PC je pomalé nejde načíst stránka v opeře
Napsal: 22 bře 2019 19:22
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019
Ran by lenha (administrator) on DESKTOP-HI8G2J4 (22-03-2019 19:09:00)
Running from F:\Download\scoped_dir6624_27267
Loaded Profiles: lenha (Available Profiles: lenha)
Platform: Windows 10 Pro Version 1809 17763.107 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Megaify Software Co.,Ltd. -> Megaify Software Co., Ltd.) C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera_crashreporter.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\lenha\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(eM Client, s.r.o. -> eM Client s.r.o.) C:\Program Files (x86)\eM Client\MailClient.exe
(eM Client, s.r.o. -> eM Client s.r.o.) C:\Program Files (x86)\eM Client\MailClient.exe
(ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Trend Micro Inc.) [File not signed] F:\Download\scoped_dir6624_8278\hijackthis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\Run: [eM Client] => C:\Program Files (x86)\eM Client\MailClient.exe [22928200 2019-03-12] (eM Client, s.r.o. -> eM Client s.r.o.)
HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTRAY.EXE [604128 2019-01-18] (ZONER software, a.s. -> ZONER software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-12-16] () [File not signed]
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.88.1 192.168.163.98 80.251.240.44
Tcpip\..\Interfaces\{66f9c843-72f5-4b50-a4b3-90d4e3f8051d}: [DhcpNameServer] 192.168.88.1 192.168.163.98 80.251.240.44
HKLM\System\...\Parameters\PersistentRoutes: [104.96.147.3,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [131.253.40.37,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.115.60,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.165.248,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.165.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.185.70,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.30.202,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [137.116.81.24,255.255.255.255,0.0.0.0,1]
PersistentRoutes: There are 65 PersistentRoutes.
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-4160050988-2886862043-3056562062-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Opera:
=======
OPR StartupUrls: "hxxp://google.cz/"
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5381624 2018-09-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\NisSrv.exe [4098064 2019-03-22] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MsMpEng.exe [113992 2019-03-22] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S4 sedsvc; "C:\Program Files\rempl\sedsvc.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [610336 2019-03-21] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros)
R3 Envy24HFS; C:\WINDOWS\system32\drivers\Envy24HF.sys [150016 2019-03-21] (Microsoft Windows Hardware Compatibility Publisher -> VIA - IC Ensemble, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_708ec8f9a4d134c6\nvlddmkm.sys [17544792 2019-03-21] (NVIDIA Corporation -> NVIDIA Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46472 2019-03-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2019-03-21] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [333792 2019-03-22] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62432 2019-03-22] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-22 19:08 - 2019-03-22 19:09 - 000000000 ____D C:\FRST
2019-03-22 19:00 - 2019-03-22 19:00 - 000000000 ____D C:\Users\lenha\AppData\Local\D3DSCache
2019-03-22 18:54 - 2019-03-22 18:54 - 000000000 ___HD C:\OneDriveTemp
2019-03-22 18:50 - 2019-03-22 18:52 - 000000390 _____ C:\WINDOWS\Tasks\DriverToolkit Autorun.job
2019-03-22 18:50 - 2019-03-22 18:50 - 000002818 _____ C:\WINDOWS\System32\Tasks\DriverToolkit Autorun
2019-03-22 18:48 - 2019-03-22 18:48 - 000000000 ____D C:\Users\lenha\AppData\Local\PeerDistRepub
2019-03-22 15:45 - 2019-03-22 15:45 - 000000000 ____D C:\Users\lenha\AppData\Local\DriverToolkit
2019-03-22 15:45 - 2019-03-22 15:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit
2019-03-22 15:45 - 2019-03-22 15:45 - 000000000 ____D C:\Program Files (x86)\DriverToolkit
2019-03-22 15:34 - 2019-03-22 15:34 - 000000000 ____D C:\Users\lenha\AppData\Local\ElevatedDiagnostics
2019-03-22 15:21 - 2019-03-22 15:21 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Mikrotik
2019-03-22 12:56 - 2019-03-22 12:56 - 000002031 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Zoner Photo Studio X.lnk
2019-03-22 12:56 - 2019-03-22 12:56 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Zoner
2019-03-22 12:56 - 2019-03-22 12:56 - 000000000 ____D C:\Users\lenha\AppData\Local\Zoner
2019-03-22 12:55 - 2019-03-22 12:55 - 000000000 ____D C:\Program Files\Zoner
2019-03-22 12:36 - 2019-03-22 12:36 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Macromedia
2019-03-22 12:35 - 2019-03-22 12:35 - 000000000 ____D C:\Users\lenha\AppData\Local\Adobe
2019-03-22 12:33 - 2019-03-22 12:33 - 000000000 ____D C:\ProgramData\Adobe
2019-03-22 12:33 - 2019-03-22 12:33 - 000000000 ____D C:\Program Files\Common Files\Adobe
2019-03-22 12:32 - 2019-03-22 12:32 - 000000000 ____D C:\ProgramData\Caphyon
2019-03-22 12:32 - 2019-03-22 12:32 - 000000000 ____D C:\Program Files (x86)\Adobe
2019-03-22 06:09 - 2019-03-22 06:18 - 000000000 ____D C:\ProgramData\Packages
2019-03-22 05:55 - 2019-03-22 10:30 - 000000000 ____D C:\Users\lenha\AppData\Local\PlaceholderTileLogoFolder
2019-03-22 05:54 - 2019-03-22 05:54 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-03-22 05:52 - 2019-03-22 15:40 - 000000000 ____D C:\Users\lenha\AppData\Local\ConnectedDevicesPlatform
2019-03-22 05:52 - 2019-03-22 05:52 - 000000020 ___SH C:\Users\lenha\ntuser.ini
2019-03-22 05:52 - 2019-03-22 05:52 - 000000000 ___RD C:\Users\lenha\3D Objects
2019-03-22 05:52 - 2019-03-22 05:52 - 000000000 ___HD C:\Users\lenha\MicrosoftEdgeBackups
2019-03-22 03:42 - 2019-03-22 18:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-03-22 03:42 - 2019-03-22 10:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-03-22 03:42 - 2019-03-22 03:42 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2019-03-22 03:42 - 2019-03-22 03:42 - 000007623 _____ C:\WINDOWS\diagerr.xml
2019-03-22 03:42 - 2019-03-22 03:42 - 000003514 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1553205429
2019-03-22 03:42 - 2019-03-22 03:42 - 000002860 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4160050988-2886862043-3056562062-1001
2019-03-22 03:40 - 2019-03-22 05:52 - 000000000 ____D C:\Users\lenha
2019-03-22 03:40 - 2019-03-22 03:40 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Šablony
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Soubory cookie
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Poslední
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Okolní tiskárny
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Okolní síť
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Nabídka Start
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Dokumenty
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Data aplikací
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\AppData\Local\Data aplikací
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 ____D C:\ProgramData\USOShared
2019-03-22 03:40 - 2018-09-15 08:29 - 000001105 _____ C:\Users\lenha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-03-22 03:40 - 2018-09-15 08:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-03-22 03:38 - 2019-03-22 18:52 - 000000000 ____D C:\ProgramData\NVIDIA
2019-03-22 03:38 - 2019-03-22 03:38 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-03-22 03:38 - 2019-03-22 03:38 - 000000000 ____D C:\Program Files\Common Files\Atheros
2019-03-22 03:38 - 2018-03-24 00:50 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-03-22 03:38 - 2018-03-24 00:02 - 005952392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 002596320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 001767824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000633224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000451040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000123840 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000083072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-03-22 03:38 - 2018-03-21 12:22 - 008114212 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-03-22 03:37 - 2019-03-22 18:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-03-22 03:37 - 2019-03-22 03:41 - 000258088 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-03-22 03:36 - 2019-03-22 03:42 - 000000000 ____D C:\Windows.old
2019-03-22 00:53 - 2019-03-22 03:36 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-03-22 00:51 - 2019-03-22 00:53 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-03-22 00:31 - 2019-03-22 00:31 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2019-03-22 00:27 - 2019-03-22 00:27 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-03-21 23:34 - 2019-03-21 23:34 - 000610336 _____ (Qualcomm Atheros) C:\WINDOWS\system32\Drivers\btfilter.sys
2019-03-21 23:34 - 2019-03-21 23:34 - 000271600 _____ (Qualcomm®Atheros®) C:\WINDOWS\system32\BtContextMenu.dll
2019-03-21 23:34 - 2019-03-21 23:34 - 000269048 _____ (Qualcomm Atheros Communications Inc.) C:\WINDOWS\system32\btcoinst.dll
2019-03-21 23:34 - 2019-03-21 23:34 - 000246804 _____ C:\WINDOWS\system32\Drivers\AtherosBT.bin
2019-03-21 23:34 - 2019-03-21 23:34 - 000098552 _____ (Qualcomm®Atheros®) C:\WINDOWS\system32\BtContextMenu.dll.muien-US
2019-03-21 23:34 - 2019-03-21 23:34 - 000046972 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x11020000.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000046908 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x31010000.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000046852 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x11020100.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000045868 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x01020201.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000044028 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x01020200.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000042908 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x31010100.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000040684 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x31010000_ss01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0xf0.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x21.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x11.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001922 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010100_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001802 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020100_40_SS01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001802 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020100_40_nf01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001802 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020100_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001796 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020000_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_SS01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_LV01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0xf1.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x22.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x12.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001512 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010100_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001242 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001228 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x04.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001214 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x03.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001204 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x02.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001204 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001198 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_26.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001192 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_26_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000296 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000278 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x04.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x03.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x02.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_26_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_26.dfu
2019-03-21 23:14 - 2019-03-22 15:43 - 000000000 ____D C:\Program Files\rempl
2019-03-21 23:14 - 2019-03-22 05:52 - 000000000 ____D C:\Program Files\CUAssistant
2019-03-21 23:14 - 2018-12-10 23:04 - 000592616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-03-21 23:13 - 2019-03-21 23:13 - 127411920 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-03-21 23:13 - 2019-03-21 23:13 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-03-21 23:12 - 2019-03-22 03:42 - 000000000 ___DC C:\WINDOWS\Panther
2019-03-21 23:11 - 2019-03-21 23:11 - 001997752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438813.dll
2019-03-21 23:11 - 2019-03-21 23:11 - 001682544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438813.dll
2019-03-21 23:11 - 2018-06-27 12:10 - 000131288 _____ (Microsoft Corporation) C:\WINDOWS\system32\osrss.dll
2019-03-21 23:10 - 2019-03-21 23:10 - 000000000 ____D C:\Users\lenha\AppData\Local\GHISLER
2019-03-21 23:09 - 2019-03-21 23:09 - 000000000 ____D C:\Users\lenha\AppData\Roaming\GHISLER
2019-03-21 23:08 - 2019-03-21 23:09 - 007664792 _____ (Ghisler Software GmbH) C:\Users\lenha\Downloads\tcmd922x32_64.exe
2019-03-21 23:03 - 2019-03-22 18:54 - 000000000 ____D C:\Users\lenha\AppData\Roaming\eM Client
2019-03-21 23:03 - 2019-03-21 23:03 - 000001133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2019-03-21 23:03 - 2019-03-21 23:03 - 000000000 ____D C:\Users\lenha\AppData\Local\eM Client
2019-03-21 23:03 - 2019-03-21 23:03 - 000000000 ____D C:\Users\lenha\AppData\Local\CEF
2019-03-21 23:03 - 2019-03-21 23:03 - 000000000 ____D C:\Program Files (x86)\eM Client
2019-03-21 23:02 - 2019-03-21 23:02 - 053764096 _____ C:\Users\lenha\Downloads\setup.msi
2019-03-21 23:01 - 2019-03-21 23:01 - 000000000 ____D C:\Users\lenha\AppData\Local\OneDrive
2019-03-21 22:58 - 2018-09-16 17:43 - 001660472 _____ C:\Users\lenha\OneDrive\Dokumenty\winbox (1).exe
2019-03-21 22:58 - 2018-01-30 15:28 - 000006382 _____ C:\Users\lenha\OneDrive\Dokumenty\zalozky_30.01.18.html
2019-03-21 22:58 - 2017-09-15 14:21 - 001588750 _____ C:\Users\lenha\OneDrive\Dokumenty\winbox.exe
2019-03-21 22:58 - 2017-06-02 21:39 - 000800904 _____ C:\Users\lenha\OneDrive\Dokumenty\palemoon-websetup.exe
2019-03-21 22:58 - 2017-05-25 10:29 - 002491932 _____ C:\Users\lenha\OneDrive\Dokumenty\Bitcoin_krok_za_krokem_ebook.pdf
2019-03-21 22:58 - 2015-08-16 21:10 - 000049776 _____ C:\Users\lenha\OneDrive\Dokumenty\Bc-prace-Vendula-Lenhartova (1).odt
2019-03-21 22:58 - 2014-02-06 09:03 - 000131072 _____ C:\Users\lenha\OneDrive\Dokumenty\Tahiti1.rom
2019-03-21 22:58 - 2014-02-06 09:03 - 000131072 _____ C:\Users\lenha\OneDrive\Dokumenty\Tahiti.rom
2019-03-21 22:58 - 2014-01-23 09:37 - 000131072 _____ C:\Users\lenha\OneDrive\Dokumenty\Tahiti.bin
2019-03-21 22:57 - 2019-03-21 22:57 - 028915808 _____ (Microsoft Corporation) C:\Users\lenha\Downloads\OneDriveSetup.exe
2019-03-21 22:57 - 2019-03-21 22:57 - 000001397 _____ C:\Users\lenha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2019-03-21 22:57 - 2019-03-21 22:57 - 000000000 ____D C:\Users\lenha\AppData\Local\Opera Software
2019-03-21 22:56 - 2019-03-22 18:56 - 001606102 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-03-21 22:56 - 2019-03-21 22:56 - 002165336 _____ (Opera Software) C:\Users\lenha\Downloads\OperaSetup.exe
2019-03-21 22:56 - 2019-03-21 22:56 - 000150016 _____ (VIA - IC Ensemble, Inc.) C:\WINDOWS\system32\Drivers\Envy24HF.sys
2019-03-21 22:56 - 2019-03-21 22:56 - 000035584 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdcsam64.sys
2019-03-21 22:56 - 2019-03-21 22:56 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Opera Software
2019-03-21 22:55 - 2019-03-22 03:38 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-03-21 22:55 - 2019-03-22 03:38 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-03-21 22:55 - 2019-03-21 22:57 - 000000000 ____D C:\Users\lenha\AppData\Local\Comms
2019-03-21 22:55 - 2019-03-21 22:56 - 000000000 ____D C:\Users\lenha\AppData\Local\MicrosoftEdge
2019-03-21 22:55 - 2019-03-21 22:55 - 040278616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 035188992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 019855144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 016496768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 013571520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 012967056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 011132384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 011001504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 004633920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 004318112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 003939624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 003719096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001985112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439135.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001690952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001683712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439135.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001355216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001346128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001153752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001138720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001067552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001065888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001061352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000998432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000950016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000902096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000811808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000749312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000650232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000633040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000625504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000608344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000516024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000235424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2019-03-21 22:55 - 2019-03-21 22:55 - 000054272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000048407 _____ C:\WINDOWS\system32\nvinfo.pb
2019-03-21 22:55 - 2019-03-21 22:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2019-03-21 22:54 - 2019-03-22 18:54 - 000000000 ___RD C:\Users\lenha\OneDrive
2019-03-21 22:53 - 2019-03-22 18:48 - 000000000 ____D C:\Users\lenha\AppData\Local\Packages
2019-03-21 22:53 - 2019-03-22 15:23 - 000000000 ____D C:\Users\lenha\AppData\Local\VirtualStore
2019-03-21 22:53 - 2019-03-22 06:20 - 000000000 ____D C:\Users\lenha\AppData\Local\Publishers
2019-03-21 22:53 - 2019-03-22 05:52 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-03-21 22:53 - 2019-03-21 23:09 - 000000000 ____D C:\Users\lenha\AppData\Local\PackageStaging
2019-03-21 22:53 - 2019-03-21 22:53 - 000016148 _____ C:\WINDOWS\system32\DESKTOP-HI8G2J4_defaultuser0_HistoryPrediction.bin
2019-03-21 22:53 - 2019-03-21 22:53 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Adobe
2019-03-21 22:53 - 2019-03-21 22:53 - 000000000 ____D C:\Users\lenha\AppData\Local\TileDataLayer
2019-03-21 22:52 - 2019-03-21 22:52 - 000195152 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Šablony
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Soubory cookie
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Poslední
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Okolní tiskárny
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Okolní síť
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Nabídka Start
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Dokumenty
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Šablony
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Plocha
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Nabídka Start
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Dokumenty
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 ____D C:\WINDOWS\CSC
2019-03-21 22:41 - 2019-03-21 22:41 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2019-03-21 22:17 - 2019-03-21 22:17 - 000000000 ___HD C:\$SysReset
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-22 18:56 - 2018-09-15 18:39 - 000682358 _____ C:\WINDOWS\system32\perfh005.dat
2019-03-22 18:56 - 2018-09-15 18:39 - 000137076 _____ C:\WINDOWS\system32\perfc005.dat
2019-03-22 18:56 - 2018-09-15 08:31 - 000000000 ____D C:\WINDOWS\INF
2019-03-22 18:54 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-03-22 18:50 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-03-22 18:50 - 2018-09-15 07:09 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2019-03-22 18:48 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-03-22 15:38 - 2018-09-15 08:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-03-22 15:35 - 2018-09-15 07:09 - 000000000 ____D C:\WINDOWS\servicing
2019-03-22 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Windows Defender
2019-03-22 06:09 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ServiceState
2019-03-22 03:58 - 2018-09-15 07:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-03-22 03:42 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\windows nt
2019-03-22 03:41 - 2018-09-15 08:33 - 000000000 __RHD C:\Users\Public\Libraries
2019-03-22 03:39 - 2018-09-15 08:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-03-22 03:38 - 2018-09-15 08:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-03-22 03:38 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Help
2019-03-22 03:36 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-03-22 03:36 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\spool
2019-03-22 03:36 - 2018-09-15 08:31 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-03-22 03:36 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-03-22 00:59 - 2018-09-15 08:36 - 000000000 ____D C:\WINDOWS\Setup
2019-03-22 00:54 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-03-22 00:53 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2019-03-22 00:53 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Resources
2019-03-22 00:32 - 2018-09-15 08:39 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2019-03-22 00:32 - 2018-09-15 08:39 - 000302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2019-03-22 00:32 - 2018-09-15 08:37 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2019-03-03 01:45 - 2018-09-15 08:36 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-03-03 01:45 - 2018-09-15 08:36 - 000179608 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by lenha (22-03-2019 19:09:48)
Running from F:\Download\scoped_dir6624_27267
Windows 10 Pro Version 1809 17763.107 (X64) (2019-03-22 02:42:25)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4160050988-2886862043-3056562062-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4160050988-2886862043-3056562062-503 - Limited - Disabled)
Guest (S-1-5-21-4160050988-2886862043-3056562062-501 - Limited - Disabled)
lenha (S-1-5-21-4160050988-2886862043-3056562062-1001 - Administrator - Enabled) => C:\Users\lenha
WDAGUtilityAccount (S-1-5-21-4160050988-2886862043-3056562062-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Photoshop CC (HKLM-x32\...\Adobe Photoshop CC 19.0) (Version: 19.0 - Adobe)
DriverToolkit version 8.5.0.0 (HKLM-x32\...\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.5.0.0 - Megaify Software)
eM Client (HKLM-x32\...\{5DAF1ADB-AD1D-457E-8803-6FA42EF5701D}) (Version: 7.2.34959.0 - eM Client Inc.)
Microsoft OneDrive (HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\OneDriveSetup.exe) (Version: 19.012.0121.0011 - Microsoft Corporation)
Opera Stable 58.0.3135.117 (HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\Opera 58.0.3135.117) (Version: 58.0.3135.117 - Opera Software)
Ovládací panel NVIDIA 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 391.35 - NVIDIA Corporation) Hidden
Total Commander 64+32-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.22 - Ghisler Software GmbH)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{FBA3961B-D1DF-493C-BC1F-E67D3B832895}) (Version: 2.56.0.0 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{344F3227-F502-4219-9DC4-1967E586FAFA}) (Version: 2.51.0.0 - Microsoft Corporation)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1809.2.93 - ZONER software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4160050988-2886862043-3056562062-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {2598A0F0-C130-4746-BED7-A8FC3216B11D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {421056A3-0F58-4EC9-959A-7E4906BFDDDB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {45CDE8E8-A1C8-427F-A2A5-5C37B31ABEE9} - System32\Tasks\Microsoft\Windows\CUAssistant\CULauncher => C:\Program Files\CUAssistant\culauncher.exe (Microsoft Windows -> Microsoft Corporation)
Task: {6D707A78-07CE-41BB-A09C-6E2FD342423A} - System32\Tasks\DriverToolkit Autorun => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe (Megaify Software Co.,Ltd. -> Megaify Software Co., Ltd.)
Task: {86795C9A-98E6-47B5-945D-0BE00386882B} - System32\Tasks\Opera scheduled Autoupdate 1553205429 => C:\Users\lenha\AppData\Local\Programs\Opera\launcher.exe (Opera Software AS -> Opera Software)
Task: {AB6BF5AE-24EE-4AEA-90AA-545F01B13CAC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {F92D7268-79C9-4CD3-AFE8-24D442B5FD41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2019-03-22 19:04 - 2019-03-22 19:04 - 000388608 _____ (Trend Micro Inc.) [File not signed] F:\Download\scoped_dir6624_8278\hijackthis.exe
2019-01-24 12:23 - 2019-01-24 12:23 - 062831616 _____ () [File not signed] C:\Program Files (x86)\eM Client\libcef.DLL
2019-01-24 12:21 - 2019-01-24 12:21 - 000840078 _____ (SQLite Development Team) [File not signed] C:\Program Files (x86)\eM Client\SQLite\x86\sqlite3.dll
2019-03-22 12:55 - 2016-10-17 18:29 - 003842048 _____ (Terra Informatica Software, Inc.) [File not signed] C:\Program Files\Zoner\Photo Studio 19\Program32\sciter32.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-07-10 12:04 - 2019-03-22 18:49 - 000004933 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 a.ads1.msn.com
0.0.0.0 a.ads2.msads.net
0.0.0.0 a.ads2.msn.com
0.0.0.0 a.rad.msn.com
0.0.0.0 a-0001.a-msedge.net
0.0.0.0 a-0002.a-msedge.net
0.0.0.0 a-0003.a-msedge.net
0.0.0.0 a-0004.a-msedge.net
0.0.0.0 a-0005.a-msedge.net
0.0.0.0 a-0006.a-msedge.net
0.0.0.0 a-0007.a-msedge.net
0.0.0.0 a-0008.a-msedge.net
0.0.0.0 a-0009.a-msedge.net
0.0.0.0 ac3.msn.com
0.0.0.0 ad.doubleclick.net
0.0.0.0 adnexus.net
0.0.0.0 adnxs.com
0.0.0.0 ads.msn.com
0.0.0.0 ads1.msads.net
0.0.0.0 ads1.msn.com
0.0.0.0 aidps.atdmt.com
0.0.0.0 aka-cdn-ns.adtech.de
0.0.0.0 a-msedge.net
0.0.0.0 apps.skype.com
0.0.0.0 az361816.vo.msecnd.net
0.0.0.0 az512334.vo.msecnd.net
0.0.0.0 b.ads1.msn.com
0.0.0.0 b.ads2.msads.net
0.0.0.0 b.rad.msn.com
0.0.0.0 bs.serving-sys.com
There are 92 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\lenha\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img1.jpg
DNS Servers: 192.168.88.1 - 192.168.163.98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{C117DEBC-A484-4FD5-B2E3-E7EA4EDD1BE6}F:\download\scoped_dir12396_20861\winbox (1).exe] => (Allow) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [UDP Query User{009F01C7-C20A-43DB-B8AE-B94B648A10CE}F:\download\scoped_dir12396_20861\winbox (1).exe] => (Allow) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [{73A59820-8767-4A18-9DD0-7FF472214B98}] => (Block) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [{47B64908-AEDE-421D-8FFD-C3D71AEBD2F8}] => (Block) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [TCP Query User{B272DA1F-918F-4E7B-81AE-EE1659ADC392}C:\users\lenha\onedrive\dokumenty\winbox.exe] => (Allow) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [UDP Query User{64571CDD-33AA-4858-9305-1DD9E38C19C2}C:\users\lenha\onedrive\dokumenty\winbox.exe] => (Allow) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [{AC2CDA9B-755D-4B05-B899-19787D927914}] => (Block) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [{CF0D121E-35E6-492B-BD4C-D43A15F7C367}] => (Block) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [TCP Query User{7C14C58A-94FE-4F09-AC9A-AC237F8D9D32}F:\download\winbox (1).exe] => (Allow) F:\download\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [UDP Query User{869B5B84-369C-498A-9F10-7694840CB9E6}F:\download\winbox (1).exe] => (Allow) F:\download\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{2765E0F4-2918-4A46-B9C9-43CDD8FCBA2B}] => (Block) C:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E02AB908-0A91-41DB-8504-5C385CC561BF}] => (Block) C:\Windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
==================== Restore Points =========================
22-03-2019 15:37:25 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/22/2019 06:11:23 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Error: (03/22/2019 06:11:23 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C003
Error: (03/22/2019 06:11:20 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Error: (03/22/2019 06:11:20 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C003
Error: (03/22/2019 06:02:53 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0xC004C003
Argument příkazového řádku:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (03/22/2019 06:02:52 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Error: (03/22/2019 06:02:52 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C003
Error: (03/22/2019 06:02:50 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
System errors:
=============
Error: (03/22/2019 06:54:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:54:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.SecurityAppBroker
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:54:06 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscCloudBackupProvider
a APPID
Není k dispozici
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:53:56 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:53:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:53:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:39:23 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 04:05:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Windows Defender:
===================================
Date: 2019-03-22 15:43:19.039
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner.BB!bit
ID: 2147716648
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_J:\Photo.scr
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.74.0, AS: 1.291.74.0, NIS: 1.291.74.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:43:15.956
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner!rfn
ID: 2147693577
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_J:\IMG001.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.74.0, AS: 1.291.74.0, NIS: 1.291.74.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:31:33.433
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner!rfn
ID: 2147693577
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_G:\IMG001.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.60.0, AS: 1.291.60.0, NIS: 1.291.60.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:31:20.491
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner.BB!bit
ID: 2147716648
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_G:\Photo.scr; file:_H:\Photo.scr
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.60.0, AS: 1.291.60.0, NIS: 1.291.60.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:31:17.437
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner!rfn
ID: 2147693577
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_G:\IMG001.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.60.0, AS: 1.291.60.0, NIS: 1.291.60.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 03:42:16.147
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o načtení podpisů a pokusí se o obnovení sady podpisů, jejichž správnost je potvrzena.
Podpisy, které se měly načíst: Aktuální
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu.
Verze podpisu: 0.0.0.0;0.0.0.0
Verze modulu: 0.0.0.0
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 17%
Total physical RAM: 16359.11 MB
Available physical RAM: 13534.66 MB
Total Virtual: 19303.11 MB
Available Virtual: 14806.18 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:223.03 GB) (Free:180.48 GB) NTFS
Drive d: (Data_D) (Fixed) (Total:237.75 GB) (Free:114.88 GB) NTFS
Drive e: () (Fixed) (Total:115.48 GB) (Free:35.59 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive f: (Data) (Fixed) (Total:117.19 GB) (Free:3.45 GB) NTFS
Drive g: (My Passport) (Fixed) (Total:3725.99 GB) (Free:3406.71 GB) NTFS
Drive h: (Video_data) (Fixed) (Total:115.69 GB) (Free:21.45 GB) NTFS
Drive i: (Data) (Fixed) (Total:227.62 GB) (Free:20.24 GB) NTFS
Drive j: (DATA) (Fixed) (Total:144.04 GB) (Free:28.26 GB) NTFS
Drive l: (MUSIK) (Fixed) (Total:931.51 GB) (Free:574.27 GB) NTFS
\\?\Volume{7a9df2d5-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{7a9df2d5-0000-0000-0000-60c837000000}\ () (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS
\\?\Volume{bf1ed8f5-0000-0000-007e-000000000000}\ (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:3.23 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: 7A9DF2D5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 1AB8D7AA)
Partition 1: (Active) - (Size=237.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=227.6 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 298.1 GB) (Disk ID: BF1ED8F5)
Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
Partition 2: (Active) - (Size=115.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=144 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=28.8 GB) - (Type=05)
========================================================
Disk: 3 (Size: 232.9 GB) (Disk ID: BCCCBCCC)
Partition 1: (Active) - (Size=117.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=115.7 GB) - (Type=0F Extended)
========================================================
Disk: 4 (Size: 3726 GB) (Disk ID: 16F2A91F)
Partition: GPT.
========================================================
Disk: 5 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: CE940487)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Ran by lenha (administrator) on DESKTOP-HI8G2J4 (22-03-2019 19:09:00)
Running from F:\Download\scoped_dir6624_27267
Loaded Profiles: lenha (Available Profiles: lenha)
Platform: Windows 10 Pro Version 1809 17763.107 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Megaify Software Co.,Ltd. -> Megaify Software Co., Ltd.) C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera_crashreporter.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\lenha\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(eM Client, s.r.o. -> eM Client s.r.o.) C:\Program Files (x86)\eM Client\MailClient.exe
(eM Client, s.r.o. -> eM Client s.r.o.) C:\Program Files (x86)\eM Client\MailClient.exe
(ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Opera Software AS -> Opera Software) C:\Users\lenha\AppData\Local\Programs\Opera\58.0.3135.117\opera.exe
(Trend Micro Inc.) [File not signed] F:\Download\scoped_dir6624_8278\hijackthis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\Run: [eM Client] => C:\Program Files (x86)\eM Client\MailClient.exe [22928200 2019-03-12] (eM Client, s.r.o. -> eM Client s.r.o.)
HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\Program Files\Zoner\Photo Studio 19\Program32\ZPSTRAY.EXE [604128 2019-01-18] (ZONER software, a.s. -> ZONER software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.bat [2018-12-16] () [File not signed]
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.88.1 192.168.163.98 80.251.240.44
Tcpip\..\Interfaces\{66f9c843-72f5-4b50-a4b3-90d4e3f8051d}: [DhcpNameServer] 192.168.88.1 192.168.163.98 80.251.240.44
HKLM\System\...\Parameters\PersistentRoutes: [104.96.147.3,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.177,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [131.253.40.37,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.115.60,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.165.248,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.165.253,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.185.70,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [134.170.30.202,255.255.255.255,0.0.0.0,1]
HKLM\System\...\Parameters\PersistentRoutes: [137.116.81.24,255.255.255.255,0.0.0.0,1]
PersistentRoutes: There are 65 PersistentRoutes.
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-4160050988-2886862043-3056562062-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Opera:
=======
OPR StartupUrls: "hxxp://google.cz/"
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5381624 2018-09-15] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\NisSrv.exe [4098064 2019-03-22] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MsMpEng.exe [113992 2019-03-22] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S4 sedsvc; "C:\Program Files\rempl\sedsvc.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [610336 2019-03-21] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros)
R3 Envy24HFS; C:\WINDOWS\system32\drivers\Envy24HF.sys [150016 2019-03-21] (Microsoft Windows Hardware Compatibility Publisher -> VIA - IC Ensemble, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_708ec8f9a4d134c6\nvlddmkm.sys [17544792 2019-03-21] (NVIDIA Corporation -> NVIDIA Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46472 2019-03-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2019-03-21] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [333792 2019-03-22] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62432 2019-03-22] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-22 19:08 - 2019-03-22 19:09 - 000000000 ____D C:\FRST
2019-03-22 19:00 - 2019-03-22 19:00 - 000000000 ____D C:\Users\lenha\AppData\Local\D3DSCache
2019-03-22 18:54 - 2019-03-22 18:54 - 000000000 ___HD C:\OneDriveTemp
2019-03-22 18:50 - 2019-03-22 18:52 - 000000390 _____ C:\WINDOWS\Tasks\DriverToolkit Autorun.job
2019-03-22 18:50 - 2019-03-22 18:50 - 000002818 _____ C:\WINDOWS\System32\Tasks\DriverToolkit Autorun
2019-03-22 18:48 - 2019-03-22 18:48 - 000000000 ____D C:\Users\lenha\AppData\Local\PeerDistRepub
2019-03-22 15:45 - 2019-03-22 15:45 - 000000000 ____D C:\Users\lenha\AppData\Local\DriverToolkit
2019-03-22 15:45 - 2019-03-22 15:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit
2019-03-22 15:45 - 2019-03-22 15:45 - 000000000 ____D C:\Program Files (x86)\DriverToolkit
2019-03-22 15:34 - 2019-03-22 15:34 - 000000000 ____D C:\Users\lenha\AppData\Local\ElevatedDiagnostics
2019-03-22 15:21 - 2019-03-22 15:21 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Mikrotik
2019-03-22 12:56 - 2019-03-22 12:56 - 000002031 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Zoner Photo Studio X.lnk
2019-03-22 12:56 - 2019-03-22 12:56 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Zoner
2019-03-22 12:56 - 2019-03-22 12:56 - 000000000 ____D C:\Users\lenha\AppData\Local\Zoner
2019-03-22 12:55 - 2019-03-22 12:55 - 000000000 ____D C:\Program Files\Zoner
2019-03-22 12:36 - 2019-03-22 12:36 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Macromedia
2019-03-22 12:35 - 2019-03-22 12:35 - 000000000 ____D C:\Users\lenha\AppData\Local\Adobe
2019-03-22 12:33 - 2019-03-22 12:33 - 000000000 ____D C:\ProgramData\Adobe
2019-03-22 12:33 - 2019-03-22 12:33 - 000000000 ____D C:\Program Files\Common Files\Adobe
2019-03-22 12:32 - 2019-03-22 12:32 - 000000000 ____D C:\ProgramData\Caphyon
2019-03-22 12:32 - 2019-03-22 12:32 - 000000000 ____D C:\Program Files (x86)\Adobe
2019-03-22 06:09 - 2019-03-22 06:18 - 000000000 ____D C:\ProgramData\Packages
2019-03-22 05:55 - 2019-03-22 10:30 - 000000000 ____D C:\Users\lenha\AppData\Local\PlaceholderTileLogoFolder
2019-03-22 05:54 - 2019-03-22 05:54 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-03-22 05:52 - 2019-03-22 15:40 - 000000000 ____D C:\Users\lenha\AppData\Local\ConnectedDevicesPlatform
2019-03-22 05:52 - 2019-03-22 05:52 - 000000020 ___SH C:\Users\lenha\ntuser.ini
2019-03-22 05:52 - 2019-03-22 05:52 - 000000000 ___RD C:\Users\lenha\3D Objects
2019-03-22 05:52 - 2019-03-22 05:52 - 000000000 ___HD C:\Users\lenha\MicrosoftEdgeBackups
2019-03-22 03:42 - 2019-03-22 18:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-03-22 03:42 - 2019-03-22 10:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-03-22 03:42 - 2019-03-22 03:42 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2019-03-22 03:42 - 2019-03-22 03:42 - 000007623 _____ C:\WINDOWS\diagerr.xml
2019-03-22 03:42 - 2019-03-22 03:42 - 000003514 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1553205429
2019-03-22 03:42 - 2019-03-22 03:42 - 000002860 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4160050988-2886862043-3056562062-1001
2019-03-22 03:40 - 2019-03-22 05:52 - 000000000 ____D C:\Users\lenha
2019-03-22 03:40 - 2019-03-22 03:40 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Šablony
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Soubory cookie
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Poslední
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Okolní tiskárny
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Okolní síť
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Nabídka Start
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Dokumenty
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\Data aplikací
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 _SHDL C:\Users\lenha\AppData\Local\Data aplikací
2019-03-22 03:40 - 2019-03-22 03:40 - 000000000 ____D C:\ProgramData\USOShared
2019-03-22 03:40 - 2018-09-15 08:29 - 000001105 _____ C:\Users\lenha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-03-22 03:40 - 2018-09-15 08:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-03-22 03:38 - 2019-03-22 18:52 - 000000000 ____D C:\ProgramData\NVIDIA
2019-03-22 03:38 - 2019-03-22 03:38 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-03-22 03:38 - 2019-03-22 03:38 - 000000000 ____D C:\Program Files\Common Files\Atheros
2019-03-22 03:38 - 2018-03-24 00:50 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-03-22 03:38 - 2018-03-24 00:02 - 005952392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 002596320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 001767824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000633224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000451040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000123840 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-03-22 03:38 - 2018-03-24 00:02 - 000083072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-03-22 03:38 - 2018-03-21 12:22 - 008114212 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-03-22 03:37 - 2019-03-22 18:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-03-22 03:37 - 2019-03-22 03:41 - 000258088 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-03-22 03:36 - 2019-03-22 03:42 - 000000000 ____D C:\Windows.old
2019-03-22 00:53 - 2019-03-22 03:36 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-03-22 00:51 - 2019-03-22 00:53 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-03-22 00:31 - 2019-03-22 00:31 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2019-03-22 00:27 - 2019-03-22 00:27 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-03-21 23:34 - 2019-03-21 23:34 - 000610336 _____ (Qualcomm Atheros) C:\WINDOWS\system32\Drivers\btfilter.sys
2019-03-21 23:34 - 2019-03-21 23:34 - 000271600 _____ (Qualcomm®Atheros®) C:\WINDOWS\system32\BtContextMenu.dll
2019-03-21 23:34 - 2019-03-21 23:34 - 000269048 _____ (Qualcomm Atheros Communications Inc.) C:\WINDOWS\system32\btcoinst.dll
2019-03-21 23:34 - 2019-03-21 23:34 - 000246804 _____ C:\WINDOWS\system32\Drivers\AtherosBT.bin
2019-03-21 23:34 - 2019-03-21 23:34 - 000098552 _____ (Qualcomm®Atheros®) C:\WINDOWS\system32\BtContextMenu.dll.muien-US
2019-03-21 23:34 - 2019-03-21 23:34 - 000046972 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x11020000.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000046908 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x31010000.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000046852 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x11020100.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000045868 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x01020201.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000044028 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x01020200.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000042908 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x31010100.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000040684 _____ C:\WINDOWS\system32\Drivers\AthrBT_0x31010000_ss01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0xf0.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x21.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x11.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001926 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001922 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010100_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001802 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020100_40_SS01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001802 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020100_40_nf01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001802 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020100_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001796 _____ C:\WINDOWS\system32\Drivers\ramps_0x11020000_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_SS01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_LV01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0xf1.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x22.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x12.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001516 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010000_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001512 _____ C:\WINDOWS\system32\Drivers\ramps_0x31010100_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001242 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001228 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x04.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001214 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x03.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001204 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40_0x02.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001204 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001198 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_26.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000001192 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020200_26_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000296 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000278 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x04.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x03.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40_0x02.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_40.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_26_0x01.dfu
2019-03-21 23:34 - 2019-03-21 23:34 - 000000264 _____ C:\WINDOWS\system32\Drivers\ramps_0x01020201_26.dfu
2019-03-21 23:14 - 2019-03-22 15:43 - 000000000 ____D C:\Program Files\rempl
2019-03-21 23:14 - 2019-03-22 05:52 - 000000000 ____D C:\Program Files\CUAssistant
2019-03-21 23:14 - 2018-12-10 23:04 - 000592616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-03-21 23:13 - 2019-03-21 23:13 - 127411920 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-03-21 23:13 - 2019-03-21 23:13 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-03-21 23:12 - 2019-03-22 03:42 - 000000000 ___DC C:\WINDOWS\Panther
2019-03-21 23:11 - 2019-03-21 23:11 - 001997752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438813.dll
2019-03-21 23:11 - 2019-03-21 23:11 - 001682544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438813.dll
2019-03-21 23:11 - 2018-06-27 12:10 - 000131288 _____ (Microsoft Corporation) C:\WINDOWS\system32\osrss.dll
2019-03-21 23:10 - 2019-03-21 23:10 - 000000000 ____D C:\Users\lenha\AppData\Local\GHISLER
2019-03-21 23:09 - 2019-03-21 23:09 - 000000000 ____D C:\Users\lenha\AppData\Roaming\GHISLER
2019-03-21 23:08 - 2019-03-21 23:09 - 007664792 _____ (Ghisler Software GmbH) C:\Users\lenha\Downloads\tcmd922x32_64.exe
2019-03-21 23:03 - 2019-03-22 18:54 - 000000000 ____D C:\Users\lenha\AppData\Roaming\eM Client
2019-03-21 23:03 - 2019-03-21 23:03 - 000001133 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eM Client.lnk
2019-03-21 23:03 - 2019-03-21 23:03 - 000000000 ____D C:\Users\lenha\AppData\Local\eM Client
2019-03-21 23:03 - 2019-03-21 23:03 - 000000000 ____D C:\Users\lenha\AppData\Local\CEF
2019-03-21 23:03 - 2019-03-21 23:03 - 000000000 ____D C:\Program Files (x86)\eM Client
2019-03-21 23:02 - 2019-03-21 23:02 - 053764096 _____ C:\Users\lenha\Downloads\setup.msi
2019-03-21 23:01 - 2019-03-21 23:01 - 000000000 ____D C:\Users\lenha\AppData\Local\OneDrive
2019-03-21 22:58 - 2018-09-16 17:43 - 001660472 _____ C:\Users\lenha\OneDrive\Dokumenty\winbox (1).exe
2019-03-21 22:58 - 2018-01-30 15:28 - 000006382 _____ C:\Users\lenha\OneDrive\Dokumenty\zalozky_30.01.18.html
2019-03-21 22:58 - 2017-09-15 14:21 - 001588750 _____ C:\Users\lenha\OneDrive\Dokumenty\winbox.exe
2019-03-21 22:58 - 2017-06-02 21:39 - 000800904 _____ C:\Users\lenha\OneDrive\Dokumenty\palemoon-websetup.exe
2019-03-21 22:58 - 2017-05-25 10:29 - 002491932 _____ C:\Users\lenha\OneDrive\Dokumenty\Bitcoin_krok_za_krokem_ebook.pdf
2019-03-21 22:58 - 2015-08-16 21:10 - 000049776 _____ C:\Users\lenha\OneDrive\Dokumenty\Bc-prace-Vendula-Lenhartova (1).odt
2019-03-21 22:58 - 2014-02-06 09:03 - 000131072 _____ C:\Users\lenha\OneDrive\Dokumenty\Tahiti1.rom
2019-03-21 22:58 - 2014-02-06 09:03 - 000131072 _____ C:\Users\lenha\OneDrive\Dokumenty\Tahiti.rom
2019-03-21 22:58 - 2014-01-23 09:37 - 000131072 _____ C:\Users\lenha\OneDrive\Dokumenty\Tahiti.bin
2019-03-21 22:57 - 2019-03-21 22:57 - 028915808 _____ (Microsoft Corporation) C:\Users\lenha\Downloads\OneDriveSetup.exe
2019-03-21 22:57 - 2019-03-21 22:57 - 000001397 _____ C:\Users\lenha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2019-03-21 22:57 - 2019-03-21 22:57 - 000000000 ____D C:\Users\lenha\AppData\Local\Opera Software
2019-03-21 22:56 - 2019-03-22 18:56 - 001606102 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-03-21 22:56 - 2019-03-21 22:56 - 002165336 _____ (Opera Software) C:\Users\lenha\Downloads\OperaSetup.exe
2019-03-21 22:56 - 2019-03-21 22:56 - 000150016 _____ (VIA - IC Ensemble, Inc.) C:\WINDOWS\system32\Drivers\Envy24HF.sys
2019-03-21 22:56 - 2019-03-21 22:56 - 000035584 _____ (Western Digital Technologies, Inc.) C:\WINDOWS\system32\Drivers\wdcsam64.sys
2019-03-21 22:56 - 2019-03-21 22:56 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Opera Software
2019-03-21 22:55 - 2019-03-22 03:38 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-03-21 22:55 - 2019-03-22 03:38 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-03-21 22:55 - 2019-03-21 22:57 - 000000000 ____D C:\Users\lenha\AppData\Local\Comms
2019-03-21 22:55 - 2019-03-21 22:56 - 000000000 ____D C:\Users\lenha\AppData\Local\MicrosoftEdge
2019-03-21 22:55 - 2019-03-21 22:55 - 040278616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 035188992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 019855144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 016496768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 013571520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 012967056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 011132384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 011001504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 004633920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 004318112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 003939624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 003719096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001985112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439135.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001690952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001683712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439135.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001355216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001346128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001153752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001138720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001067552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001065888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 001061352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000998432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000950016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000902096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000811808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000749312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000650232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000633040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000625504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000608344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000516024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000235424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2019-03-21 22:55 - 2019-03-21 22:55 - 000054272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2019-03-21 22:55 - 2019-03-21 22:55 - 000048407 _____ C:\WINDOWS\system32\nvinfo.pb
2019-03-21 22:55 - 2019-03-21 22:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2019-03-21 22:54 - 2019-03-22 18:54 - 000000000 ___RD C:\Users\lenha\OneDrive
2019-03-21 22:53 - 2019-03-22 18:48 - 000000000 ____D C:\Users\lenha\AppData\Local\Packages
2019-03-21 22:53 - 2019-03-22 15:23 - 000000000 ____D C:\Users\lenha\AppData\Local\VirtualStore
2019-03-21 22:53 - 2019-03-22 06:20 - 000000000 ____D C:\Users\lenha\AppData\Local\Publishers
2019-03-21 22:53 - 2019-03-22 05:52 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-03-21 22:53 - 2019-03-21 23:09 - 000000000 ____D C:\Users\lenha\AppData\Local\PackageStaging
2019-03-21 22:53 - 2019-03-21 22:53 - 000016148 _____ C:\WINDOWS\system32\DESKTOP-HI8G2J4_defaultuser0_HistoryPrediction.bin
2019-03-21 22:53 - 2019-03-21 22:53 - 000000000 ____D C:\Users\lenha\AppData\Roaming\Adobe
2019-03-21 22:53 - 2019-03-21 22:53 - 000000000 ____D C:\Users\lenha\AppData\Local\TileDataLayer
2019-03-21 22:52 - 2019-03-21 22:52 - 000195152 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Šablony
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Soubory cookie
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Poslední
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Okolní tiskárny
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Okolní síť
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Nabídka Start
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Dokumenty
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Šablony
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Plocha
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Nabídka Start
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Dokumenty
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 _SHDL C:\ProgramData\Data aplikací
2019-03-21 22:47 - 2019-03-21 22:47 - 000000000 ____D C:\WINDOWS\CSC
2019-03-21 22:41 - 2019-03-21 22:41 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2019-03-21 22:17 - 2019-03-21 22:17 - 000000000 ___HD C:\$SysReset
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-22 18:56 - 2018-09-15 18:39 - 000682358 _____ C:\WINDOWS\system32\perfh005.dat
2019-03-22 18:56 - 2018-09-15 18:39 - 000137076 _____ C:\WINDOWS\system32\perfc005.dat
2019-03-22 18:56 - 2018-09-15 08:31 - 000000000 ____D C:\WINDOWS\INF
2019-03-22 18:54 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-03-22 18:50 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-03-22 18:50 - 2018-09-15 07:09 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2019-03-22 18:48 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-03-22 15:38 - 2018-09-15 08:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-03-22 15:35 - 2018-09-15 07:09 - 000000000 ____D C:\WINDOWS\servicing
2019-03-22 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Windows Defender
2019-03-22 06:09 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ServiceState
2019-03-22 03:58 - 2018-09-15 07:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-03-22 03:42 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\windows nt
2019-03-22 03:41 - 2018-09-15 08:33 - 000000000 __RHD C:\Users\Public\Libraries
2019-03-22 03:39 - 2018-09-15 08:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-03-22 03:38 - 2018-09-15 08:33 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-03-22 03:38 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Help
2019-03-22 03:36 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-03-22 03:36 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\spool
2019-03-22 03:36 - 2018-09-15 08:31 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-03-22 03:36 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-03-22 00:59 - 2018-09-15 08:36 - 000000000 ____D C:\WINDOWS\Setup
2019-03-22 00:54 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-03-22 00:53 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2019-03-22 00:53 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Resources
2019-03-22 00:32 - 2018-09-15 08:39 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2019-03-22 00:32 - 2018-09-15 08:39 - 000302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2019-03-22 00:32 - 2018-09-15 08:37 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2019-03-03 01:45 - 2018-09-15 08:36 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-03-03 01:45 - 2018-09-15 08:36 - 000179608 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by lenha (22-03-2019 19:09:48)
Running from F:\Download\scoped_dir6624_27267
Windows 10 Pro Version 1809 17763.107 (X64) (2019-03-22 02:42:25)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4160050988-2886862043-3056562062-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4160050988-2886862043-3056562062-503 - Limited - Disabled)
Guest (S-1-5-21-4160050988-2886862043-3056562062-501 - Limited - Disabled)
lenha (S-1-5-21-4160050988-2886862043-3056562062-1001 - Administrator - Enabled) => C:\Users\lenha
WDAGUtilityAccount (S-1-5-21-4160050988-2886862043-3056562062-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Photoshop CC (HKLM-x32\...\Adobe Photoshop CC 19.0) (Version: 19.0 - Adobe)
DriverToolkit version 8.5.0.0 (HKLM-x32\...\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.5.0.0 - Megaify Software)
eM Client (HKLM-x32\...\{5DAF1ADB-AD1D-457E-8803-6FA42EF5701D}) (Version: 7.2.34959.0 - eM Client Inc.)
Microsoft OneDrive (HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\OneDriveSetup.exe) (Version: 19.012.0121.0011 - Microsoft Corporation)
Opera Stable 58.0.3135.117 (HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\...\Opera 58.0.3135.117) (Version: 58.0.3135.117 - Opera Software)
Ovládací panel NVIDIA 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 391.35 - NVIDIA Corporation) Hidden
Total Commander 64+32-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.22 - Ghisler Software GmbH)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{FBA3961B-D1DF-493C-BC1F-E67D3B832895}) (Version: 2.56.0.0 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{344F3227-F502-4219-9DC4-1967E586FAFA}) (Version: 2.51.0.0 - Microsoft Corporation)
Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_CZ_is1) (Version: 19.1809.2.93 - ZONER software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4160050988-2886862043-3056562062-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {2598A0F0-C130-4746-BED7-A8FC3216B11D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {421056A3-0F58-4EC9-959A-7E4906BFDDDB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {45CDE8E8-A1C8-427F-A2A5-5C37B31ABEE9} - System32\Tasks\Microsoft\Windows\CUAssistant\CULauncher => C:\Program Files\CUAssistant\culauncher.exe (Microsoft Windows -> Microsoft Corporation)
Task: {6D707A78-07CE-41BB-A09C-6E2FD342423A} - System32\Tasks\DriverToolkit Autorun => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe (Megaify Software Co.,Ltd. -> Megaify Software Co., Ltd.)
Task: {86795C9A-98E6-47B5-945D-0BE00386882B} - System32\Tasks\Opera scheduled Autoupdate 1553205429 => C:\Users\lenha\AppData\Local\Programs\Opera\launcher.exe (Opera Software AS -> Opera Software)
Task: {AB6BF5AE-24EE-4AEA-90AA-545F01B13CAC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {F92D7268-79C9-4CD3-AFE8-24D442B5FD41} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1902.2-0\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2019-03-22 19:04 - 2019-03-22 19:04 - 000388608 _____ (Trend Micro Inc.) [File not signed] F:\Download\scoped_dir6624_8278\hijackthis.exe
2019-01-24 12:23 - 2019-01-24 12:23 - 062831616 _____ () [File not signed] C:\Program Files (x86)\eM Client\libcef.DLL
2019-01-24 12:21 - 2019-01-24 12:21 - 000840078 _____ (SQLite Development Team) [File not signed] C:\Program Files (x86)\eM Client\SQLite\x86\sqlite3.dll
2019-03-22 12:55 - 2016-10-17 18:29 - 003842048 _____ (Terra Informatica Software, Inc.) [File not signed] C:\Program Files\Zoner\Photo Studio 19\Program32\sciter32.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-07-10 12:04 - 2019-03-22 18:49 - 000004933 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0 a.ads1.msn.com
0.0.0.0 a.ads2.msads.net
0.0.0.0 a.ads2.msn.com
0.0.0.0 a.rad.msn.com
0.0.0.0 a-0001.a-msedge.net
0.0.0.0 a-0002.a-msedge.net
0.0.0.0 a-0003.a-msedge.net
0.0.0.0 a-0004.a-msedge.net
0.0.0.0 a-0005.a-msedge.net
0.0.0.0 a-0006.a-msedge.net
0.0.0.0 a-0007.a-msedge.net
0.0.0.0 a-0008.a-msedge.net
0.0.0.0 a-0009.a-msedge.net
0.0.0.0 ac3.msn.com
0.0.0.0 ad.doubleclick.net
0.0.0.0 adnexus.net
0.0.0.0 adnxs.com
0.0.0.0 ads.msn.com
0.0.0.0 ads1.msads.net
0.0.0.0 ads1.msn.com
0.0.0.0 aidps.atdmt.com
0.0.0.0 aka-cdn-ns.adtech.de
0.0.0.0 a-msedge.net
0.0.0.0 apps.skype.com
0.0.0.0 az361816.vo.msecnd.net
0.0.0.0 az512334.vo.msecnd.net
0.0.0.0 b.ads1.msn.com
0.0.0.0 b.ads2.msads.net
0.0.0.0 b.rad.msn.com
0.0.0.0 bs.serving-sys.com
There are 92 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4160050988-2886862043-3056562062-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\lenha\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img1.jpg
DNS Servers: 192.168.88.1 - 192.168.163.98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{C117DEBC-A484-4FD5-B2E3-E7EA4EDD1BE6}F:\download\scoped_dir12396_20861\winbox (1).exe] => (Allow) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [UDP Query User{009F01C7-C20A-43DB-B8AE-B94B648A10CE}F:\download\scoped_dir12396_20861\winbox (1).exe] => (Allow) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [{73A59820-8767-4A18-9DD0-7FF472214B98}] => (Block) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [{47B64908-AEDE-421D-8FFD-C3D71AEBD2F8}] => (Block) F:\download\scoped_dir12396_20861\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [TCP Query User{B272DA1F-918F-4E7B-81AE-EE1659ADC392}C:\users\lenha\onedrive\dokumenty\winbox.exe] => (Allow) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [UDP Query User{64571CDD-33AA-4858-9305-1DD9E38C19C2}C:\users\lenha\onedrive\dokumenty\winbox.exe] => (Allow) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [{AC2CDA9B-755D-4B05-B899-19787D927914}] => (Block) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [{CF0D121E-35E6-492B-BD4C-D43A15F7C367}] => (Block) C:\users\lenha\onedrive\dokumenty\winbox.exe () [File not signed]
FirewallRules: [TCP Query User{7C14C58A-94FE-4F09-AC9A-AC237F8D9D32}F:\download\winbox (1).exe] => (Allow) F:\download\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [UDP Query User{869B5B84-369C-498A-9F10-7694840CB9E6}F:\download\winbox (1).exe] => (Allow) F:\download\winbox (1).exe (Mikrotikls SIA -> )
FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe (Microsoft Windows Publisher -> Microsoft Corporation)
FirewallRules: [{2765E0F4-2918-4A46-B9C9-43CDD8FCBA2B}] => (Block) C:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E02AB908-0A91-41DB-8504-5C385CC561BF}] => (Block) C:\Windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
==================== Restore Points =========================
22-03-2019 15:37:25 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/22/2019 06:11:23 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Error: (03/22/2019 06:11:23 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C003
Error: (03/22/2019 06:11:20 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Error: (03/22/2019 06:11:20 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C003
Error: (03/22/2019 06:02:53 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0xC004C003
Argument příkazového řádku:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (03/22/2019 06:02:52 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
Error: (03/22/2019 06:02:52 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: Podrobnosti chyby získávání licence
hr=0xC004C003
Error: (03/22/2019 06:02:50 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: )
Description: Získání licence koncového uživatele se nezdařilo. hr=0xC004C003
ID SKU=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c
System errors:
=============
Error: (03/22/2019 06:54:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:54:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.SecurityAppBroker
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:54:06 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscCloudBackupProvider
a APPID
Není k dispozici
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:53:56 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:53:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:53:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 06:39:23 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Error: (03/22/2019 04:05:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HI8G2J4)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
a APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
uživateli DESKTOP-HI8G2J4\lenha (SID: S-1-5-21-4160050988-2886862043-3056562062-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Windows Defender:
===================================
Date: 2019-03-22 15:43:19.039
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner.BB!bit
ID: 2147716648
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_J:\Photo.scr
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.74.0, AS: 1.291.74.0, NIS: 1.291.74.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:43:15.956
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner!rfn
ID: 2147693577
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_J:\IMG001.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.74.0, AS: 1.291.74.0, NIS: 1.291.74.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:31:33.433
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner!rfn
ID: 2147693577
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_G:\IMG001.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.60.0, AS: 1.291.60.0, NIS: 1.291.60.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:31:20.491
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner.BB!bit
ID: 2147716648
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_G:\Photo.scr; file:_H:\Photo.scr
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.60.0, AS: 1.291.60.0, NIS: 1.291.60.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 15:31:17.437
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/CoinMiner!rfn
ID: 2147693577
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_G:\IMG001.exe
Původ zjišťování: Místní počítač
Typ zjišťování: Konkrétní
Zdroj zjišťování: Ochrana v reálném čase
Uživatel: DESKTOP-HI8G2J4\lenha
Název procesu: C:\totalcmd\TOTALCMD64.EXE
Verze podpisu: AV: 1.291.60.0, AS: 1.291.60.0, NIS: 1.291.60.0
Verze modulu: AM: 1.1.15800.1, NIS: 1.1.15800.1
Date: 2019-03-22 03:42:16.147
Description:
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o načtení podpisů a pokusí se o obnovení sady podpisů, jejichž správnost je potvrzena.
Podpisy, které se měly načíst: Aktuální
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu.
Verze podpisu: 0.0.0.0;0.0.0.0
Verze modulu: 0.0.0.0
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 17%
Total physical RAM: 16359.11 MB
Available physical RAM: 13534.66 MB
Total Virtual: 19303.11 MB
Available Virtual: 14806.18 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:223.03 GB) (Free:180.48 GB) NTFS
Drive d: (Data_D) (Fixed) (Total:237.75 GB) (Free:114.88 GB) NTFS
Drive e: () (Fixed) (Total:115.48 GB) (Free:35.59 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive f: (Data) (Fixed) (Total:117.19 GB) (Free:3.45 GB) NTFS
Drive g: (My Passport) (Fixed) (Total:3725.99 GB) (Free:3406.71 GB) NTFS
Drive h: (Video_data) (Fixed) (Total:115.69 GB) (Free:21.45 GB) NTFS
Drive i: (Data) (Fixed) (Total:227.62 GB) (Free:20.24 GB) NTFS
Drive j: (DATA) (Fixed) (Total:144.04 GB) (Free:28.26 GB) NTFS
Drive l: (MUSIK) (Fixed) (Total:931.51 GB) (Free:574.27 GB) NTFS
\\?\Volume{7a9df2d5-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{7a9df2d5-0000-0000-0000-60c837000000}\ () (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS
\\?\Volume{bf1ed8f5-0000-0000-007e-000000000000}\ (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:3.23 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: 7A9DF2D5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 1AB8D7AA)
Partition 1: (Active) - (Size=237.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=227.6 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 298.1 GB) (Disk ID: BF1ED8F5)
Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
Partition 2: (Active) - (Size=115.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=144 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=28.8 GB) - (Type=05)
========================================================
Disk: 3 (Size: 232.9 GB) (Disk ID: BCCCBCCC)
Partition 1: (Active) - (Size=117.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=115.7 GB) - (Type=0F Extended)
========================================================
Disk: 4 (Size: 3726 GB) (Disk ID: 16F2A91F)
Partition: GPT.
========================================================
Disk: 5 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: CE940487)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================