Stránka 1 z 1

Prosím o konrolu logu

Napsal: 20 led 2019 12:25
od Bruno39
Prosím o konrolu logu lebo uz 2krat mi ukardli steam ucet
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16.01.2019 01
Ran by Bruno (administrator) on DESKTOP-KN6KRSK (20-01-2019 12:21:59)
Running from C:\Users\Bruno\Desktop
Loaded Profiles: Bruno (Available Profiles: Bruno)
Platform: Windows 10 Enterprise LTSC 2019 Version 1809 17763.253 (X64) Language: Čeština (Česká republika)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\DriverStore\FileRepository\c0337288.inf_amd64_3c3211f00f323cb5\B337205\atiesrxx.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdredline.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe
(Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0337288.inf_amd64_3c3211f00f323cb5\B337205\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\schtasks.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper32.exe
(Microsoft Corporation) C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\PeopleExperienceHost.exe
(Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SoftEther VPN Client UI Helper] => C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5258552 2018-11-17] (SoftEther VPN Project at University of Tsukuba, Japan.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5889480 2018-12-14] (LogMeIn Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3133216 2019-01-05] (Valve Corporation)
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35184016 2019-01-10] (Epic Games, Inc.)
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [Discord] => C:\Users\Bruno\AppData\Local\Discord\app-0.0.304\Discord.exe [81747288 2019-01-15] (Discord Inc.)
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [BitTorrent] => C:\Users\Bruno\AppData\Roaming\BitTorrent\BitTorrent.exe [1746368 2018-11-17] (BitTorrent Inc.)
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [WallpaperEngine] => E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper32.exe [1698296 2018-12-15] ()
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [vibranceGUI] => C:\Users\Bruno\Desktop\vibranceGUI.exe [794624 2018-12-10] (juvlarN)
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Run: [FACEIT] => C:\Users\Bruno\AppData\Local\FACEITApp\update.exe [2203584 2019-01-20] ()
IFEO\SppExtComObj.exe: [Debugger] rundll32.exe SppExtComObjHook.dll,PatcherMain
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SoftEther VPN Client Manager Startup.lnk [2018-11-17]
ShortcutTarget: SoftEther VPN Client Manager Startup.lnk -> C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2019-01-19]
ShortcutTarget: Twitch.lnk -> C:\Users\Bruno\AppData\Roaming\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{fd7bb464-5075-44c3-9abd-c63c303a5e70}: [DhcpNameServer] 192.168.31.1

Internet Explorer:
==================
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: jugn7tq7.default
FF ProfilePath: C:\Users\Bruno\AppData\Roaming\Mozilla\Firefox\Profiles\jugn7tq7.default [2019-01-20]
FF Homepage: Mozilla\Firefox\Profiles\jugn7tq7.default -> hxxps://www.google.sk
FF NewTab: Mozilla\Firefox\Profiles\jugn7tq7.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10420__181117
FF Extension: (AdBlocker Ultimate) - C:\Users\Bruno\AppData\Roaming\Mozilla\Firefox\Profiles\jugn7tq7.default\Extensions\adblockultimate@adblockultimate.net.xpi [2018-12-10]
FF Extension: (Enhanced Steam) - C:\Users\Bruno\AppData\Roaming\Mozilla\Firefox\Profiles\jugn7tq7.default\Extensions\jid1-YdiFiTEkQgInxA@jetpack.xpi [2019-01-10]
FF Extension: (Touch VPN) - C:\Users\Bruno\AppData\Roaming\Mozilla\Firefox\Profiles\jugn7tq7.default\Extensions\touch-vpn@anchorfree.com.xpi [2018-12-11]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD External Events Utility; C:\Windows\System32\DriverStore\FileRepository\c0337288.inf_amd64_3c3211f00f323cb5\B337205\atiesrxx.exe [508512 2018-12-19] (AMD)
R2 bdredline; C:\Program Files\Bitdefender Antivirus Free\bdredline.exe [2195280 2018-03-22] (Bitdefender)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8352184 2019-01-12] ()
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2018-11-16] (EasyAntiCheat Ltd)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3366344 2018-12-14] (LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2269504 2018-11-16] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3130184 2018-11-16] (Electronic Arts)
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1293936 2018-11-15] (Bitdefender)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5381128 2019-01-10] (Microsoft Corporation)
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5258552 2018-11-17] (SoftEther VPN Project at University of Tsukuba, Japan.)
S4 ssh-agent; C:\Windows\System32\OpenSSH\ssh-agent.exe [384512 2018-09-15] ()
R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [246688 2018-11-13] (Bitdefender)
R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [341136 2018-11-13] (Bitdefender)
R2 vsservppl; C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe [246688 2018-11-13] (Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\NisSrv.exe [3880120 2018-12-10] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MsMpEng.exe [114208 2018-12-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [67576 2018-12-19] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0337288.inf_amd64_3c3211f00f323cb5\B337205\atikmdag.sys [52749408 2018-12-19] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0337288.inf_amd64_3c3211f00f323cb5\B337205\atikmpag.sys [590432 2018-12-19] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [112688 2018-11-08] (Advanced Micro Devices, Inc.)
R1 atc; C:\Windows\System32\DRIVERS\atc.sys [1423336 2018-10-29] (BitDefender S.R.L. Bucharest, ROMANIA)
R2 BdDci; C:\Windows\system32\DRIVERS\bddci.sys [367096 2018-12-04] (Bitdefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23032 2018-04-19] (Bitdefender)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 edrsensor; C:\Windows\System32\DRIVERS\edrsensor.sys [290688 2018-12-03] (BitDefender S.R.L. Bucharest, ROMANIA)
R1 Gemma; C:\Windows\System32\DRIVERS\gemma.sys [374632 2018-11-19] (BitDefender S.R.L. Bucharest, ROMANIA)
R0 gzflt; C:\Windows\System32\drivers\gzflt.sys [201000 2018-11-20] (BitDefender LLC)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2018-12-14] (LogMeIn Inc.)
R3 Neo_VPN; C:\Windows\System32\drivers\Neo6_x64_VPN.sys [37824 2018-11-17] (SoftEther Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [605696 2018-09-15] (Realtek )
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [8206848 2018-09-15] (Realtek Semiconductor Corporation )
R1 SeLow; C:\Windows\system32\DRIVERS\SeLow_x64.sys [50624 2018-11-17] (SoftEther Corporation)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 tap-tb-0901; C:\Windows\System32\drivers\tap-tb-0901.sys [38656 2018-07-31] (The OpenVPN Project)
R2 trufos; C:\Windows\System32\drivers\trufos.sys [610840 2018-12-07] (Bitdefender)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46680 2018-12-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [330936 2018-12-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [62136 2018-12-10] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-20 12:21 - 2019-01-20 12:22 - 000012108 _____ C:\Users\Bruno\Desktop\FRST.txt
2019-01-20 12:17 - 2019-01-20 12:21 - 000000000 ____D C:\FRST
2019-01-20 12:07 - 2019-01-20 12:15 - 002427904 _____ (Farbar) C:\Users\Bruno\Desktop\FRST64.exe
2019-01-20 12:06 - 2019-01-20 12:06 - 007320272 _____ (Malwarebytes) C:\Users\Bruno\Desktop\adwcleaner_7.2.6.0.exe
2019-01-20 10:01 - 2019-01-20 10:01 - 007657592 _____ (ESET spol. s r.o.) C:\Users\Bruno\Downloads\esetonlinescanner_enu.exe
2019-01-20 10:01 - 2019-01-20 10:01 - 000000000 ____D C:\Users\Bruno\AppData\Local\ESET
2019-01-20 07:14 - 2019-01-20 07:21 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\FACEIT
2019-01-20 07:14 - 2019-01-20 07:14 - 078145312 _____ (TeamSpeak Systems GmbH) C:\Users\Bruno\Downloads\TeamSpeak3-Client-win64-3.2.3.exe
2019-01-20 07:14 - 2019-01-20 07:14 - 000002250 _____ C:\Users\Bruno\Desktop\FACEIT.lnk
2019-01-20 07:14 - 2019-01-20 07:14 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FACEIT Ltd
2019-01-20 07:14 - 2019-01-20 07:14 - 000000000 ____D C:\Users\Bruno\AppData\Local\FACEITApp
2019-01-20 05:50 - 2019-01-20 05:50 - 000000000 ____D C:\ProgramData\bdch
2019-01-19 15:07 - 2019-01-20 12:09 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\Twitch
2019-01-19 15:07 - 2019-01-19 15:07 - 000000972 _____ C:\Users\Bruno\Desktop\Twitch.lnk
2019-01-19 15:07 - 2019-01-19 15:07 - 000000958 _____ C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk
2019-01-19 15:07 - 2019-01-19 15:07 - 000000000 ____D C:\ProgramData\Twitch
2019-01-19 15:06 - 2019-01-19 15:07 - 087474720 _____ C:\Users\Bruno\Downloads\TwitchSetup_[usher-401747221].exe
2019-01-18 22:17 - 2019-01-18 22:18 - 000000021 _____ C:\Users\Bruno\Desktop\screens.txt
2019-01-14 19:26 - 2019-01-14 19:26 - 000001019 _____ C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2019-01-14 19:26 - 2019-01-14 19:26 - 000001011 _____ C:\Users\Bruno\Desktop\osu!.lnk
2019-01-14 19:25 - 2019-01-14 19:35 - 000000000 ____D C:\Users\Bruno\AppData\Local\osu!
2019-01-14 19:25 - 2019-01-14 19:25 - 000000000 ____D C:\Users\Bruno\Downloads\Localisation
2019-01-14 19:24 - 2019-01-14 19:24 - 004156096 _____ (ppy) C:\Users\Bruno\Downloads\osu!install.exe
2019-01-12 14:20 - 2019-01-12 14:20 - 000000000 ____D C:\Users\Bruno\AppData\Local\BattlEye
2019-01-12 14:11 - 2019-01-12 14:11 - 000076764 _____ C:\ProgramData\agent.update.1547298680.bdinstall.v2.bin
2019-01-12 11:51 - 2019-01-12 11:51 - 000001192 _____ C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free.lnk
2019-01-12 11:51 - 2018-04-19 21:37 - 000023032 _____ (Bitdefender) C:\Windows\system32\Drivers\bdelam.sys
2019-01-12 11:50 - 2019-01-12 11:50 - 000001207 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free.lnk
2019-01-12 11:50 - 2019-01-12 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free
2019-01-12 11:50 - 2019-01-12 11:50 - 000000000 ____D C:\ProgramData\Bitdefender
2019-01-12 11:50 - 2018-12-04 17:28 - 000367096 _____ (Bitdefender) C:\Windows\system32\Drivers\bddci.sys
2019-01-12 11:50 - 2018-12-03 17:06 - 000290688 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\edrsensor.sys
2019-01-12 11:50 - 2018-11-20 10:42 - 000201000 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2019-01-12 11:50 - 2018-11-19 13:10 - 000374632 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\gemma.sys
2019-01-12 11:50 - 2018-10-29 11:24 - 001423336 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\Windows\system32\Drivers\atc.sys
2019-01-12 11:49 - 2019-01-12 11:49 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\QuickScan
2019-01-12 11:49 - 2018-12-07 05:10 - 000610840 _____ (Bitdefender) C:\Windows\system32\Drivers\trufos.sys
2019-01-12 11:48 - 2019-01-20 12:21 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2019-01-12 11:47 - 2019-01-12 11:47 - 000003802 _____ C:\Windows\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2019-01-12 11:45 - 2019-01-12 14:11 - 000000000 ____D C:\Program Files\Bitdefender Agent
2019-01-12 11:45 - 2019-01-12 11:45 - 010372016 _____ C:\Users\Bruno\Downloads\bitdefender_online.exe
2019-01-12 11:45 - 2019-01-12 11:45 - 000103476 _____ C:\ProgramData\agent.1547289951.bdinstall.v2.bin
2019-01-12 11:45 - 2019-01-12 11:45 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2019-01-12 11:35 - 2019-01-12 11:51 - 000000000 ____D C:\Users\Bruno\Downloads\KRT CLUB 2.1.2.69 By Onhax Pk
2019-01-12 11:34 - 2019-01-12 11:34 - 014475993 _____ C:\Users\Bruno\Downloads\KRT CLUB 2.1.2.69 By Onhax Pk.rar
2019-01-12 09:49 - 2019-01-12 09:49 - 000000992 _____ C:\Users\Bruno\Downloads\hosts.txt
2019-01-12 09:42 - 2019-01-13 17:50 - 000000000 ____D C:\Program Files\Common Files\AV
2019-01-12 09:40 - 2019-01-12 09:41 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-01-12 09:22 - 2019-01-12 15:19 - 000000000 ____D C:\Users\Bruno\Downloads\KIS19
2019-01-12 09:09 - 2015-09-01 16:19 - 000020950 _____ C:\Users\Bruno\Downloads\csgo_text.txt
2019-01-12 08:09 - 2019-01-12 08:09 - 000000000 ____D C:\Program Files\Malwarebytes
2019-01-12 08:07 - 2019-01-12 08:56 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-01-12 06:42 - 2019-01-12 06:42 - 000000000 ____D C:\AdwCleaner
2019-01-10 19:15 - 2019-01-10 19:15 - 000001116 _____ C:\Users\Public\Desktop\OpenOffice 4.1.6.lnk
2019-01-10 19:15 - 2019-01-10 19:15 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.6
2019-01-10 19:15 - 2019-01-10 19:15 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\OpenOffice
2019-01-10 19:15 - 2019-01-10 19:15 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4
2019-01-10 19:14 - 2019-01-10 19:14 - 000000000 ____D C:\Users\Bruno\Desktop\OpenOffice 4.1.6 (cs) Installation Files
2019-01-10 13:57 - 2019-01-10 13:57 - 002854419 _____ C:\Users\Bruno\Downloads\csgo-callouts-radar.zip
2019-01-10 07:19 - 2019-01-10 07:19 - 026806784 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 023440384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 020811776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 019024384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 012858368 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 012151808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 009677352 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-01-10 07:19 - 2019-01-10 07:19 - 007857152 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 007645600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 006544800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 006057984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 005440016 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 004588544 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2019-01-10 07:19 - 2019-01-10 07:19 - 003952952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Mirage.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 003550592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 003380224 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 003338328 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 003270144 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002986352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002929152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002777432 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002626360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-01-10 07:19 - 2019-01-10 07:19 - 002594872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002469648 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002437552 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002323696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002275896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002186752 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 002021584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001641616 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001616384 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001602560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001388032 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001309696 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001255736 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2019-01-10 07:19 - 2019-01-10 07:19 - 001212416 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001201136 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 001058848 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2019-01-10 07:19 - 2019-01-10 07:19 - 001050936 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2019-01-10 07:19 - 2019-01-10 07:19 - 000998912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000912384 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000833536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000773120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000735232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000570368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000463672 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000448000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000387384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000178696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-01-10 07:19 - 2019-01-10 07:19 - 000155648 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000140808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys
2019-01-10 07:19 - 2019-01-10 07:19 - 000139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintWorkflowService.dll
2019-01-10 07:19 - 2019-01-10 07:19 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2019-01-10 07:19 - 2019-01-10 07:19 - 000047112 _____ (Microsoft Corporation) C:\Windows\system32\browser_broker.exe
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
2019-01-10 07:19 - 2019-01-10 07:19 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
2019-01-09 18:07 - 2019-01-09 18:08 - 000840413 _____ C:\Users\Bruno\Desktop\Vojtech Mihálik prezentacia.pptm
2019-01-09 16:22 - 2019-01-09 16:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2019-01-09 16:22 - 2019-01-09 16:22 - 000000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2019-01-09 16:22 - 2019-01-09 16:22 - 000000000 ____D C:\Windows\SHELLNEW
2019-01-09 16:22 - 2019-01-09 16:22 - 000000000 ____D C:\Windows\PCHEALTH
2019-01-09 16:22 - 2019-01-09 16:22 - 000000000 ____D C:\Program Files\Microsoft Office
2019-01-09 16:22 - 2019-01-09 16:22 - 000000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2019-01-09 16:22 - 2019-01-09 16:22 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2019-01-09 16:21 - 2019-01-09 16:22 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-01-09 16:21 - 2019-01-09 16:21 - 000000000 __RHD C:\MSOCache
2019-01-09 16:21 - 2019-01-09 16:21 - 000000000 ____D C:\Users\Bruno\AppData\Local\Microsoft Help
2019-01-09 16:17 - 2019-01-09 16:19 - 000000000 ____D C:\Users\Bruno\Downloads\Microsoft powerpoint
2019-01-07 13:22 - 2019-01-07 13:22 - 000000023 _____ C:\Users\Bruno\Downloads\Counter Strike Global Offensive Steam 52.txt
2019-01-07 06:58 - 2019-01-07 06:58 - 006082499 _____ C:\Users\Bruno\Downloads\dai_alfa.zip
2019-01-06 15:39 - 2017-05-14 11:04 - 000000000 ____D C:\Users\Bruno\Downloads\2016 Rossa - Ridna zemľa ( CD 2 )
2019-01-06 15:35 - 2014-01-05 11:16 - 000000000 ____D C:\Users\Bruno\Downloads\ROSSA - Uno - ludovky vychod new 2013
2019-01-06 09:49 - 2019-01-06 09:49 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\TunnelBear
2019-01-06 09:49 - 2019-01-06 09:49 - 000000000 ____D C:\Users\Bruno\AppData\Local\IsolatedStorage
2019-01-06 09:31 - 2019-01-06 09:44 - 000000000 ____D C:\Program Files (x86)\VyprVPN
2019-01-04 22:19 - 2019-01-04 22:19 - 000007861 _____ C:\Users\Bruno\Downloads\funplay.jpeg
2018-12-28 21:54 - 2018-12-28 22:59 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\obs-studio
2018-12-28 21:54 - 2018-12-28 21:54 - 000001052 _____ C:\Users\Public\Desktop\OBS Studio.lnk
2018-12-28 21:54 - 2018-12-28 21:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2018-12-28 21:54 - 2018-12-28 21:54 - 000000000 ____D C:\Program Files\obs-studio
2018-12-28 12:32 - 2018-12-28 12:32 - 000011700 _____ C:\Users\Bruno\Downloads\Q3279WG5B_D65.icm
2018-12-26 20:21 - 2018-12-26 20:21 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\vibranceGUI
2018-12-26 20:21 - 2018-12-10 19:29 - 000794624 _____ (juvlarN) C:\Users\Bruno\Desktop\vibranceGUI.exe
2018-12-25 10:11 - 2018-12-25 10:13 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\audacity
2018-12-25 10:11 - 2018-12-25 10:11 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2018-12-25 10:11 - 2018-12-25 10:11 - 000001076 _____ C:\Users\Public\Desktop\Audacity.lnk
2018-12-25 10:11 - 2018-12-25 10:11 - 000000000 ____D C:\Users\Bruno\AppData\Local\Audacity
2018-12-25 10:11 - 2018-12-25 10:11 - 000000000 ____D C:\Program Files (x86)\Audacity
2018-12-23 21:42 - 2018-12-23 21:42 - 000044896 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tapvyprvpn.sys
2018-12-23 21:42 - 2018-12-23 21:42 - 000036496 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tap0901.sys
2018-12-22 14:17 - 2018-12-22 14:17 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\TownOfSalem
2018-12-22 14:12 - 2018-12-22 14:12 - 000000222 _____ C:\Users\Bruno\Desktop\Town of Salem.url
2018-12-22 11:21 - 2018-12-22 11:21 - 000019696 _____ (EasyAntiCheat Oy) C:\Windows\system32\eac_usermode_270061471175634.dll
2018-12-21 22:44 - 2018-12-21 22:44 - 000000000 ____D C:\Users\Bruno\Desktop\DMS.Prepacte.official.2018.320.kbps.MP3-luk366
2018-12-21 16:26 - 2018-12-21 16:37 - 000000186 _____ C:\Users\Bruno\Desktop\info ku acc.txt
2018-12-21 12:08 - 2019-01-06 15:11 - 000000000 ____D C:\Users\Bruno\Downloads\hudba

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-20 12:21 - 2018-11-16 19:18 - 000000000 ____D C:\ProgramData\Package Cache
2019-01-20 12:18 - 2018-11-16 19:52 - 000000000 ____D C:\Users\Bruno\AppData\LocalLow\Mozilla
2019-01-20 12:15 - 2018-11-16 19:17 - 000000000 ____D C:\AMD
2019-01-20 12:06 - 2018-11-16 19:23 - 000004210 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{7362245D-3FE2-47C7-9D52-DFBCC5B3E989}
2019-01-20 11:44 - 2018-11-16 18:57 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-01-20 11:44 - 2018-09-15 08:31 - 000000000 ____D C:\Windows\INF
2019-01-20 11:04 - 2018-11-16 19:43 - 000000836 _____ C:\Users\Bruno\Desktop\bruno.txt
2019-01-20 10:00 - 2018-11-19 13:18 - 000000000 ____D C:\Users\Bruno\AppData\Local\CrashDumps
2019-01-20 09:47 - 2018-11-16 20:13 - 000000000 ____D C:\Program Files (x86)\Steam
2019-01-20 07:14 - 2018-11-16 21:56 - 000000000 ____D C:\Users\Bruno\AppData\Local\SquirrelTemp
2019-01-20 07:14 - 2018-11-16 19:32 - 000000000 ____D C:\Users\Bruno\AppData\Local\D3DSCache
2019-01-20 05:43 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-01-19 17:18 - 2018-11-16 21:56 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\discord
2019-01-19 14:12 - 2018-11-17 07:53 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\BitTorrent
2019-01-19 13:57 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\AppReadiness
2019-01-19 13:46 - 2018-12-16 08:35 - 000003112 _____ C:\Windows\System32\Tasks\AMDLinkUpdate
2019-01-18 05:11 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-01-16 18:59 - 2018-11-16 21:56 - 000002233 _____ C:\Users\Bruno\Desktop\Discord.lnk
2019-01-16 18:59 - 2018-11-16 21:56 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2019-01-16 18:59 - 2018-11-16 21:56 - 000000000 ____D C:\Users\Bruno\AppData\Local\Discord
2019-01-15 20:05 - 2018-11-16 19:56 - 000000000 ____D C:\Users\Bruno\AppData\Local\Ubisoft Game Launcher
2019-01-14 06:34 - 2018-09-15 07:09 - 000032768 _____ C:\Windows\system32\config\ELAM
2019-01-13 22:19 - 2018-11-16 19:17 - 000000000 ____D C:\Users\Bruno
2019-01-13 17:57 - 2018-11-16 19:07 - 001693636 _____ C:\Windows\system32\PerfStringBackup.INI
2019-01-13 17:57 - 2018-09-15 18:33 - 000716902 _____ C:\Windows\system32\perfh005.dat
2019-01-13 17:57 - 2018-09-15 18:33 - 000144982 _____ C:\Windows\system32\perfc005.dat
2019-01-13 17:55 - 2018-12-19 16:38 - 000000000 ____D C:\Users\Bruno\AppData\Local\LogMeIn Hamachi
2019-01-13 17:52 - 2018-11-17 11:04 - 000000000 ____D C:\Program Files\SoftEther VPN Client
2019-01-13 17:51 - 2018-11-16 18:57 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-01-12 11:51 - 2018-09-15 08:33 - 000000000 ___HD C:\Windows\ELAMBKUP
2019-01-12 11:43 - 2018-11-16 19:52 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-01-12 11:43 - 2018-11-16 19:17 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2019-01-12 11:43 - 2018-09-15 07:09 - 000032768 _____ C:\Windows\system32\config\BBI
2019-01-12 06:51 - 2018-11-16 18:57 - 000341496 _____ C:\Windows\system32\FNTCACHE.DAT
2019-01-12 06:50 - 2018-11-16 19:52 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-01-10 09:59 - 2018-11-16 19:52 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-01-10 09:21 - 2018-09-15 18:35 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2019-01-10 09:21 - 2018-09-15 18:35 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-01-10 09:21 - 2018-09-15 18:35 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2019-01-10 09:21 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\bcastdvr
2019-01-10 07:21 - 2018-11-16 19:44 - 000000000 ____D C:\Windows\system32\MRT
2019-01-10 07:21 - 2018-09-15 08:23 - 000000000 ____D C:\Windows\CbsTemp
2019-01-10 07:20 - 2018-11-16 19:44 - 132790320 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-01-09 16:22 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-01-02 20:48 - 2018-09-15 08:36 - 000835480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-01-02 20:48 - 2018-09-15 08:36 - 000179600 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-12-30 23:54 - 2018-11-18 07:05 - 000000000 ____D C:\Users\Bruno\Downloads\filmy
2018-12-29 06:00 - 2018-12-11 10:56 - 000000000 ____D C:\Users\Bruno\AppData\Local\Battle.net
2018-12-28 10:11 - 2018-12-11 11:27 - 000000000 ____D C:\Program Files (x86)\Call of Duty Black Ops 4
2018-12-28 09:27 - 2018-11-16 19:19 - 000000000 ____D C:\Users\Bruno\AppData\Local\Packages
2018-12-28 08:16 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\SysWOW64\WCN
2018-12-28 08:16 - 2018-09-15 18:33 - 000000000 ____D C:\Windows\system32\WCN
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ___SD C:\Windows\SysWOW64\F12
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ___SD C:\Windows\system32\F12
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ___RD C:\Program Files\Windows Defender
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\SysWOW64\oobe
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\system32\oobe
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\system32\migwiz
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\PolicyDefinitions
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Windows\IME
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\system
2018-12-28 08:16 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2018-12-28 08:16 - 2018-09-15 07:09 - 000000000 ____D C:\Windows\servicing
2018-12-28 07:23 - 2018-12-16 12:17 - 000000000 ____D C:\Users\Bruno\Downloads\Posel ztracených duší (Ghost Whisperer)
2018-12-27 17:33 - 2018-09-15 18:34 - 000000000 ____D C:\Windows\OCR

Some zero byte size files/folders:
==========================
C:\Windows\System32\SppExtComObjHook.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16.01.2019 01
Ran by Bruno (20-01-2019 12:22:55)
Running from C:\Users\Bruno\Desktop
Windows 10 Enterprise LTSC 2019 Version 1809 17763.253 (X64) (2018-11-16 18:00:37)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4026889717-166049279-3436938343-500 - Administrator - Disabled)
Bruno (S-1-5-21-4026889717-166049279-3436938343-1001 - Administrator - Enabled) => C:\Users\Bruno
DefaultAccount (S-1-5-21-4026889717-166049279-3436938343-503 - Limited - Disabled)
Guest (S-1-5-21-4026889717-166049279-3436938343-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4026889717-166049279-3436938343-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {EA21BCE8-A461-99C3-3A0D-4C964E75494E}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {51405D0C-825B-964D-00BD-77E435F203F3}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.12.3 - Advanced Micro Devices, Inc.)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassin's Creed: Odyssey (HKLM-x32\...\Assassin's Creed: Odyssey_is1) (Version: - )
Audacity 2.3.0 (HKLM-x32\...\Audacity_is1) (Version: 2.3.0 - Audacity Team)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender)
Bitdefender Antivirus Free (HKLM\...\{1FCCF41D-5F00-4FE2-9653-162D0486C8B4}) (Version: 1.0.15.77 - Bitdefender)
BitTorrent (HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\BitTorrent) (Version: 7.10.4.44847 - BitTorrent Inc.)
Branding64 (HKLM\...\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
Call of Duty Black Ops 4 (HKLM-x32\...\Call of Duty Black Ops 4) (Version: - Blizzard Entertainment)
Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Counter Strike 1.6 GT (HKLM-x32\...\Counter Strike 1.6 GT) (Version: - )
Counter-Strike 1.6 v43g (HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Counter-Strike 1.6_is1) (Version: - Valve)
Discord (HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\Discord) (Version: 0.0.304 - Discord Inc.)
Epic Games Launcher (HKLM-x32\...\{0E63B233-DC24-442C-BD38-0B91D90FEC5B}) (Version: 1.1.167.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FACEIT (HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\FACEITApp) (Version: 1.20.0 - FACEIT Ltd.)
FIFA 19 (HKLM-x32\...\{3391E07D-8484-4124-817E-FCBDA859FD62}) (Version: 1.0.58.64628 - Electronic Arts)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\{86C80028-CB1C-42B7-8FAA-C486A0B1996A}) (Version: 2.2.0.627 - LogMeIn, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.627 - LogMeIn, Inc.)
Microsoft PowerPoint 2010 (HKLM-x32\...\Office14.POWERPOINT) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{d98165f5-8b37-4100-8852-a0664374ff8a}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.16.27012 (HKLM-x32\...\{427ada59-85e7-4bc8-b8d5-ebf59db60423}) (Version: 14.16.27012.6 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation)
Monster Hunter: World (HKLM-x32\...\Monster Hunter: World_is1) (Version: - )
Mozilla Firefox 64.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 64.0.2 (x64 en-US)) (Version: 64.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 63.0.3 - Mozilla)
MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 22.0.2 - OBS Project)
OpenOffice 4.1.6 (HKLM-x32\...\{8DADDDBF-EB36-4D00-9291-8C281F1755A6}) (Version: 4.16.9790 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.30.15625 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{52ee272d-8d33-481d-8301-3b4b0bb89a31}) (Version: latest - ppy Pty Ltd)
Roblox Player for Bruno (HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\roblox-player) (Version: - Roblox Corporation)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.28.9669 - SoftEther VPN Project)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
Tom Clancy's Rainbow Six Siege RUS (HKLM-x32\...\Uplay Install 1842) (Version: - Ubisoft Montreal)
Twitch (HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 7.0.0.0 - Twitch Interactive, Inc.)
Uplay (HKLM-x32\...\Uplay) (Version: 73.2 - Ubisoft)
WinRAR 5.61 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH)
XCOM 2 (HKLM-x32\...\XCOM 2_is1) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (Alexander Roshal)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-12-17] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {05A904F5-405C-4CA6-A82A-2D31DDB1FDC7} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-11-15] (Bitdefender)
Task: {206FF9C8-96C1-4920-83C3-7BC275C479B4} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [2018-12-18] (Advanced Micro Devices, Inc.)
Task: {3B193614-2B8D-4A2B-A50C-793D00D33561} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
Task: {56F6710B-F095-4B2D-A987-F2AFF5D6F6A1} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-12-17] (Advanced Micro Devices, Inc.)
Task: {9C0235BB-C157-4AA5-8564-3CAC661E41CD} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [2018-12-18] (Advanced Micro Devices, Inc.)
Task: {E39F8E32-F4B6-44B2-B8AF-D84A6CFEB7B8} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-09-15] ()
Task: {EDDAA302-C4B0-490F-9D37-74460EB146CF} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2019-01-12 11:50 - 2017-11-21 12:29 - 000278280 _____ () C:\Program Files\Bitdefender Antivirus Free\txmlutil.dll
2019-01-12 11:50 - 2018-11-14 21:28 - 000994752 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpbr.mdl
2019-01-12 11:50 - 2018-11-14 21:28 - 000544880 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpdsp.mdl
2019-01-12 11:50 - 2018-11-14 21:28 - 003240080 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpph.mdl
2019-01-12 11:50 - 2018-11-14 21:28 - 001530368 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttprbl.mdl
2018-09-15 08:28 - 2018-09-15 08:28 - 000834088 _____ () C:\Windows\System32\InputHost.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 000474624 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-12-12 16:29 - 2018-12-12 16:29 - 002801152 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-12-13 14:29 - 2018-12-13 14:29 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-12-13 14:29 - 2018-12-13 14:29 - 002551808 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 001740288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-12-15 22:29 - 2018-12-15 22:20 - 001698296 _____ () E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\wallpaper32.exe
2018-09-15 08:28 - 2018-09-15 08:28 - 001942528 _____ () C:\Windows\ShellExperiences\PeopleCommonControls.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 001396224 _____ () C:\Windows\ShellExperiences\PeopleBarFlyout.dll
2018-12-12 16:29 - 2018-12-12 16:29 - 002877952 _____ () C:\Windows\ShellExperiences\WindowsInternal.People.PeoplePicker.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 000551424 _____ () C:\Windows\ShellExperiences\WindowsInternal.People.Relevance.QueryClient.dll
2018-12-15 22:29 - 2018-12-15 22:20 - 000932856 _____ () E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\plugins\corsair\cueextensions32.dll
2018-12-15 22:29 - 2018-12-15 22:20 - 000979960 _____ () E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\bin\resourceutil32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Bruno\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Bruno\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\localhost -> localhost

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-01-12 09:55 - 2019-01-13 17:51 - 000000162 _____ C:\Windows\system32\drivers\etc\hosts

127.0.0.1 activation-v2.kaspersky.com
127.0.0.1 activation-v2.geo.kaspersky.com
0.0.0.0 activation-v2.kaspersky.com
0.0.0.0 activation-v2.geo.kaspersky.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4026889717-166049279-3436938343-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.31.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\StartupFolder: => "SoftEther VPN Client Manager Startup.lnk"
HKLM\...\StartupApproved\Run: => "SoftEther VPN Client UI Helper"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "BCSSync"
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\StartupApproved\Run: => "Ubisoft Game Launcher"
HKU\S-1-5-21-4026889717-166049279-3436938343-1001\...\StartupApproved\Run: => "vibranceGUI"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{13EF2B93-16F4-41E6-B402-441A8E26480F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [{E77A42DF-9160-4CEE-AEFE-63041568C363}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [{2180BCA5-300E-4E4C-B72A-64DD347F502C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
FirewallRules: [{3E7FCE2D-79AD-44D3-922B-2799C17628B7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
FirewallRules: [TCP Query User{B8CE4087-20CD-464D-BEE6-11C0FEE8293D}E:\program files\grand theft auto v\gta5.exe] => (Allow) E:\program files\grand theft auto v\gta5.exe (Rockstar Games)
FirewallRules: [UDP Query User{50B839F3-2824-4DBE-B505-DB65FE0B3EF9}E:\program files\grand theft auto v\gta5.exe] => (Allow) E:\program files\grand theft auto v\gta5.exe (Rockstar Games)
FirewallRules: [{9EAE5113-1046-4E8C-913D-4ABCA830D406}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{A8535528-1F08-489B-AEB0-E4D06A7A9B06}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{F8408AE2-DB85-44C5-8010-D33AED50FA26}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe ()
FirewallRules: [{4816FC49-D06F-4C86-9B3F-C4BB9BB5D3D8}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe ()
FirewallRules: [{26B4C273-0D16-4C2C-96E3-DC159618D840}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Zula EU\zula_launcher.exe (MadByte Games)
FirewallRules: [{458033D3-CF0F-436E-B040-E4E4395748AC}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Zula EU\zula_launcher.exe (MadByte Games)
FirewallRules: [TCP Query User{9E256236-7203-48EC-831A-D265D290AA9E}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games, Inc.)
FirewallRules: [UDP Query User{834AEE38-B266-4617-871B-6C4406AEC26F}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games, Inc.)
FirewallRules: [TCP Query User{AB32BF8E-01CC-4860-809C-E9ECC3E22009}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games, Inc.)
FirewallRules: [UDP Query User{E91887BE-81A1-45BF-B5C1-D09DAC10787A}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games, Inc.)
FirewallRules: [{2CD7FB64-C3C0-4C8E-9580-2B6EF421EB7E}] => (Allow) C:\Users\Bruno\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)
FirewallRules: [{2015D4B0-D530-4A3D-8CA4-6A24880D5A31}] => (Allow) C:\Users\Bruno\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)
FirewallRules: [{6D65C64C-5A32-48A9-9D0B-1DA0954AE76B}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (PUBG Corporation )
FirewallRules: [{F45CA1BE-BCA1-4C5C-9459-D3318E20DCDC}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe (PUBG Corporation )
FirewallRules: [{3922AC21-A32D-4BED-A511-8287F502D557}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
FirewallRules: [{EDA4CA64-723E-43C1-919A-1196DD3D24D0}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
FirewallRules: [{DE892E07-9A95-4994-960B-29A85461E0C6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
FirewallRules: [{A9A9408A-F436-44C9-A321-0E09C75859D2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
FirewallRules: [{A01748B7-15D9-4785-B34C-77167BB8A2CB}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
FirewallRules: [{62285035-142C-4157-893E-DBE846A3F950}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
FirewallRules: [{B4F615E1-146E-4515-B485-2472F4CC4F18}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\ShadowOfWar\x64\ShadowOfWar.exe (WB Games, Inc.)
FirewallRules: [{312168EC-B0D1-4298-B21D-C041EDE74D23}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\ShadowOfWar\x64\ShadowOfWar.exe (WB Games, Inc.)
FirewallRules: [{6CB55A74-1C3C-44EE-9A76-D80C02FD96C8}] => (Allow) E:\Program Files\Assassin's Creed Odyssey\ACOdyssey.exe No File
FirewallRules: [{AC13625D-482E-4120-8ED7-13C562111E9A}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 19\FIFASetup\fifaconfig.exe (Electronic Arts)
FirewallRules: [{0134D831-D578-4A7D-A2A0-70C5A6C522DE}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 19\FIFASetup\fifaconfig.exe (Electronic Arts)
FirewallRules: [{13468DC1-2B81-4181-A050-CB07F4C54B1F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation)
FirewallRules: [{316FC0F7-B130-479A-9DD0-C14EF3189F55}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation)
FirewallRules: [TCP Query User{76383718-D13D-48AD-AB56-D5190CD0A61E}C:\program files (x86)\xcom 2\binaries\win64\xcomgame.exe] => (Allow) C:\program files (x86)\xcom 2\binaries\win64\xcomgame.exe (Firaxis Games)
FirewallRules: [UDP Query User{2CBFFA9C-EB8C-4ABA-8217-40290BED7708}C:\program files (x86)\xcom 2\binaries\win64\xcomgame.exe] => (Allow) C:\program files (x86)\xcom 2\binaries\win64\xcomgame.exe (Firaxis Games)
FirewallRules: [TCP Query User{E103C4C8-5AA2-402F-95F1-9F9B99647689}C:\program files (x86)\call of duty black ops 4\blackops4.exe] => (Allow) C:\program files (x86)\call of duty black ops 4\blackops4.exe (Activision Publishing, Inc.)
FirewallRules: [UDP Query User{9E72D5D6-7696-43CC-BDE0-B6FEF0290F8F}C:\program files (x86)\call of duty black ops 4\blackops4.exe] => (Allow) C:\program files (x86)\call of duty black ops 4\blackops4.exe (Activision Publishing, Inc.)
FirewallRules: [TCP Query User{56805C76-1ADB-4F11-8752-9A882B8D1B1F}C:\games\counter strike 1.6 gt\hl.exe] => (Block) C:\games\counter strike 1.6 gt\hl.exe No File
FirewallRules: [UDP Query User{7A9E6A3F-5E1E-4040-BFC9-F639B8FF6BE6}C:\games\counter strike 1.6 gt\hl.exe] => (Block) C:\games\counter strike 1.6 gt\hl.exe No File
FirewallRules: [{177A58DA-D10C-4F28-8786-298B9B4C18A0}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\launcher.exe ()
FirewallRules: [{1F0926B1-5BBC-4264-A1A1-77218A6B2EB3}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\wallpaper_engine\launcher.exe ()
FirewallRules: [{666C0091-CE81-4E45-A7F9-02BE51C7C110}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Half-Life\hl.exe (Valve)
FirewallRules: [{21FBB596-A69D-47A1-820D-7C485615803F}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Half-Life\hl.exe (Valve)
FirewallRules: [TCP Query User{9A692F37-3269-465F-B782-863253E5653F}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe No File
FirewallRules: [UDP Query User{88585BFC-570E-4938-B5A7-149EF704017E}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe No File
FirewallRules: [{D79F8046-97CC-491C-A88A-197360B8DC15}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Ring of Elysium\SLauncher.exe ()
FirewallRules: [{90206C3B-7638-40A4-AED4-560ACF733FF5}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Ring of Elysium\SLauncher.exe ()
FirewallRules: [{8B7B94FB-7C87-4390-96BC-E6B8DCE4B949}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\SCP Secret Laboratory\SCPSL.exe ()
FirewallRules: [{9D519E2A-A001-4382-9669-363DD99AF503}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\SCP Secret Laboratory\SCPSL.exe ()
FirewallRules: [{52FD6EA1-0645-487E-A615-52A8A48172C6}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\SCP Secret Laboratory\LocalAdmin.exe ()
FirewallRules: [{5C7CC7F5-776F-4155-B043-0057DAFA5986}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\SCP Secret Laboratory\LocalAdmin.exe ()
FirewallRules: [{DAC4B0A6-F686-418C-B9AE-E2DAE06D685B}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Town of Salem\TownOfSalem.exe ()
FirewallRules: [{AEED8B67-667A-4A24-B7D2-C8D51814074F}] => (Allow) E:\Program Files\SteamLibrary\steamapps\common\Town of Salem\TownOfSalem.exe ()
FirewallRules: [TCP Query User{A9812F82-3395-4143-97E7-A1F112780EF1}E:\program files\tom clancy's rainbow six siege rus\rainbowsix.exe] => (Allow) E:\program files\tom clancy's rainbow six siege rus\rainbowsix.exe (Ubisoft)
FirewallRules: [UDP Query User{8FE22C93-8DA2-426E-B1D4-A60121F1FA45}E:\program files\tom clancy's rainbow six siege rus\rainbowsix.exe] => (Allow) E:\program files\tom clancy's rainbow six siege rus\rainbowsix.exe (Ubisoft)

==================== Restore Points =========================

04-01-2019 09:54:17 Naplánovaný kontrolní bod
06-01-2019 09:49:07 TunnelBear
09-01-2019 16:21:43 Installed Microsoft PowerPoint 2010
10-01-2019 19:14:56 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
19-01-2019 19:53:22 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/20/2019 11:51:25 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: )
Description: Stroji pravidel se nepodařilo provést některé naplánované akce.
Kód chyby:0x80080005
Cesta:<none>
Argumenty:<none>

Error: (01/20/2019 11:48:15 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: )
Description: Stroji pravidel se nepodařilo provést některé naplánované akce.
Kód chyby:0x80080005
Cesta:<none>
Argumenty:<none>

Error: (01/20/2019 11:46:14 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: )
Description: Stroji pravidel se nepodařilo provést některé naplánované akce.
Kód chyby:0x80080005
Cesta:<none>
Argumenty:<none>

Error: (01/20/2019 10:00:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: bdagent.exe, verzia: 1.0.15.77, časová značka: 0x5c385878
Názov chybujúceho modulu: MSVCR120.dll, verzia: 12.0.21005.1, časová značka: 0x524f83ff
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000074a30
Identifikácia chybujúceho procesu: 0x1610
Čas spustenia chybujúcej aplikácie: 0x01d4b09d60764768
Cesta chybujúcej aplikácie: C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
Cesta chybujúceho modulu: C:\Program Files\Bitdefender Antivirus Free\MSVCR120.dll
Identifikácia hlásenia: 5a03f4d1-94c4-48e7-b169-09d8266c3fdd
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (01/20/2019 05:50:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: bdagent.exe, verzia: 1.0.15.77, časová značka: 0x5c385878
Názov chybujúceho modulu: MSVCR120.dll, verzia: 12.0.21005.1, časová značka: 0x524f83ff
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000074a30
Identifikácia chybujúceho procesu: 0xf64
Čas spustenia chybujúcej aplikácie: 0x01d4aff528c42a3c
Cesta chybujúcej aplikácie: C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
Cesta chybujúceho modulu: C:\Program Files\Bitdefender Antivirus Free\MSVCR120.dll
Identifikácia hlásenia: 8543483e-d735-473b-9b68-1338138c5f84
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (01/20/2019 05:47:29 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: )
Description: Stroji pravidel se nepodařilo provést některé naplánované akce.
Kód chyby:0x80080005
Cesta:<none>
Argumenty:<none>

Error: (01/20/2019 05:44:20 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: )
Description: Stroji pravidel se nepodařilo provést některé naplánované akce.
Kód chyby:0x80080005
Cesta:<none>
Argumenty:<none>

Error: (01/20/2019 05:42:19 AM) (Source: Software Protection Platform Service) (EventID: 8229) (User: )
Description: Stroji pravidel se nepodařilo provést některé naplánované akce.
Kód chyby:0x80080005
Cesta:<none>
Argumenty:<none>


System errors:
=============
Error: (01/20/2019 12:13:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby eapihdrv zlyhalo kvôli nasledujúcej chybe:
Načtení tohoto ovladače je blokováno.

Error: (01/20/2019 12:13:33 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\Bruno\AppData\Local\Temp\ehdrv.sys

Error: (01/20/2019 12:13:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby eapihdrv zlyhalo kvôli nasledujúcej chybe:
Načtení tohoto ovladače je blokováno.

Error: (01/20/2019 12:13:32 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\Bruno\AppData\Local\Temp\ehdrv.sys

Error: (01/20/2019 12:13:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby eapihdrv zlyhalo kvôli nasledujúcej chybe:
Načtení tohoto ovladače je blokováno.

Error: (01/20/2019 12:13:32 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\Bruno\AppData\Local\Temp\ehdrv.sys

Error: (01/20/2019 12:13:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Spustenie služby eapihdrv zlyhalo kvôli nasledujúcej chybe:
Načtení tohoto ovladače je blokováno.

Error: (01/20/2019 12:13:32 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\Bruno\AppData\Local\Temp\ehdrv.sys


Windows Defender:
===================================
Date: 2019-01-12 11:50:41.682
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Occamy.C
ID: 2147726780
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\Bruno\Downloads\KRT CLUB 2.1.2.69 By Onhax Pk\KRT_CLUB_2.1.2.69.exe
Původ zjišťování: Místní počítač
Typ zjišťování: FastPath
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-KN6KRSK\Bruno
Název procesu: C:\Program Files\Bitdefender Antivirus Free\kitinstaller\BPInstaller.exe
Verze podpisu: AV: 1.283.2804.0, AS: 1.283.2804.0, NIS: 1.283.2804.0
Verze modulu: AM: 1.1.15500.2, NIS: 1.1.15500.2

Date: 2019-01-12 11:32:36.039
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Kapahyku.A
ID: 2147707350
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\Users\Bruno\Downloads\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: C:\Windows\System32\SearchProtocolHost.exe
Verze podpisu: AV: 1.283.2800.0, AS: 1.283.2800.0, NIS: 1.283.2800.0
Verze modulu: AM: 1.1.15500.2, NIS: 1.1.15500.2

Date: 2019-01-12 11:32:30.170
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Kapahyku.A
ID: 2147707350
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\Users\Bruno\AppData\Local\Temp\Rar$DRa7236.15091\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-KN6KRSK\Bruno
Název procesu: C:\Program Files\WinRAR\WinRAR.exe
Verze podpisu: AV: 1.283.2800.0, AS: 1.283.2800.0, NIS: 1.283.2800.0
Verze modulu: AM: 1.1.15500.2, NIS: 1.1.15500.2

Date: 2019-01-12 09:51:52.651
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Occamy.C
ID: 2147726780
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\Bruno\Downloads\KIS19\Trial reset\KRT_CLUB_2.1.2.69.exe
Původ zjišťování: Místní počítač
Typ zjišťování: FastPath
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: C:\Windows\explorer.exe
Verze podpisu: AV: 1.283.2788.0, AS: 1.283.2788.0, NIS: 1.283.2788.0
Verze modulu: AM: 1.1.15500.2, NIS: 1.1.15500.2

Date: 2019-01-12 09:51:43.228
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Occamy.C
ID: 2147726780
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\Bruno\Downloads\KIS19\Trial reset\KRT_CLUB_2.1.2.69.exe
Původ zjišťování: Místní počítač
Typ zjišťování: FastPath
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: C:\Windows\explorer.exe
Verze podpisu: AV: 1.283.2788.0, AS: 1.283.2788.0, NIS: 1.283.2788.0
Verze modulu: AM: 1.1.15500.2, NIS: 1.1.15500.2

Date: 2019-01-12 10:18:09.215
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.283.2800.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15500.2
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2019-01-12 09:55:21.566
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.283.2788.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15500.2
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-12-27 12:27:16.795
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu:
Předchozí verze podpisu: 1.283.1524.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15500.2
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2018-12-07 16:24:24.224
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Tiggre!plock
ID: 2147723626
Závažnost: Vážné
Kategorie: Trojský kůň
Uživatel: DESKTOP-KN6KRSK\Bruno
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit.
Verze podpisu: AV: 1.283.25.0, AS: 1.283.25.0
Verze modulu: 1.1.15500.2

Date: 2018-12-07 16:24:21.430
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Tiggre!plock
ID: 2147723626
Závažnost: Vážné
Kategorie: Trojský kůň
Uživatel: DESKTOP-KN6KRSK\Bruno
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit.
Verze podpisu: AV: 1.283.25.0, AS: 1.283.25.0
Verze modulu: 1.1.15500.2

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3570 CPU @ 3.40GHz
Percentage of memory in use: 41%
Total physical RAM: 8137.71 MB
Available physical RAM: 4746.99 MB
Total Virtual: 15561.71 MB
Available Virtual: 8722.6 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:446.59 GB) (Free:161.32 GB) NTFS
Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.02 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: () (Fixed) (Total:931.41 GB) (Free:88.22 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{3f80a835-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.54 GB) (Free:0.15 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 3FC5B496)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=931.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 447.1 GB) (Disk ID: 3F80A835)
Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=446.6 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Re: Prosím o konrolu logu

Napsal: 20 led 2019 13:04
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Prosím o konrolu logu

Napsal: 20 led 2019 13:17
od Bruno39
# -------------------------------
# Malwarebytes AdwCleaner 7.2.6.0
# -------------------------------
# Build: 12-18-2018
# Database: 2019-01-10.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 01-20-2019
# Duration: 00:00:00
# OS: Windows 10 Enterprise LTSC 2019
# Cleaned: 0
# Failed: 1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

Not Deleted api.bing.com


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1894 octets] - [12/01/2019 06:42:26]
AdwCleaner[C00].txt - [1928 octets] - [12/01/2019 06:42:39]
AdwCleaner[S01].txt - [1400 octets] - [12/01/2019 08:37:24]
AdwCleaner[C01].txt - [1566 octets] - [12/01/2019 08:37:32]
AdwCleaner[S02].txt - [1522 octets] - [20/01/2019 13:13:46]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########

Re: Prosím o konrolu logu

Napsal: 20 led 2019 15:12
od Rudy
Toto je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
FF NewTab: Mozilla\Firefox\Profiles\jugn7tq7.default -> hxxp://securedsearch.lavasoft.com/?pr=v ... 20__181117
C:\Windows\System32\SppExtComObjHook.dll
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
AlternateDataStreams: C:\Users\Bruno\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Bruno\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]
FirewallRules: [{6CB55A74-1C3C-44EE-9A76-D80C02FD96C8}] => (Allow) E:\Program Files\Assassin's Creed Odyssey\ACOdyssey.exe No File
FirewallRules: [TCP Query User{56805C76-1ADB-4F11-8752-9A882B8D1B1F}C:\games\counter strike 1.6 gt\hl.exe] => (Block) C:\games\counter strike 1.6 gt\hl.exe No File
FirewallRules: [UDP Query User{7A9E6A3F-5E1E-4040-BFC9-F639B8FF6BE6}C:\games\counter strike 1.6 gt\hl.exe] => (Block) C:\games\counter strike 1.6 gt\hl.exe No File
FirewallRules: [TCP Query User{9A692F37-3269-465F-B782-863253E5653F}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe No File
FirewallRules: [UDP Query User{88585BFC-570E-4938-B5A7-149EF704017E}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe No File
C:\Users\Bruno\Downloads\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe
C:\Users\Bruno\AppData\Local\Temp\Rar$DRa7236.15091\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe

EmptyTemp:
Hosts:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosím o konrolu logu

Napsal: 20 led 2019 15:38
od Bruno39
Fix result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019
Ran by Bruno (20-01-2019 15:33:32) Run:1
Running from C:\Users\Bruno\Desktop
Loaded Profiles: Bruno (Available Profiles: Bruno)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
FF NewTab: Mozilla\Firefox\Profiles\jugn7tq7.default -> hxxp://securedsearch.lavasoft.com/?pr=v ... 20__181117
C:\Windows\System32\SppExtComObjHook.dll
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
AlternateDataStreams: C:\Users\Bruno\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Bruno\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [362]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]
FirewallRules: [{6CB55A74-1C3C-44EE-9A76-D80C02FD96C8}] => (Allow) E:\Program Files\Assassin's Creed Odyssey\ACOdyssey.exe No File
FirewallRules: [TCP Query User{56805C76-1ADB-4F11-8752-9A882B8D1B1F}C:\games\counter strike 1.6 gt\hl.exe] => (Block) C:\games\counter strike 1.6 gt\hl.exe No File
FirewallRules: [UDP Query User{7A9E6A3F-5E1E-4040-BFC9-F639B8FF6BE6}C:\games\counter strike 1.6 gt\hl.exe] => (Block) C:\games\counter strike 1.6 gt\hl.exe No File
FirewallRules: [TCP Query User{9A692F37-3269-465F-B782-863253E5653F}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe No File
FirewallRules: [UDP Query User{88585BFC-570E-4938-B5A7-149EF704017E}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe No File
C:\Users\Bruno\Downloads\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe
C:\Users\Bruno\AppData\Local\Temp\Rar$DRa7236.15091\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe

EmptyTemp:
Hosts:
End
*****************

Processes closed successfully.
"Firefox newtab" => removed successfully
Symbolic link found: "C:\Windows\System32\SppExtComObjHook.dll" => "C:\Windows\AKMS\x64\SppExtComObjHook.dll"
"C:\Windows\System32\SppExtComObjHook.dll" => Symbolic link removed successfully
C:\Windows\System32\SppExtComObjHook.dll => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\CLSID\{B298D29A-A6ED-11DE-BA8C-A68E55D89593} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\CLSID\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
C:\Users\Bruno\Data aplikací => ":00e481b5e22dbe1f649fcddd505d3eb7" ADS removed successfully
"C:\Users\Bruno\AppData\Roaming" => ":00e481b5e22dbe1f649fcddd505d3eb7" ADS not found.
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6CB55A74-1C3C-44EE-9A76-D80C02FD96C8}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{56805C76-1ADB-4F11-8752-9A882B8D1B1F}C:\games\counter strike 1.6 gt\hl.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7A9E6A3F-5E1E-4040-BFC9-F639B8FF6BE6}C:\games\counter strike 1.6 gt\hl.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9A692F37-3269-465F-B782-863253E5653F}C:\counter-strike 1.6\hl.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{88585BFC-570E-4938-B5A7-149EF704017E}C:\counter-strike 1.6\hl.exe" => removed successfully
"C:\Users\Bruno\Downloads\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe" => not found
"C:\Users\Bruno\AppData\Local\Temp\Rar$DRa7236.15091\Kaspersky Reset Trial [KRT] 5.1.0.35\KRT_5.1.0.35.exe" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 6053888 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44224029 B
Java, Flash, Steam htmlcache => 414051659 B
Windows/system/drivers => 18784949 B
Edge => 0 B
Chrome => 0 B
Firefox => 1099442126 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 16684 B
LocalService => 0 B
NetworkService => 160066 B
NetworkService => 0 B
Bruno => 15260319 B

RecycleBin => 0 B
EmptyTemp: => 1.5 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 15:34:53 ====

Re: Prosím o konrolu logu

Napsal: 20 led 2019 16:04
od Rudy
Smazáno, log je již OK. Pro jistotu bych provedl ještě kompletní sken MBAM: http://www.malwarebytes.org/mbam.php . Dejte log, předem nic nemažte.

Re: Prosím o konrolu logu

Napsal: 20 led 2019 16:17
od Bruno39
Sken MBAM nic nenasiel takze by to malo byt dobre dakujem za pomoc

Re: Prosím o konrolu logu

Napsal: 20 led 2019 17:07
od Rudy
OK, nemáte zač! :)