF9DC4002685}) (Version: 1.00.0001 - Pinnacle Systems) Hidden
Zoner Photo Studio 15 - Obálky a šablony (HKLM\...\ZonerPhotoStudio15_Templates_CZ_is1) (Version: 15.0.1.1 - ZONER software)
Zoner Photo Studio 15 (HKLM\...\ZonerPhotoStudio15_CZ_is1) (Version: 15.0.1.3 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-341233860-2387372215-3518537327-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers2-x32: [Ulead UDF Driver] -> {DBD8E168-244D-448C-9922-25508950D1DC} => C:\Program Files (x86)\Common Files\Ulead Systems\DVD\USIShex.dll [2007-03-03] (Ulead Systems, Inc.)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {050EED22-E9CB-409E-B513-8BAB80E601E4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {24709E92-C601-4229-A88B-A0204885780F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2018-10-12] (Microsoft Corporation)
Task: {2F0BBCA7-1AD0-4D17-9603-A1ABCD83B168} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-13] (Realtek Semiconductor)
Task: {459FBC32-99B5-4C54-B16F-B3BDAE46EB28} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-24] (Google Inc.)
Task: {45CF7F9E-DCEA-44A0-9CDF-910C4F67F333} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-07-31] (Bitdefender)
Task: {4AC6203E-0DF0-4CE4-AD18-2F94BF0A59ED} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {5C58ED13-3DF4-4C48-918E-DCAC8B8D726C} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2017-03-09] (AsusTek)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {C451479F-BB05-4E44-A32B-446A60591D15} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-13] (Realtek Semiconductor)
Task: {D1061EE3-7FFB-4180-812C-5CBEA277678D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {FAA6D6A1-F189-444D-B6B9-BDE68E301384} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender Security\bdagent.exe [2018-11-01] (Bitdefender)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Vilem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Multiecuscan\Multiecuscan Web Site.lnk -> hxxp://www.multiecuscan.net

==================== Loaded Modules (Whitelisted) ==============

2018-09-24 13:49 - 2018-09-24 13:49 - 000994752 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttpbr.mdl
2018-09-24 13:49 - 2018-09-24 13:49 - 000544880 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttpdsp.mdl
2018-09-24 13:49 - 2018-09-24 13:49 - 003240080 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttpph.mdl
2018-09-24 13:49 - 2018-09-24 13:49 - 001530368 _____ () C:\Program Files\Bitdefender\Bitdefender Security\otengines_02851_004\ashttprbl.mdl
2017-07-26 08:58 - 2017-07-26 08:58 - 000192200 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-10-12 14:31 - 2018-09-20 04:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-10-15 22:36 - 2018-10-15 22:37 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\ChakraBridge.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000019456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeProxiesAndStubs.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 010978304 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\LibWrapper.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 002810368 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\skypert.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000685056 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-10-24 11:16 - 2018-10-24 11:17 - 000183808 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
2018-10-06 07:11 - 2018-10-06 07:12 - 000194048 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll
2018-08-01 16:33 - 2018-08-01 16:34 - 002447072 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-10-06 07:11 - 2018-10-06 07:11 - 001689088 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11809.1001.8.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.dll
2018-10-31 20:33 - 2018-10-23 22:24 - 005020504 _____ () C:\Program Files (x86)\Google\Chrome\Application\70.0.3538.77\libglesv2.dll
2018-10-31 20:33 - 2018-10-23 22:24 - 000116056 _____ () C:\Program Files (x86)\Google\Chrome\Application\70.0.3538.77\libegl.dll
2016-02-07 04:06 - 2016-02-07 04:06 - 003182080 _____ () C:\Program Files (x86)\PicosmosTools\FFImage.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\WINDOWS\system32\AERTAC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\AERTAR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPD64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPO64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPONS64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSLFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSLimiterDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSNeoPCDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSSymmetryDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PGFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PLFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PREC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\FMAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\igfxCoIn_v4252.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KAAPORT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO20.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO30.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioEQ64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxVolumeSDAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEA64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RCoInstII64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RltkAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RP3DAA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RP3DHT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtCRX64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RtDataProc64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkApi64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkCfg64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkCoLDR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtlCPAPI64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtPgEx64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTSnMg64.cpl:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFNHK64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFSS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSHP64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSTSH64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSTSX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSWOW64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tadefxapo.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tadefxapo264.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tepeqapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tosade.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\glprop.ax:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\gluninstall.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RsCRIcon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SFCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\glavcam.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\RTKVHD64.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\RtsBaStor.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Desktop\0631f272458601909cfdcaf416b11b64_b.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\2014-patrovy-sedlova-strecha-dus.xls:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (1).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (10).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (11).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (2).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (3).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (4).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (5).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (6).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (7).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (8).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (9).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923.csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_rc2.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\mont_navod_plast_zlab_5360944.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\nova_78_38_2m_garaz_33718.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Nový+objekt+-+Dokument+aplikace+Microsoft+Word.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (3).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (4).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (3).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (4).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (5).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_25840.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_26496.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS2.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS4.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\script.module.stream.resolver-1.6.32.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tb_free.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_613900002411.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (3).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (4).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TOPS4.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-master.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-old-master.zip:$CmdZnID [26]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys => ""="Driver"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-08-23 18:26 - 2018-11-05 21:40 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-341233860-2387372215-3518537327-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Vilem\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\asus.jpg
DNS Servers: 192.168.88.1 - 85.162.162.162
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{DEA3B2F4-018E-4A58-9CEF-6F56B769702A}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe
FirewallRules: [{6CD0E4B2-C063-480B-81A1-15E01001B6F6}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe
FirewallRules: [{CA0C52EB-68CC-4CBE-9AF2-4E3BF9835CDB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{03A55787-F0A1-4797-88E5-9386276EC7F8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{9B3F2063-BA19-4489-A0D9-25E1FBA456FB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{AF0964AB-F8E3-40EE-828D-382E70B538B9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [UDP Query User{855D51EC-4483-4D53-8B9F-25AB59DE07C3}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [TCP Query User{0EED3124-A357-4A63-931B-27F0139799FA}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{0A850433-2D85-43E3-990E-C7B582D6C55E}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [TCP Query User{7B5BDBFB-2B22-4FBD-A954-9D0DED2402A2}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{C2B0D30A-2312-456E-ABE4-B83538724EAD}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{4D98E928-F7C6-4EC8-9067-D379924C4E67}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{79A5F907-0204-4F90-98A9-335F8F8E2F23}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{B4737BBD-BA34-4D14-B683-0D0311C12227}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{AB503824-2478-4380-859E-DFC7ABA04FC0}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{3480BACB-58D0-413A-B04D-7132885A4D18}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

19-10-2018 19:09:36 Naplánovaný kontrolní bod
02-11-2018 23:06:45 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/05/2018 07:11:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: sznpp_64.exe, verze: 2.1.32.0, časové razítko: 0x5ae9c366
Název chybujícího modulu: sznpp_64.exe, verze: 2.1.32.0, časové razítko: 0x5ae9c366
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000140dc
ID chybujícího procesu: 0xacc
Čas spuštění chybující aplikace: 0x01d47532faec9686
Cesta k chybující aplikaci: C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\sznpp_64.exe
Cesta k chybujícímu modulu: C:\Users\Vilem\AppData\Roaming\Seznam.cz\bin\sznpp_64.exe
ID zprávy: 573a3ca9-072a-48a9-829e-5f2365183ee1
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (11/02/2018 03:50:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: kodi.exe, verze: 17.6.0.0, časové razítko: 0x5a2d50f5
Název chybujícího modulu: kodi.exe, verze: 17.6.0.0, časové razítko: 0x5a2d50f5
Kód výjimky: 0xc0000005
Posun chyby: 0x001c975a
ID chybujícího procesu: 0x15b0
Čas spuštění chybující aplikace: 0x01d472b547a41e1e
Cesta k chybující aplikaci: C:\Program Files (x86)\Kodi\kodi.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Kodi\kodi.exe
ID zprávy: 802f5152-7181-401a-adec-939019ca563d
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (10/22/2018 08:10:41 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {41FD88F7-F295-4D39-91AC-A85F3149A05B} byla odmítnuta.

Error: (10/22/2018 08:10:41 PM) (Source: COM) (EventID: 10031) (User: )
Description: Při zrušení zařazení vlastního zařazeného objektu byla provedena kontrola zásad zrušení zařazení a třída {95CABCC9-BC57-4C12-B8DF-BA193232AA01} byla odmítnuta.

Error: (10/16/2018 12:36:28 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SkypeApp.exe verze 8.32.0.55 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 3e88

Čas spuštění: 01d464cf610655de

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.32.55.0_x64__kzf8qxf38zg5c\SkypeApp.exe

ID hlášení: 7c9dacf5-686e-4d36-b780-0ca53e99a78f

Úplný název balíčku s chybou: Microsoft.SkypeApp_14.32.55.0_x64__kzf8qxf38zg5c

ID aplikace související s balíčkem s chybou: App

Error: (10/15/2018 08:10:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: backgroundTaskHost.exe, verze: 10.0.17134.1, časové razítko: 0xcb43d9c5
Název chybujícího modulu: combase.dll, verze: 10.0.17134.112, časové razítko: 0xfad18dc5
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000421cc
ID chybujícího procesu: 0x1b00
Čas spuštění chybující aplikace: 0x01d46456274c7627
Cesta k chybující aplikaci: C:\WINDOWS\system32\backgroundTaskHost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\combase.dll
ID zprávy: 0259c443-de31-4585-8c56-9c3042bb4b61
Úplný název chybujícího balíčku: Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy
ID aplikace související s chybujícím balíčkem: App

Error: (10/13/2018 08:59:51 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
Spouštění asynchronní operace

Kontext:
Aktuální stav: DoSnapshotSet

Error: (10/13/2018 03:01:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program xnview.exe verze 2.34.0.0 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 1f40

Čas spuštění: 01d462fd1496d3a2

Čas ukončení: 25

Cesta k aplikaci: C:\Program Files (x86)\XnView\xnview.exe

ID hlášení: 470db75d-36cb-4ecb-97dc-638f4f4e2eab

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:


System errors:
=============
Error: (11/05/2018 09:33:42 PM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 09:33:17 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 08:36:32 PM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 08:35:32 PM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 08:16:09 PM) (Source: DCOM) (EventID: 10016) (User: DEDA)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli DEDA\Vilem (SID: S-1-5-21-341233860-2387372215-3518537327-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 08:13:01 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 08:13:01 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/05/2018 08:13:00 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2018-10-06 08:26:40.282
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FB9B08F4-7D45-4AF9-B7B8-267EEFB19DB3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-03 21:03:44.193
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {F49D8E54-A33B-48E5-A89C-13874BE43B4C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-02 20:10:29.674
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {B8FB8C5D-E144-4114-913E-9E38EE3FC6E5}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-02 16:34:16.512
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {D5EB768D-DEEB-4BA9-98CA-FA83C82D8424}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-02 11:51:50.824
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Windows Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x80004005
Popis chyby: Nespecifikovaná chyba
Důvod: Ovladač filtru přeskočil prohledávání položek a je v režimu průchodu. Příčinou může být nízký stav prostředků.

CodeIntegrity:
===================================

Date: 2018-11-05 20:12:29.778
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-11-03 21:35:13.820
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-11-03 16:57:44.988
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-10-22 21:08:05.407
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\bdservicehost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-10-22 20:58:37.052
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\vsservp.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-10-13 05:37:27.888
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\vsservp.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender\Bitdefender Security\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2018-09-30 17:22:39.789
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.1809.2-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\win32kbase.sys that did not meet the Microsoft signing level requirements.

Date: 2018-09-30 17:06:02.625
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\win32kbase.sys that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU N3540 @ 2.16GHz
Percentage of memory in use: 55%
Total physical RAM: 3982.55 MB
Available physical RAM: 1785.4 MB
Total Virtual: 5582.55 MB
Available Virtual: 2810.04 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:94.04 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Data) (Fixed) (Total:258.35 GB) (Free:40.69 GB) NTFS

\\?\Volume{f3a1877d-0eb1-4eab-bb8c-50dcd183886f}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.59 GB) NTFS
\\?\Volume{a36cb6bd-1001-49e2-b7eb-6618d67926af}\ (Restore) (Fixed) (Total:20.01 GB) (Free:9.18 GB) NTFS
\\?\Volume{8e42827b-8a41-41ec-8b3a-a7a7e706d199}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 285C82C9)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Prosím o preventivní kontrolu

Napsal: 06 lis 2018 22:56
od Conder
:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
    S3 PCASp60; System32\Drivers\PCASp60.sys [X]
    2018-11-05 19:12 - 2015-11-28 22:24 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\Seznam.cz
    2018-11-05 19:11 - 2015-11-28 22:25 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
    Task: {4AC6203E-0DF0-4CE4-AD18-2F94BF0A59ED} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    
    AlternateDataStreams: C:\WINDOWS\system32\AERTAC64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\AERTAR64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DDPA64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DDPD64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DDPO64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DDPP64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSBoostDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPO64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPONS64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSLFXAPO64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSLimiterDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSNeoPCDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSSymmetryDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSU2PGFX64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSU2PLFX64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSU2PREC64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\FMAPO64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\igfxCoIn_v4252.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\KAAPORT64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO20.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO30.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO4064.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioEQ64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\MaxxVolumeSDAPO.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\R4EEA64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\R4EED64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\R4EEG64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\R4EEL64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\R4EEP64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RCoInstII64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RltkAPO64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RP3DAA64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RP3DHT64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTCOM64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RtCRX64.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\RtDataProc64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTEED64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTEEG64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTEEL64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTEEP64A.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RtkApi64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RtkCfg64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RtkCoLDR64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RtlCPAPI64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RtPgEx64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\RTSnMg64.cpl:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SFAPO64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SFCOM64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SFNHK64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SFSS_APO.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SRSHP64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SRSTSH64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SRSTSX64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\SRSWOW64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\tadefxapo.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\tadefxapo264.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\tepeqapo64.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\tosade.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\glprop.ax:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\gluninstall.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\RsCRIcon.dll:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\SysWOW64\SFCOM.dll:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\glavcam.sys:$CmdTcID [64]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\RTKVHD64.sys:$CmdTcID [130]
    AlternateDataStreams: C:\WINDOWS\system32\Drivers\RtsBaStor.sys:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Desktop\0631f272458601909cfdcaf416b11b64_b.jpg:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\2014-patrovy-sedlova-strecha-dus.xls:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (1).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (10).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (11).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (2).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (3).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (4).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (5).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (6).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (7).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (8).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (9).csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\604693923.csv:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdTcID [130]
    AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_rc2.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\mont_navod_plast_zlab_5360944.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\nova_78_38_2m_garaz_33718.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Nový+objekt+-+Dokument+aplikace+Microsoft+Word.doc:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (1).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (2).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (3).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (4).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (1).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (2).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (3).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (4).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový (5).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrový.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_25840.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_26496.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (1).pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (2).pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS2.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS4.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\script.module.stream.resolver-1.6.32.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tb_free.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_613900002411.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (1).pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (2).pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (3).pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (4).pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601.pdf:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\TOPS4.rar:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (1).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (2).zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdTcID [64]
    AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-master.zip:$CmdZnID [26]
    AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-old-master.zip:$CmdZnID [26]
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj

Re: Prosím o preventivní kontrolu

Napsal: 07 lis 2018 14:12
od Robotka
Tady je log:

Fix result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
Ran by Vilem (07-11-2018 13:56:54) Run:1
Running from C:\Users\Vilem\Desktop
Loaded Profiles: Vilem (Available Profiles: Vilem)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
S3 PCASp60; System32\Drivers\PCASp60.sys [X]
2018-11-05 19:12 - 2015-11-28 22:24 - 000000000 ____D C:\Users\Vilem\AppData\Roaming\Seznam.cz
2018-11-05 19:11 - 2015-11-28 22:25 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {4AC6203E-0DF0-4CE4-AD18-2F94BF0A59ED} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION

AlternateDataStreams: C:\WINDOWS\system32\AERTAC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\AERTAR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPD64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPO64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DDPP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSBoostDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSGFXAPONS64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSLFXAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSLimiterDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSNeoPCDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSSymmetryDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PGFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PLFX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSU2PREC64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\FMAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\igfxCoIn_v4252.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KAAPORT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO20.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO30.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioAPO4064.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxAudioEQ64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\MaxxVolumeSDAPO.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEA64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\R4EEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RCoInstII64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RltkAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RP3DAA64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RP3DHT64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtCRX64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RtDataProc64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEED64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEG64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEL64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTEEP64A.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkApi64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkCfg64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtkCoLDR64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtlCPAPI64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RtPgEx64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\RTSnMg64.cpl:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFAPO64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFCOM64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFNHK64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SFSS_APO.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSHP64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSTSH64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSTSX64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\SRSWOW64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tadefxapo.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tadefxapo264.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tepeqapo64.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\tosade.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\glprop.ax:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\gluninstall.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\RsCRIcon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SFCOM.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\glavcam.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\RTKVHD64.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\RtsBaStor.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Desktop\0631f272458601909cfdcaf416b11b64_b.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\2014-patrovy-sedlova-strecha-dus.xls:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (1).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (10).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (11).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (2).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (3).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (4).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (5).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (6).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (7).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (8).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923 (9).csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\604693923.csv:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdTcID [130]
AlternateDataStreams: C:\Users\Vilem\Downloads\7z920-x64.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\ChromeSetup.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\fz30.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\kodi-15.0-Isengard_rc2.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\mont_navod_plast_zlab_5360944.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\nova_78_38_2m_garaz_33718.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Nov�+objekt+-+Dokument+aplikace+Microsoft+Word.doc:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\picasa39-setup.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (3).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov (4).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy - bungalov.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrov� (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrov� (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrov� (3).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrov� (4).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrov� (5).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\Pohledy patrov�.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_25840.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\prilohy_26496.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\PS-081_MZZ51900.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS2.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\SanSwiss-TOPS4.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\script.module.stream.resolver-1.6.32.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tb_free.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_613900002411.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (1).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (2).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (3).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601 (4).pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\tech_nakres_w914601.pdf:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TOPS4.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ (2).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\TranslationCZ.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-master.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Vilem\Downloads\xbmc-doplnky-old-master.zip:$CmdZnID [26]

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.

========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========



Count : 2262
Average :
Sum : 6730119297
Maximum :
Minimum :
Property : Length




========= End of Powershell: =========

HKLM\System\CurrentControlSet\Services\PCASp60 => removed successfully
PCASp60 => service removed successfully
C:\Users\Vilem\AppData\Roaming\Seznam.cz => moved successfully
C:\Program Files (x86)\Seznam.cz => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AC6203E-0DF0-4CE4-AD18-2F94BF0A59ED}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AC6203E-0DF0-4CE4-AD18-2F94BF0A59ED}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
C:\WINDOWS\system32\AERTAC64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\AERTAR64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DDPA64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DDPD64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DDPO64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DDPP64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSBoostDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSGFXAPO64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSGFXAPONS64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSLFXAPO64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSLimiterDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSNeoPCDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSSymmetryDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSU2PGFX64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSU2PLFX64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSU2PREC64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\FMAPO64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\igfxCoIn_v4252.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\KAAPORT64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\MaxxAudioAPO20.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\MaxxAudioAPO30.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\MaxxAudioAPO4064.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\MaxxAudioEQ64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\MaxxVolumeSDAPO.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\R4EEA64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\R4EED64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\R4EEG64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\R4EEL64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\R4EEP64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RCoInstII64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RltkAPO64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RP3DAA64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RP3DHT64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RTCOM64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtCRX64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtDataProc64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RTEED64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RTEEG64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RTEEL64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RTEEP64A.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtkApi64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtkCfg64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtkCoLDR64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtlCPAPI64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RtPgEx64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\RTSnMg64.cpl => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SFAPO64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SFCOM64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SFNHK64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SFSS_APO.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SRSHP64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SRSTSH64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SRSTSX64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\SRSWOW64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\tadefxapo.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\tadefxapo264.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\tepeqapo64.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\tosade.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\SysWOW64\glprop.ax => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\SysWOW64\gluninstall.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\SysWOW64\RsCRIcon.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\SysWOW64\SFCOM.dll => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\Drivers\glavcam.sys => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\Drivers\RTKVHD64.sys => ":$CmdTcID" ADS removed successfully
C:\WINDOWS\system32\Drivers\RtsBaStor.sys => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Desktop\0631f272458601909cfdcaf416b11b64_b.jpg => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\2014-patrovy-sedlova-strecha-dus.xls => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (1).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (10).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (11).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (2).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (3).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (4).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (5).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (6).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (7).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (8).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923 (9).csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\604693923.csv => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\7z920-x64 (1).exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\7z920-x64 (1).exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\7z920-x64.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\7z920-x64.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\ChromeSetup.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\ChromeSetup.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\fz30.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\fz30.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\kodi-15.0-Isengard_beta1.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\kodi-15.0-Isengard_rc2.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\mont_navod_plast_zlab_5360944.pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\nova_78_38_2m_garaz_33718.pdf => ":$CmdZnID" ADS removed successfully
"C:\Users\Vilem\Downloads\Nov�+objekt+-+Dokument+aplikace+Microsoft+Word.doc" => ":$CmdZnID" ADS not found.
C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\pf7-setup-en-7.2.1.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\picasa39-setup.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\picasa39-setup.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\Pohledy - bungalov (1).zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\Pohledy - bungalov (2).zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\Pohledy - bungalov (3).zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\Pohledy - bungalov (4).zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\Pohledy - bungalov.zip => ":$CmdZnID" ADS removed successfully
"C:\Users\Vilem\Downloads\Pohledy patrov� (1).zip" => ":$CmdZnID" ADS not found.
"C:\Users\Vilem\Downloads\Pohledy patrov� (2).zip" => ":$CmdZnID" ADS not found.
"C:\Users\Vilem\Downloads\Pohledy patrov� (3).zip" => ":$CmdZnID" ADS not found.
"C:\Users\Vilem\Downloads\Pohledy patrov� (4).zip" => ":$CmdZnID" ADS not found.
"C:\Users\Vilem\Downloads\Pohledy patrov� (5).zip" => ":$CmdZnID" ADS not found.
"C:\Users\Vilem\Downloads\Pohledy patrov�.zip" => ":$CmdZnID" ADS not found.
C:\Users\Vilem\Downloads\prilohy_25840.zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\prilohy_26496.zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\PS-081_MZZ51900 (1).pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\PS-081_MZZ51900 (2).pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\PS-081_MZZ51900.pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\SanSwiss-TOPS2.pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\SanSwiss-TOPS4.pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\script.module.stream.resolver-1.6.32.zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tb_free.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\TeamViewer_Setup_cs-iuu.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tech_nakres_613900002411.pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tech_nakres_w914601 (1).pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tech_nakres_w914601 (2).pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tech_nakres_w914601 (3).pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tech_nakres_w914601 (4).pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\tech_nakres_w914601.pdf => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\TOPS4.rar => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\TranslationCZ (1).zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\TranslationCZ (2).zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\TranslationCZ.zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (1).exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524 (2).exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe => ":$CmdTcID" ADS removed successfully
C:\Users\Vilem\Downloads\WebStorageSyncAgent2.2.2.524.exe => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\xbmc-doplnky-master.zip => ":$CmdZnID" ADS removed successfully
C:\Users\Vilem\Downloads\xbmc-doplnky-old-master.zip => ":$CmdZnID" ADS removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 33786375 B
Java, Flash, Steam htmlcache => 1714 B
Windows/system/drivers => 2754243 B
Edge => 2891388 B
Chrome => 377349584 B
Firefox => 786432 B
Opera => 17563301 B

Temp, IE cache, history, cookies, recent:
Default => 26492 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 50376 B
LocalService => 0 B
NetworkService => 50890 B
NetworkService => 0 B
Vilem => 37996351 B

RecycleBin => 0 B
EmptyTemp: => 461.4 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 14:06:23 ====

Re: Prosím o preventivní kontrolu

Napsal: 07 lis 2018 17:57
od Conder
:arrow: Vyzera to OK. Su nejake problemy s PC?

:arrow: Plocha ma vyse 6 GB. Presun vsetky subory a zlozky z plochy do dokumentov a na ploche nechaj iba odkazy/zastupcov. Prilis velka velkost plochy moze sposobit spomalenie systemu.

Re: Prosím o preventivní kontrolu

Napsal: 07 lis 2018 19:33
od Robotka
OK. vypadá že to bude dobré.
tu plochu opravím.
Zatím moc děkuji.

Re: Prosím o preventivní kontrolu

Napsal: 08 lis 2018 17:05
od Conder
:arrow: Tak este upraceme po pouzitych nastrojoch: