problémy se zvukem
Napsal: 31 bře 2019 18:58
Prosím o kontrolu logu borci. Když spustím jakékoliv video tak se mi zapne současně se zvukem i mikrofon a píská to jak... Jo a není třeba nějaký lepší ovladač zvuku než ten co tu mám??? A současně bych rád poprosil o celkovou kontrolu. Moc díky.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019
Ran by Royce (administrator) on ROLLS (31-03-2019 19:45:41)
Running from C:\Users\Royce\Desktop
Loaded Profiles: UpdatusUser & Royce (Available Profiles: UpdatusUser & Royce & DefaultAppPool)
Platform: Windows 10 Home Version 1511 10586.420 (X64) Language: Čeština (Česká republika)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxext.exe
(CyberLink Corp.) [File not signed] C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.424_none_767fbf7a263fc7d3\TiWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Temp\799986D3-B241-46A4-B814-16B438FABC19\DismHost.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Royce\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows10Upgrade\Windows10UpgraderApp.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\$GetCurrent\media\setup.exe
(Microsoft Windows -> Microsoft Corporation) C:\$GetCurrent\media\sources\setupprep.exe
(Microsoft Windows -> Microsoft Corporation) C:\$WINDOWS.~BT\Sources\SetupHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2012-09-13] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated -> Acer Incorporated)
HKLM-x32\...\Run: [EverioService] => C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe [151552 2008-04-03] (CyberLink Corp.) [File not signed]
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc. -> Dritek System Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\RunOnce: [!GetCurrentRollback] => C:\Windows10Upgrade\GetCurrentRollback.exe [73400 2018-02-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1109928582-2299394210-491478186-1000\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1109928582-2299394210-491478186-1000\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22488952 2019-03-11] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Uninstall 19.033.0218.0009\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\19.033.0218.0009\amd64"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Uninstall 19.033.0218.0009] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\19.033.0218.0009"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\MountPoints2: {79ef2bbe-3569-11e6-a93b-dc0ea11db256} - "E:\autorun.exe"
HKLM\...\Drivers32: [msacm.l3codecp] => C:\WINDOWS\SysWOW64\l3codecp.acm [193024 2015-10-30] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\Software\Microsoft\Active Setup\Installed Components: [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] -> %SystemRoot%\inf\unregmp2.exe /ShowWMP
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-21] (Google LLC -> Google Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [183144 2017-01-17] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [183144 2017-01-17] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [161016 2017-01-17] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{001a20c1-bd11-4513-ac70-d2c4bf450827}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{7056d5fb-7014-47bc-9702-64c4b4d20328}: [NameServer] 10.0.0.241,10.145.38.75
Tcpip\..\Interfaces\{7056d5fb-7014-47bc-9702-64c4b4d20328}: [DhcpNameServer] 192.168.1.20
Internet Explorer:
==================
HKU\S-1-5-21-1109928582-2299394210-491478186-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=B21A74DE2BB880B3&affID=119292&tt=080913_ctrl&tsp=5000
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
URLSearchHook: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B21A74DE2BB880B3&affID=119292&tt=080913_ctrl&tsp=5000
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2018-10-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-21] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKU\S-1-5-21-1109928582-2299394210-491478186-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-10-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-10-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-29] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-29] (Google Inc -> Google LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Royce\AppData\Local\Google\Chrome\User Data\Default [2019-03-31]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Royce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-06-01]
CHR Extension: (Chrome Media Router) - C:\Users\Royce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-22]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-08-02] (Acer Incorporated -> Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated -> Acer Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\WINDOWS\System32\drivers\athwnx.sys [4207104 2015-10-30] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.)
R3 b57xdbd; C:\WINDOWS\System32\drivers\b57xdbd.sys [67624 2011-01-21] (Broadcom Corporation -> Broadcom Corporation)
R3 b57xdmp; C:\WINDOWS\System32\drivers\b57xdmp.sys [19496 2011-01-21] (Broadcom Corporation -> Broadcom Corporation)
S3 bcmfn; C:\WINDOWS\System32\drivers\bcmfn.sys [9728 2015-10-30] (Microsoft Windows -> Windows (R) Win 7 DDK provider)
R3 bScsiMSa; C:\WINDOWS\System32\drivers\bScsiMSa.sys [51240 2011-05-16] (Broadcom Corporation -> Broadcom Corporation)
R3 bScsiSDa; C:\WINDOWS\System32\drivers\bScsiSDa.sys [86056 2011-05-06] (Broadcom Corporation -> Broadcom Corporation)
R3 igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [5382856 2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R3 IntcDAud; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [317440 2010-10-15] (Microsoft Windows Hardware Compatibility Publisher -> Intel(R) Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-31 19:45 - 2019-03-31 19:48 - 000023709 _____ C:\Users\Royce\Desktop\FRST.txt
2019-03-31 19:45 - 2019-03-31 19:45 - 000000000 ____D C:\FRST
2019-03-31 19:39 - 2019-03-31 19:39 - 002434048 _____ (Farbar) C:\Users\Royce\Desktop\FRST64.exe
2019-03-31 19:36 - 2019-03-31 19:36 - 006108480 _____ (Microsoft Corporation) C:\Users\Royce\Downloads\Windows10Upgrade28092 (1).exe
2019-03-31 19:06 - 2019-03-31 19:06 - 000000000 ___HD C:\$WINDOWS.~BT
2019-03-29 18:23 - 2019-03-29 18:28 - 609277568 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 díl 886 Taneční večer 4.4.2019.avi
2019-03-27 19:55 - 2019-03-27 19:55 - 001145114 _____ C:\Users\Royce\Downloads\N199298.pdf
2019-03-27 18:43 - 2019-03-27 18:47 - 548438502 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 díl 885, 2.4.2019 Horší už to nebude OD SOUČKA TOMÁŠE.avi
2019-03-23 20:10 - 2019-03-23 20:19 - 952609674 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 884.avi
2019-03-22 20:13 - 2019-03-22 20:28 - 2357496534 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 883 díl.mp4
2019-03-21 23:02 - 2019-03-21 23:07 - 555096924 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2-883-Otrávená rusalka--26.3.2019.avi
2019-03-21 22:38 - 2019-03-21 22:42 - 555096924 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2-883--Otrávená Rusalka---26.3.2019).avi
2019-03-21 07:47 - 2019-03-21 07:48 - 000000000 ____D C:\75f919e41dc3706ccd265aeafad0
2019-03-21 07:47 - 2019-03-21 07:47 - 000000000 ___HT C:\WINDOWS\wusa.lock
2019-03-21 02:35 - 2019-03-21 02:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-03-20 21:54 - 2019-03-20 21:54 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2019-03-20 21:50 - 2019-03-23 19:59 - 000000000 ____D C:\Program Files\CUAssistant
2019-03-20 21:16 - 2019-03-20 21:29 - 1949559806 _____ C:\Users\Royce\Downloads\Po čem muži touží CZ komedie 2018.mkv
2019-03-19 01:57 - 2019-03-22 07:50 - 000000000 ____D C:\WINDOWS\SysWOW64\NV
2019-03-19 01:57 - 2019-03-22 07:50 - 000000000 ____D C:\WINDOWS\system32\NV
2019-03-19 01:57 - 2019-03-19 01:57 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2019-03-19 01:57 - 2016-09-09 20:25 - 000269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-03-19 01:57 - 2016-09-09 20:25 - 000261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-03-19 01:57 - 2016-09-09 20:25 - 000110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-03-19 01:57 - 2016-09-09 20:24 - 000125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-03-19 01:56 - 2017-01-17 06:57 - 000222648 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-03-19 01:56 - 2017-01-17 06:57 - 000210360 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-03-19 01:56 - 2016-12-29 15:10 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-03-18 21:46 - 2019-03-18 21:47 - 021205512 _____ (Piriform Software Ltd) C:\Users\Royce\Downloads\ccsetup555.exe
2019-03-18 21:45 - 2019-03-18 21:45 - 006108480 _____ (Microsoft Corporation) C:\Users\Royce\Downloads\Windows10Upgrade28092.exe
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-31 19:43 - 2014-10-06 20:33 - 000000000 ____D C:\Users\Royce\AppData\Local\ElevatedDiagnostics
2019-03-31 19:30 - 2015-10-30 09:21 - 000000000 ____D C:\WINDOWS\INF
2019-03-31 19:06 - 2019-02-15 22:24 - 000000000 ____D C:\Windows10Upgrade
2019-03-31 19:06 - 2018-04-07 19:37 - 000000036 _____ C:\WINDOWS\progress.ini
2019-03-31 19:06 - 2016-03-23 18:15 - 000000000 ___DC C:\WINDOWS\Panther
2019-03-31 19:06 - 2016-03-23 17:34 - 000001890 _____ C:\WINDOWS\diagwrn.xml
2019-03-31 19:06 - 2016-03-23 17:34 - 000001890 _____ C:\WINDOWS\diagerr.xml
2019-03-31 19:06 - 2014-01-06 20:22 - 000000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2019-03-31 18:55 - 2018-04-07 18:44 - 000000000 ___HD C:\$GetCurrent
2019-03-31 18:42 - 2016-03-23 18:26 - 002039722 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-03-31 18:42 - 2015-10-30 20:31 - 000844980 _____ C:\WINDOWS\system32\perfh005.dat
2019-03-31 18:42 - 2015-10-30 20:31 - 000192958 _____ C:\WINDOWS\system32\perfc005.dat
2019-03-31 18:41 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-03-30 22:15 - 2019-02-15 22:24 - 000000815 _____ C:\Users\Royce\Desktop\Pomocník s aktualizací Windows 10.lnk
2019-03-30 22:15 - 2018-04-07 18:40 - 000000827 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pomocník s aktualizací Windows 10.lnk
2019-03-29 18:34 - 2013-10-20 23:01 - 000003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-03-29 18:34 - 2013-10-20 23:01 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-03-26 21:52 - 2018-03-25 22:19 - 000003358 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1109928582-2299394210-491478186-1001
2019-03-26 21:52 - 2016-03-30 14:09 - 000002373 _____ C:\Users\Royce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-03-26 21:52 - 2016-03-30 14:09 - 000000000 ___RD C:\Users\Royce\OneDrive
2019-03-24 21:17 - 2015-10-30 09:11 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-03-22 20:13 - 2015-10-30 09:24 - 000000000 ___HD C:\Program Files\WindowsApps
2019-03-22 08:24 - 2016-03-30 14:00 - 000000000 ____D C:\Users\Royce\AppData\Local\Packages
2019-03-22 07:52 - 2016-03-23 18:22 - 000000000 ____D C:\ProgramData\NVIDIA
2019-03-22 07:51 - 2016-03-23 19:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-03-22 07:51 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-03-22 07:51 - 2015-10-30 08:28 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2019-03-21 22:57 - 2013-12-10 18:10 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-03-21 22:35 - 2013-07-02 22:00 - 000000000 ____D C:\Users\Royce\AppData\Local\CrashDumps
2019-03-21 02:51 - 2014-10-06 21:12 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-03-21 02:50 - 2009-07-14 04:34 - 000000478 _____ C:\WINDOWS\win.ini
2019-03-20 21:51 - 2018-03-25 22:20 - 000000000 ____D C:\Program Files\rempl
2019-03-20 21:06 - 2016-03-23 18:27 - 000000000 ____D C:\Users\UpdatusUser
2019-03-20 21:04 - 2016-03-23 18:27 - 000000000 ____D C:\Users\Royce
2019-03-20 21:02 - 2019-01-19 09:39 - 000000000 ____D C:\Program Files\CCleaner
2019-03-19 01:56 - 2016-03-23 18:21 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-03-19 01:56 - 2016-03-23 18:21 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-03-18 21:52 - 2011-10-11 14:20 - 000000000 ____D C:\Program Files (x86)\Adobe
2019-03-18 21:51 - 2011-10-11 14:20 - 000000000 ____D C:\ProgramData\Adobe
2019-03-18 21:47 - 2019-01-19 09:39 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-03-18 21:47 - 2019-01-19 09:39 - 000000875 _____ C:\Users\Public\Desktop\CCleaner.lnk
==================== Files in the root of some directories =======
2013-07-31 19:34 - 2013-07-31 19:34 - 000170753 _____ () C:\Users\Royce\AppData\Local\9f2c10a0-f56c-464d-b90f-23109eb5be53
2013-07-24 21:12 - 2013-07-24 21:12 - 000003584 _____ () C:\Users\Royce\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
2019-03-20 21:19 - 2019-03-30 22:17 - 006612768 _____ (Microsoft Corporation) C:\Users\Royce\AppData\Local\Temp\Windows10Upgrade.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2019-03-20 22:49
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019
Ran by Royce (administrator) on ROLLS (31-03-2019 19:45:41)
Running from C:\Users\Royce\Desktop
Loaded Profiles: UpdatusUser & Royce (Available Profiles: UpdatusUser & Royce & DefaultAppPool)
Platform: Windows 10 Home Version 1511 10586.420 (X64) Language: Čeština (Česká republika)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxext.exe
(CyberLink Corp.) [File not signed] C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc. -> Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.424_none_767fbf7a263fc7d3\TiWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Temp\799986D3-B241-46A4-B814-16B438FABC19\DismHost.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Royce\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows10Upgrade\Windows10UpgraderApp.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\$GetCurrent\media\setup.exe
(Microsoft Windows -> Microsoft Corporation) C:\$GetCurrent\media\sources\setupprep.exe
(Microsoft Windows -> Microsoft Corporation) C:\$WINDOWS.~BT\Sources\SetupHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2012-09-13] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [799904 2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated -> Acer Incorporated)
HKLM-x32\...\Run: [EverioService] => C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe [151552 2008-04-03] (CyberLink Corp.) [File not signed]
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc. -> Dritek System Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\RunOnce: [!GetCurrentRollback] => C:\Windows10Upgrade\GetCurrentRollback.exe [73400 2018-02-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1109928582-2299394210-491478186-1000\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1109928582-2299394210-491478186-1000\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22488952 2019-03-11] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Uninstall 19.033.0218.0009\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\19.033.0218.0009\amd64"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\RunOnce: [Uninstall 19.033.0218.0009] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Royce\AppData\Local\Microsoft\OneDrive\19.033.0218.0009"
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\...\MountPoints2: {79ef2bbe-3569-11e6-a93b-dc0ea11db256} - "E:\autorun.exe"
HKLM\...\Drivers32: [msacm.l3codecp] => C:\WINDOWS\SysWOW64\l3codecp.acm [193024 2015-10-30] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\Software\Microsoft\Active Setup\Installed Components: [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] -> %SystemRoot%\inf\unregmp2.exe /ShowWMP
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-21] (Google LLC -> Google Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [183144 2017-01-17] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [183144 2017-01-17] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [161016 2017-01-17] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{001a20c1-bd11-4513-ac70-d2c4bf450827}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{7056d5fb-7014-47bc-9702-64c4b4d20328}: [NameServer] 10.0.0.241,10.145.38.75
Tcpip\..\Interfaces\{7056d5fb-7014-47bc-9702-64c4b4d20328}: [DhcpNameServer] 192.168.1.20
Internet Explorer:
==================
HKU\S-1-5-21-1109928582-2299394210-491478186-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=B21A74DE2BB880B3&affID=119292&tt=080913_ctrl&tsp=5000
HKU\S-1-5-21-1109928582-2299394210-491478186-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
URLSearchHook: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B21A74DE2BB880B3&affID=119292&tt=080913_ctrl&tsp=5000
SearchScopes: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2018-10-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-09-17] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-21] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKU\S-1-5-21-1109928582-2299394210-491478186-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1109928582-2299394210-491478186-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-10-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-10-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-29] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-29] (Google Inc -> Google LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Royce\AppData\Local\Google\Chrome\User Data\Default [2019-03-31]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Royce\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-06-01]
CHR Extension: (Chrome Media Router) - C:\Users\Royce\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-22]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-08-02] (Acer Incorporated -> Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated -> Acer Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\WINDOWS\System32\drivers\athwnx.sys [4207104 2015-10-30] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.)
R3 b57xdbd; C:\WINDOWS\System32\drivers\b57xdbd.sys [67624 2011-01-21] (Broadcom Corporation -> Broadcom Corporation)
R3 b57xdmp; C:\WINDOWS\System32\drivers\b57xdmp.sys [19496 2011-01-21] (Broadcom Corporation -> Broadcom Corporation)
S3 bcmfn; C:\WINDOWS\System32\drivers\bcmfn.sys [9728 2015-10-30] (Microsoft Windows -> Windows (R) Win 7 DDK provider)
R3 bScsiMSa; C:\WINDOWS\System32\drivers\bScsiMSa.sys [51240 2011-05-16] (Broadcom Corporation -> Broadcom Corporation)
R3 bScsiSDa; C:\WINDOWS\System32\drivers\bScsiSDa.sys [86056 2011-05-06] (Broadcom Corporation -> Broadcom Corporation)
R3 igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [5382856 2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R3 IntcDAud; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [317440 2010-10-15] (Microsoft Windows Hardware Compatibility Publisher -> Intel(R) Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Windows -> Microsoft Corporation)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-31 19:45 - 2019-03-31 19:48 - 000023709 _____ C:\Users\Royce\Desktop\FRST.txt
2019-03-31 19:45 - 2019-03-31 19:45 - 000000000 ____D C:\FRST
2019-03-31 19:39 - 2019-03-31 19:39 - 002434048 _____ (Farbar) C:\Users\Royce\Desktop\FRST64.exe
2019-03-31 19:36 - 2019-03-31 19:36 - 006108480 _____ (Microsoft Corporation) C:\Users\Royce\Downloads\Windows10Upgrade28092 (1).exe
2019-03-31 19:06 - 2019-03-31 19:06 - 000000000 ___HD C:\$WINDOWS.~BT
2019-03-29 18:23 - 2019-03-29 18:28 - 609277568 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 díl 886 Taneční večer 4.4.2019.avi
2019-03-27 19:55 - 2019-03-27 19:55 - 001145114 _____ C:\Users\Royce\Downloads\N199298.pdf
2019-03-27 18:43 - 2019-03-27 18:47 - 548438502 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 díl 885, 2.4.2019 Horší už to nebude OD SOUČKA TOMÁŠE.avi
2019-03-23 20:10 - 2019-03-23 20:19 - 952609674 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 884.avi
2019-03-22 20:13 - 2019-03-22 20:28 - 2357496534 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2 883 díl.mp4
2019-03-21 23:02 - 2019-03-21 23:07 - 555096924 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2-883-Otrávená rusalka--26.3.2019.avi
2019-03-21 22:38 - 2019-03-21 22:42 - 555096924 _____ C:\Users\Royce\Downloads\Ordinace v růžové zahradě 2-883--Otrávená Rusalka---26.3.2019).avi
2019-03-21 07:47 - 2019-03-21 07:48 - 000000000 ____D C:\75f919e41dc3706ccd265aeafad0
2019-03-21 07:47 - 2019-03-21 07:47 - 000000000 ___HT C:\WINDOWS\wusa.lock
2019-03-21 02:35 - 2019-03-21 02:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-03-20 21:54 - 2019-03-20 21:54 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2019-03-20 21:50 - 2019-03-23 19:59 - 000000000 ____D C:\Program Files\CUAssistant
2019-03-20 21:16 - 2019-03-20 21:29 - 1949559806 _____ C:\Users\Royce\Downloads\Po čem muži touží CZ komedie 2018.mkv
2019-03-19 01:57 - 2019-03-22 07:50 - 000000000 ____D C:\WINDOWS\SysWOW64\NV
2019-03-19 01:57 - 2019-03-22 07:50 - 000000000 ____D C:\WINDOWS\system32\NV
2019-03-19 01:57 - 2019-03-19 01:57 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2019-03-19 01:57 - 2016-09-09 20:25 - 000269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-03-19 01:57 - 2016-09-09 20:25 - 000261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-03-19 01:57 - 2016-09-09 20:25 - 000110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-03-19 01:57 - 2016-09-09 20:24 - 000125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-03-19 01:56 - 2017-01-17 06:57 - 000222648 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-03-19 01:56 - 2017-01-17 06:57 - 000210360 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-03-19 01:56 - 2016-12-29 15:10 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-03-18 21:46 - 2019-03-18 21:47 - 021205512 _____ (Piriform Software Ltd) C:\Users\Royce\Downloads\ccsetup555.exe
2019-03-18 21:45 - 2019-03-18 21:45 - 006108480 _____ (Microsoft Corporation) C:\Users\Royce\Downloads\Windows10Upgrade28092.exe
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-31 19:43 - 2014-10-06 20:33 - 000000000 ____D C:\Users\Royce\AppData\Local\ElevatedDiagnostics
2019-03-31 19:30 - 2015-10-30 09:21 - 000000000 ____D C:\WINDOWS\INF
2019-03-31 19:06 - 2019-02-15 22:24 - 000000000 ____D C:\Windows10Upgrade
2019-03-31 19:06 - 2018-04-07 19:37 - 000000036 _____ C:\WINDOWS\progress.ini
2019-03-31 19:06 - 2016-03-23 18:15 - 000000000 ___DC C:\WINDOWS\Panther
2019-03-31 19:06 - 2016-03-23 17:34 - 000001890 _____ C:\WINDOWS\diagwrn.xml
2019-03-31 19:06 - 2016-03-23 17:34 - 000001890 _____ C:\WINDOWS\diagerr.xml
2019-03-31 19:06 - 2014-01-06 20:22 - 000000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2019-03-31 18:55 - 2018-04-07 18:44 - 000000000 ___HD C:\$GetCurrent
2019-03-31 18:42 - 2016-03-23 18:26 - 002039722 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-03-31 18:42 - 2015-10-30 20:31 - 000844980 _____ C:\WINDOWS\system32\perfh005.dat
2019-03-31 18:42 - 2015-10-30 20:31 - 000192958 _____ C:\WINDOWS\system32\perfc005.dat
2019-03-31 18:41 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-03-30 22:15 - 2019-02-15 22:24 - 000000815 _____ C:\Users\Royce\Desktop\Pomocník s aktualizací Windows 10.lnk
2019-03-30 22:15 - 2018-04-07 18:40 - 000000827 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pomocník s aktualizací Windows 10.lnk
2019-03-29 18:34 - 2013-10-20 23:01 - 000003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-03-29 18:34 - 2013-10-20 23:01 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-03-26 21:52 - 2018-03-25 22:19 - 000003358 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1109928582-2299394210-491478186-1001
2019-03-26 21:52 - 2016-03-30 14:09 - 000002373 _____ C:\Users\Royce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-03-26 21:52 - 2016-03-30 14:09 - 000000000 ___RD C:\Users\Royce\OneDrive
2019-03-24 21:17 - 2015-10-30 09:11 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-03-22 20:13 - 2015-10-30 09:24 - 000000000 ___HD C:\Program Files\WindowsApps
2019-03-22 08:24 - 2016-03-30 14:00 - 000000000 ____D C:\Users\Royce\AppData\Local\Packages
2019-03-22 07:52 - 2016-03-23 18:22 - 000000000 ____D C:\ProgramData\NVIDIA
2019-03-22 07:51 - 2016-03-23 19:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-03-22 07:51 - 2015-10-30 09:24 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-03-22 07:51 - 2015-10-30 08:28 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2019-03-21 22:57 - 2013-12-10 18:10 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-03-21 22:35 - 2013-07-02 22:00 - 000000000 ____D C:\Users\Royce\AppData\Local\CrashDumps
2019-03-21 02:51 - 2014-10-06 21:12 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-03-21 02:50 - 2009-07-14 04:34 - 000000478 _____ C:\WINDOWS\win.ini
2019-03-20 21:51 - 2018-03-25 22:20 - 000000000 ____D C:\Program Files\rempl
2019-03-20 21:06 - 2016-03-23 18:27 - 000000000 ____D C:\Users\UpdatusUser
2019-03-20 21:04 - 2016-03-23 18:27 - 000000000 ____D C:\Users\Royce
2019-03-20 21:02 - 2019-01-19 09:39 - 000000000 ____D C:\Program Files\CCleaner
2019-03-19 01:56 - 2016-03-23 18:21 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-03-19 01:56 - 2016-03-23 18:21 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-03-18 21:52 - 2011-10-11 14:20 - 000000000 ____D C:\Program Files (x86)\Adobe
2019-03-18 21:51 - 2011-10-11 14:20 - 000000000 ____D C:\ProgramData\Adobe
2019-03-18 21:47 - 2019-01-19 09:39 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-03-18 21:47 - 2019-01-19 09:39 - 000000875 _____ C:\Users\Public\Desktop\CCleaner.lnk
==================== Files in the root of some directories =======
2013-07-31 19:34 - 2013-07-31 19:34 - 000170753 _____ () C:\Users\Royce\AppData\Local\9f2c10a0-f56c-464d-b90f-23109eb5be53
2013-07-24 21:12 - 2013-07-24 21:12 - 000003584 _____ () C:\Users\Royce\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
Some files in TEMP:
====================
2019-03-20 21:19 - 2019-03-30 22:17 - 006612768 _____ (Microsoft Corporation) C:\Users\Royce\AppData\Local\Temp\Windows10Upgrade.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2019-03-20 22:49
==================== End of FRST.txt ============================