Vyskakující záložky v prohlížeči
Napsal: 27 lis 2019 07:51
Zdravím, natahal jsem si do PC nějakou havěť, MSE je v jednom kole, tak bych to rád prošel důkladněji. Aktuálně se to projevuje vyskakujícími záložkami v prohlížeči na nějaké kasino. Datum nainstalované havěti by mělo být dnešní. Díky.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-11-2019 01
Ran by Tomáš (administrator) on TOMÁŠ-PC (Gigabyte Technology Co., Ltd. P67X-UD3-B3) (27-11-2019 07:50:32)
Running from C:\Users\Tomáš\Downloads
Loaded Profiles: Tomáš (Available Profiles: Tomáš)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Users\TOM~1\AppData\Local\Temp\7669842675.exe
() [File not signed] C:\Users\TOM~1\AppData\Local\Temp\is-420ED.tmp\axdciqkfxmj.tmp
(Access Denied) [File not signed] C:\Users\Tomáš\AppData\Roaming\gx2zgx0xfzd\axdciqkfxmj.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Canon Inc. -> CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Dashlane USA, Inc. -> Dashlane, Inc.) C:\Users\Tomáš\AppData\Roaming\Dashlane\Dashlane.exe
(Dashlane USA, Inc. -> Dashlane, Inc.) C:\Users\Tomáš\AppData\Roaming\Dashlane\DashlanePlugin.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (Canon Inc. -> CANON INC.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4926664 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
HKLM-x32\...\Run: [TeamsMachineUninstallerLocalAppData] => C:\Users\Tomáš\AppData\Local\Microsoft\Teams\Update.exe [1789552 2019-08-21] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-11-20] (Valve -> Valve Corporation)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36054928 2019-11-26] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Dashlane] => C:\Users\Tomáš\AppData\Roaming\Dashlane\Dashlane.exe [390144 2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [DashlanePlugin] => C:\Users\Tomáš\AppData\Roaming\Dashlane\DashlanePlugin.exe [412160 2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [735336 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-15] (Piriform Software Ltd -> Piriform Ltd)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Discord] => C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [83524968 2019-11-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [322807] => C:\Users\TOM~1\AppData\Local\Temp\is-H43MQ.tmp\MoocBook.exe [4761857 2019-11-26] (Access Denied) [File not signed] <==== ATTENTION
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [nvsetting] => C:\Users\TOM~1\AppData\Local\Temp\7669842675.exe [512512 2019-11-27] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [2915708] => C:\Users\Tomáš\AppData\Roaming\gx2zgx0xfzd\axdciqkfxmj.exe [4761857 2019-11-27] (Access Denied) [File not signed]
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Uninstall 19.174.0902.0013\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\19.174.0902.0013\amd64"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Uninstall 19.174.0902.0013] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\19.174.0902.0013"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\MountPoints2: {f73e253e-4e30-11e9-8377-50e54931da7d} - G:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.108\Installer\chrmstp.exe [2019-11-22] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0F9197D6-21AA-49AA-A0DE-53B7456857EF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [156200 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {13ABF6E7-D7F0-4FA1-A4C3-9217AE558242} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2378032 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {24FEC834-0BB2-41BC-8064-04EF7C4B9458} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {3D0180F4-3065-491C-8CB7-DE1858917E12} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6260640 2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {400B8522-8475-4C27-979D-492F80F2E78E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [638976 2019-11-27] (Access Denied) [File not signed] (Access Denied) <==== ATTENTION
Task: {4318C57C-86FC-4545-8E83-AD934544C129} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [10219208 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {6DC58EB2-3274-4C7C-B3EA-B9A2EB438087} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-15] (Piriform Software Ltd -> Piriform Ltd)
Task: {73F42CEE-CA6A-462E-A705-0FCB8798DA3A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2170168 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {969514B3-F225-4A74-B54A-4D2A8242C5C7} - System32\Tasks\{F678378B-5BB6-400E-98C0-B8B4EF152F07} => C:\Windows\system32\pcalua.exe -a "C:\Games\Knights Of Honor\KoH.exe" -d "C:\Games\Knights Of Honor\"
Task: {A2797CDF-107F-47A9-AB0B-B1B48266B2DD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2019-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {B3C9EC78-EE82-4185-8814-9551B4397181} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2019-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {C43A0102-D2B6-417F-83C7-ACEFD376DFC8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6260640 2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {C50460AF-6697-4BB3-A81D-DDF177CAA6D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [638976 2019-11-27] (Access Denied) [File not signed] (Access Denied) <==== ATTENTION
Task: {CFE6938E-F1EA-43C3-833E-C6D0DF00B7F8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-15] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E509DD7F-44DE-4209-9A4D-12BDC8C44872} - System32\Tasks\mwTLuksuBTRA => C:\Windows\system32\rundll32.exe "C:\Program Files (x86)\mwTLuksuBTRA\mwTLuksuBTRA.dll",mwTLuksuBTRA <==== ATTENTION
Task: {F3F3C121-C553-4631-9CA1-4F72C66E6B6C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2170168 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {F57FC5BE-9B94-49AF-AD23-3C5CF649FA1D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [156200 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{D75AC7FC-F1C4-42CB-83C8-71F09D42EDAC}: [DhcpNameServer] 213.46.172.37 213.46.172.36
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-1564068326-3056932736-4007049450-1000 -> {1C97CE63-7012-4159-B919-799BEECCCA7C} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV
SearchScopes: HKU\S-1-5-21-1564068326-3056932736-4007049450-1000 -> {596ED836-A012-4eef-B071-52CA4946BE13} URL = hxxp://www.google.com/custom?client=pub-379428 ... earchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2019-07-02] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-04-07] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Dashlane BHO -> {42D79B50-CC4A-4A8E-860F-BE674AF053A2} -> C:\Users\Tomáš\AppData\Roaming\Dashlane\ie\Dashlanei.dll [2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\URLREDIR.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Tomáš\AppData\Roaming\Dashlane\ie\KWIEBar.dll [2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: rmexdf8j.default
FF ProfilePath: C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\rmexdf8j.default [2019-09-14]
FF ProfilePath: C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\bme2j14t.default-release-1573616899805 [2019-11-27]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-07-02] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 -> C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-06-08] (Unity Technologies ApS -> Unity Technologies ApS)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-04-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-04] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-04] (Google Inc -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-11] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR Notifications: Default -> hxxps://agar.io; hxxps://aukro.cz; hxxps://secrethitler.io
CHR Profile: C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default [2019-11-27]
CHR Extension: (Prezentace) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-06-13]
CHR Extension: (Dokumenty) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-06-13]
CHR Extension: (Disk Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-06-13]
CHR Extension: (YouTube) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-06-13]
CHR Extension: (Adobe Acrobat) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-09-26]
CHR Extension: (Dashlane - Password Manager) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2019-11-05]
CHR Extension: (Tabulky) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-06-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-11-06]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [249344 2016-02-26] (Advanced Micro Devices, Inc. -> AMD)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] (Giga-Byte Technology -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11652168 2019-11-21] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4132456 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2348336 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3228464 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [23981568 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [674816 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] (Giga-Byte Technology -> )
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [104976 2016-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S1 dpwqhbpx; C:\Windows\system32\drivers\dpwqhbpx.sys [72816 2019-11-27] (Microsoft Corporation -> Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [42256 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [59360 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [40832 2011-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [65280 2011-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
S1 yvnokupc; C:\Windows\system32\drivers\yvnokupc.sys [72816 2019-11-27] (Microsoft Corporation -> Microsoft Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-07 09:35 - 2019-12-07 09:35 - 000000000 ____D C:\Users\Tomáš\AppData\Local\SKIDROW
2019-12-07 09:35 - 2019-11-26 13:30 - 000000000 ____D C:\Users\Public\Documents\Jagged Alliance - Back in Action
2019-12-07 09:35 - 2019-11-26 13:30 - 000000000 ____D C:\ProgramData\Documents\Jagged Alliance - Back in Action
2019-11-27 07:51 - 2019-11-27 07:51 - 000072816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\yvnokupc.sys
2019-11-27 07:51 - 2019-11-27 07:51 - 000072816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dpwqhbpx.sys
2019-11-27 07:50 - 2019-11-27 07:51 - 000028112 _____ C:\Users\Tomáš\Downloads\FRST.txt
2019-11-27 07:49 - 2019-11-27 07:51 - 000000000 ____D C:\FRST
2019-11-27 07:49 - 2019-11-27 07:49 - 002262016 _____ (Farbar) C:\Users\Tomáš\Downloads\FRST64.exe
2019-11-27 07:40 - 2019-11-27 07:40 - 000016724 _____ C:\Windows\system32\Tasks\mwTLuksuBTRA
2019-11-27 07:40 - 2019-11-27 07:40 - 000000270 __RSH C:\ProgramData\ntuser.pol
2019-11-27 07:40 - 2019-11-27 07:40 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\ScreenToGif
2019-11-27 07:40 - 2019-11-27 07:40 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\InstallPack
2019-11-27 07:40 - 2019-11-27 07:40 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\gx2zgx0xfzd
2019-11-27 07:40 - 2018-11-13 06:35 - 000000000 ____D C:\Program Files (x86)\mwTLuksuBTRA
2019-11-27 07:39 - 2019-11-27 07:40 - 000000000 ____D C:\Program Files (x86)\eCertification
2019-11-27 07:39 - 2019-11-27 07:39 - 000000000 ____D C:\Program Files (x86)\MachinerData
2019-11-27 06:23 - 2019-11-27 07:03 - 736252301 _____ C:\Users\Tomáš\Downloads\Jagged Alliance - Back in Action CZ.zip.002
2019-11-27 05:23 - 2019-11-27 06:20 - 1047527424 _____ C:\Users\Tomáš\Downloads\Jagged Alliance - Back in Action CZ.zip.001
2019-11-26 09:07 - 2019-11-26 09:08 - 074157419 _____ C:\Users\Tomáš\Desktop\Mutant Chronicles - The Brotherhood Sourcebook.pdf
2019-11-23 07:44 - 2019-11-23 07:44 - 000000742 _____ C:\Users\Tomáš\Desktop\Thief Simulator.lnk
2019-11-23 07:44 - 2019-11-23 07:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thief Simulator
2019-11-23 06:20 - 2019-11-23 07:28 - 1254372703 _____ (Tomi2k9 ) C:\Users\Tomáš\Downloads\Jagged Alliance - Back in Action.exe
2019-11-23 06:16 - 2019-11-23 07:02 - 3421037191 _____ C:\Users\Tomáš\Downloads\codex-thief.simulator.v1.2.rar
2019-11-23 05:52 - 2019-11-23 06:01 - 1173821319 _____ C:\Users\Tomáš\Downloads\Thief.Simulator.Update.v1.2.6-CODEX.rar
2019-11-23 05:07 - 2019-11-23 05:14 - 1056210622 _____ C:\Users\Tomáš\Downloads\Thief.Simulator.Update.v1.3-CODEX.rar
2019-11-22 19:53 - 2019-11-22 19:53 - 000000261 _____ C:\Users\Tomáš\Desktop\Subnautica.url
2019-11-22 08:39 - 2019-11-22 08:39 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Plausible Concept
2019-11-19 21:12 - 2019-11-19 21:12 - 000000000 ____D C:\Users\Tomáš\AppData\Local\DOSBox
2019-11-19 21:11 - 2019-11-19 21:11 - 001493703 _____ (DOSBox Team) C:\Users\Tomáš\Downloads\DOSBox0.74-3-win32-installer.exe
2019-11-19 21:11 - 2019-11-19 21:11 - 000001615 _____ C:\Users\Public\Desktop\DOSBox 0.74-3.lnk
2019-11-19 21:11 - 2019-11-19 21:11 - 000001615 _____ C:\ProgramData\Desktop\DOSBox 0.74-3.lnk
2019-11-19 21:11 - 2019-11-19 21:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.74-3
2019-11-18 22:07 - 2019-11-18 22:07 - 000412538 _____ C:\Users\Tomáš\Desktop\Fišer se přiznává.dib
2019-11-13 22:33 - 2019-11-13 22:33 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Noble Muffins
2019-11-13 04:48 - 2019-11-13 04:57 - 000000000 ____D C:\Program Files\Unity
2019-11-13 04:47 - 2019-11-15 03:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-11-13 04:47 - 2019-11-13 04:48 - 000000000 ____D C:\Users\Tomáš\Desktop\Původní data aplikace Firefox
2019-11-13 04:46 - 2019-11-13 04:53 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Unity
2019-11-13 04:46 - 2019-11-13 04:53 - 000000000 ____D C:\Users\Tomáš\AppData\Local\Unity
2019-11-06 16:49 - 2019-11-06 16:49 - 000638938 _____ C:\Users\Tomáš\Downloads\omluva z jednání 2.pages
2019-11-05 21:33 - 2019-11-05 21:33 - 000305304 _____ C:\Windows\Minidump\110519-8595-01.dmp
2019-11-05 12:40 - 2019-11-05 12:40 - 000305240 _____ C:\Windows\Minidump\110519-8767-01.dmp
2019-11-04 19:46 - 2019-11-06 13:22 - 000344030 _____ C:\Users\Tomáš\Desktop\Švec přihláška pohledávky.pdf
2019-11-04 19:46 - 2019-11-04 19:46 - 000129816 _____ C:\Users\Tomáš\Desktop\Švec příloha příkaz exe.pdf
2019-11-04 19:45 - 2019-11-04 19:45 - 000520256 _____ C:\Users\Tomáš\Desktop\Švec příloha rozsudek.pdf
2019-11-04 18:53 - 2019-11-04 19:45 - 000342819 _____ C:\Users\Tomáš\Desktop\Prihlaska_pohledavky Švec.pdf
2019-11-04 15:00 - 2019-11-04 15:00 - 000120086 _____ C:\Users\Tomáš\Downloads\mandatni-smlouva-pdf.pdf
2019-11-04 14:28 - 2019-11-04 14:28 - 000204001 _____ C:\Users\Tomáš\Downloads\Prihlaska_pohledavky_pokyny.pdf
2019-11-04 12:46 - 2019-11-04 12:46 - 000327464 _____ C:\Users\Tomáš\Downloads\Prihlaska_pohledavky.pdf
2019-11-04 12:46 - 2019-11-04 12:46 - 000327464 _____ C:\Users\Tomáš\Downloads\Prihlaska_pohledavky (1).pdf
2019-11-02 18:59 - 2019-11-02 18:59 - 000129015 _____ C:\Users\Tomáš\Downloads\obhajoba-pred-soudem-i--stupne-vcetne-dokazovani---judr--tomas-durdik.pptx
2019-10-29 15:46 - 2019-10-29 15:47 - 000000000 ____D C:\Users\Tomáš\Desktop\7 Cm 133 2016 (cee direct)
2019-10-29 15:46 - 2019-10-29 15:46 - 000000000 ____D C:\Users\Tomáš\Desktop\7 Cm 178 2014 (Koutný I)
2019-10-29 15:45 - 2019-10-29 15:45 - 000000000 ____D C:\Users\Tomáš\Desktop\53 Cm 211 2017 (Felcmanová)
2019-10-29 15:39 - 2019-10-29 17:16 - 000000000 ____D C:\Users\Tomáš\Desktop\7 Cm 17 2017 (Koutný II)
2019-10-29 14:24 - 2019-10-29 14:24 - 000447217 _____ C:\Users\Tomáš\Downloads\DPTX_2010_1__0_39118_0_79690.pdf
2019-10-29 09:46 - 2019-10-29 09:46 - 000304976 _____ C:\Windows\Minidump\102919-9594-01.dmp
2019-10-29 09:40 - 2019-10-29 09:40 - 000305304 _____ C:\Windows\Minidump\102919-9094-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-07 09:03 - 2018-10-08 19:48 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-12-07 09:03 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2019-12-07 09:02 - 2018-10-08 19:45 - 000000000 ____D C:\Program Files\Microsoft Office
2019-11-27 07:40 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-11-27 07:22 - 2018-07-02 12:20 - 000000000 ____D C:\Games
2019-11-27 03:51 - 2019-05-04 10:21 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\Doomtrooper
2019-11-27 03:48 - 2009-07-14 05:45 - 000015344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-11-27 03:48 - 2009-07-14 05:45 - 000015344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-11-26 09:36 - 2019-03-17 03:08 - 000005335 _____ C:\Users\Tomáš\Desktop\MCh-krystalové nebe.txt
2019-11-26 04:55 - 2018-10-09 17:26 - 000003174 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1564068326-3056932736-4007049450-1000
2019-11-26 04:55 - 2018-10-08 19:50 - 000002120 _____ C:\Users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2019-11-26 04:55 - 2018-10-08 19:50 - 000000000 ___RD C:\Users\Tomáš\OneDrive
2019-11-24 08:43 - 2019-10-25 17:59 - 000002337 _____ C:\Users\Tomáš\Desktop\Doomtrooper.lnk
2019-11-23 10:34 - 2009-07-14 16:18 - 000668542 _____ C:\Windows\system32\perfh005.dat
2019-11-23 10:34 - 2009-07-14 16:18 - 000141202 _____ C:\Windows\system32\perfc005.dat
2019-11-23 10:34 - 2009-07-14 06:13 - 001583226 _____ C:\Windows\system32\PerfStringBackup.INI
2019-11-23 10:34 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2019-11-23 10:29 - 2019-05-27 18:50 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\Discord
2019-11-23 10:29 - 2018-07-25 21:07 - 000000000 ____D C:\Users\Tomáš\AppData\Local\LogMeIn Hamachi
2019-11-23 10:29 - 2018-06-13 12:17 - 000000000 ____D C:\Program Files (x86)\Steam
2019-11-23 10:28 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-11-22 19:40 - 2018-12-18 15:27 - 000000000 ____D C:\Program Files\Epic Games
2019-11-22 08:32 - 2018-06-13 11:54 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-11-22 08:22 - 2019-02-01 20:38 - 000001879 _____ C:\Users\Tomáš\Desktop\Dashlane.lnk
2019-11-22 08:22 - 2019-02-01 20:37 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\Dashlane
2019-11-21 05:00 - 2019-09-23 08:56 - 000000000 ____D C:\Users\Tomáš\Desktop\42 C 328 2019 (Bočková)
2019-11-15 03:44 - 2018-06-15 05:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-11-13 21:56 - 2019-02-20 03:06 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\DAEMON Tools Lite
2019-11-13 20:25 - 2018-10-08 20:46 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-11-13 04:54 - 2019-09-14 17:51 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Mozilla
2019-11-13 04:52 - 2018-06-13 11:53 - 000000000 ____D C:\Users\Tomáš\AppData\Local\Deployment
2019-11-12 22:03 - 2018-06-13 13:51 - 000748816 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2019-11-05 21:33 - 2019-10-27 11:06 - 670099608 _____ C:\Windows\MEMORY.DMP
2019-11-05 21:33 - 2019-03-24 13:33 - 000000000 ____D C:\Windows\Minidump
2019-11-04 23:56 - 2018-06-13 11:53 - 000000000 ____D C:\Program Files (x86)\Google
2019-11-03 19:29 - 2018-07-18 06:26 - 000000000 ____D C:\ProgramData\Package Cache
2019-11-01 22:55 - 2019-08-01 07:56 - 000000000 ____D C:\Users\Tomáš\Desktop\Nguyen
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-11-19 04:44
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-11-2019 01
Ran by Tomáš (administrator) on TOMÁŠ-PC (Gigabyte Technology Co., Ltd. P67X-UD3-B3) (27-11-2019 07:50:32)
Running from C:\Users\Tomáš\Downloads
Loaded Profiles: Tomáš (Available Profiles: Tomáš)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Users\TOM~1\AppData\Local\Temp\7669842675.exe
() [File not signed] C:\Users\TOM~1\AppData\Local\Temp\is-420ED.tmp\axdciqkfxmj.tmp
(Access Denied) [File not signed] C:\Users\Tomáš\AppData\Roaming\gx2zgx0xfzd\axdciqkfxmj.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Canon Inc. -> CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Dashlane USA, Inc. -> Dashlane, Inc.) C:\Users\Tomáš\AppData\Roaming\Dashlane\Dashlane.exe
(Dashlane USA, Inc. -> Dashlane, Inc.) C:\Users\Tomáš\AppData\Roaming\Dashlane\DashlanePlugin.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Discord Inc. -> Discord Inc.) C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (Canon Inc. -> CANON INC.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4926664 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
HKLM-x32\...\Run: [TeamsMachineUninstallerLocalAppData] => C:\Users\Tomáš\AppData\Local\Microsoft\Teams\Update.exe [1789552 2019-08-21] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3288016 2019-11-20] (Valve -> Valve Corporation)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36054928 2019-11-26] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Dashlane] => C:\Users\Tomáš\AppData\Roaming\Dashlane\Dashlane.exe [390144 2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [DashlanePlugin] => C:\Users\Tomáš\AppData\Roaming\Dashlane\DashlanePlugin.exe [412160 2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [735336 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-15] (Piriform Software Ltd -> Piriform Ltd)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Discord] => C:\Users\Tomáš\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [83524968 2019-11-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [322807] => C:\Users\TOM~1\AppData\Local\Temp\is-H43MQ.tmp\MoocBook.exe [4761857 2019-11-26] (Access Denied) [File not signed] <==== ATTENTION
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [nvsetting] => C:\Users\TOM~1\AppData\Local\Temp\7669842675.exe [512512 2019-11-27] () [File not signed] <==== ATTENTION
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\Run: [2915708] => C:\Users\Tomáš\AppData\Roaming\gx2zgx0xfzd\axdciqkfxmj.exe [4761857 2019-11-27] (Access Denied) [File not signed]
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Uninstall 19.174.0902.0013\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\19.174.0902.0013\amd64"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\RunOnce: [Uninstall 19.174.0902.0013] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Tomáš\AppData\Local\Microsoft\OneDrive\19.174.0902.0013"
HKU\S-1-5-21-1564068326-3056932736-4007049450-1000\...\MountPoints2: {f73e253e-4e30-11e9-8377-50e54931da7d} - G:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.108\Installer\chrmstp.exe [2019-11-22] (Google LLC -> Google LLC)
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0F9197D6-21AA-49AA-A0DE-53B7456857EF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [156200 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {13ABF6E7-D7F0-4FA1-A4C3-9217AE558242} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2378032 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {24FEC834-0BB2-41BC-8064-04EF7C4B9458} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {3D0180F4-3065-491C-8CB7-DE1858917E12} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6260640 2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {400B8522-8475-4C27-979D-492F80F2E78E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [638976 2019-11-27] (Access Denied) [File not signed] (Access Denied) <==== ATTENTION
Task: {4318C57C-86FC-4545-8E83-AD934544C129} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [10219208 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {6DC58EB2-3274-4C7C-B3EA-B9A2EB438087} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-15] (Piriform Software Ltd -> Piriform Ltd)
Task: {73F42CEE-CA6A-462E-A705-0FCB8798DA3A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2170168 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {969514B3-F225-4A74-B54A-4D2A8242C5C7} - System32\Tasks\{F678378B-5BB6-400E-98C0-B8B4EF152F07} => C:\Windows\system32\pcalua.exe -a "C:\Games\Knights Of Honor\KoH.exe" -d "C:\Games\Knights Of Honor\"
Task: {A2797CDF-107F-47A9-AB0B-B1B48266B2DD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2019-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {B3C9EC78-EE82-4185-8814-9551B4397181} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27366472 2019-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {C43A0102-D2B6-417F-83C7-ACEFD376DFC8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6260640 2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {C50460AF-6697-4BB3-A81D-DDF177CAA6D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [638976 2019-11-27] (Access Denied) [File not signed] (Access Denied) <==== ATTENTION
Task: {CFE6938E-F1EA-43C3-833E-C6D0DF00B7F8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-15] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E509DD7F-44DE-4209-9A4D-12BDC8C44872} - System32\Tasks\mwTLuksuBTRA => C:\Windows\system32\rundll32.exe "C:\Program Files (x86)\mwTLuksuBTRA\mwTLuksuBTRA.dll",mwTLuksuBTRA <==== ATTENTION
Task: {F3F3C121-C553-4631-9CA1-4F72C66E6B6C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2170168 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {F57FC5BE-9B94-49AF-AD23-3C5CF649FA1D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [156200 2019-12-07] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{D75AC7FC-F1C4-42CB-83C8-71F09D42EDAC}: [DhcpNameServer] 213.46.172.37 213.46.172.36
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-1564068326-3056932736-4007049450-1000 -> {1C97CE63-7012-4159-B919-799BEECCCA7C} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV
SearchScopes: HKU\S-1-5-21-1564068326-3056932736-4007049450-1000 -> {596ED836-A012-4eef-B071-52CA4946BE13} URL = hxxp://www.google.com/custom?client=pub-379428 ... earchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2019-07-02] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-04-07] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Dashlane BHO -> {42D79B50-CC4A-4A8E-860F-BE674AF053A2} -> C:\Users\Tomáš\AppData\Roaming\Dashlane\ie\Dashlanei.dll [2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\URLREDIR.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Tomáš\AppData\Roaming\Dashlane\ie\KWIEBar.dll [2019-11-12] (Dashlane USA, Inc. -> Dashlane, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-11-04] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: rmexdf8j.default
FF ProfilePath: C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\rmexdf8j.default [2019-09-14]
FF ProfilePath: C:\Users\Tomáš\AppData\Roaming\Mozilla\Firefox\Profiles\bme2j14t.default-release-1573616899805 [2019-11-27]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-07-02] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @unity3d.com/UnityPlayer64,version=1.0 -> C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll [2015-06-08] (Unity Technologies ApS -> Unity Technologies ApS)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-20] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-04-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-04] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-04] (Google Inc -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-11] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR Notifications: Default -> hxxps://agar.io; hxxps://aukro.cz; hxxps://secrethitler.io
CHR Profile: C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default [2019-11-27]
CHR Extension: (Prezentace) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-06-13]
CHR Extension: (Dokumenty) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-06-13]
CHR Extension: (Disk Google) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-06-13]
CHR Extension: (YouTube) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-06-13]
CHR Extension: (Adobe Acrobat) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-09-26]
CHR Extension: (Dashlane - Password Manager) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2019-11-05]
CHR Extension: (Tabulky) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-06-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-11-06]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [249344 2016-02-26] (Advanced Micro Devices, Inc. -> AMD)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] (Giga-Byte Technology -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11652168 2019-11-21] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4132456 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2348336 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3228464 2019-09-25] (Electronic Arts, Inc. -> Electronic Arts)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [23981568 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [674816 2016-02-26] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] (Giga-Byte Technology -> )
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [104976 2016-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S1 dpwqhbpx; C:\Windows\system32\drivers\dpwqhbpx.sys [72816 2019-11-27] (Microsoft Corporation -> Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [42256 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [59360 2019-02-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [40832 2011-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [65280 2011-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
S1 yvnokupc; C:\Windows\system32\drivers\yvnokupc.sys [72816 2019-11-27] (Microsoft Corporation -> Microsoft Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-07 09:35 - 2019-12-07 09:35 - 000000000 ____D C:\Users\Tomáš\AppData\Local\SKIDROW
2019-12-07 09:35 - 2019-11-26 13:30 - 000000000 ____D C:\Users\Public\Documents\Jagged Alliance - Back in Action
2019-12-07 09:35 - 2019-11-26 13:30 - 000000000 ____D C:\ProgramData\Documents\Jagged Alliance - Back in Action
2019-11-27 07:51 - 2019-11-27 07:51 - 000072816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\yvnokupc.sys
2019-11-27 07:51 - 2019-11-27 07:51 - 000072816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dpwqhbpx.sys
2019-11-27 07:50 - 2019-11-27 07:51 - 000028112 _____ C:\Users\Tomáš\Downloads\FRST.txt
2019-11-27 07:49 - 2019-11-27 07:51 - 000000000 ____D C:\FRST
2019-11-27 07:49 - 2019-11-27 07:49 - 002262016 _____ (Farbar) C:\Users\Tomáš\Downloads\FRST64.exe
2019-11-27 07:40 - 2019-11-27 07:40 - 000016724 _____ C:\Windows\system32\Tasks\mwTLuksuBTRA
2019-11-27 07:40 - 2019-11-27 07:40 - 000000270 __RSH C:\ProgramData\ntuser.pol
2019-11-27 07:40 - 2019-11-27 07:40 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\ScreenToGif
2019-11-27 07:40 - 2019-11-27 07:40 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\InstallPack
2019-11-27 07:40 - 2019-11-27 07:40 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\gx2zgx0xfzd
2019-11-27 07:40 - 2018-11-13 06:35 - 000000000 ____D C:\Program Files (x86)\mwTLuksuBTRA
2019-11-27 07:39 - 2019-11-27 07:40 - 000000000 ____D C:\Program Files (x86)\eCertification
2019-11-27 07:39 - 2019-11-27 07:39 - 000000000 ____D C:\Program Files (x86)\MachinerData
2019-11-27 06:23 - 2019-11-27 07:03 - 736252301 _____ C:\Users\Tomáš\Downloads\Jagged Alliance - Back in Action CZ.zip.002
2019-11-27 05:23 - 2019-11-27 06:20 - 1047527424 _____ C:\Users\Tomáš\Downloads\Jagged Alliance - Back in Action CZ.zip.001
2019-11-26 09:07 - 2019-11-26 09:08 - 074157419 _____ C:\Users\Tomáš\Desktop\Mutant Chronicles - The Brotherhood Sourcebook.pdf
2019-11-23 07:44 - 2019-11-23 07:44 - 000000742 _____ C:\Users\Tomáš\Desktop\Thief Simulator.lnk
2019-11-23 07:44 - 2019-11-23 07:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thief Simulator
2019-11-23 06:20 - 2019-11-23 07:28 - 1254372703 _____ (Tomi2k9 ) C:\Users\Tomáš\Downloads\Jagged Alliance - Back in Action.exe
2019-11-23 06:16 - 2019-11-23 07:02 - 3421037191 _____ C:\Users\Tomáš\Downloads\codex-thief.simulator.v1.2.rar
2019-11-23 05:52 - 2019-11-23 06:01 - 1173821319 _____ C:\Users\Tomáš\Downloads\Thief.Simulator.Update.v1.2.6-CODEX.rar
2019-11-23 05:07 - 2019-11-23 05:14 - 1056210622 _____ C:\Users\Tomáš\Downloads\Thief.Simulator.Update.v1.3-CODEX.rar
2019-11-22 19:53 - 2019-11-22 19:53 - 000000261 _____ C:\Users\Tomáš\Desktop\Subnautica.url
2019-11-22 08:39 - 2019-11-22 08:39 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Plausible Concept
2019-11-19 21:12 - 2019-11-19 21:12 - 000000000 ____D C:\Users\Tomáš\AppData\Local\DOSBox
2019-11-19 21:11 - 2019-11-19 21:11 - 001493703 _____ (DOSBox Team) C:\Users\Tomáš\Downloads\DOSBox0.74-3-win32-installer.exe
2019-11-19 21:11 - 2019-11-19 21:11 - 000001615 _____ C:\Users\Public\Desktop\DOSBox 0.74-3.lnk
2019-11-19 21:11 - 2019-11-19 21:11 - 000001615 _____ C:\ProgramData\Desktop\DOSBox 0.74-3.lnk
2019-11-19 21:11 - 2019-11-19 21:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.74-3
2019-11-18 22:07 - 2019-11-18 22:07 - 000412538 _____ C:\Users\Tomáš\Desktop\Fišer se přiznává.dib
2019-11-13 22:33 - 2019-11-13 22:33 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Noble Muffins
2019-11-13 04:48 - 2019-11-13 04:57 - 000000000 ____D C:\Program Files\Unity
2019-11-13 04:47 - 2019-11-15 03:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-11-13 04:47 - 2019-11-13 04:48 - 000000000 ____D C:\Users\Tomáš\Desktop\Původní data aplikace Firefox
2019-11-13 04:46 - 2019-11-13 04:53 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Unity
2019-11-13 04:46 - 2019-11-13 04:53 - 000000000 ____D C:\Users\Tomáš\AppData\Local\Unity
2019-11-06 16:49 - 2019-11-06 16:49 - 000638938 _____ C:\Users\Tomáš\Downloads\omluva z jednání 2.pages
2019-11-05 21:33 - 2019-11-05 21:33 - 000305304 _____ C:\Windows\Minidump\110519-8595-01.dmp
2019-11-05 12:40 - 2019-11-05 12:40 - 000305240 _____ C:\Windows\Minidump\110519-8767-01.dmp
2019-11-04 19:46 - 2019-11-06 13:22 - 000344030 _____ C:\Users\Tomáš\Desktop\Švec přihláška pohledávky.pdf
2019-11-04 19:46 - 2019-11-04 19:46 - 000129816 _____ C:\Users\Tomáš\Desktop\Švec příloha příkaz exe.pdf
2019-11-04 19:45 - 2019-11-04 19:45 - 000520256 _____ C:\Users\Tomáš\Desktop\Švec příloha rozsudek.pdf
2019-11-04 18:53 - 2019-11-04 19:45 - 000342819 _____ C:\Users\Tomáš\Desktop\Prihlaska_pohledavky Švec.pdf
2019-11-04 15:00 - 2019-11-04 15:00 - 000120086 _____ C:\Users\Tomáš\Downloads\mandatni-smlouva-pdf.pdf
2019-11-04 14:28 - 2019-11-04 14:28 - 000204001 _____ C:\Users\Tomáš\Downloads\Prihlaska_pohledavky_pokyny.pdf
2019-11-04 12:46 - 2019-11-04 12:46 - 000327464 _____ C:\Users\Tomáš\Downloads\Prihlaska_pohledavky.pdf
2019-11-04 12:46 - 2019-11-04 12:46 - 000327464 _____ C:\Users\Tomáš\Downloads\Prihlaska_pohledavky (1).pdf
2019-11-02 18:59 - 2019-11-02 18:59 - 000129015 _____ C:\Users\Tomáš\Downloads\obhajoba-pred-soudem-i--stupne-vcetne-dokazovani---judr--tomas-durdik.pptx
2019-10-29 15:46 - 2019-10-29 15:47 - 000000000 ____D C:\Users\Tomáš\Desktop\7 Cm 133 2016 (cee direct)
2019-10-29 15:46 - 2019-10-29 15:46 - 000000000 ____D C:\Users\Tomáš\Desktop\7 Cm 178 2014 (Koutný I)
2019-10-29 15:45 - 2019-10-29 15:45 - 000000000 ____D C:\Users\Tomáš\Desktop\53 Cm 211 2017 (Felcmanová)
2019-10-29 15:39 - 2019-10-29 17:16 - 000000000 ____D C:\Users\Tomáš\Desktop\7 Cm 17 2017 (Koutný II)
2019-10-29 14:24 - 2019-10-29 14:24 - 000447217 _____ C:\Users\Tomáš\Downloads\DPTX_2010_1__0_39118_0_79690.pdf
2019-10-29 09:46 - 2019-10-29 09:46 - 000304976 _____ C:\Windows\Minidump\102919-9594-01.dmp
2019-10-29 09:40 - 2019-10-29 09:40 - 000305304 _____ C:\Windows\Minidump\102919-9094-01.dmp
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-07 09:03 - 2018-10-08 19:48 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-12-07 09:03 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2019-12-07 09:02 - 2018-10-08 19:45 - 000000000 ____D C:\Program Files\Microsoft Office
2019-11-27 07:40 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-11-27 07:22 - 2018-07-02 12:20 - 000000000 ____D C:\Games
2019-11-27 03:51 - 2019-05-04 10:21 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\Doomtrooper
2019-11-27 03:48 - 2009-07-14 05:45 - 000015344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-11-27 03:48 - 2009-07-14 05:45 - 000015344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-11-26 09:36 - 2019-03-17 03:08 - 000005335 _____ C:\Users\Tomáš\Desktop\MCh-krystalové nebe.txt
2019-11-26 04:55 - 2018-10-09 17:26 - 000003174 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1564068326-3056932736-4007049450-1000
2019-11-26 04:55 - 2018-10-08 19:50 - 000002120 _____ C:\Users\Tomáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2019-11-26 04:55 - 2018-10-08 19:50 - 000000000 ___RD C:\Users\Tomáš\OneDrive
2019-11-24 08:43 - 2019-10-25 17:59 - 000002337 _____ C:\Users\Tomáš\Desktop\Doomtrooper.lnk
2019-11-23 10:34 - 2009-07-14 16:18 - 000668542 _____ C:\Windows\system32\perfh005.dat
2019-11-23 10:34 - 2009-07-14 16:18 - 000141202 _____ C:\Windows\system32\perfc005.dat
2019-11-23 10:34 - 2009-07-14 06:13 - 001583226 _____ C:\Windows\system32\PerfStringBackup.INI
2019-11-23 10:34 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2019-11-23 10:29 - 2019-05-27 18:50 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\Discord
2019-11-23 10:29 - 2018-07-25 21:07 - 000000000 ____D C:\Users\Tomáš\AppData\Local\LogMeIn Hamachi
2019-11-23 10:29 - 2018-06-13 12:17 - 000000000 ____D C:\Program Files (x86)\Steam
2019-11-23 10:28 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-11-22 19:40 - 2018-12-18 15:27 - 000000000 ____D C:\Program Files\Epic Games
2019-11-22 08:32 - 2018-06-13 11:54 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-11-22 08:22 - 2019-02-01 20:38 - 000001879 _____ C:\Users\Tomáš\Desktop\Dashlane.lnk
2019-11-22 08:22 - 2019-02-01 20:37 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\Dashlane
2019-11-21 05:00 - 2019-09-23 08:56 - 000000000 ____D C:\Users\Tomáš\Desktop\42 C 328 2019 (Bočková)
2019-11-15 03:44 - 2018-06-15 05:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-11-13 21:56 - 2019-02-20 03:06 - 000000000 ____D C:\Users\Tomáš\AppData\Roaming\DAEMON Tools Lite
2019-11-13 20:25 - 2018-10-08 20:46 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-11-13 04:54 - 2019-09-14 17:51 - 000000000 ____D C:\Users\Tomáš\AppData\LocalLow\Mozilla
2019-11-13 04:52 - 2018-06-13 11:53 - 000000000 ____D C:\Users\Tomáš\AppData\Local\Deployment
2019-11-12 22:03 - 2018-06-13 13:51 - 000748816 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2019-11-05 21:33 - 2019-10-27 11:06 - 670099608 _____ C:\Windows\MEMORY.DMP
2019-11-05 21:33 - 2019-03-24 13:33 - 000000000 ____D C:\Windows\Minidump
2019-11-04 23:56 - 2018-06-13 11:53 - 000000000 ____D C:\Program Files (x86)\Google
2019-11-03 19:29 - 2018-07-18 06:26 - 000000000 ____D C:\ProgramData\Package Cache
2019-11-01 22:55 - 2019-08-01 07:56 - 000000000 ____D C:\Users\Tomáš\Desktop\Nguyen
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-11-19 04:44
==================== End of FRST.txt ========================