Zavirovaný pc s pomocí viru yundooo Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 02 bře 2017 09:49

[2017/02/15 07:12:23 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSyncHost.exe
[2017/02/15 07:12:23 | 000,520,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingSync.dll
[2017/02/15 07:12:23 | 000,336,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\stobject.dll
[2017/02/15 07:12:23 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingMonitor.dll
[2017/02/15 07:12:22 | 001,348,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\AppXDeploymentServer.dll
[2017/02/15 07:12:22 | 001,197,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\usercpl.dll
[2017/02/15 07:12:22 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SettingMonitor.dll
[2017/02/15 07:12:22 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TSWbPrxy.exe
[2017/02/15 07:11:41 | 001,673,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\workfolderssvc.dll
[2017/02/15 07:11:41 | 000,787,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WorkfoldersControl.dll
[2017/02/15 07:11:40 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rgb9rast.dll
[2017/02/15 07:11:38 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PhotoMetadataHandler.dll
[2017/02/15 07:11:38 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PhotoMetadataHandler.dll
[2017/02/15 07:11:27 | 000,177,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wscapi.dll
[2017/02/15 07:11:27 | 000,148,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wscapi.dll
[2017/02/15 07:11:14 | 000,166,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mtxoci.dll
[2017/02/15 07:11:14 | 000,161,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msorcl32.dll
[2017/02/15 07:11:14 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mtxoci.dll
[2017/02/15 07:10:34 | 005,273,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\glcndFilter.dll
[2017/02/15 07:10:34 | 005,268,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Data.Pdf.dll
[2017/02/15 07:10:34 | 000,803,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\oleaut32.dll
[2017/02/15 07:10:33 | 007,795,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Data.Pdf.dll
[2017/02/15 07:10:33 | 007,076,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\glcndFilter.dll
[2017/02/15 07:10:22 | 000,360,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sechost.dll
[2017/02/15 07:10:21 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tracerpt.exe
[2017/02/15 07:10:21 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tracerpt.exe
[2017/02/15 07:10:21 | 000,072,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\vpci.sys
[2017/02/15 07:10:08 | 002,487,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storagewmi.dll
[2017/02/15 07:10:08 | 001,482,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\storagewmi.dll
[2017/02/15 07:09:55 | 000,780,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsm.dll
[2017/02/15 07:09:55 | 000,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\InkEd.dll
[2017/02/15 07:09:55 | 000,230,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\InkEd.dll
[2017/02/15 07:09:50 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dsparse.dll
[2017/02/15 07:09:50 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dsparse.dll
[2017/02/15 07:09:47 | 000,669,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hhctrl.ocx
[2017/02/15 07:09:47 | 000,536,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hhctrl.ocx
[2017/02/15 07:09:36 | 000,410,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\services.exe
[2017/02/15 07:09:36 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usb8023.sys
[2017/02/15 07:09:34 | 000,270,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2017/02/15 07:09:34 | 000,114,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2017/02/15 07:09:34 | 000,044,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2017/02/15 07:09:33 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2017/02/15 07:09:33 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2017/02/15 07:09:16 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\davclnt.dll
[2017/02/15 07:09:10 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdc.ocx
[2017/02/15 07:09:09 | 000,200,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GlobCollationHost.dll
[2017/02/15 07:09:09 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2017/02/15 07:09:09 | 000,087,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdc.ocx
[2017/02/15 07:09:09 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2017/02/15 07:09:08 | 000,725,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2017/02/15 07:09:08 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GlobCollationHost.dll
[2017/02/15 07:09:08 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2017/02/15 07:09:07 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2017/02/15 07:09:07 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2017/02/15 07:09:07 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2017/02/15 07:09:07 | 000,315,224 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2017/02/15 07:09:06 | 002,131,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2017/02/15 07:09:06 | 000,806,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2017/02/15 07:09:06 | 000,576,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2017/02/15 07:09:06 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DafPrintProvider.dll
[2017/02/15 07:09:05 | 001,541,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\user32.dll
[2017/02/15 07:09:05 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2017/02/15 07:09:04 | 001,380,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2017/02/15 07:09:04 | 000,922,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\refs.sys
[2017/02/15 07:09:04 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2017/02/15 07:09:04 | 000,422,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\spaceport.sys
[2017/02/15 07:09:04 | 000,372,568 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2017/02/15 07:09:04 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2017/02/15 07:09:04 | 000,269,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DafPrintProvider.dll
[2017/02/15 07:09:03 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2017/02/15 07:09:02 | 006,049,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2017/02/15 07:09:02 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2017/02/15 07:09:02 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2017/02/15 07:09:02 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2017/02/15 07:09:01 | 007,444,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2017/02/15 07:09:01 | 001,988,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2017/02/15 07:09:00 | 002,463,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2017/02/15 07:09:00 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UtcResources.dll
[2017/02/15 07:08:59 | 002,778,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2017/02/15 07:08:59 | 001,628,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2017/02/15 07:08:59 | 001,385,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctf.dll
[2017/02/15 07:08:59 | 001,220,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.appcore.dll
[2017/02/15 07:08:59 | 000,868,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Globalization.dll
[2017/02/15 07:08:59 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2017/02/15 07:08:59 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2017/02/15 07:08:59 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-system-events.dll
[2017/02/15 07:08:59 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2017/02/15 07:08:58 | 001,200,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Globalization.dll
[2017/02/15 07:08:58 | 001,094,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2017/02/15 07:08:58 | 000,864,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2017/02/15 07:08:58 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2017/02/15 07:08:57 | 001,445,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2017/02/15 07:08:57 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dnsapi.dll
[2017/02/15 07:08:57 | 000,377,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\clfs.sys
[2017/02/15 07:08:56 | 015,431,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmp.dll
[2017/02/15 07:08:56 | 013,317,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmp.dll
[2017/02/15 07:08:56 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2017/02/15 07:08:56 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2017/02/15 07:08:55 | 000,954,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.appcore.dll
[2017/02/15 07:08:54 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2017/02/15 07:08:54 | 002,896,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\esent.dll
[2017/02/15 07:08:54 | 002,537,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\esent.dll
[2017/02/15 07:08:54 | 001,754,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\GdiPlus.dll
[2017/02/15 07:08:54 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2017/02/15 07:08:54 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2017/02/15 07:08:53 | 003,320,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2017/02/15 07:08:53 | 001,491,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\GdiPlus.dll
[2017/02/15 07:08:53 | 001,335,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mispace.dll
[2017/02/15 07:08:53 | 001,063,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mispace.dll
[2017/02/15 07:08:53 | 000,531,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ci.dll
[2017/02/15 07:08:53 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2017/02/15 07:08:53 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2017/02/15 07:08:53 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hlink.dll
[2017/02/15 07:08:53 | 000,044,032 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2017/02/15 07:08:53 | 000,035,840 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2017/02/15 07:08:52 | 002,315,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d11.dll
[2017/02/15 07:08:52 | 001,969,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\crypt32.dll
[2017/02/15 07:08:52 | 001,946,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3d11.dll
[2017/02/15 07:08:52 | 001,317,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Media.Streaming.dll
[2017/02/15 07:08:52 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiobj.dll
[2017/02/15 07:08:52 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiobj.dll
[2017/02/15 07:08:52 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\puiapi.dll
[2017/02/15 07:08:52 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2017/02/15 07:08:51 | 001,660,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ole32.dll
[2017/02/15 07:08:51 | 001,102,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Media.Streaming.dll
[2017/02/15 07:08:51 | 000,721,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msdtcprx.dll
[2017/02/15 07:08:51 | 000,497,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfsvr.dll
[2017/02/15 07:08:51 | 000,399,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfsvr.dll
[2017/02/15 07:08:51 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\compstui.dll
[2017/02/15 07:08:50 | 001,663,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2017/02/15 07:08:50 | 001,523,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2017/02/15 07:08:50 | 001,490,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2017/02/15 07:08:50 | 001,358,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2017/02/15 07:08:50 | 000,871,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msdtcprx.dll
[2017/02/15 07:08:50 | 000,840,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netlogon.dll
[2017/02/15 07:08:50 | 000,747,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntshrui.dll
[2017/02/15 07:08:50 | 000,738,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d10level9.dll
[2017/02/15 07:08:50 | 000,512,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winspool.drv
[2017/02/15 07:08:50 | 000,379,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\storport.sys
[2017/02/15 07:08:50 | 000,377,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vmrdvcore.dll
[2017/02/15 07:08:50 | 000,332,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAnimation.dll
[2017/02/15 07:08:50 | 000,324,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wintrust.dll
[2017/02/15 07:08:50 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAnimation.dll
[2017/02/15 07:08:50 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\puiapi.dll
[2017/02/15 07:08:50 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\cmimcext.sys
[2017/02/15 07:08:49 | 000,306,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pdh.dll
[2017/02/15 07:08:48 | 009,323,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wmploc.DLL
[2017/02/15 07:08:48 | 000,262,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\pdh.dll
[2017/02/15 07:08:48 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TpmTasks.dll
[2017/02/15 07:08:48 | 000,152,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcrypt.dll
[2017/02/15 07:08:47 | 009,323,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wmploc.DLL
[2017/02/15 07:08:47 | 000,289,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PlayToDevice.dll
[2017/02/15 07:08:47 | 000,263,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\input.dll
[2017/02/15 07:08:47 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ActionQueue.dll
[2017/02/15 07:08:47 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastapi.dll
[2017/02/15 07:08:47 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastapi.dll
[2017/02/15 07:08:47 | 000,116,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shsetup.dll
[2017/02/15 07:08:47 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adsmsext.dll
[2017/02/15 07:08:47 | 000,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\shsetup.dll
[2017/02/15 07:08:47 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\adsmsext.dll
[2017/02/15 07:08:46 | 000,121,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\tm.sys
[2017/02/15 07:08:45 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\input.dll
[2017/02/15 07:08:45 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PlayToDevice.dll
[2017/02/15 07:08:45 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iscsiwmi.dll
[2017/02/15 07:08:45 | 000,069,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\apisetschema.dll
[2017/02/15 07:08:45 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iscsiwmi.dll
[2017/02/15 07:08:44 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dab.dll
[2017/02/15 07:08:44 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iscsidsc.dll
[2017/02/15 07:08:44 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xolehlp.dll
[2017/02/15 07:08:44 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\offreg.dll
[2017/02/15 07:08:44 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iscsidsc.dll
[2017/02/15 07:08:44 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xolehlp.dll
[2017/02/15 07:08:44 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\offreg.dll
[2017/02/15 07:08:29 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2017/02/15 07:08:29 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2017/02/15 07:08:21 | 000,222,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpsapi.dll
[2017/02/15 07:08:21 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dhcpsapi.dll
[2017/02/15 07:08:20 | 004,298,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_47.dll
[2017/02/15 07:08:20 | 001,488,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfc42u.dll
[2017/02/15 07:08:20 | 001,230,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc42u.dll
[2017/02/15 07:08:20 | 001,204,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc42.dll
[2017/02/15 07:08:19 | 003,551,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_47.dll
[2017/02/15 07:08:19 | 001,464,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfc42.dll
[2017/02/15 07:08:19 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\atlthunk.dll
[2017/02/15 07:05:54 | 001,707,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comsvcs.dll
[2017/02/15 07:05:54 | 001,344,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\comsvcs.dll
[2017/02/15 07:05:54 | 000,522,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\catsrvut.dll
[2017/02/15 07:05:54 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\catsrvut.dll
[2017/02/15 07:05:51 | 001,728,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Immersive.dll
[2017/02/15 07:05:50 | 001,546,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Immersive.dll
[2017/02/15 07:05:50 | 000,994,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ucrtbase.dll
[2017/02/15 07:05:50 | 000,922,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ucrtbase.dll
[2017/02/15 07:05:32 | 000,779,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsAnytimeUpgradeui.exe
[2017/02/15 07:05:27 | 000,971,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2017/02/15 07:05:26 | 000,811,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2017/02/15 07:05:26 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2017/02/15 07:05:26 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2017/02/15 07:05:19 | 000,470,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\netio.sys
[2017/02/15 07:05:18 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\shacct.dll
[2017/02/15 07:05:18 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\shacct.dll
[2017/02/15 07:05:14 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasapi32.dll
[2017/02/15 07:05:14 | 000,429,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vpnike.dll
[2017/02/15 07:05:14 | 000,377,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mprddm.dll
[2017/02/15 07:05:14 | 000,360,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpclip.exe
[2017/02/15 07:05:14 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iprtrmgr.dll
[2017/02/15 07:05:14 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mprddm.dll
[2017/02/15 07:05:14 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasppp.dll
[2017/02/15 07:05:14 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rascustom.dll
[2017/02/15 07:05:14 | 000,197,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dssenh.dll
[2017/02/15 07:05:14 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rasman.dll
[2017/02/15 07:05:14 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2017/02/15 07:05:13 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\nshwfp.dll
[2017/02/15 07:05:13 | 000,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iprtrmgr.dll
[2017/02/15 07:05:13 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rasppp.dll
[2017/02/15 07:05:02 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StorageContextHandler.dll
[2017/02/15 07:05:02 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\StorageContextHandler.dll
[2017/02/15 07:04:40 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PCPKsp.dll
[2017/02/15 07:04:40 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PCPKsp.dll
[2017/02/15 07:04:38 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authz.dll
[2017/02/15 07:04:15 | 000,292,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMASF.DLL
[2017/02/15 07:04:14 | 000,397,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bcryptprimitives.dll
[2017/02/15 07:04:14 | 000,340,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\bcryptprimitives.dll
[2017/02/15 07:04:14 | 000,179,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sspicli.dll
[2017/02/15 07:04:12 | 002,175,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\combase.dll
[2017/02/15 07:04:11 | 001,564,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\combase.dll
[2017/02/15 07:04:11 | 001,063,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinTypes.dll
[2017/02/15 07:04:11 | 000,548,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WinTypes.dll
[2017/02/15 07:04:11 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wincorlib.dll
[2017/02/15 07:03:56 | 000,468,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2017/02/15 07:03:56 | 000,443,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbport.sys
[2017/02/15 07:03:56 | 000,027,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbd.sys
[2017/02/15 07:03:55 | 001,249,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UIAutomationCore.dll
[2017/02/15 07:03:55 | 001,018,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UIAutomationCore.dll
[2017/02/15 07:03:33 | 000,203,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ubpm.dll
[2017/02/15 07:03:22 | 000,653,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\comctl32.dll
[2017/02/15 07:03:17 | 000,325,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBXHCI.SYS
[2017/02/15 07:03:09 | 000,487,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\netcfgx.dll
[2017/02/15 07:03:09 | 000,393,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\netcfgx.dll
[2017/02/15 07:03:00 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fhcpl.dll
[2017/02/15 07:03:00 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2017/02/15 07:02:55 | 000,360,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncsi.dll
[2017/02/15 07:02:54 | 000,239,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdbus.sys
[2017/02/15 07:02:54 | 000,154,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpsd.sys
[2017/02/15 07:02:53 | 000,186,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2017/02/15 07:02:49 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eappcfg.dll
[2017/02/15 07:02:49 | 000,339,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eapphost.dll
[2017/02/15 07:02:49 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eapp3hst.dll
[2017/02/15 07:02:49 | 000,278,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eappcfg.dll
[2017/02/15 07:02:49 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eapphost.dll
[2017/02/15 07:02:49 | 000,250,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eapp3hst.dll
[2017/02/15 07:02:49 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eappgnui.dll
[2017/02/15 07:02:49 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eappgnui.dll
[2017/02/15 07:02:26 | 002,755,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2017/02/15 07:02:26 | 002,411,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2017/02/15 07:02:23 | 014,466,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\twinui.dll
[2017/02/15 07:02:23 | 012,879,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\twinui.dll
[2017/02/15 07:02:22 | 002,881,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2017/02/15 07:02:22 | 000,133,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\RestoreOptIn.exe
[2017/02/15 07:02:22 | 000,113,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\RestoreOptIn.exe
[2017/02/15 07:02:20 | 001,737,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2017/02/15 07:02:20 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\csrsrv.dll
[2017/02/15 07:02:07 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinSync.dll
[2017/02/15 07:02:07 | 000,578,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WinSync.dll
[2017/02/15 07:02:07 | 000,468,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\taskeng.exe
[2017/02/15 07:02:07 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\schtasks.exe
[2017/02/15 07:02:07 | 000,182,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\schtasks.exe
[2017/02/15 07:02:04 | 000,428,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2017/02/15 07:02:04 | 000,160,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\IPHLPAPI.DLL
[2017/02/15 07:02:03 | 000,402,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPhoto.dll
[2017/02/15 07:02:03 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPhoto.dll
[2017/02/15 07:02:01 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\basesrv.dll
[2017/02/15 07:01:58 | 000,200,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\storewuauth.dll
[2017/02/15 07:01:53 | 007,032,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2017/02/15 07:01:53 | 006,213,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2017/02/15 07:01:53 | 000,856,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdvidcrl.dll
[2017/02/15 07:01:53 | 000,363,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ws2_32.dll
[2017/02/15 07:01:52 | 002,551,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssrch.dll
[2017/02/15 07:01:52 | 001,920,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssrch.dll
[2017/02/15 07:01:52 | 001,101,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdvidcrl.dll
[2017/02/15 07:01:52 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clfsw32.dll
[2017/02/15 07:01:52 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NcdAutoSetup.dll
[2017/02/15 07:01:52 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clfsw32.dll
[2017/02/15 07:01:50 | 003,633,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tquery.dll
[2017/02/15 07:01:50 | 002,749,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tquery.dll
[2017/02/15 07:01:50 | 002,067,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpdshext.dll
[2017/02/15 07:01:50 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssvp.dll
[2017/02/15 07:01:50 | 000,699,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssvp.dll
[2017/02/15 07:01:50 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msra.exe
[2017/02/15 07:01:50 | 000,570,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winlogon.exe
[2017/02/15 07:01:50 | 000,468,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssph.dll
[2017/02/15 07:01:50 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mssph.dll
[2017/02/15 07:01:50 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchProtocolHost.exe
[2017/02/15 07:01:50 | 000,248,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mssphtb.dll
[2017/02/15 07:01:50 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wininit.exe
[2017/02/15 07:01:49 | 003,084,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2017/02/15 07:01:49 | 002,471,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2017/02/15 07:01:49 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfds.dll
[2017/02/15 07:01:49 | 000,483,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfds.dll
[2017/02/15 07:01:48 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tzsync.exe
[2017/02/15 07:01:47 | 001,156,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanmm.dll
[2017/02/15 07:01:47 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pnidui.dll
[2017/02/15 07:01:47 | 000,455,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wwanconn.dll
[2017/02/15 07:01:47 | 000,074,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appidapi.dll
[2017/02/15 07:01:47 | 000,065,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\appidapi.dll
[2017/02/15 07:01:45 | 001,090,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2017/02/15 07:01:45 | 000,791,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2017/02/15 07:01:41 | 000,046,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContentServer.exe
[2017/02/15 07:01:29 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll
[2017/02/15 07:01:24 | 000,685,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\advapi32.dll
[2017/02/15 00:19:42 | 000,359,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinSetupUI.dll
[2017/02/15 00:19:42 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BdeHdCfgLib.dll
[2017/02/15 00:19:42 | 000,032,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\hidparse.sys
[2017/02/15 00:19:41 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\webio.dll
[2017/02/15 00:19:41 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\webio.dll
[2017/02/15 00:19:41 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\hidclass.sys
[2017/02/15 00:19:41 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wow32.dll
[2017/02/15 00:19:41 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\user.exe
[2017/02/15 00:19:40 | 000,136,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\wfplwfs.sys
[2017/02/15 00:19:39 | 001,134,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2017/02/15 00:19:39 | 000,137,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncrypt.dll
[2017/02/15 00:19:38 | 000,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wow64.dll
[2017/02/15 00:19:38 | 000,034,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UserAccountBroker.exe
[2017/02/15 00:19:38 | 000,030,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\UserAccountBroker.exe
[2017/02/15 00:19:38 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wfapigp.dll
[2017/02/15 00:19:38 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wfapigp.dll
[2017/02/15 00:19:38 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wow64cpu.dll
[2017/02/15 00:19:36 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll
[2017/02/15 00:19:36 | 000,118,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2017/02/15 00:19:36 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll
[2017/02/15 00:19:36 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wups.dll
[2017/02/15 00:19:36 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxp.dll
[2017/02/15 00:19:36 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wu.upgrade.ps.dll
[2017/02/15 00:19:34 | 000,072,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpfve.sys
[2017/02/15 00:19:33 | 000,322,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fvecpl.dll
[2017/02/15 00:19:32 | 000,125,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cryptxml.dll
[2017/02/15 00:19:32 | 000,107,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncryptsslp.dll
[2017/02/15 00:19:32 | 000,099,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\cryptxml.dll
[2017/02/15 00:19:32 | 000,091,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncryptsslp.dll
[2017/02/15 00:19:32 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntvdm64.dll
[2017/02/15 00:19:32 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ntvdm64.dll
[2017/02/15 00:19:32 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\instnm.exe
[2017/02/15 00:19:31 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hbaapi.dll
[2017/02/15 00:19:31 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hbaapi.dll
[2017/02/15 00:19:31 | 000,057,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\stornvme.sys
[2017/02/15 00:19:30 | 000,737,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll
[2017/02/15 00:19:30 | 000,482,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tpmvsc.dll
[2017/02/15 00:19:29 | 000,306,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.Devices.Geolocation.dll
[2017/02/15 00:19:29 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.Devices.Geolocation.dll
[2017/02/15 00:19:29 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpresult.exe
[2017/02/15 00:19:29 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpresult.exe
[2017/02/15 00:19:29 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\setup16.exe
[2017/02/15 00:19:28 | 000,754,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FirewallAPI.dll
[2017/02/15 00:19:28 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2017/02/15 00:19:28 | 000,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2017/02/15 00:19:28 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuaext.dll
[2017/02/15 00:19:24 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certenc.dll
[2017/02/15 00:19:24 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certenc.dll
[2017/02/15 00:19:22 | 000,331,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\Classpnp.sys
[2017/02/15 00:19:21 | 000,561,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\nshwfp.dll
[2017/02/15 00:19:21 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\FWPUCLNT.DLL
[2017/02/15 00:19:21 | 000,272,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\FWPUCLNT.DLL
[2017/02/15 00:19:20 | 000,897,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2017/02/15 00:19:20 | 000,727,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2017/02/15 00:19:20 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LocationApi.dll
[2017/02/15 00:19:20 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\LocationApi.dll
[2017/02/15 00:19:20 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2017/02/15 00:19:20 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2017/02/15 00:19:20 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2017/02/15 00:19:20 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2017/02/15 00:19:20 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2017/02/15 00:19:19 | 001,487,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppobjs.dll
[2017/02/15 00:19:19 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2017/02/15 00:19:19 | 000,261,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sppwinob.dll
[2017/02/15 00:19:19 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2017/02/15 00:19:19 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2017/02/15 00:19:18 | 003,820,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcore.dll
[2017/02/15 00:19:18 | 003,273,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rdpcore.dll
[2017/02/15 00:19:17 | 002,317,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\CertEnroll.dll
[2017/02/15 00:19:17 | 001,291,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certutil.exe
[2017/02/15 00:19:17 | 001,060,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certutil.exe
[2017/02/15 00:19:16 | 002,635,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CertEnroll.dll
[2017/02/15 00:19:16 | 002,230,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2017/02/15 00:19:13 | 018,825,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2017/02/15 00:19:13 | 015,158,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2017/02/15 00:12:55 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\poqexec.exe
[2017/02/15 00:12:55 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\poqexec.exe
[2017/02/14 22:36:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Riot Games
[2017/02/14 21:51:51 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_39.dll
[2017/02/14 21:51:51 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_39.dll
[2017/02/14 21:51:51 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_39.dll
[2017/02/14 21:51:51 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_39.dll
[2017/02/14 21:51:50 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_39.dll
[2017/02/14 21:51:50 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_39.dll
[2017/02/14 21:50:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2017/02/14 21:47:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2017/02/14 21:47:15 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\InstallShield
[2017/02/14 21:22:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2017/02/14 21:22:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2017/02/14 21:21:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2017/02/14 21:21:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHEALTH
[2017/02/14 21:19:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2017/02/14 21:19:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2017/02/14 21:19:22 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Microsoft Help
[2017/02/14 21:19:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2017/02/14 21:19:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2017/02/14 21:10:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2017/02/14 21:10:15 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2017/02/14 21:10:15 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2017/02/14 21:09:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2017/02/14 21:08:59 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Programs
[2017/02/14 19:59:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
[2017/02/14 19:58:35 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\VEGAS
[2017/02/14 19:58:35 | 000,000,000 | ---D | C] -- C:\ProgramData\VEGAS
[2017/02/14 19:58:35 | 000,000,000 | ---D | C] -- C:\Program Files\VEGAS
[2017/02/14 19:58:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VEGAS
[2017/02/14 19:57:26 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Sony
[2017/02/14 19:16:53 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2017/02/14 19:11:17 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2017/02/14 19:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2017/02/14 19:09:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2017/02/14 19:08:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2017/02/14 19:07:37 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Adobe
[2017/02/14 18:46:19 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2017/02/14 18:35:59 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Steam
[2017/02/14 18:35:59 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\CEF
[2017/02/14 18:27:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2017/02/14 18:27:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2017/02/14 18:27:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2017/02/14 18:25:25 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Skype
[2017/02/14 18:25:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2017/02/14 18:25:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2017/02/14 18:25:19 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2017/02/14 18:25:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2017/02/14 18:22:14 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\WebStorage
[2017/02/14 18:22:13 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\awsRun
[2017/02/14 18:21:59 | 000,000,000 | ---D | C] -- C:\ProgramData\WebStorage
[2017/02/14 18:21:59 | 000,000,000 | ---D | C] -- C:\ProgramData\ASUS WebStorage
[2017/02/14 18:21:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AWS
[2017/02/14 18:19:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2017/02/14 18:19:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2017/02/14 18:19:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\XPSViewer
[2017/02/14 18:19:45 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2017/02/14 18:19:45 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2017/02/14 18:18:04 | 000,778,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationNative_v0300.dll
[2017/02/14 18:18:03 | 001,166,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationNative_v0300.dll
[2017/02/14 18:17:34 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_7.dll
[2017/02/14 18:17:34 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_7.dll
[2017/02/14 18:17:34 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_5.dll
[2017/02/14 18:17:34 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_5.dll
[2017/02/14 18:17:32 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_43.dll
[2017/02/14 18:17:32 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_43.dll
[2017/02/14 18:17:32 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dcsx_43.dll

Reklama
Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 02 bře 2017 09:50

[2017/02/14 18:17:32 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dcsx_43.dll
[2017/02/14 18:17:32 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_7.dll
[2017/02/14 18:17:32 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_7.dll
[2017/02/14 18:17:28 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_6.dll
[2017/02/14 18:17:28 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_6.dll
[2017/02/14 18:17:28 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_4.dll
[2017/02/14 18:17:28 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_4.dll
[2017/02/14 18:17:27 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_6.dll
[2017/02/14 18:17:27 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_6.dll
[2017/02/14 18:17:26 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_7.dll
[2017/02/14 18:17:26 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_7.dll
[2017/02/14 18:17:24 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_5.dll
[2017/02/14 18:17:24 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_5.dll
[2017/02/14 18:17:23 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_5.dll
[2017/02/14 18:17:23 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_5.dll
[2017/02/14 18:17:22 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_42.dll
[2017/02/14 18:17:22 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_42.dll
[2017/02/14 18:17:21 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dcsx_42.dll
[2017/02/14 18:17:21 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dcsx_42.dll
[2017/02/14 18:17:21 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx11_42.dll
[2017/02/14 18:17:21 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx11_42.dll
[2017/02/14 18:17:20 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_42.dll
[2017/02/14 18:17:20 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_42.dll
[2017/02/14 18:17:19 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_41.dll
[2017/02/14 18:17:19 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_41.dll
[2017/02/14 18:17:19 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_42.dll
[2017/02/14 18:17:19 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_41.dll
[2017/02/14 18:17:19 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_42.dll
[2017/02/14 18:17:19 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_41.dll
[2017/02/14 18:17:19 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_41.dll
[2017/02/14 18:17:19 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_41.dll
[2017/02/14 18:17:18 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_4.dll
[2017/02/14 18:17:18 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_4.dll
[2017/02/14 18:17:18 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_3.dll
[2017/02/14 18:17:18 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_3.dll
[2017/02/14 18:17:17 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_4.dll
[2017/02/14 18:17:17 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_4.dll
[2017/02/14 18:17:17 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_6.dll
[2017/02/14 18:17:17 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_6.dll
[2017/02/14 18:17:16 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_40.dll
[2017/02/14 18:17:16 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_40.dll
[2017/02/14 18:17:16 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_40.dll
[2017/02/14 18:17:16 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_40.dll
[2017/02/14 18:17:15 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_40.dll
[2017/02/14 18:17:15 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_40.dll
[2017/02/14 18:17:15 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_3.dll
[2017/02/14 18:17:15 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_3.dll
[2017/02/14 18:17:15 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_2.dll
[2017/02/14 18:17:15 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_2.dll
[2017/02/14 18:17:14 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_3.dll
[2017/02/14 18:17:14 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_3.dll
[2017/02/14 18:17:13 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_2.dll
[2017/02/14 18:17:13 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_2.dll
[2017/02/14 18:17:13 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_1.dll
[2017/02/14 18:17:13 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_1.dll
[2017/02/14 18:17:13 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_5.dll
[2017/02/14 18:17:13 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_5.dll
[2017/02/14 18:17:12 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_2.dll
[2017/02/14 18:17:12 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_2.dll
[2017/02/14 18:17:10 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_1.dll
[2017/02/14 18:17:10 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_1.dll
[2017/02/14 18:17:10 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_1.dll
[2017/02/14 18:17:10 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_1.dll
[2017/02/14 18:17:10 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_0.dll
[2017/02/14 18:17:10 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_0.dll
[2017/02/14 18:17:09 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_4.dll
[2017/02/14 18:17:09 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_4.dll
[2017/02/14 18:17:08 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_38.dll
[2017/02/14 18:17:08 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_38.dll
[2017/02/14 18:17:08 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_38.dll
[2017/02/14 18:17:08 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_38.dll
[2017/02/14 18:17:08 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_38.dll
[2017/02/14 18:17:08 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_38.dll
[2017/02/14 18:17:07 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_0.dll
[2017/02/14 18:17:07 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_0.dll
[2017/02/14 18:17:06 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_0.dll
[2017/02/14 18:17:06 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_0.dll
[2017/02/14 18:17:05 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_3.dll
[2017/02/14 18:17:05 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_3.dll
[2017/02/14 18:17:04 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_37.dll
[2017/02/14 18:17:04 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_37.dll
[2017/02/14 18:17:04 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_37.dll
[2017/02/14 18:17:04 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_37.dll
[2017/02/14 18:17:03 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_37.dll
[2017/02/14 18:17:03 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_37.dll
[2017/02/14 18:17:03 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_10.dll
[2017/02/14 18:17:03 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_10.dll
[2017/02/14 18:17:01 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_36.dll
[2017/02/14 18:17:01 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_36.dll
[2017/02/14 18:17:01 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_36.dll
[2017/02/14 18:17:01 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_36.dll
[2017/02/14 18:16:59 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_36.dll
[2017/02/14 18:16:59 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_36.dll
[2017/02/14 18:16:58 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_9.dll
[2017/02/14 18:16:58 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_9.dll
[2017/02/14 18:16:57 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_35.dll
[2017/02/14 18:16:57 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_35.dll
[2017/02/14 18:16:57 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_35.dll
[2017/02/14 18:16:57 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_35.dll
[2017/02/14 18:16:56 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_35.dll
[2017/02/14 18:16:56 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_35.dll
[2017/02/14 18:16:55 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_8.dll
[2017/02/14 18:16:55 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_8.dll
[2017/02/14 18:16:55 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_2.dll
[2017/02/14 18:16:55 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_2.dll
[2017/02/14 18:16:54 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_34.dll
[2017/02/14 18:16:54 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_34.dll
[2017/02/14 18:16:54 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_34.dll
[2017/02/14 18:16:54 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_34.dll
[2017/02/14 18:16:54 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_34.dll
[2017/02/14 18:16:54 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_34.dll
[2017/02/14 18:16:53 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_7.dll
[2017/02/14 18:16:53 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_7.dll
[2017/02/14 18:16:53 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xinput1_3.dll
[2017/02/14 18:16:53 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xinput1_3.dll
[2017/02/14 18:16:52 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_33.dll
[2017/02/14 18:16:52 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_33.dll
[2017/02/14 18:16:52 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_33.dll
[2017/02/14 18:16:52 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_33.dll
[2017/02/14 18:16:52 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_33.dll
[2017/02/14 18:16:52 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_33.dll
[2017/02/14 18:16:51 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_6.dll
[2017/02/14 18:16:51 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_6.dll
[2017/02/14 18:16:50 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10.dll
[2017/02/14 18:16:50 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10.dll
[2017/02/14 18:16:50 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_5.dll
[2017/02/14 18:16:50 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_5.dll
[2017/02/14 18:16:49 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_32.dll
[2017/02/14 18:16:49 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_32.dll
[2017/02/14 18:16:49 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_4.dll
[2017/02/14 18:16:49 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_4.dll
[2017/02/14 18:16:49 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\x3daudio1_1.dll
[2017/02/14 18:16:49 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\x3daudio1_1.dll
[2017/02/14 18:16:48 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_31.dll
[2017/02/14 18:16:48 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_31.dll
[2017/02/14 18:16:48 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_3.dll
[2017/02/14 18:16:48 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_3.dll
[2017/02/14 18:16:47 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xinput1_2.dll
[2017/02/14 18:16:47 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xinput1_2.dll
[2017/02/14 18:16:46 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_2.dll
[2017/02/14 18:16:46 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_2.dll
[2017/02/14 18:16:46 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xinput1_1.dll
[2017/02/14 18:16:46 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xinput1_1.dll
[2017/02/14 18:16:45 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_30.dll
[2017/02/14 18:16:45 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_30.dll
[2017/02/14 18:16:45 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_1.dll
[2017/02/14 18:16:45 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_1.dll
[2017/02/14 18:16:44 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_29.dll
[2017/02/14 18:16:44 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_28.dll
[2017/02/14 18:16:44 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_29.dll
[2017/02/14 18:16:44 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_28.dll
[2017/02/14 18:16:44 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_0.dll
[2017/02/14 18:16:44 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_0.dll
[2017/02/14 18:16:44 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\x3daudio1_0.dll
[2017/02/14 18:16:44 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\x3daudio1_0.dll
[2017/02/14 18:16:43 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_27.dll
[2017/02/14 18:16:43 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_27.dll
[2017/02/14 18:16:42 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_25.dll
[2017/02/14 18:16:42 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_26.dll
[2017/02/14 18:16:42 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_25.dll
[2017/02/14 18:16:42 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_26.dll
[2017/02/14 18:16:41 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_24.dll
[2017/02/14 18:16:41 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_24.dll
[2017/02/14 18:11:47 | 000,063,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-private-l1-1-0.dll
[2017/02/14 18:11:47 | 000,022,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-math-l1-1-0.dll
[2017/02/14 18:11:47 | 000,020,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-math-l1-1-0.dll
[2017/02/14 18:11:47 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
[2017/02/14 18:11:47 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-multibyte-l1-1-0.dll
[2017/02/14 18:11:47 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-string-l1-1-0.dll
[2017/02/14 18:11:47 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-string-l1-1-0.dll
[2017/02/14 18:11:47 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
[2017/02/14 18:11:47 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-stdio-l1-1-0.dll
[2017/02/14 18:11:47 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
[2017/02/14 18:11:47 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-runtime-l1-1-0.dll
[2017/02/14 18:11:47 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
[2017/02/14 18:11:47 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-convert-l1-1-0.dll
[2017/02/14 18:11:47 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-time-l1-1-0.dll
[2017/02/14 18:11:47 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-time-l1-1-0.dll
[2017/02/14 18:11:47 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
[2017/02/14 18:11:47 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-filesystem-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-process-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-process-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-heap-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-conio-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-utility-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-locale-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
[2017/02/14 18:11:47 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-environment-l1-1-0.dll
[2017/02/14 18:11:46 | 000,066,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-private-l1-1-0.dll
[2017/02/14 18:11:07 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2017/02/14 18:06:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2017/02/14 18:03:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
[2017/02/14 18:03:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Asus
[2017/02/14 18:00:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2017/02/14 17:52:42 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2017/02/14 17:51:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA
[2017/02/14 17:51:47 | 000,000,000 | ---D | C] -- C:\Program Files\VIA
[2017/02/14 17:51:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SRSLabs
[2017/02/14 17:51:24 | 000,414,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\difxapi.dll
[2017/02/14 17:51:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VIA
[2017/02/14 17:51:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2017/02/14 17:50:35 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\NVIDIA Corporation
[2017/02/14 17:50:34 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\NVIDIA
[2017/02/14 17:50:20 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_43.dll
[2017/02/14 17:50:20 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_43.dll
[2017/02/14 17:50:20 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx11_43.dll
[2017/02/14 17:50:20 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx11_43.dll
[2017/02/14 17:50:19 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_43.dll
[2017/02/14 17:50:19 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_43.dll
[2017/02/14 17:50:14 | 001,854,400 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspcap64.dll
[2017/02/14 17:50:14 | 001,755,072 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspbridge64.dll
[2017/02/14 17:50:13 | 001,452,480 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspcap.dll
[2017/02/14 17:50:13 | 001,317,312 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspbridge.dll
[2017/02/14 17:50:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2017/02/14 17:48:53 | 000,134,592 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2017/02/14 17:48:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2017/02/14 17:44:48 | 000,101,824 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvaudcap64v.dll
[2017/02/14 17:44:48 | 000,091,584 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvaudcap32v.dll
[2017/02/14 17:44:48 | 000,046,016 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvvad64v.sys
[2017/02/14 17:44:47 | 001,600,056 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvhdagenco6420103.dll
[2017/02/14 17:44:47 | 000,217,528 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvhda64v.sys
[2017/02/14 17:44:47 | 000,047,664 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvhdap64.dll
[2017/02/14 17:44:46 | 019,110,088 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvwgf2umx.dll
[2017/02/14 17:44:46 | 016,510,160 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvwgf2um.dll
[2017/02/14 17:44:46 | 000,492,744 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvumdshimx.dll
[2017/02/14 17:44:45 | 034,937,280 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2017/02/14 17:44:45 | 028,212,280 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglv32.dll
[2017/02/14 17:44:45 | 019,006,832 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2017/02/14 17:44:45 | 016,398,896 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvd3dumx.dll
[2017/02/14 17:44:45 | 014,674,896 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2017/02/14 17:44:45 | 013,377,072 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvd3dum.dll
[2017/02/14 17:44:45 | 011,019,704 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvptxJitCompiler.dll
[2017/02/14 17:44:45 | 008,990,072 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvptxJitCompiler.dll
[2017/02/14 17:44:45 | 001,983,424 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6437866.dll
[2017/02/14 17:44:45 | 001,589,696 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6437866.dll
[2017/02/14 17:44:45 | 001,051,584 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2017/02/14 17:44:45 | 000,989,120 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2017/02/14 17:44:45 | 000,961,080 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2017/02/14 17:44:45 | 000,912,440 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2017/02/14 17:44:45 | 000,895,272 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmcumd.dll
[2017/02/14 17:44:45 | 000,687,224 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvfatbinaryLoader.dll
[2017/02/14 17:44:45 | 000,611,384 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2017/02/14 17:44:45 | 000,576,192 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvfatbinaryLoader.dll
[2017/02/14 17:44:45 | 000,504,104 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2017/02/14 17:44:45 | 000,500,792 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2017/02/14 17:44:45 | 000,425,288 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2017/02/14 17:44:45 | 000,408,272 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvumdshim.dll
[2017/02/14 17:44:45 | 000,170,360 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvinitx.dll
[2017/02/14 17:44:45 | 000,153,184 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglshim64.dll
[2017/02/14 17:44:45 | 000,148,016 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvinit.dll
[2017/02/14 17:44:45 | 000,131,720 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglshim32.dll
[2017/02/14 17:44:44 | 011,122,912 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2017/02/14 17:44:44 | 009,305,984 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2017/02/14 17:44:44 | 003,627,064 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2017/02/14 17:44:44 | 003,187,256 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2017/02/14 17:44:41 | 004,064,088 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvapi64.dll
[2017/02/14 17:44:41 | 003,583,560 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvapi.dll
[2017/02/14 17:40:40 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Broadcom
[2017/02/14 17:40:35 | 000,161,560 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\drivers\btwampfl.sys
[2017/02/14 17:39:09 | 002,265,400 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\BcmBtRSupport.dll
[2017/02/14 17:39:09 | 002,252,088 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\BtwRSupportService.exe
[2017/02/14 17:39:07 | 000,224,568 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\drivers\btwavdt.sys
[2017/02/14 17:39:07 | 000,186,648 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\drivers\btwaudio.sys
[2017/02/14 17:39:07 | 000,165,688 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\drivers\bcbtums.sys
[2017/02/14 17:39:07 | 000,040,248 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\drivers\btwl2cap.sys
[2017/02/14 17:39:07 | 000,022,328 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\SysNative\drivers\btwrchid.sys
[2017/02/14 17:38:46 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2017/02/14 17:37:51 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\WinRAR
[2017/02/14 17:37:44 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2017/02/14 17:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2017/02/14 17:37:42 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2017/02/14 17:32:16 | 006,403,640 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcpl.dll
[2017/02/14 17:32:16 | 002,477,504 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvc64.dll
[2017/02/14 17:32:16 | 001,764,408 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvcr.dll
[2017/02/14 17:32:16 | 000,548,288 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshext.dll
[2017/02/14 17:32:16 | 000,393,784 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmctray.dll
[2017/02/14 17:32:16 | 000,083,512 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshextr.dll
[2017/02/14 17:32:16 | 000,071,224 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvshext.dll
[2017/02/14 17:31:22 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2017/02/14 17:31:11 | 000,514,616 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2017/02/14 17:31:11 | 000,418,752 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.dll
[2017/02/14 17:30:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2017/02/14 17:30:29 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2017/02/14 17:30:26 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Google
[2017/02/14 17:30:15 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2017/02/14 17:30:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2017/02/14 17:28:47 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Macromedia
[2017/02/14 17:22:15 | 000,000,000 | R--D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2017/02/14 17:22:15 | 000,000,000 | R--D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2017/02/14 17:22:14 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Searches
[2017/02/14 17:21:47 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Adobe
[2017/02/14 17:21:44 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\VirtualStore
[2017/02/14 17:21:33 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Packages
[2017/02/14 17:20:17 | 000,000,000 | -HSD | C] -- C:\ProgramData\Šablony
[2017/02/14 17:20:17 | 000,000,000 | -HSD | C] -- C:\ProgramData\Plocha
[2017/02/14 17:20:17 | 000,000,000 | -HSD | C] -- C:\ProgramData\Oblíbené položky
[2017/02/14 17:20:17 | 000,000,000 | -HSD | C] -- C:\ProgramData\Nabídka Start
[2017/02/14 17:20:17 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2017/02/14 17:20:17 | 000,000,000 | -HSD | C] -- C:\ProgramData\Data aplikací
[2017/02/14 17:18:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\AppData\Local\Temporary Internet Files
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Šablony
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Soubory cookie
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\SendTo
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Poslední
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Okolní tiskárny
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Okolní síť
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Documents\Obrázky
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Nabídka Start
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Local Settings
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Documents\Hudba
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\AppData\Local\History
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Documents\Filmy
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Dokumenty
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\Data aplikací
[2017/02/14 17:16:59 | 000,000,000 | -HSD | C] -- C:\Users\ASUS\AppData\Local\Data aplikací
[2017/02/14 17:16:57 | 000,000,000 | --SD | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft
[2017/02/14 17:16:57 | 000,000,000 | R--D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2017/02/14 17:16:57 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Favorites
[2017/02/14 17:16:57 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Documents
[2017/02/14 17:16:57 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Desktop
[2017/02/14 17:16:57 | 000,000,000 | R--D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2017/02/14 17:16:57 | 000,000,000 | R--D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2017/02/14 17:16:57 | 000,000,000 | -H-D | C] -- C:\Users\ASUS\AppData
[2017/02/14 17:16:57 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Local\Microsoft
[2017/02/14 17:16:57 | 000,000,000 | ---D | C] -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2017/02/14 17:12:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2017/02/14 17:10:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2017/02/14 17:09:26 | 000,000,000 | ---D | C] -- C:\Windows.old
[2017/02/14 17:09:00 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sdbinst.exe
[2017/02/14 17:09:00 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sdbinst.exe
[2017/02/14 10:17:54 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Creative Cloud Files
[2017/02/13 18:20:37 | 000,000,000 | -H-D | C] -- C:\$SysReset
[2017/02/13 17:21:19 | 002,994,808 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\VIAPropPageExt.dll
[2017/02/13 17:21:19 | 002,206,864 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\drivers\viahduaa.sys
[2017/02/13 17:21:19 | 002,080,120 | ---- | C] (Waves Audio Ltd.) -- C:\WINDOWS\SysNative\WavesGUILib64.dll
[2017/02/13 17:21:19 | 001,161,336 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\ViaKaraokeApo.dll
[2017/02/13 17:21:19 | 001,119,352 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\ViaMicArrayAPO.dll
[2017/02/13 17:21:19 | 000,879,616 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysNative\VMAPO64.DLL
[2017/02/13 17:21:19 | 000,739,328 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysWow64\VMAPO32.DLL
[2017/02/13 17:21:19 | 000,683,640 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\VIASysFx.dll

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 02 bře 2017 09:50

[2017/02/13 17:21:19 | 000,619,520 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysNative\VMTHX64.DLL
[2017/02/13 17:21:19 | 000,554,496 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysWow64\VMTHX32.DLL
[2017/02/13 17:21:19 | 000,123,512 | ---- | C] (VIA Technologies,Inc.) -- C:\WINDOWS\SysNative\ViaKaraokePropPageExt.dll
[2017/02/13 17:21:19 | 000,095,352 | ---- | C] (VIA Technologies,Inc.) -- C:\WINDOWS\SysNative\ViaMicArrayPropPageExt.dll
[2017/02/13 17:21:19 | 000,074,240 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysNative\VMWRP64.DLL
[2017/02/13 17:21:19 | 000,070,776 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\SysNative\VtSrdAPO.dll
[2017/02/13 17:21:19 | 000,057,856 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysNative\VMPPLD64.DLL
[2017/02/13 17:21:19 | 000,053,760 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysNative\VMPPCN64.DLL
[2017/02/13 17:21:19 | 000,027,768 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\ViakaraokeSrv.exe
[2017/02/13 17:21:19 | 000,025,600 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\SysNative\drivers\VMfilt64.sys
[2017/02/13 17:21:18 | 007,163,744 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEP64H.dll
[2017/02/13 17:21:18 | 000,055,416 | ---- | C] (TODO: <Company name>) -- C:\WINDOWS\SysNative\PropPageExt.dll
[2017/02/13 17:21:17 | 007,163,744 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEP64A.dll
[2017/02/13 17:21:17 | 003,141,496 | ---- | C] (Waves Audio Ltd.) -- C:\WINDOWS\SysNative\MaxxAudioVIA64.dll
[2017/02/13 17:21:17 | 000,860,024 | ---- | C] (Waves Audio Ltd.) -- C:\WINDOWS\SysNative\MaxxAudioAPOShell64.dll
[2017/02/13 17:21:17 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EED64H.dll
[2017/02/13 17:21:17 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EED64A.dll
[2017/02/13 17:21:17 | 000,394,104 | ---- | C] (Waves Audio Ltd.) -- C:\WINDOWS\SysNative\MaxxAudioAPO30.dll
[2017/02/13 17:21:17 | 000,248,952 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\SysNative\Dts2APO.dll
[2017/02/13 17:21:17 | 000,137,056 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEL64H.dll
[2017/02/13 17:21:17 | 000,137,056 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEL64A.dll
[2017/02/13 17:21:17 | 000,120,160 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEA64H.dll
[2017/02/13 17:21:17 | 000,120,160 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEA64A.dll
[2017/02/13 17:21:17 | 000,092,280 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\SysNative\Dts2PropPageExt.dll
[2017/02/13 17:21:17 | 000,086,016 | ---- | C] (QSound Labs, Inc.) -- C:\WINDOWS\SysNative\nQPropPageExt.dll
[2017/02/13 17:21:17 | 000,083,968 | ---- | C] (QSound Labs, Inc.) -- C:\WINDOWS\SysNative\nQAPO.dll
[2017/02/13 17:21:17 | 000,075,104 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEG64H.dll
[2017/02/13 17:21:17 | 000,075,104 | ---- | C] (Dolby Laboratories) -- C:\WINDOWS\SysNative\EEG64A.dll
[2017/02/13 16:51:49 | 000,000,000 | -HSD | C] -- C:\Recovery
[2017/02/13 15:30:07 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Documents\Složka Bluetooth Exchange
[2017/02/13 14:47:44 | 000,000,000 | RH-D | C] -- C:\ESD
[2017/02/13 14:46:15 | 000,000,000 | -H-D | C] -- C:\$Windows.~WS
[2017/02/12 21:37:34 | 000,000,000 | R--D | C] -- C:\Users\ASUS\OneDrive
[2017/02/10 23:13:37 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Desktop\Loga do Youtube
[2017/02/10 16:41:25 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Desktop\DirectX
[2017/02/10 15:15:47 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2017/02/09 20:18:27 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Documents\League of Legends
[2017/02/09 18:28:08 | 000,000,000 | ---D | C] -- C:\Users\ASUS\.QtWebEngineProcess
[2017/02/09 18:26:29 | 000,000,000 | ---D | C] -- C:\Users\ASUS\.TeamSpeak 3
[2017/02/09 17:46:14 | 000,000,000 | ---D | C] -- C:\AsusVibeData
[2017/02/09 17:45:35 | 000,000,000 | ---D | C] -- C:\Asus WebStorage
[2017/02/09 17:44:42 | 000,000,000 | -HSD | C] -- C:\aws
[2017/02/09 17:19:20 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Documents\My Games
[2017/02/09 17:19:15 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Documents\Lucius
[2017/02/09 17:13:46 | 000,000,000 | ---D | C] -- C:\Users\ASUS\Tracing
[2017/02/09 16:57:27 | 000,000,000 | -H-D | C] -- C:\temp
[2017/02/09 16:57:27 | 000,000,000 | -H-D | C] -- C:\dvmexp
[2017/02/09 16:57:13 | 000,000,000 | -H-D | C] -- C:\ASUS.000
[2017/02/09 16:56:58 | 000,000,000 | -H-D | C] -- C:\ASUS.SYS
[2017/02/09 16:53:33 | 000,000,000 | ---D | C] -- C:\Intel
[2017/02/09 16:52:52 | 000,097,792 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\SysNative\RTNUninst64.dll
[2017/02/09 16:32:30 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2017/02/09 16:25:19 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Contacts
[2017/02/09 16:25:05 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Videos
[2017/02/09 16:25:05 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Saved Games
[2017/02/09 16:25:05 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Pictures
[2017/02/09 16:25:05 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Music
[2017/02/09 16:25:05 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Links
[2017/02/09 16:25:05 | 000,000,000 | R--D | C] -- C:\Users\ASUS\Downloads
[2017/02/09 16:24:53 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Obrázky
[2017/02/09 16:24:53 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Hudba
[2017/02/09 16:24:53 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Filmy
[2017/02/09 16:17:05 | 000,000,000 | -HSD | C] -- C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2017/03/02 09:37:31 | 000,888,125 | ---- | M] () -- C:\WINDOWS\ZAM.krnl.trace
[2017/03/02 09:37:31 | 000,866,584 | ---- | M] () -- C:\WINDOWS\ZAM_Guard.krnl.trace
[2017/03/02 09:32:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ASUS\Desktop\OTL.exe
[2017/03/02 08:37:15 | 000,091,584 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2017/03/02 08:05:11 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2017/03/01 11:14:33 | 000,001,024 | ---- | M] () -- C:\WINDOWS\SysWow64\%TMP%
[2017/03/01 11:14:25 | 001,771,058 | ---- | M] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2017/03/01 11:14:25 | 000,741,366 | ---- | M] () -- C:\WINDOWS\SysNative\perfh005.dat
[2017/03/01 11:14:25 | 000,724,962 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2017/03/01 11:14:25 | 000,152,614 | ---- | M] () -- C:\WINDOWS\SysNative\perfc005.dat
[2017/03/01 11:14:25 | 000,136,604 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2017/03/01 11:14:22 | 000,001,219 | ---- | M] () -- C:\Users\Public\Desktop\VMware Workstation Pro.lnk
[2017/02/27 14:26:08 | 000,176,584 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMChameleon.sys
[2017/02/27 14:26:02 | 000,110,536 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\farflt.sys
[2017/02/27 14:26:01 | 000,043,968 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2017/02/27 14:26:00 | 000,251,848 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2017/02/25 19:55:09 | 000,002,619 | ---- | M] () -- C:\Users\Public\Desktop\ASUS MultiFrame.lnk
[2017/02/25 19:46:15 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2017/02/25 19:46:11 | 851,484,671 | -HS- | M] () -- C:\hiberfil.sys
[2017/02/24 20:48:49 | 002,423,296 | ---- | M] (Farbar) -- C:\Users\ASUS\Desktop\FRST64.exe
[2017/02/23 20:14:10 | 000,000,753 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\etc\hosts
[2017/02/23 20:12:43 | 000,024,064 | ---- | M] () -- C:\WINDOWS\zoek-delete.exe
[2017/02/23 20:12:08 | 001,309,184 | ---- | M] () -- C:\Users\ASUS\Desktop\zoek.exe
[2017/02/23 19:51:25 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\WINDOWS\SysNative\drivers\zamguard64.sys
[2017/02/23 19:51:25 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\WINDOWS\SysNative\drivers\zam64.sys
[2017/02/23 19:51:23 | 000,001,164 | ---- | M] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
[2017/02/23 19:03:50 | 000,002,064 | ---- | M] () -- C:\Users\ASUS\Desktop\FL Studio 12 (64bit).lnk
[2017/02/23 19:03:50 | 000,002,048 | ---- | M] () -- C:\Users\ASUS\Desktop\FL Studio 12.lnk
[2017/02/23 15:35:53 | 000,028,272 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\TrueSight.sys
[2017/02/23 12:24:10 | 000,002,775 | ---- | M] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2017/02/22 14:32:27 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\ASUS\Desktop\hijackthis.exe
[2017/02/22 11:42:47 | 001,663,040 | ---- | M] (Malwarebytes) -- C:\Users\ASUS\Desktop\JRT.exe
[2017/02/21 21:17:12 | 000,035,973 | ---- | M] () -- C:\Users\ASUS\Desktop\large.jpg
[2017/02/21 10:22:26 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2017/02/20 19:05:49 | 000,000,352 | ---- | M] () -- C:\Users\ASUS\Documents\Dokument.rtf
[2017/02/19 14:50:33 | 000,001,184 | ---- | M] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
[2017/02/19 14:38:08 | 000,001,004 | ---- | M] () -- C:\Users\Public\Desktop\Bandicam.lnk
[2017/02/19 14:16:35 | 000,001,086 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2017/02/19 14:10:36 | 000,001,222 | ---- | M] () -- C:\Users\Public\Desktop\OBS Studio.lnk
[2017/02/19 12:57:06 | 025,983,048 | ---- | M] () -- C:\Users\ASUS\Desktop\RogueKillerX64.exe
[2017/02/19 10:58:10 | 000,001,883 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2017/02/19 00:59:35 | 005,147,664 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2017/02/19 00:28:41 | 004,015,056 | ---- | M] () -- C:\Users\ASUS\Desktop\adwcleaner_6.043.exe
[2017/02/19 00:26:55 | 000,047,672 | ---- | M] (Disc Soft Ltd) -- C:\WINDOWS\SysNative\drivers\dtliteusbbus.sys
[2017/02/19 00:26:52 | 000,030,264 | ---- | M] (Disc Soft Ltd) -- C:\WINDOWS\SysNative\drivers\dtlitescsibus.sys
[2017/02/19 00:26:52 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2017/02/19 00:22:43 | 000,002,679 | ---- | M] () -- C:\Users\ASUS\Desktop\µTorrent.lnk
[2017/02/17 15:49:04 | 001,745,984 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2017/02/17 09:59:28 | 000,004,498 | ---- | M] () -- C:\Users\ASUS\Desktop\logo cloudgirl ggg.bmp
[2017/02/17 09:47:39 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Install Creator Pro.lnk
[2017/02/16 19:45:22 | 000,001,216 | ---- | M] () -- C:\Users\ASUS\Desktop\CrystalDiskInfo.lnk
[2017/02/16 18:04:15 | 000,001,047 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 12.lnk
[2017/02/16 11:41:36 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2017/02/15 11:41:36 | 000,068,530 | ---- | M] () -- C:\Users\ASUS\Desktop\10891425_374932039345838_7875696020907174589_n.jpg
[2017/02/15 11:41:20 | 000,017,154 | ---- | M] () -- C:\Users\ASUS\Desktop\1800394_343746145797761_819933406258150838_n.jpg
[2017/02/15 10:40:11 | 000,001,428 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo Burning Studio 16.lnk
[2017/02/15 09:20:25 | 000,001,648 | ---- | M] () -- C:\Users\Public\Desktop\BlueStacks.lnk
[2017/02/14 21:09:14 | 000,001,023 | ---- | M] () -- C:\Users\Public\Desktop\Audacity.lnk
[2017/02/14 19:59:26 | 000,001,061 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Pro 14.0 (64-bit).lnk
[2017/02/14 19:49:56 | 000,001,550 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Application Manager.lnk
[2017/02/14 18:27:22 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2017/02/14 18:25:22 | 000,002,747 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2017/02/14 18:21:59 | 000,001,306 | ---- | M] () -- C:\Users\Public\Desktop\WebStorage.lnk
[2017/02/14 18:11:26 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2017/02/14 18:06:26 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2017/02/14 18:03:22 | 000,002,080 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
[2017/02/14 18:03:22 | 000,002,048 | ---- | M] () -- C:\Users\Public\Desktop\ASUS Vibe Fun Center.lnk
[2017/02/14 17:51:59 | 000,001,226 | ---- | M] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2017/02/14 17:50:28 | 000,001,432 | ---- | M] () -- C:\Users\Public\Desktop\GeForce Experience.lnk
[2017/02/14 17:39:45 | 000,000,850 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2017/02/14 17:32:20 | 000,002,279 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2017/02/14 17:18:11 | 000,009,528 | ---- | M] () -- C:\WINDOWS\diagwrn.xml
[2017/02/14 17:18:11 | 000,009,528 | ---- | M] () -- C:\WINDOWS\diagerr.xml
[2017/02/14 17:09:00 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sdbinst.exe
[2017/02/14 17:09:00 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sdbinst.exe
[2017/02/14 17:00:33 | 000,000,177 | -H-- | M] () -- C:\dvmexp.idx
[2017/02/14 16:07:31 | 000,461,075 | ---- | M] () -- C:\Users\ASUS\Desktop\computer-water-feature-hampton-court-flower-show-use-of-junk-material-A1A511.jpg
[2017/02/13 18:48:01 | 000,337,233 | ---- | M] () -- C:\Users\ASUS\Desktop\Bez názvu.wma
[2017/02/11 20:19:00 | 000,000,163 | ---- | M] () -- C:\Users\ASUS\Documents\ClownfishForTeamspeak.ini
[2017/02/10 01:52:40 | 040,192,056 | ---- | M] () -- C:\WINDOWS\SysNative\nvcompiler.dll
[2017/02/10 01:52:40 | 035,272,760 | ---- | M] () -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2017/02/10 01:52:40 | 034,937,280 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2017/02/10 01:52:40 | 028,212,280 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglv32.dll
[2017/02/10 01:52:40 | 019,110,088 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvwgf2umx.dll
[2017/02/10 01:52:40 | 019,006,832 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2017/02/10 01:52:40 | 016,510,160 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvwgf2um.dll
[2017/02/10 01:52:40 | 016,398,896 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvd3dumx.dll
[2017/02/10 01:52:40 | 014,674,896 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2017/02/10 01:52:40 | 013,377,072 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvd3dum.dll
[2017/02/10 01:52:40 | 011,122,912 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2017/02/10 01:52:40 | 011,019,704 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvptxJitCompiler.dll
[2017/02/10 01:52:40 | 009,305,984 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2017/02/10 01:52:40 | 008,990,072 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvptxJitCompiler.dll
[2017/02/10 01:52:40 | 004,064,088 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvapi64.dll
[2017/02/10 01:52:40 | 003,627,064 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2017/02/10 01:52:40 | 003,583,560 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvapi.dll
[2017/02/10 01:52:40 | 003,187,256 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2017/02/10 01:52:40 | 001,983,424 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6437866.dll
[2017/02/10 01:52:40 | 001,854,400 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspcap64.dll
[2017/02/10 01:52:40 | 001,755,072 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspbridge64.dll
[2017/02/10 01:52:40 | 001,600,056 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvhdagenco6420103.dll
[2017/02/10 01:52:40 | 001,589,696 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6437866.dll
[2017/02/10 01:52:40 | 001,452,480 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspcap.dll
[2017/02/10 01:52:40 | 001,317,312 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspbridge.dll
[2017/02/10 01:52:40 | 001,051,584 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2017/02/10 01:52:40 | 000,989,120 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2017/02/10 01:52:40 | 000,961,080 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2017/02/10 01:52:40 | 000,912,440 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2017/02/10 01:52:40 | 000,895,272 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmcumd.dll
[2017/02/10 01:52:40 | 000,687,224 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvfatbinaryLoader.dll
[2017/02/10 01:52:40 | 000,611,384 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2017/02/10 01:52:40 | 000,576,192 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvfatbinaryLoader.dll
[2017/02/10 01:52:40 | 000,514,616 | ---- | M] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2017/02/10 01:52:40 | 000,504,104 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2017/02/10 01:52:40 | 000,500,792 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2017/02/10 01:52:40 | 000,492,744 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvumdshimx.dll
[2017/02/10 01:52:40 | 000,425,288 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2017/02/10 01:52:40 | 000,418,752 | ---- | M] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.dll
[2017/02/10 01:52:40 | 000,408,272 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvumdshim.dll
[2017/02/10 01:52:40 | 000,217,528 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvhda64v.sys
[2017/02/10 01:52:40 | 000,170,360 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvinitx.dll
[2017/02/10 01:52:40 | 000,153,184 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglshim64.dll
[2017/02/10 01:52:40 | 000,148,016 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvinit.dll
[2017/02/10 01:52:40 | 000,131,720 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglshim32.dll
[2017/02/10 01:52:40 | 000,120,256 | ---- | M] () -- C:\WINDOWS\SysNative\NvRtmpStreamer64.dll
[2017/02/10 01:52:40 | 000,101,824 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvaudcap64v.dll
[2017/02/10 01:52:40 | 000,091,584 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvaudcap32v.dll
[2017/02/10 01:52:40 | 000,047,664 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvhdap64.dll
[2017/02/10 01:52:40 | 000,046,016 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvvad64v.sys
[2017/02/10 01:52:40 | 000,042,606 | ---- | M] () -- C:\WINDOWS\SysNative\nvinfo.pb
[2017/02/10 01:52:40 | 000,001,951 | ---- | M] () -- C:\WINDOWS\NvContainerRecovery.bat
[2017/02/10 01:52:40 | 000,000,669 | ---- | M] () -- C:\WINDOWS\SysNative\nv-vk64.json
[2017/02/10 01:52:40 | 000,000,669 | ---- | M] () -- C:\WINDOWS\SysWow64\nv-vk32.json
[2017/02/09 23:57:14 | 006,403,640 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcpl.dll
[2017/02/09 23:57:14 | 002,477,504 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvc64.dll
[2017/02/09 23:57:12 | 001,764,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvsvcr.dll
[2017/02/09 23:57:12 | 000,548,288 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshext.dll
[2017/02/09 23:57:12 | 000,393,784 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvmctray.dll
[2017/02/09 23:57:12 | 000,083,512 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nv3dappshextr.dll
[2017/02/09 23:57:12 | 000,071,224 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvshext.dll
[2017/02/09 23:57:04 | 007,791,217 | ---- | M] () -- C:\WINDOWS\SysNative\nvcoproc.bin
[2017/02/09 23:39:48 | 000,134,592 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2017/02/09 16:57:14 | 000,000,071 | -H-- | M] () -- C:\splash.idx
[2017/02/06 20:41:09 | 000,835,576 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2017/02/06 20:41:09 | 000,177,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2017/02/03 18:37:38 | 000,093,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CompatTelRunner.exe
[2017/02/02 15:37:54 | 000,650,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll

========== Files Created - No Company Name ==========

[2017/03/01 11:14:33 | 000,001,024 | ---- | C] () -- C:\WINDOWS\SysWow64\%TMP%
[2017/03/01 11:14:25 | 001,771,058 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2017/03/01 11:14:22 | 000,001,219 | ---- | C] () -- C:\Users\Public\Desktop\VMware Workstation Pro.lnk
[2017/02/25 19:55:09 | 000,002,619 | ---- | C] () -- C:\Users\Public\Desktop\ASUS MultiFrame.lnk
[2017/02/23 20:35:27 | 000,024,064 | ---- | C] () -- C:\WINDOWS\zoek-delete.exe
[2017/02/23 20:12:04 | 001,309,184 | ---- | C] () -- C:\Users\ASUS\Desktop\zoek.exe
[2017/02/23 19:51:30 | 000,888,009 | ---- | C] () -- C:\WINDOWS\ZAM.krnl.trace
[2017/02/23 19:51:30 | 000,866,462 | ---- | C] () -- C:\WINDOWS\ZAM_Guard.krnl.trace
[2017/02/23 19:51:23 | 000,001,164 | ---- | C] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
[2017/02/23 19:03:50 | 000,002,064 | ---- | C] () -- C:\Users\ASUS\Desktop\FL Studio 12 (64bit).lnk
[2017/02/23 19:03:50 | 000,002,048 | ---- | C] () -- C:\Users\ASUS\Desktop\FL Studio 12.lnk
[2017/02/23 12:24:10 | 000,002,775 | ---- | C] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2017/02/21 21:17:12 | 000,035,973 | ---- | C] () -- C:\Users\ASUS\Desktop\large.jpg
[2017/02/21 10:22:26 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2017/02/20 19:05:49 | 000,000,352 | ---- | C] () -- C:\Users\ASUS\Documents\Dokument.rtf
[2017/02/19 14:50:33 | 000,001,184 | ---- | C] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
[2017/02/19 14:38:08 | 000,001,004 | ---- | C] () -- C:\Users\Public\Desktop\Bandicam.lnk
[2017/02/19 14:16:35 | 000,001,086 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2017/02/19 14:10:35 | 000,001,222 | ---- | C] () -- C:\Users\Public\Desktop\OBS Studio.lnk
[2017/02/19 12:59:14 | 000,028,272 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\TrueSight.sys
[2017/02/19 12:57:00 | 025,983,048 | ---- | C] () -- C:\Users\ASUS\Desktop\RogueKillerX64.exe
[2017/02/19 10:58:10 | 000,001,883 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2017/02/19 10:58:06 | 000,077,416 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\mbae64.sys
[2017/02/19 00:30:02 | 000,010,848 | R--- | C] () -- C:\WINDOWS\SysWow64\drivers\SECDRV.SYS
[2017/02/19 00:28:40 | 004,015,056 | ---- | C] () -- C:\Users\ASUS\Desktop\adwcleaner_6.043.exe
[2017/02/19 00:26:52 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2017/02/19 00:22:43 | 000,002,679 | ---- | C] () -- C:\Users\ASUS\Desktop\µTorrent.lnk
[2017/02/17 19:35:10 | 000,088,064 | ---- | C] () -- C:\WINDOWS\SysNative\CNC176DD.TBL
[2017/02/17 09:59:26 | 000,004,498 | ---- | C] () -- C:\Users\ASUS\Desktop\logo cloudgirl ggg.bmp
[2017/02/17 09:47:39 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\Install Creator Pro.lnk
[2017/02/16 19:45:22 | 000,001,216 | ---- | C] () -- C:\Users\ASUS\Desktop\CrystalDiskInfo.lnk
[2017/02/16 18:04:15 | 000,001,059 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
[2017/02/16 18:04:15 | 000,001,047 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 12.lnk
[2017/02/16 11:41:36 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2017/02/15 11:41:43 | 000,068,530 | ---- | C] () -- C:\Users\ASUS\Desktop\10891425_374932039345838_7875696020907174589_n.jpg
[2017/02/15 11:41:32 | 000,017,154 | ---- | C] () -- C:\Users\ASUS\Desktop\1800394_343746145797761_819933406258150838_n.jpg
[2017/02/15 10:40:11 | 000,001,428 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Burning Studio 16.lnk
[2017/02/15 09:21:03 | 000,000,570 | ---- | C] () -- C:\Users\ASUS\AppData\Local\TroubleshooterConfig.json
[2017/02/15 09:20:25 | 000,001,648 | ---- | C] () -- C:\Users\Public\Desktop\BlueStacks.lnk
[2017/02/15 07:09:01 | 000,445,873 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2017/02/15 07:08:44 | 000,016,303 | ---- | C] () -- C:\WINDOWS\SysWow64\ieuinit.inf
[2017/02/15 07:08:44 | 000,016,303 | ---- | C] () -- C:\WINDOWS\SysNative\ieuinit.inf
[2017/02/14 21:09:14 | 000,001,035 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2017/02/14 21:09:14 | 000,001,023 | ---- | C] () -- C:\Users\Public\Desktop\Audacity.lnk
[2017/02/14 19:59:26 | 000,001,061 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Pro 14.0 (64-bit).lnk
[2017/02/14 19:53:17 | 000,001,122 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CC 2014.lnk
[2017/02/14 19:40:23 | 000,001,056 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2014.lnk
[2017/02/14 19:31:43 | 000,001,134 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2014.lnk
[2017/02/14 19:27:18 | 000,001,511 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CC 2014.lnk
[2017/02/14 19:16:44 | 000,001,242 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2014.lnk
[2017/02/14 19:11:30 | 000,001,562 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
[2017/02/14 19:11:30 | 000,001,550 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Application Manager.lnk
[2017/02/14 18:27:22 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2017/02/14 18:21:59 | 000,001,306 | ---- | C] () -- C:\Users\Public\Desktop\WebStorage.lnk
[2017/02/14 18:11:26 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2017/02/14 18:11:26 | 000,000,941 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
[2017/02/14 18:06:26 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2017/02/14 18:04:10 | 000,451,072 | ---- | C] () -- C:\WINDOWS\SysWow64\ISSRemoveSP.exe
[2017/02/14 18:03:22 | 000,002,080 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
[2017/02/14 18:03:22 | 000,002,048 | ---- | C] () -- C:\Users\Public\Desktop\ASUS Vibe Fun Center.lnk
[2017/02/14 17:51:58 | 000,001,226 | ---- | C] () -- C:\Users\Public\Desktop\HD VDeck.lnk
[2017/02/14 17:50:28 | 000,001,432 | ---- | C] () -- C:\Users\Public\Desktop\GeForce Experience.lnk
[2017/02/14 17:50:14 | 000,120,256 | ---- | C] () -- C:\WINDOWS\SysNative\NvRtmpStreamer64.dll
[2017/02/14 17:48:47 | 000,326,656 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1.dll
[2017/02/14 17:48:47 | 000,322,560 | ---- | C] () -- C:\WINDOWS\SysNative\vulkan-1.dll
[2017/02/14 17:48:47 | 000,118,272 | ---- | C] () -- C:\WINDOWS\SysNative\vulkaninfo.exe
[2017/02/14 17:48:47 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo.exe
[2017/02/14 17:44:41 | 040,192,056 | ---- | C] () -- C:\WINDOWS\SysNative\nvcompiler.dll
[2017/02/14 17:44:41 | 035,272,760 | ---- | C] () -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2017/02/14 17:44:41 | 000,000,669 | ---- | C] () -- C:\WINDOWS\SysNative\nv-vk64.json
[2017/02/14 17:44:41 | 000,000,669 | ---- | C] () -- C:\WINDOWS\SysWow64\nv-vk32.json
[2017/02/14 17:39:08 | 000,057,263 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\BCM20702A1_001.002.014.0889.0928.hex
[2017/02/14 17:38:54 | 000,000,850 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2017/02/14 17:32:20 | 000,002,291 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2017/02/14 17:32:20 | 000,002,279 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2017/02/14 17:32:16 | 007,791,217 | ---- | C] () -- C:\WINDOWS\SysNative\nvcoproc.bin
[2017/02/14 17:31:38 | 000,001,951 | ---- | C] () -- C:\WINDOWS\NvContainerRecovery.bat
[2017/02/14 17:21:47 | 000,001,426 | ---- | C] () -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2017/02/14 17:17:39 | 000,009,528 | ---- | C] () -- C:\WINDOWS\diagwrn.xml
[2017/02/14 17:17:39 | 000,009,528 | ---- | C] () -- C:\WINDOWS\diagerr.xml
[2017/02/14 17:16:58 | 000,000,369 | ---- | C] () -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
[2017/02/14 17:16:58 | 000,000,369 | ---- | C] () -- C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
[2017/02/14 17:11:43 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
[2017/02/14 16:06:20 | 000,461,075 | ---- | C] () -- C:\Users\ASUS\Desktop\computer-water-feature-hampton-court-flower-show-use-of-junk-material-A1A511.jpg
[2017/02/13 18:48:00 | 000,337,233 | ---- | C] () -- C:\Users\ASUS\Desktop\Bez názvu.wma
[2017/02/13 18:32:53 | 851,484,671 | -HS- | C] () -- C:\hiberfil.sys
[2017/02/11 12:18:54 | 000,000,163 | ---- | C] () -- C:\Users\ASUS\Documents\ClownfishForTeamspeak.ini
[2017/02/09 17:13:39 | 000,002,747 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2017/02/09 17:04:51 | 000,000,177 | -H-- | C] () -- C:\dvmexp.idx
[2017/01/26 01:13:16 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkaninfo-1-1-0-39-1.exe
[2017/01/26 01:12:46 | 000,326,656 | ---- | C] () -- C:\WINDOWS\SysWow64\vulkan-1-1-0-39-1.dll

========== ZeroAccess Check ==========

[2017/02/14 20:04:25 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2016/08/27 20:44:44 | 022,360,288 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016/08/27 19:26:06 | 019,789,232 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/11/21 06:24:57 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/11/21 06:25:59 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/11/21 06:24:57 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Purity Check ==========



< End of report >

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 02 bře 2017 09:51

OTL Extras logfile created on: 2. 3. 2017 9:34:11 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ASUS\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18538)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy

5,99 Gb Total Physical Memory | 3,75 Gb Available Physical Memory | 62,53% Memory free
8,30 Gb Paging File | 5,96 Gb Available in Paging File | 71,80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 404,88 Gb Total Space | 303,79 Gb Free Space | 75,03% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 135,05 Gb Free Space | 29,00% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 335,15 Gb Free Space | 71,96% Space Free | Partition Type: NTFS
Drive F: | 292,97 Gb Total Space | 280,20 Gb Free Space | 95,64% Space Free | Partition Type: NTFS

Computer Name: ASUS-PC | User Name: ASUS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17BC9CD0-3EED-4238-8C35-7062617687A9}" = lport=445 | protocol=6 | dir=in | app=system |
"{1AEE9FB0-138F-4146-BAEB-B6BB1AD33432}" = lport=137 | protocol=17 | dir=in | app=system |
"{1D18AD0E-45F2-4205-9E52-40F6A1EC0ABF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{26CB033D-669F-4B4D-AC09-6AE11E3E57C2}" = rport=137 | protocol=17 | dir=out | app=system |
"{2EF5D31B-C314-4507-A142-F726B508FA1C}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3D4C8C2D-4771-46E4-9175-4A9FD56ED6FC}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvcontainer\nvcontainer.exe |
"{3DEA9D49-9E9F-42F4-8C93-A70A4A659134}" = lport=139 | protocol=6 | dir=in | app=system |
"{40F6EF02-8CDC-4FE2-A0D9-B77D4413E658}" = lport=47995 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{479683E0-338A-400C-A9DB-4C5B9986CE7C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{56A43CC2-78FC-4A08-9A32-3558F2C1BD48}" = rport=139 | protocol=6 | dir=out | app=system |
"{6E5D2764-A97A-4D01-8BFE-906437319118}" = lport=35043 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{76CCCF00-E55C-4E09-AEAF-1E8563302B49}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8D8A1B0C-98BA-42B2-AB73-A59D8F78BFB9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9AE56D07-EBF8-4B8E-8FB4-90F2381A67B8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AA118010-3592-46FF-ABB3-F63344A5CF8C}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{AB53534C-7A8E-483A-A016-CE0A0E2327D2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B465D0A9-C7C8-4C6F-B8EC-56AFCC1ED4E6}" = lport=8317 | protocol=6 | dir=in | name=techsmith camtasia studio |
"{B9BF3D22-3767-4EEC-A30F-1385DCA2C3B9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DB986FD7-6970-4516-9EBA-23731096DD11}" = rport=138 | protocol=17 | dir=out | app=system |
"{E09145F9-4EB9-46A1-AF3B-E32EC9C78FB8}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{E380A6D3-B686-452E-B539-FD4193A38667}" = rport=445 | protocol=6 | dir=out | app=system |
"{E87FC704-E4C4-4067-8E13-6E09AC241B6A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E952C88E-EA52-47C3-B4A6-9ED2E42B828B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F03A7BAE-C754-412B-A12A-910A9EC53506}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvcontainer\nvcontainer.exe |
"{F37F5FB9-9DFB-4E44-97A3-7B99C08A0BBA}" = lport=138 | protocol=17 | dir=in | app=system |
"{F5C5686D-A7DE-43F0-B04C-D09B2FBE8D49}" = lport=10243 | protocol=6 | dir=in | app=system |
"{F649C08B-2B69-4F8E-8094-DA4EDF1346B9}" = lport=47998 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamuseragent.exe |
"{F7AB6E3F-D7DF-49B1-8798-3D0F4A74441D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F872167C-5260-4E06-955E-69B195DBB357}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{042DD561-6958-4BE6-ACCE-52B37F45565F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{056AAC07-454D-4674-A218-1340087261ED}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{06482A28-FD34-479B-83D2-42BD09997929}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command and conquer 3 tw and kw\cnc3launcher.exe |
"{07741EE7-693F-4D4A-BEEC-7861F469CE59}" = dir=out | name=@{microsoft.bingfinance_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{07A4A051-0A5C-46B0-AA48-0CE472579605}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{092CD12E-7F9E-436A-B383-5A6EC8DB6C94}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B9DBAA1-F9EA-4FB6-8939-B6483CF3ECBB}" = dir=out | name=@{microsoft.zunevideo_2.6.446.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{0E5266F0-C387-470C-B407-00B5B67C0224}" = dir=out | name=windows_ie_ac_001 |
"{12015D80-7FD5-4DAE-B20E-72640FD3DA40}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command and conquer generals zero hour\generals.exe |
"{149E605E-AD6B-4704-8D9E-3DA4F6F5EBC0}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\euro truck simulator 2\bin\win_x64\eurotrucks2.exe |
"{14F52A4A-9277-4155-BAD6-C8AA4AEEF102}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{154E0169-F70E-4118-A29D-915BB59DB466}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\garrysmod\hl2.exe |
"{1A2E4CEB-1802-47AE-A89A-05FA77D4ECA4}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\paladins\binaries\win32\hirezbridge.exe |
"{1CB143BB-66DB-437D-B391-F803DB4533E3}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{273DD849-9B0B-4D94-AC74-46065D72DDBA}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\team fortress 2\hl2.exe |
"{32ADF508-94C7-4B74-806A-D27B02BA7419}" = protocol=6 | dir=out | app=system |
"{364DC8D3-4B70-4472-909C-CAC3486B368E}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\payday 2\payday2_win32_release.exe |
"{3A6F6ADB-121D-4640-A6C1-1FE69DA03D22}" = protocol=6 | dir=in | app=c:\users\asus\appdata\roaming\utorrent\utorrent.exe |
"{3EFD62A2-367A-4615-AE6C-3ECE03EB6617}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{41E59624-CA0E-4255-B76B-5EAEC1664BDC}" = dir=in | name=onenote |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{431C756E-07C1-43A6-B028-02AC986938C9}" = protocol=6 | dir=in | app=f:\v1.05_raft_win64\v1.05_raft_win64.exe |
"{45E6B5E3-BE44-423C-87B0-EC4F1CC9719A}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{4603488F-C77B-448C-AAC4-923D2CD04C81}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{464D998F-88E7-4156-A9B0-EE93C7A6FA4A}" = dir=out | name=@{microsoft.bingweather_3.0.4.350_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{47640C93-7007-4714-8018-7A827C17DCD0}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
"{49B2F452-17ED-490E-A1BB-E91B3115F783}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\euro truck simulator 2\bin\win_x64\eurotrucks2.exe |
"{4B205728-EC0F-4B47-A279-C0E385436F00}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\garrysmod\hl2.exe |
"{4C1AE4F7-D4B7-4805-9939-0A1ACE2FDFBD}" = dir=out | name=@{microsoft.bingsports_3.0.4.345_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{4CBCE68C-E530-4265-83F2-00016DB7FF37}" = dir=out | name=shazam |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{54DD3E2E-6EC5-446D-BC0D-65DCFA9D5706}" = protocol=17 | dir=in | app=c:\users\asus\appdata\roaming\utorrent\utorrent.exe |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{5A71FE59-697A-479A-BD92-5FEB475B53D9}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\paladins\binaries\win32\hirezbridge.exe |
"{5B5BC6B2-479E-47EC-A40B-57DA79EC0F6B}" = protocol=6 | dir=out | app=c:\users\asus\appdata\roaming\utorrent\utorrent.exe |
"{5C210A80-77DA-4213-8703-A73B56CE1BB1}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{627A1710-A7A5-4EF6-98DB-97138365FA59}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{63D96D53-D593-40C9-803C-CC8EC0629679}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe |
"{64C0767B-FD23-4D86-8E9D-BE0D1F0697A1}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{652E0F19-EBB6-4535-97D6-34A0D187E9DD}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command and conquer generals zero hour\generals.exe |
"{66018E03-6A40-423A-90E3-A36D5ADE837D}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
"{66EA0FA6-636E-4B2C-B5AD-0EA78AFFC467}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{6B73620F-C8F0-47A3-8692-2C8A473C0B82}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\dead by daylight\deadbydaylight.exe |
"{72785864-3937-483E-BEB4-C7AB0FF9D832}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{74118972-C180-4287-9966-5724AE942C60}" = protocol=58 | dir=in | app=system |
"{76C7D39B-12AE-466F-80AF-FC58F78758E2}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{7AD2200C-8CC0-42FD-939B-10B9B1451867}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\left 4 dead 2\left4dead2.exe |
"{7CA5BB1F-DF3E-4F7A-832F-55826A7135CA}" = dir=in | name=skype |
"{7EA5CD95-90A9-4560-8881-EB96B8711167}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8516FFA8-2346-4DB0-9F41-E2A0B6671ED4}" = protocol=17 | dir=in | app=c:\users\asus\appdata\roaming\utorrent\utorrent.exe |
"{8B6BB0B8-0BC7-40C3-B27B-0C28CBAAEEEE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{912002B5-E203-4C91-929F-30661D693C8E}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{9CD40811-8DA1-4C39-B0CA-81A9089DBB7D}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe |
"{9DFAD6B5-01CB-4BDF-83FF-72ABD58CAA4A}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.21234_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9E64C33F-10D3-4C9E-A7E7-DFF2DF0D7FAC}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
"{A19EE73E-BAB6-4108-AE9F-C4D73983A79A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A1E86E0E-D401-47F5-B168-884F02927EDB}" = dir=out | name=@{microsoft.bingnews_3.0.4.344_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{A73954D9-4141-4DFF-B840-AFAAC7434723}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A7A1C30A-85DF-4357-9688-30AD41F06AC9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{A8780268-959F-4225-9A8E-47ED08724813}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command conquer 4 tiberian twilight\cnc4.exe |
"{A90E0559-B5B8-47CF-83A2-75086443D0BB}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command and conquer 3 tw and kw\cnc3launcher.exe |
"{ACD8E8A8-6F34-4996-9CE8-39D58DE07DD5}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\team fortress 2\hl2.exe |
"{ADA1EA90-6089-4575-8825-2B9EAC7549F2}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B099CA9B-7434-45C4-A51C-CD2DE802D05F}" = protocol=17 | dir=in | app=f:\v1.05_raft_win64\v1.05_raft_win64.exe |
"{B335DCFB-51B0-4017-9A38-556FBBE63F5C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B85B64D7-B962-4D66-818C-B4C016715AE5}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{B9AE19FC-D933-4C30-B887-93217FD0F76D}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\payday 2\payday2_win32_release.exe |
"{BA0C19DC-B528-4288-BCBB-8080F5B15903}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BABCDD87-A893-4F25-AE3A-ED0767BCD90C}" = dir=out | name=skype |
"{BDBAC66A-6F87-4D1E-B30D-1A1D526B7CA5}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{C14FFC88-6903-4365-85EB-555AFEDC61DA}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\euro truck simulator 2\bin\win_x86\eurotrucks2.exe |
"{C41D61CD-F126-4184-B9E2-11A2903759E8}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command conquer 4 tiberian twilight\cnc4.exe |
"{C4D4D4FD-661F-4E78-A2E4-1F3E6853CE1A}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\voxelized\voxelized.exe |
"{C7A8D742-B36E-4F3A-999A-CFEB4A2C7772}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{CC455075-67D1-4C54-BF3D-ADA5D29E8201}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\dead by daylight\deadbydaylight.exe |
"{CF171403-97FA-4244-B8E5-EBC354A84983}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{CF80A663-C849-430A-83D8-DE833D88FECE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe |
"{D339379D-61FB-497B-A7B2-1AF3F0FFEBBA}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D3C086D1-8905-4DE4-B6D3-4DDE322AB25B}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D8860037-AA22-48A5-9D6E-737F571A6281}" = protocol=17 | dir=in | app=c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe |
"{D91931AF-937A-43E0-BC36-221CB3A698CD}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{D99ED6B5-DA2F-48F3-B4B4-5B1D08B67909}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DB6BD26A-A657-48E0-B173-47D8637CE1FE}" = protocol=6 | dir=in | app=c:\users\asus\appdata\roaming\utorrent\utorrent.exe |
"{DD6B1293-9B82-4B78-B388-485B5A0AF930}" = dir=out | name=@{microsoft.bingtravel_3.0.4.336_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{DEB1E0C3-C3AE-4061-BB65-C9C805AA0AEF}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
"{E8D964F7-51F9-4169-AE5E-4410D4DEDF74}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{E9328374-1FBA-4843-AB89-70C16DF9D61C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{EDB73A1C-BFA8-4FB5-B724-F8DB4449F41C}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\left 4 dead 2\left4dead2.exe |
"{F102EFE8-2AA6-4BE2-AE0B-F3BE66249EA1}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\euro truck simulator 2\bin\win_x86\eurotrucks2.exe |
"{F140B2A1-76EE-4424-BC34-E4F0142B15E7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F1AF1430-9544-4061-A83A-CAC6E84A8623}" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\voxelized\voxelized.exe |
"{F2508019-5972-4695-99C0-945DBA5F5499}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F3030A57-FED4-4F8C-8043-8D2F778D9EB3}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{F3E5BBCE-A878-43F4-AD8C-2BE63A3DE64C}" = dir=out | name=@{microsoft.zunemusic_2.6.672.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{F444D3B9-9136-49C2-A940-0E672FF0214F}" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe |
"{F5A03E2B-4F20-4640-B1D0-A45AC903F833}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F66530BA-43A4-495E-A834-395F679D5C33}" = protocol=17 | dir=out | app=c:\users\asus\appdata\roaming\utorrent\utorrent.exe |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{F7F15645-E52C-41D3-832C-247E2C22B799}" = dir=out | name=onenote |
"{FF2992CA-10D8-4407-8A80-9418CC66338A}" = protocol=6 | dir=in | app=c:\program files (x86)\logmein hamachi\hamachi-2-ui.exe |
"TCP Query User{5B4B9375-F1D8-4FFC-8B2E-8F431A610E7B}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{64947AB4-1DC4-49F9-AB37-DDF1806ED283}D:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe" = protocol=6 | dir=in | app=d:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe |
"TCP Query User{A55675FB-D434-444B-BC38-0DBEE8490A93}F:\v1.05_raft_win64\v1.05_raft_win64.exe" = protocol=6 | dir=in | app=f:\v1.05_raft_win64\v1.05_raft_win64.exe |
"UDP Query User{183DED9A-1513-4003-A060-42C0F552D050}F:\v1.05_raft_win64\v1.05_raft_win64.exe" = protocol=17 | dir=in | app=f:\v1.05_raft_win64\v1.05_raft_win64.exe |
"UDP Query User{37DB813C-EE9E-48DC-AE72-883F1D61158E}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{48C699F8-7271-4407-BC68-04532BAC3768}D:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe" = protocol=17 | dir=in | app=d:\steamlibrary\steamapps\common\counter-strike global offensive\csgo.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07C33FB0-25C8-4723-A1E4-01868089B961}" = VMware Workstation
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{2539B193-C4AD-455E-8A76-86A8AA88CD7B}" = ESET NOD32 Antivirus
"{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes verze 3.0.6.1469
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{4C79D80F-79F9-11E6-8402-BB95F5A309BD}" = VEGAS Pro 14.0 (64-bit)
"{52116C70-79F9-11E6-9541-BB95F5A309BD}" = MSVCRT Redists
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{A1C31BA5-5438-3A07-9EEE-A5FB2D0FDE36}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23506
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B0B194F8-E0CE-33FE-AA11-636428A4B73D}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23506
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel" = Ansel
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Ovladač 3D Vision 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 3.1.2.31
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Ovladač řídící jednotky 3D Vision 369.04
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Systémový software PhysX 9.16.0318
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 2.13.0.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA Wireless Controller Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Ovladač HD audia 1.3.34.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio" = NVIDIA Virtuální audio Miracast 378.66
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend" = NVIDIA Backend
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer" = NVIDIA Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem" = NVIDIA LocalSystem Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus" = NVIDIA Message Bus for NvContainer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService" = NVIDIA NetworkService Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User" = NVIDIA User Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.UserElevated" = NVIDIA Elevated User Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer" = NVIDIA Display Container
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS" = NVIDIA Display Container LS
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs" = NvNodejs
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog" = NVIDIA Watchdog Plugin for NvContainer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry" = NvTelemetry
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC" = Nvidia Share
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 2.13.0.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 3.40.1
"{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}" = WIDCOMM Bluetooth Software
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"DAEMON Tools Lite" = DAEMON Tools Lite
"Steam App 440" = Team Fortress 2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VulkanRT1.0.39.1" = Vulkan Run Time Libraries 1.0.39.1
"WinRAR archiver" = WinRAR 5.40 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{07BE616F-9E42-4C90-AF4F-0F32A5B088E7}" = Adobe Premiere Pro CC 2014
"{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1" = Red Giant Link
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{192E2132-E977-4D3E-90BA-9DBCE1B57F8C}" = Heroes of Might and Magic® IV
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2B22C750-5C3B-4738-B621-BA786AC7A494}" = Adobe After Effects CC 2014
"{2B4B4082-8043-4646-8334-B0A29E641211}" = Adobe Illustrator CC 2014
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{35A2FE53-CC80-4D17-941F-3A7C82824FC7}" = Command & Conquer™ 3 Tiberium Wars and Kane's Wrath
"{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506
"{556BEFE2-30FF-4113-98F4-01234396DF2B}" = ASUS PCE-N15 WLAN Card Utilities & Driver
"{609F6FD5-4B22-4D7A-AD30-8C9DD480D5BE}" = Command & Conquer™: Generals and Zero Hour
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{663DEEEF-EF34-4DCB-8687-73A7AA146E02}" = Adobe Media Encoder CC 2014
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{78A2D999-4673-4FCC-818E-57B0AF8F3B70}" = BikaQ Rss
"{82FF9CEB-A50B-45A4-B6B1-7BF8C585D8CA}" = Heroes of Might and Magic V - Tribes of the East
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1" = Zemana AntiMalware
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0405-1000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{91B33C97-A730-69CE-7A4F-4ADF378BB993}_is1" = Ashampoo Burning Studio 16
"{91B5DF26-717A-4A5F-AB10-CD450FAD428C}" = LogMeIn Hamachi
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B22D57A-5338-49A5-AC08-70FE3E8B878B}" = Heroes of Might and Magic V
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2A41B60-D51F-4C04-BC94-B4C94F7B6DC0}" = Camtasia Studio 8
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B829E117-D072-41EA-9606-9826A38D34C1}" = Sophos Virus Removal Tool
"{BA4C8F9F-D81B-4AFE-AE5A-3837830F5B89}" = Command & Conquer™ 4 Tiberian Twilight
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}" = Adobe Photoshop CC 2014
"{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1" = Trapcode Suite v13.1.0
"{EEF7568A-BD2C-42B7-A22E-6D55EA287C34}" = Heroes of Might and Magic V - Hammers of Fate
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"{F70BCE36-25F2-4475-A918-6209B3D85BF3}" = Intel(R) C++ Redistributables on Intel(R) 64
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FB4D076A-DEFD-4EAF-AD63-70D5A3BC262A}" = ASUS MultiFrame
"{FC965A47-4839-40CA-B618-18F486F042C6}" = Skype™ 7.32
"4K Video Downloader_is1" = 4K Video Downloader 3.8
"ASIO4ALL" = ASIO4ALL
"Asus Vibe2.0" = AsusVibe2.0
"Audacity®_is1" = Audacity 2.1.2
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"BlueStacks" = BlueStacks App Player
"CrystalDiskInfo_is1" = CrystalDiskInfo 7.0.5
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FL Studio 12" = FL Studio 12
"FL Studio ASIO" = FL Studio ASIO
"Google Chrome" = Google Chrome
"Heroes of Might and Magic 3 Complete_is1" = Heroes of Might and Magic 3 Complete
"IL Download Manager" = IL Download Manager
"Install Creator Pro" = Install Creator Pro
"InstallShield_{192E2132-E977-4D3E-90BA-9DBCE1B57F8C}" = Heroes of Might and Magic® IV
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platforma Ovladače zařízení
"LogMeIn Hamachi" = LogMeIn Hamachi
"Need For Speed - Porsche Unleashed" = Need For Speed - Porsche Unleashed
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OBS Studio" = OBS Studio
"Origin" = Origin
"Steam" = Steam
"TeamViewer" = TeamViewer 12
"VLC media player" = VLC media player
"WebStorage" = WebStorage

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = ROBLOX Player for ASUS
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1. 3. 2017 17:34:23 | Computer Name = ASUS-PC | Source = MsiInstaller | ID = 11723
Description =

Error - 2. 3. 2017 3:07:03 | Computer Name = ASUS-PC | Source = Perflib | ID = 1008
Description =

Error - 2. 3. 2017 3:07:04 | Computer Name = ASUS-PC | Source = Perflib | ID = 1008
Description =

Error - 2. 3. 2017 3:07:04 | Computer Name = ASUS-PC | Source = Perflib | ID = 1008
Description =

Error - 2. 3. 2017 3:07:07 | Computer Name = ASUS-PC | Source = Perflib | ID = 1008
Description =

Error - 2. 3. 2017 3:07:09 | Computer Name = ASUS-PC | Source = PerfNet | ID = 2004
Description =

Error - 2. 3. 2017 3:07:10 | Computer Name = ASUS-PC | Source = Perflib | ID = 1023
Description =

Error - 2. 3. 2017 3:07:13 | Computer Name = ASUS-PC | Source = Perflib | ID = 1022
Description =

Error - 2. 3. 2017 3:07:13 | Computer Name = ASUS-PC | Source = Perflib | ID = 1018
Description =

Error - 2. 3. 2017 3:07:13 | Computer Name = ASUS-PC | Source = Perflib | ID = 1008
Description =

[ System Events ]
Error - 1. 3. 2017 3:14:06 | Computer Name = ASUS-PC | Source = NetBT | ID = 4321
Description = Název ASUS-PC :0 nelze zaregistrovat v rozhraní s IP adresou
192.168.0.106. Počítač s IP adresou 192.168.0.104 nepovolil získání názvu tímto počítačem.

Error - 1. 3. 2017 3:31:38 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 3:32:08 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 7:27:40 | Computer Name = ASUS-PC | Source = Service Control Manager | ID = 7023
Description = Služba WinSAPSvc byla ukončena s následující chybou: %%193

Error - 1. 3. 2017 8:02:44 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 8:02:50 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 8:02:50 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 8:02:50 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 8:02:50 | Computer Name = ASUS-PC | Source = DCOM | ID = 10010
Description =

Error - 1. 3. 2017 17:34:15 | Computer Name = ASUS-PC | Source = Service Control Manager | ID = 7023
Description = Služba WinSAPSvc byla ukončena s následující chybou: %%193


< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod jaro3 » 02 bře 2017 19:06

C:\Program Files (x86)\BikaQRss
PRC - C:\Users\ASUS\AppData\Roaming\Kyubey\Kyubey.exe ()
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
C:\Users\ASUS\AppData\Roaming\Kyubey
C:\Users\ASUS\AppData\Roaming\WinSAPSvc
C:\ProgramData\Red Giant
(Trapcode AB) -- C:\WINDOWS\SysNative\TCParticleBuilder.dll
C:\Program Files (x86)\Red Giant
C:\ProgramData\RedGiant
C:\Program Files (x86)\w8i3w1l6

znáš ty programy/složky?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 03 bře 2017 06:37

C:\ProgramData\Red Giant
(Trapcode AB) -- C:\WINDOWS\SysNative\TCParticleBuilder.dll
C:\Program Files (x86)\Red Giant
C:\ProgramData\RedGiant

Tyhle programy co jsem vypsala patří k programu Adobe After Effects. Ty efekty mi zajišťuji hýbání obrazu dle hudby :)

Ty ostatní opravdu neznám :crazy:

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod jaro3 » 03 bře 2017 09:27

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
C:\Users\ASUS\AppData\Local\EmieBrowserModeList
[2017/02/14 20:04:25 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2016/08/27 20:44:44 | 022,360,288 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016/08/27 19:26:06 | 019,789,232 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/11/21 06:24:57 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/11/21 06:25:59 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/11/21 06:24:57 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\Program Files (x86)\BikaQRss
PRC - C:\Users\ASUS\AppData\Roaming\Kyubey\Kyubey.exe ()
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
C:\Users\ASUS\AppData\Roaming\Kyubey
C:\Users\ASUS\AppData\Roaming\WinSAPSvc
C:\Program Files (x86)\w8i3w1l6

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 04 bře 2017 08:00

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
C:\WINDOWS\assembly\Desktop.ini moved successfully.
File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
File\Folder c:\windows\Tasks\*.job not found.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Program Files\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
C:\Program Files (x86)\BikaQRss folder moved successfully.
File\Folder PRC - C:\Users\ASUS\AppData\Roaming\Kyubey\Kyubey.exe () not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ folder moved successfully.
C:\Users\ASUS\AppData\Roaming\Kyubey folder moved successfully.
C:\Users\ASUS\AppData\Roaming\WinSAPSvc folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{CE3E1F86-5FFB-46B3-99EE-6FEB90991064} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{C0F7F3CB-E4DE-4620-AB35-761D3A18867F} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{A0C5201D-9C6D-45CC-8589-FF6729D60B38} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{81A763DE-981D-4067-93F1-D2D41EEA1CC9} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{78D6C4E5-3455-464C-B45A-575295CC27D9} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{75A6C7FE-5AE4-44EB-BE75-F9FB3F0240A5} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{6BE0B26A-F4C7-4A05-B809-FEABE224F90F} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{6592B0DB-39C0-4F1A-B4A8-7A3B7709D51F} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{57DDA1F8-FB7C-4CB9-BD89-E8D8F8A10397} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{52706E7B-CFBE-42A8-81B6-F36D99DD3A56} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{469C3ACD-B119-4F74-8DD0-A62242674894} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{141C151D-3CC1-4286-8C17-A017CF3906FA} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{040B91C2-E26B-44CB-9F8A-43BE26EE7CFB} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6\{02D03B9E-4082-4847-A156-1B3033782049} folder moved successfully.
C:\Program Files (x86)\w8i3w1l6 folder moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: ASUS
->Temp folder emptied: 1296154230 bytes
->Temporary Internet Files folder emptied: 3534232 bytes
->Flash cache emptied: 15 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 70351283 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 337233 bytes

Total Files Cleaned = 1 307,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03042017_075227

Files\Folders moved on Reboot...
C:\Users\ASUS\AppData\Local\Temp\~DF9156F6922D5E4EC2.TMP moved successfully.
C:\Users\ASUS\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File move failed. C:\WINDOWS\temp\vmware-SYSTEM\vmauthd.log scheduled to be moved on reboot.
C:\WINDOWS\temp\vmware-SYSTEM\vmware-usbarb-3576.log moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 04 bře 2017 08:00

Čas;Skener;Typ objektu;Objekt;Hrozba;Akce;Uživatel;Informace;Hash;První výskyt
1. 3. 2017 12:28:28;Pokročilá kontrola paměti;soubor;Operační paměť » qderch.exe(3924);varianta infiltrace Win32/Obfuscated.NGT trojský kůň;vyléčen - obsahoval infikované soubory;;;4A5F5D9A941683715FE2D8EA63B30FF43441D097;

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod Orcus » 04 bře 2017 08:18

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.

Co problémy?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
AngelikaB
Level 6
Level 6
Příspěvky: 3135
Registrován: červen 13
Pohlaví: Žena
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod AngelikaB » 04 bře 2017 08:20

Windows se výrazně z toho zpomalil :/ Videa na youtube se sekaj. :/No teď nevím co dělat.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Zavirovaný pc s pomocí viru yundooo

Příspěvekod jaro3 » 04 bře 2017 09:09

Stáhni Kaspersky VRT
na svojí plochu.
Spusť program Kaspersky VRT, .Program se nainstaluje.
Potvrď licenci a klikni na „Start“ . Pokud program nabídne aktualizaci , klikni dole na na „Download Now“.
- Klikni na ozubené kolečko v pravém horním rohu. V okně vyber kromě již zatržených , svojí jednotku disku , pokud jich máš víc , můžeš zatrhnout všechny.
- zvol „Automatic Scan“ nahoře vlevo. a stiskni tlačítko „Start Scanning
- Program začne skenovat zatržené jednotky

Zaškrtnuté :
Hidden startup objects
System Memory
Disk boot sectors

Počítač
Místní disk C

Nezašrkrtnuté:
Dokumenty
My email
Místní disk D
Jednotka DVD-Rom (E)
Jednotka BD-ROM (G)
Disketová jednotka

A jiné , např. Flash disky , které máš připojeny.

- povol programu Virus Removal Tool odstranit všechny nalezené infekce
- jakmile sken skončí ,zvol záložku „Report“ , vpravo nahoře (vedle ozubeného kolečka)
- klikni na „Detected Threads“ a klikni na obrázek diskety („Save“)
- ulož do počítače zprávu a vložit ji sem do příspěvku


Stáhni si Memtest:

Políčko , ve kterém je napsáno:
All unused RAM -ponech , jak je.
-dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
V případě vyšších kapacit RAM je třeba Memtest spustit několikrát , pro 2GB ( jednotlivá největší kapacita RAM) 2x , pro 4GB 3x , pro 8Gb 4x ap.

Ještě zkontrolovat HDD na chyby ,popř. zkusit jeho defragmentaci ..

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 4 hosti