Prosím o kontrolu logu z HJT - infikovaný notebook Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 07:14

MemTest prešiel bez chyby.

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 05 bře 2017 09:23

GoodByeMomo píše:MemTest idem spustiť teraz.
Pred chvíľou som mal problém s pripojením na wifi: pripojené - žiadny internet, ale internet 100% išiel (vyskúšané na dvoch mobiloch).
Skúšal som aj spomínaný štart: notebook som vypol a zapol, pri štarte Windows bola čierna obrazovka s kurzorom, naštartoval až na druhý krát. Doteraz som ho zriedka vypínal. Používam Microsoft konto - nemôže to byť problém?


to asi ne.

Temperature : 43 C (109 F) --- více chladit HDD
000000000099 Počet udalostí zaznamenaných otrasovým senzorom
CCDB000010D7 Počet udalostí s cieľom realokovania sektorov -- tohle číslo se mi nezdá.

Stáhni HWMonitor a nainstaluj jej.
- Spusť, případně proveď update pokud bude-li potřeba, a uveď PC do plného zatížení na alespoň 15 minut, abychom mohli vidět maximální teploty, kterých HW dosahuje.
- Udělej screenshot teplot a ten sem vlož, tak jak je popsáno v návodu k tomuto fóru.
pak--file---save monitoring data --ulož si na plochu a celej obsah sem vlož.

HD Tune
Stáhni si HD Tune
http://www.svethardware.cz/forum/downlo ... ile&id=202

-nainstaluj, spusť program, klikni na záložku Error scan
Spusť Start a počkej , až skončí svojí práci. Pokud budou všechny čtverečky zelené je disk OK , pokud budou některá červená , disk odchází.

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 11:46

Tu je log bez zaťaženia. Neviem akým spôsobom by som mohol notebook priviesť do plného zaťaženia.

CPUID HWMonitor Report
-------------------------------------------------------------------------

Binaries
-------------------------------------------------------------------------

HWMonitor version 1.3.0.0

Monitoring
-------------------------------------------------------------------------

Mainboard Model Product Name (0x00000482 - 0xFB9476A0)

LPCIO
-------------------------------------------------------------------------

Hardware Monitors
-------------------------------------------------------------------------

Hardware monitor ACPI
Temperature 0 38 degC (100 degF) [0xC28] (TZ00)

Hardware monitor Battery
Voltage 0 12.19 Volts [0x2F9B] (Current Voltage)
Capacity 0 3888 mWh [0xF30] (Designed Capacity)
Capacity 1 3831 mWh [0xEF7] (Full Charge Capacity)
Capacity 2 3831 mWh [0xEF7] (Current Capacity)
Level 0 2 pc [0x62] (Wear Level)
Level 1 100 pc [0x64] (Charge Level)

Hardware monitor Intel I/O
Clock Speed 0 349.20 MHz [0x15D] (Graphics)


Processors
-------------------------------------------------------------------------

Number of processors 1
Number of threads 4

APICs
-------------------------------------------------------------------------

Processor 0
-- Core 0
-- Thread 0 0
-- Thread 1 1
-- Core 1
-- Thread 0 2
-- Thread 1 3

Timers
-------------------------------------------------------------------------

Perf timer 2.533 MHz
Sys timer 1.000 KHz


Processors Information
-------------------------------------------------------------------------

Processor 1 ID = 0
Number of cores 2 (max 2)
Number of threads 4 (max 4)
Name Intel Core i5 3230M
Codename Ivy Bridge
Specification Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Package (platform ID) Socket 988B rPGA (0x4)
CPUID 6.A.9
Extended CPUID 6.3A
Core Stepping E1/L1
Technology 22 nm
TDP Limit 35.0 Watts
Tjmax 105.0 °C
Core Speed 1197.3 MHz
Multiplier x Bus Speed 12.0 x 99.8 MHz
Stock frequency 2600 MHz
Instructions sets MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, EM64T, VT-x, AES, AVX
L1 Data cache 2 x 32 KBytes, 8-way set associative, 64-byte line size
L1 Instruction cache 2 x 32 KBytes, 8-way set associative, 64-byte line size
L2 cache 2 x 256 KBytes, 8-way set associative, 64-byte line size
L3 cache 3 MBytes, 12-way set associative, 64-byte line size
FID/VID Control yes


Turbo Mode supported, enabled
Max non-turbo ratio 26x
Max turbo ratio 32x
Max efficiency ratio 12x
Min Power 24 Watts
O/C bins none
Ratio 1 core 32x
Ratio 2 cores 30x
Ratio 3 cores 30x
Ratio 4 cores 30x
TSC 2594.0 MHz
APERF 3157.0 MHz
MPERF 2556.0 MHz

Temperature 0 38 degC (100 degF) (Core #0)
Temperature 1 38 degC (100 degF) (Core #1)
Temperature 2 39 degC (102 degF) (Package)
Voltage 0 0.84 Volts (VID)
Power 0 2.73 W (Package)
Power 1 0.79 W (IA Cores)
Power 2 0.02 W (GT)
Power 3 1.92 W (Uncore)
Clock Speed 0 1197.25 MHz (Core #0)
Clock Speed 1 1197.25 MHz (Core #1)


Thread dumps
-------------------------------------------------------------------------

CPU Thread 0
APIC ID 0
Topology Processor ID 0, Core ID 0, Thread ID 0
Type 01020105h
Max CPUID level 0000000Dh
Max CPUID ext. level 80000008h
Cache descriptor Level 1, D, 32 KB, 2 thread(s)
Cache descriptor Level 1, I, 32 KB, 2 thread(s)
Cache descriptor Level 2, U, 256 KB, 2 thread(s)
Cache descriptor Level 3, U, 3 MB, 16 thread(s)

CPUID
0x00000000 0x0000000D 0x756E6547 0x6C65746E 0x49656E69
0x00000001 0x000306A9 0x02100800 0x7FBAE3BF 0xBFEBFBFF
0x00000002 0x76035A01 0x00F0B2FF 0x00000000 0x00CA0000
0x00000003 0x00000000 0x00000000 0x00000000 0x00000000
0x00000004 0x1C004121 0x01C0003F 0x0000003F 0x00000000
0x00000004 0x1C004122 0x01C0003F 0x0000003F 0x00000000
0x00000004 0x1C004143 0x01C0003F 0x000001FF 0x00000000
0x00000004 0x1C03C163 0x02C0003F 0x00000FFF 0x00000006
0x00000005 0x00000040 0x00000040 0x00000003 0x00021120
0x00000006 0x00000077 0x00000002 0x00000009 0x00000000
0x00000007 0x00000000 0x00000281 0x00000000 0x00000000
0x00000008 0x00000000 0x00000000 0x00000000 0x00000000
0x00000009 0x00000000 0x00000000 0x00000000 0x00000000
0x0000000A 0x07300403 0x00000000 0x00000000 0x00000603
0x0000000B 0x00000001 0x00000002 0x00000100 0x00000002
0x0000000B 0x00000004 0x00000004 0x00000201 0x00000002
0x0000000C 0x00000000 0x00000000 0x00000000 0x00000000
0x0000000D 0x00000007 0x00000340 0x00000340 0x00000000
0x80000000 0x80000008 0x00000000 0x00000000 0x00000000
0x80000001 0x00000000 0x00000000 0x00000001 0x28100800
0x80000002 0x20202020 0x49202020 0x6C65746E 0x20295228
0x80000003 0x65726F43 0x294D5428 0x2D356920 0x30333233
0x80000004 0x5043204D 0x20402055 0x30362E32 0x007A4847
0x80000005 0x00000000 0x00000000 0x00000000 0x00000000
0x80000006 0x00000000 0x00000000 0x01006040 0x00000000
0x80000007 0x00000000 0x00000000 0x00000000 0x00000100
0x80000008 0x00003024 0x00000000 0x00000000 0x00000000

MSR 0x0000001B 0x00000000 0xFEE00900
MSR 0x0000003A 0x00000000 0x00000001
MSR 0x000001A0 0x00000000 0x00850089
MSR 0x000000CE 0x00080C10 0xE0011A00
MSR 0x00000017 0x00100000 0x00000000
MSR 0x00000035 0x00000000 0x00020004
MSR 0x000000C1 0x00000000 0x00000000
MSR 0x000000C2 0x00000000 0x00000000
MSR 0x000000C3 0x00000000 0x00000000
MSR 0x000000C4 0x00000000 0x00000000
MSR 0x00000186 0x00000000 0x00000000
MSR 0x00000187 0x00000000 0x00000000
MSR 0x000001AD 0x00000000 0x1E1E1E20
MSR 0x00000194 0x00000000 0x00110000
MSR 0x0000019A 0x00000000 0x00000008
MSR 0x000001A4 0x00000000 0x00000000
MSR 0x000001FC 0x00000000 0x0014005F
MSR 0x00000601 0x18141494 0x80000380
MSR 0x00000602 0x18141494 0x80000190
MSR 0x00000606 0x00000000 0x000A1003
MSR 0x00000610 0x8000815E 0x00DC8118
MSR 0x00000611 0x00000000 0x02D69AA8
MSR 0x00000639 0x00000000 0x01EBC1E8
MSR 0x00000641 0x00000000 0x00052FE7
MSR 0x00000614 0x00100000 0x00C00118
MSR 0x0000019C 0x00000000 0x88430000
MSR 0x000001A2 0x00000000 0x00691200
MSR 0x000001B1 0x00000000 0x88420000
MSR 0x00000198 0x000021C9 0x00001E00
MSR 0x00000199 0x00000000 0x00002000


Storage
-------------------------------------------------------------------------

Drive 0
Device Path \\?\ide#diskst500lt012-9ws142_______________________0001lvm1#4&3359eddd&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Type Fixed
Name ST500LT0 12-9WS142
Capacity 465.8 GB
SMART Support Yes
Volume c:\, 237.8 GBytes (43.2 percent available)
Volume d:\, 226.8 GBytes (81.7 percent available)

USB Devices
-------------------------------------------------------------------------

USB Device USB Input Device, class=0x00, subclass=0x00, vendor=0x045E, product=0x0095
USB Device Generic USB Hub, class=0x09, subclass=0x00, vendor=0x8087, product=0x0024
USB Device Qualcomm Atheros AR3012 Bluetooth 4.0, class=0xE0, subclass=0x01, vendor=0x0CF3, product=0x3004
USB Device Generic USB Hub, class=0x09, subclass=0x00, vendor=0x8087, product=0x0024
USB Device USB Composite Device, class=0xEF, subclass=0x02, vendor=0x5986, product=0x0295

Graphic APIs
-------------------------------------------------------------------------

API Intel I/O

Display Adapters
-------------------------------------------------------------------------

Display adapter 0
Display name \\.\DISPLAY1
Name Intel(R) HD Graphics 4000
Board Manufacturer Lenovo
PCI device bus 0 (0x0), device 2 (0x2), function 0 (0x0)
Vendor ID 0x8086 (0x17AA)
Model ID 0x0166 (0x3901)
Performance Level 0
Core clock 349.2 MHz


Monitor 0
Model (Seiko Epson)
ID SEC4252
Serial
Manufacturing Date Week 0, Year 2010
Size 15.3 inches
Max Resolution 1366 x 768 @ 60 Hz
Horizontal Freq. Range 0-0 kHz
Vertical Freq. Range 0-0 Hz
Max Pixel Clock 0 MHz
Gamma Factor 2.2

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 13:37

Test HD Tune je OK - všetky štvorčeky sú zelené.
FarbarRecovery Scan Tool spustím neskôr.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 05 bře 2017 19:05

OK.

udělej znovu CDI.

Stáhni si Speedfan
http://www.filehippo.com/download_speedfan/
vpravo nahoře Download Latest Version
Nainstaluj a spusť program. V okně Hint , klikni na Close. Počkej určitý čas , až se hodnoty načtou.
Vlož sem prosím obrázek (screen) z toho programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 21:35

Tu sú chýbajúce logy z FarbarRecovery Scan Tool:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-03-2017
Ran by Lenovo (administrator) on LENOVO-PC (05-03-2017 21:28:52)
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo (Available Profiles: Lenovo)
Platform: Windows 10 Pro Version 1607 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files (x86)\Lenovo\System Update\SUService.exe
(Lenovo) C:\Users\Lenovo\AppData\Local\Apps\2.0\Q1EDNP1W.L40\TJZG0DTA.YHN\lsb...tion_2d7b41b05b24775e_0001.0006_3b0a905c8de4f74a\LSB.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-04-28] (Atheros Commnucations)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8071680 2013-09-24] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6193152 2013-09-24] (Lenovo(beijing) Limited)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [410896 2012-03-26] (Synaptics)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-25] (CANON INC.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-26] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1795912 2015-07-23] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [935104 2014-11-25] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [548864 2011-12-09] (Vimicro)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-19] (Valve Corporation)
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [WebcamMaxAutoRun] => C:\Program Files (x86)\WebcamMax\wcmmon.exe [1038848 2011-07-17] ()
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [EADM] => D:\hry\Origin\Origin.exe [3600216 2014-10-19] (Electronic Arts)
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2424320 2016-06-25] (RemoteMouse.net)
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [Dropbox Update] => C:\Users\Lenovo\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-08] (Piriform Ltd)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll [2017-02-07] (Dropbox, Inc.)
Startup: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-12-05]
ShortcutTarget: Dropbox.lnk -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0bc811b5-113f-4d20-b2ef-565f38091bea}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{bb371c6f-adfb-4015-a3a0-c72d5fd0978c}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-104870834-3866067964-3722874268-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-104870834-3866067964-3722874268-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-29] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-04-28] (Atheros Commnucations)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-29] (Oracle Corporation)
Toolbar: HKLM-x32 - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Program Files (x86)\PC Translator\webie.dll [2004-05-13] ()
DPF: HKLM {233C1507-6A77-46A4-9443-F871F945D258} hxxps://fpdownload.macromedia.com/pub/s ... tor/sw.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166 [2017-03-05]
FF NewTab: Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166 -> about:newtab
FF Homepage: Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166 -> about:home
FF Extension: (Firefox Hotfix) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166\Extensions\firefox-hotfix@mozilla.org.xpi [2017-03-02]
FF Extension: (Tiny JavaScript Debugger) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166\Extensions\tinyjsdebugger@enigmail.net.xpi [2016-11-19]
FF Extension: (QuickJava) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2016-11-19]
FF Extension: (JavaScript Debugger) - C:\Users\Lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166\Extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi [2016-11-19]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-09-17] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-17] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1221171.dll [2015-10-19] (Adobe Systems, Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-15] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-10-02] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
FF Plugin HKU\S-1-5-21-104870834-3866067964-3722874268-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Lenovo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-104870834-3866067964-3722874268-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-10-02] (Pando Networks)

Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-03-04]
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-04]
CHR Extension: (Prezentácie Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-04]
CHR Extension: (Dokumenty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-04]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-04]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-04]
CHR Extension: (Tabuľky Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-04]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-04]
CHR Extension: (Skype) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-04]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-04]
CHR Extension: (Chrome Media Router) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-04]
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile [2017-03-04]
CHR Extension: (Prezentácie Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-28]
CHR Extension: (Dokumenty Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-30]
CHR Extension: (Disk Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-30]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-30]
CHR Extension: (Google Search) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-30]
CHR Extension: (Tabuľky Google) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-28]
CHR Extension: (Gmail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-30]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [182304 2014-12-13] (EasyAntiCheat Ltd)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2836296 2016-12-14] (ESET)
S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
S4 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [61768 2017-02-15] (Lenovo Group Limited)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-29] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2015-09-29] ()
S4 RemoteMouseService; C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe [18432 2016-06-25] () [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [23416 2017-01-18] ()
S4 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
S4 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-04-28] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132272 2017-01-17] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15488 2017-01-17] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180544 2017-01-17] (ESET)
R1 epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [70960 2017-01-17] (ESET)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2017-01-20] ()
S3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2016-07-20] (LogMeIn Inc.)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176584 2017-03-04] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [110536 2017-03-05] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-03-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251848 2017-03-05] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_0221ce4ec0827f74\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 SmbDrvIntel; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-03-04] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-03-04] (Zemana Ltd.)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-03-05 21:28 - 2017-03-05 21:29 - 00022456 _____ C:\Users\Lenovo\Desktop\FRST.txt
2017-03-05 21:28 - 2017-03-05 21:28 - 00000000 ____D C:\Users\Lenovo\Desktop\FRST-OlderVersion
2017-03-05 21:28 - 2017-03-05 21:28 - 00000000 ____D C:\FRST
2017-03-05 12:54 - 2017-03-05 21:28 - 02423808 _____ (Farbar) C:\Users\Lenovo\Desktop\FRST64.exe
2017-03-05 11:47 - 2017-03-05 11:47 - 00000995 _____ C:\Users\Lenovo\Desktop\HD Tune.lnk
2017-03-05 11:47 - 2017-03-05 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
2017-03-05 11:47 - 2017-03-05 11:47 - 00000000 ____D C:\Program Files (x86)\HD Tune
2017-03-05 11:44 - 2017-03-05 11:46 - 08101056 _____ C:\Users\Lenovo\Downloads\hdtune_255.exe
2017-03-05 11:14 - 2017-03-05 11:14 - 01189840 _____ ( ) C:\Users\Lenovo\Downloads\hwmonitor_1.30.exe
2017-03-05 11:14 - 2017-03-05 11:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-03-05 11:14 - 2017-03-05 11:14 - 00000000 ____D C:\Program Files\CPUID
2017-03-05 00:18 - 2017-03-05 00:19 - 05200384 _____ (AVAST Software) C:\Users\Lenovo\Desktop\aswmbr.exe
2017-03-04 23:05 - 2017-03-04 23:05 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-03-04 21:55 - 2017-03-05 21:30 - 00008508 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2017-03-04 21:48 - 2017-03-04 21:48 - 00194504 _____ C:\Users\Default\AppData\Local\FontCache3.0.0.0.dat
2017-03-04 21:48 - 2017-03-04 21:48 - 00194504 _____ C:\Users\Default User\AppData\Local\FontCache3.0.0.0.dat
2017-03-04 21:45 - 2017-03-04 21:45 - 02365296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WudfUpdate_01011.dll
2017-03-04 21:41 - 2017-03-04 21:41 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Tvsukernel
2017-03-04 21:40 - 2017-03-04 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2017-03-04 21:40 - 2017-03-04 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2017-03-04 21:22 - 2017-03-04 22:22 - 00000000 ____D C:\ProgramData\Lenovo
2017-03-04 21:01 - 2017-03-04 21:02 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2017-03-04 21:01 - 2017-03-04 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-03-04 20:39 - 2017-03-04 20:39 - 00000000 ____D C:\Users\Lenovo\AppData\Local\NetworkTiles
2017-03-04 17:52 - 2017-03-04 17:52 - 00000000 ____D C:\Users\Lenovo\AppData\Local\PeerDistRepub
2017-03-04 17:17 - 2017-03-04 17:17 - 00000000 ____H C:\Users\Lenovo\Documents\Default.rdp
2017-03-04 17:13 - 2017-03-05 21:30 - 00060817 _____ C:\WINDOWS\ZAM.krnl.trace
2017-03-04 17:13 - 2017-03-05 21:30 - 00028306 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-03-04 17:13 - 2017-03-04 17:13 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2017-03-04 17:13 - 2017-03-04 17:13 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys
2017-03-04 17:13 - 2017-03-04 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-03-04 17:13 - 2017-03-04 17:13 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-03-04 17:12 - 2017-03-04 17:12 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Zemana
2017-03-04 17:11 - 2017-03-04 17:12 - 05677776 _____ (Zemana Ltd. ) C:\Users\Lenovo\Desktop\Zemana.AntiMalware.Setup.exe
2017-03-04 17:08 - 2017-03-04 22:24 - 00000000 ____D C:\Users\Lenovo\AppData\Local\CrashDumps
2017-03-04 17:07 - 2017-03-04 17:07 - 00000000 ____D C:\Users\Default\AppData\Local\NetworkTiles
2017-03-04 17:07 - 2017-03-04 17:07 - 00000000 ____D C:\Users\Default User\AppData\Local\NetworkTiles
2017-03-04 17:06 - 2017-03-04 16:56 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2017-03-04 11:20 - 2017-03-04 11:33 - 00000000 ____D C:\zoek_backup
2017-03-02 18:10 - 2017-03-03 22:31 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-03-02 17:46 - 2017-03-02 17:46 - 00000000 ____D C:\ProgramData\RogueKiller
2017-03-02 17:45 - 2017-03-02 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2017-03-02 17:44 - 2015-04-18 10:26 - 00427224 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe
2017-03-02 17:44 - 2014-11-26 11:01 - 00004664 _____ C:\WINDOWS\system32\Drivers\CxSfPt.dat
2017-03-02 17:43 - 2017-03-02 17:43 - 00000000 ____D C:\Program Files\Dolby Digital Plus
2017-03-02 17:43 - 2013-07-25 14:39 - 00206552 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
2017-03-02 17:38 - 2017-03-02 17:44 - 00000000 ____D C:\Program Files\CONEXANT
2017-03-01 23:36 - 2017-03-01 23:36 - 00064728 _____ C:\WINDOWS\SysWOW64\RebootPrompt.exe
2017-03-01 21:37 - 2017-03-01 21:37 - 00000000 ____D C:\ProgramData\Sophos
2017-03-01 21:36 - 2017-03-01 21:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-03-01 21:36 - 2017-03-01 21:36 - 00000000 ____D C:\Program Files (x86)\Sophos
2017-02-27 13:22 - 2017-03-05 02:00 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Adobe
2017-02-27 13:06 - 2017-03-05 21:31 - 00004200 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E8DC9F36-2844-4DE5-B31A-F01BDE07B946}
2017-02-26 21:08 - 2017-02-26 21:10 - 00388608 _____ (Trend Micro Inc.) C:\Users\Lenovo\Desktop\HijackThis.exe
2017-02-26 20:16 - 2017-03-05 21:24 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-26 20:16 - 2017-03-05 21:24 - 00110536 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-02-26 20:16 - 2017-03-05 21:24 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-02-26 20:16 - 2017-03-04 23:47 - 00176584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-02-26 20:16 - 2017-03-04 23:06 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-02-26 20:16 - 2017-02-26 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-02-26 20:15 - 2017-02-26 20:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-26 20:15 - 2017-02-26 20:15 - 00000000 ____D C:\Program Files\Malwarebytes
2017-02-26 20:15 - 2017-01-20 07:47 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-02-26 13:00 - 2017-03-02 18:02 - 00000000 ____D C:\AdwCleaner
2017-02-26 12:57 - 2017-02-26 13:15 - 00000000 ____D C:\Program Files\CCleaner
2017-02-26 12:57 - 2017-02-26 12:57 - 00002860 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-02-26 12:57 - 2017-02-26 12:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-02-26 12:01 - 2017-03-04 21:40 - 00000000 ____D C:\WINDOWS\System32\Tasks\TVT
2017-02-26 11:59 - 2017-03-04 21:21 - 00000000 ____D C:\Users\Lenovo\AppData\Local\LenovoServiceBridge
2017-02-26 11:58 - 2017-03-04 21:13 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Deployment
2017-02-26 11:58 - 2017-02-26 11:58 - 00611400 _____ () C:\Users\Lenovo\Downloads\LSBsetup (1).exe
2017-02-26 10:25 - 2017-02-26 10:25 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Lenovo
2017-02-26 10:25 - 2017-02-26 10:25 - 00000000 ____D C:\Users\Lenovo\.QtWebEngineProcess
2017-02-26 10:25 - 2017-02-26 10:25 - 00000000 ____D C:\Users\Lenovo\.LSC
2017-02-26 10:19 - 2017-03-04 22:22 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2017-02-26 10:18 - 2017-02-26 10:36 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2017-02-26 10:13 - 2017-02-26 10:18 - 68929352 _____ (Lenovo) C:\Users\Lenovo\Downloads\lscsetup_x64_34002.exe
2017-02-26 10:06 - 2017-02-26 10:06 - 00611400 _____ () C:\Users\Lenovo\Downloads\LSBsetup.exe
2017-02-25 14:34 - 2016-12-21 08:43 - 04130440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-02-25 14:34 - 2016-12-21 08:43 - 01454504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2017-02-25 14:34 - 2016-12-21 08:42 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-02-25 14:34 - 2016-12-21 08:06 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-02-25 14:34 - 2016-12-14 05:38 - 17188864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-02-25 14:34 - 2016-12-09 11:42 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-02-25 14:34 - 2016-12-09 11:42 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-02-25 14:34 - 2016-12-09 11:29 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-02-25 14:34 - 2016-12-09 11:20 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-02-25 14:34 - 2016-12-09 11:01 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-02-25 14:34 - 2016-12-09 10:56 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-02-25 14:34 - 2016-12-09 10:33 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-02-25 14:34 - 2016-11-11 11:02 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2017-02-25 14:34 - 2016-11-11 10:57 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-02-25 14:34 - 2016-11-11 10:56 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-02-25 14:34 - 2016-11-11 10:16 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-02-25 14:34 - 2016-11-11 10:11 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-02-25 14:34 - 2016-11-11 10:03 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-02-25 14:34 - 2016-11-11 08:47 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-02-25 14:34 - 2016-11-11 08:38 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-02-25 14:34 - 2016-11-11 08:18 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2017-02-25 14:34 - 2016-11-11 08:15 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2017-02-25 14:34 - 2016-11-11 08:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-02-25 14:34 - 2016-11-11 08:09 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-02-25 14:34 - 2016-11-11 08:06 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2017-02-25 14:34 - 2016-11-11 08:06 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2017-02-25 14:33 - 2016-12-21 08:49 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-02-25 14:33 - 2016-12-21 08:46 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-02-25 14:33 - 2016-12-21 08:43 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-02-25 14:33 - 2016-12-21 08:43 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-02-25 14:33 - 2016-12-21 08:42 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-02-25 14:33 - 2016-12-21 08:42 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-02-25 14:33 - 2016-12-21 08:42 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-02-25 14:33 - 2016-12-21 08:41 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-02-25 14:33 - 2016-12-21 08:15 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-02-25 14:33 - 2016-12-21 08:14 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2017-02-25 14:33 - 2016-12-21 08:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-02-25 14:33 - 2016-12-21 08:08 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2017-02-25 14:33 - 2016-12-21 08:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-02-25 14:33 - 2016-12-21 08:05 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-02-25 14:33 - 2016-12-21 08:05 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-02-25 14:33 - 2016-12-21 08:05 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-02-25 14:33 - 2016-12-21 08:01 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-02-25 14:33 - 2016-12-21 07:59 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-02-25 14:33 - 2016-12-21 07:59 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-02-25 14:33 - 2016-12-21 07:58 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-02-25 14:33 - 2016-12-21 07:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-02-25 14:33 - 2016-12-21 07:56 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-02-25 14:33 - 2016-12-21 07:55 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-02-25 14:33 - 2016-12-21 07:55 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-02-25 14:33 - 2016-12-21 07:53 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-02-25 14:33 - 2016-12-21 07:53 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-02-25 14:33 - 2016-12-21 07:51 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-02-25 14:33 - 2016-12-21 07:51 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-02-25 14:33 - 2016-12-21 07:50 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-02-25 14:33 - 2016-12-21 07:49 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-02-25 14:33 - 2016-12-21 07:47 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-02-25 14:33 - 2016-12-21 06:59 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2017-02-25 14:33 - 2016-12-21 06:09 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-02-25 14:33 - 2016-12-21 06:01 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-02-25 14:33 - 2016-12-21 05:46 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2017-02-25 14:33 - 2016-12-21 05:43 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-02-25 14:33 - 2016-12-21 05:41 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2017-02-25 14:33 - 2016-12-21 05:41 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-02-25 14:33 - 2016-12-21 05:40 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-02-25 14:33 - 2016-12-21 05:40 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2017-02-25 14:33 - 2016-12-21 05:40 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-02-25 14:33 - 2016-12-21 05:40 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-02-25 14:33 - 2016-12-21 05:39 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-02-25 14:33 - 2016-12-21 05:39 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-02-25 14:33 - 2016-12-21 05:38 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2017-02-25 14:33 - 2016-12-21 05:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2017-02-25 14:33 - 2016-12-21 05:34 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-02-25 14:33 - 2016-12-21 05:33 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-02-25 14:33 - 2016-12-21 05:32 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-02-25 14:33 - 2016-12-21 05:30 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2017-02-25 14:33 - 2016-12-21 05:30 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-02-25 14:33 - 2016-12-21 05:26 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2017-02-25 14:33 - 2016-12-21 05:25 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-02-25 14:33 - 2016-12-21 05:25 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-02-25 14:33 - 2016-12-21 05:24 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-02-25 14:33 - 2016-12-21 05:22 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-02-25 14:33 - 2016-12-14 06:41 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-02-25 14:33 - 2016-12-14 06:34 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 02169184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 01669984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 01400160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 01054048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00992096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00822624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2017-02-25 14:33 - 2016-12-14 06:33 - 00813408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00779616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00752992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00571744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00513376 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00406368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2017-02-25 14:33 - 2016-12-14 06:33 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2017-02-25 14:33 - 2016-12-14 06:33 - 00190816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
2017-02-25 14:33 - 2016-12-14 06:23 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-02-25 14:33 - 2016-12-14 06:21 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2017-02-25 14:33 - 2016-12-14 06:17 - 00319288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2017-02-25 14:33 - 2016-12-14 06:14 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-02-25 14:33 - 2016-12-14 06:01 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-02-25 14:33 - 2016-12-14 06:01 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2017-02-25 14:33 - 2016-12-14 06:01 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 21:35

2017-02-25 14:33 - 2016-12-14 05:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-02-25 14:33 - 2016-12-14 05:46 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-02-25 14:33 - 2016-12-14 05:43 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2017-02-25 14:33 - 2016-12-14 05:42 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2017-02-25 14:33 - 2016-12-14 05:42 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-25 14:33 - 2016-12-14 05:42 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
2017-02-25 14:33 - 2016-12-14 05:40 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-02-25 14:33 - 2016-12-14 05:40 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-02-25 14:33 - 2016-12-14 05:39 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-02-25 14:33 - 2016-12-14 05:38 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-02-25 14:33 - 2016-12-14 05:38 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2017-02-25 14:33 - 2016-12-14 05:37 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-02-25 14:33 - 2016-12-14 05:36 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-02-25 14:33 - 2016-12-14 05:36 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-02-25 14:33 - 2016-12-14 05:35 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-02-25 14:33 - 2016-12-14 05:35 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-02-25 14:33 - 2016-12-14 05:35 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2017-02-25 14:33 - 2016-12-14 05:26 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-02-25 14:33 - 2016-12-14 05:26 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-02-25 14:33 - 2016-12-14 05:24 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2017-02-25 14:33 - 2016-12-14 05:24 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-02-25 14:33 - 2016-12-14 05:23 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-02-25 14:33 - 2016-12-14 05:22 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2017-02-25 14:33 - 2016-12-14 05:22 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-02-25 14:33 - 2016-12-14 05:22 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-02-25 14:33 - 2016-12-14 05:22 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-02-25 14:33 - 2016-12-09 11:28 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-02-25 14:33 - 2016-12-09 11:27 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-02-25 14:33 - 2016-12-09 11:20 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-02-25 14:33 - 2016-12-09 11:20 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-02-25 14:33 - 2016-12-09 11:20 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-02-25 14:33 - 2016-12-09 11:20 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-02-25 14:33 - 2016-12-09 11:19 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-02-25 14:33 - 2016-12-09 11:18 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-02-25 14:33 - 2016-12-09 11:18 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-02-25 14:33 - 2016-12-09 11:18 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-02-25 14:33 - 2016-12-09 11:18 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-02-25 14:33 - 2016-12-09 11:18 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-02-25 14:33 - 2016-12-09 11:18 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-02-25 14:33 - 2016-12-09 11:15 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-02-25 14:33 - 2016-12-09 11:11 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-02-25 14:33 - 2016-12-09 11:01 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-02-25 14:33 - 2016-12-09 11:00 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-02-25 14:33 - 2016-12-09 10:59 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-02-25 14:33 - 2016-12-09 10:59 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2017-02-25 14:33 - 2016-12-09 10:57 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-02-25 14:33 - 2016-12-09 10:52 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-02-25 14:33 - 2016-12-09 10:42 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2017-02-25 14:33 - 2016-12-09 10:41 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2017-02-25 14:33 - 2016-12-09 10:41 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2017-02-25 14:33 - 2016-12-09 10:37 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2017-02-25 14:33 - 2016-12-09 10:36 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2017-02-25 14:33 - 2016-12-09 10:36 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-02-25 14:33 - 2016-12-09 10:34 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2017-02-25 14:33 - 2016-12-09 10:32 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-02-25 14:33 - 2016-12-09 10:31 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2017-02-25 14:33 - 2016-12-09 10:31 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-02-25 14:33 - 2016-12-09 10:28 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-02-25 14:33 - 2016-12-09 10:27 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-02-25 14:33 - 2016-12-09 10:25 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2017-02-25 14:33 - 2016-12-09 10:21 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-02-25 14:33 - 2016-12-09 10:20 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-02-25 14:33 - 2016-12-09 10:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2017-02-25 14:33 - 2016-12-09 10:20 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2017-02-25 14:33 - 2016-12-09 10:18 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-02-25 14:33 - 2016-12-09 10:18 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-02-25 14:33 - 2016-12-09 10:18 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2017-02-25 14:33 - 2016-12-09 10:16 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2017-02-25 14:33 - 2016-12-09 10:15 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2017-02-25 14:33 - 2016-12-09 10:15 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2017-02-25 14:33 - 2016-12-09 10:15 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2017-02-25 14:33 - 2016-12-09 09:54 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-02-25 14:33 - 2016-11-11 11:15 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
2017-02-25 14:33 - 2016-11-11 11:14 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2017-02-25 14:33 - 2016-11-11 11:14 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-02-25 14:33 - 2016-11-11 11:13 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-02-25 14:33 - 2016-11-11 11:13 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-02-25 14:33 - 2016-11-11 11:13 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-02-25 14:33 - 2016-11-11 11:12 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2017-02-25 14:33 - 2016-11-11 11:08 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
2017-02-25 14:33 - 2016-11-11 11:03 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-02-25 14:33 - 2016-11-11 11:03 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-02-25 14:33 - 2016-11-11 11:01 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2017-02-25 14:33 - 2016-11-11 11:00 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-02-25 14:33 - 2016-11-11 11:00 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-02-25 14:33 - 2016-11-11 10:59 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-02-25 14:33 - 2016-11-11 10:56 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-02-25 14:33 - 2016-11-11 10:56 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
2017-02-25 14:33 - 2016-11-11 10:56 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
2017-02-25 14:33 - 2016-11-11 10:55 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2017-02-25 14:33 - 2016-11-11 10:55 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-02-25 14:33 - 2016-11-11 10:51 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2017-02-25 14:33 - 2016-11-11 10:27 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2017-02-25 14:33 - 2016-11-11 10:26 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-02-25 14:33 - 2016-11-11 10:26 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-02-25 14:33 - 2016-11-11 10:26 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
2017-02-25 14:33 - 2016-11-11 10:26 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
2017-02-25 14:33 - 2016-11-11 10:25 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
2017-02-25 14:33 - 2016-11-11 10:25 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-02-25 14:33 - 2016-11-11 10:25 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-02-25 14:33 - 2016-11-11 10:25 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2017-02-25 14:33 - 2016-11-11 10:25 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2017-02-25 14:33 - 2016-11-11 10:24 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-02-25 14:33 - 2016-11-11 10:23 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-02-25 14:33 - 2016-11-11 10:23 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-02-25 14:33 - 2016-11-11 10:23 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
2017-02-25 14:33 - 2016-11-11 10:22 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-02-25 14:33 - 2016-11-11 10:22 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
2017-02-25 14:33 - 2016-11-11 10:21 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-02-25 14:33 - 2016-11-11 10:21 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2017-02-25 14:33 - 2016-11-11 10:21 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-02-25 14:33 - 2016-11-11 10:20 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-02-25 14:33 - 2016-11-11 10:20 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2017-02-25 14:33 - 2016-11-11 10:20 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-02-25 14:33 - 2016-11-11 10:20 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-02-25 14:33 - 2016-11-11 10:20 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2017-02-25 14:33 - 2016-11-11 10:20 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-02-25 14:33 - 2016-11-11 10:19 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2017-02-25 14:33 - 2016-11-11 10:19 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-02-25 14:33 - 2016-11-11 10:19 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-02-25 14:33 - 2016-11-11 10:19 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2017-02-25 14:33 - 2016-11-11 10:19 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-02-25 14:33 - 2016-11-11 10:19 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-02-25 14:33 - 2016-11-11 10:18 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-02-25 14:33 - 2016-11-11 10:18 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-02-25 14:33 - 2016-11-11 10:18 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2017-02-25 14:33 - 2016-11-11 10:16 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-02-25 14:33 - 2016-11-11 10:16 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2017-02-25 14:33 - 2016-11-11 10:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2017-02-25 14:33 - 2016-11-11 10:15 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2017-02-25 14:33 - 2016-11-11 10:14 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-02-25 14:33 - 2016-11-11 10:14 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-02-25 14:33 - 2016-11-11 10:14 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
2017-02-25 14:33 - 2016-11-11 10:13 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-02-25 14:33 - 2016-11-11 10:11 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2017-02-25 14:33 - 2016-11-11 10:09 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2017-02-25 14:33 - 2016-11-11 10:07 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-02-25 14:33 - 2016-11-11 10:07 - 00779776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2017-02-25 14:33 - 2016-11-11 10:07 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2017-02-25 14:33 - 2016-11-11 10:06 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2017-02-25 14:33 - 2016-11-11 10:06 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-02-25 14:33 - 2016-11-11 10:05 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2017-02-25 14:33 - 2016-11-11 10:05 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2017-02-25 14:33 - 2016-11-11 10:04 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2017-02-25 14:33 - 2016-11-11 10:03 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-02-25 14:33 - 2016-11-11 10:03 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2017-02-25 14:33 - 2016-11-11 10:03 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2017-02-25 14:33 - 2016-11-11 10:03 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2017-02-25 14:33 - 2016-11-11 09:01 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2017-02-25 14:33 - 2016-11-11 09:00 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-02-25 14:33 - 2016-11-11 08:54 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll
2017-02-25 14:33 - 2016-11-11 08:49 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2017-02-25 14:33 - 2016-11-11 08:49 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2017-02-25 14:33 - 2016-11-11 08:47 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-02-25 14:33 - 2016-11-11 08:42 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
2017-02-25 14:33 - 2016-11-11 08:41 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-02-25 14:33 - 2016-11-11 08:25 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2017-02-25 14:33 - 2016-11-11 08:25 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2017-02-25 14:33 - 2016-11-11 08:24 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2017-02-25 14:33 - 2016-11-11 08:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2017-02-25 14:33 - 2016-11-11 08:23 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2017-02-25 14:33 - 2016-11-11 08:22 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2017-02-25 14:33 - 2016-11-11 08:21 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2017-02-25 14:33 - 2016-11-11 08:21 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-25 14:33 - 2016-11-11 08:20 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-02-25 14:33 - 2016-11-11 08:19 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-02-25 14:33 - 2016-11-11 08:19 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-02-25 14:33 - 2016-11-11 08:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-02-25 14:33 - 2016-11-11 08:19 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-02-25 14:33 - 2016-11-11 08:18 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2017-02-25 14:33 - 2016-11-11 08:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2017-02-25 14:33 - 2016-11-11 08:17 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2017-02-25 14:33 - 2016-11-11 08:16 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-25 14:33 - 2016-11-11 08:15 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2017-02-25 14:33 - 2016-11-11 08:14 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2017-02-25 14:33 - 2016-11-11 08:12 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
2017-02-25 14:33 - 2016-11-11 08:06 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-02-25 14:33 - 2016-11-11 08:05 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2017-02-25 14:33 - 2016-11-11 08:04 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-02-25 14:33 - 2016-11-11 08:04 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-02-25 14:33 - 2016-11-11 08:04 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2017-02-25 14:33 - 2016-11-11 08:04 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2017-02-25 14:33 - 2016-11-11 08:03 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2017-02-25 14:33 - 2016-11-11 08:03 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2017-02-25 14:33 - 2016-11-11 08:03 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-02-25 14:33 - 2016-11-11 08:03 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2017-02-25 14:33 - 2016-11-11 08:03 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2017-02-25 14:33 - 2016-11-11 08:03 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2017-02-25 14:33 - 2016-11-11 08:02 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-02-25 14:32 - 2016-12-21 09:04 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-02-25 14:32 - 2016-12-21 08:42 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-02-25 14:32 - 2016-12-21 08:37 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-02-25 14:32 - 2016-12-21 08:13 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2017-02-25 14:32 - 2016-12-21 08:12 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2017-02-25 14:32 - 2016-12-21 08:10 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2017-02-25 14:32 - 2016-12-21 08:09 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-02-25 14:32 - 2016-12-21 08:08 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-02-25 14:32 - 2016-12-21 08:08 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-02-25 14:32 - 2016-12-21 08:08 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-02-25 14:32 - 2016-12-21 08:08 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-02-25 14:32 - 2016-12-21 08:07 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-02-25 14:32 - 2016-12-21 08:06 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-02-25 14:32 - 2016-12-21 08:06 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-02-25 14:32 - 2016-12-21 08:06 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-02-25 14:32 - 2016-12-21 08:00 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2017-02-25 14:32 - 2016-12-21 07:57 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2017-02-25 14:32 - 2016-12-21 07:54 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2017-02-25 14:32 - 2016-12-21 07:53 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-02-25 14:32 - 2016-12-21 07:51 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-02-25 14:32 - 2016-12-21 07:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-02-25 14:32 - 2016-12-21 07:49 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-02-25 14:32 - 2016-12-21 06:03 - 00136544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqmigplugin.dll
2017-02-25 14:32 - 2016-12-21 06:02 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-02-25 14:32 - 2016-12-21 06:02 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-02-25 14:32 - 2016-12-21 06:02 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-02-25 14:32 - 2016-12-21 06:02 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-02-25 14:32 - 2016-12-21 06:02 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-02-25 14:32 - 2016-12-21 06:02 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-02-25 14:32 - 2016-12-21 05:35 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-02-25 14:32 - 2016-12-21 05:27 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2017-02-25 14:32 - 2016-12-21 05:24 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-02-25 14:32 - 2016-12-21 05:24 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-02-25 14:32 - 2016-12-21 05:24 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-02-25 14:32 - 2016-12-21 05:22 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-02-25 14:32 - 2016-12-14 06:41 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-02-25 14:32 - 2016-12-14 06:33 - 01356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-02-25 14:32 - 2016-12-14 06:26 - 01469792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2017-02-25 14:32 - 2016-12-14 06:19 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-02-25 14:32 - 2016-12-14 06:18 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-02-25 14:32 - 2016-12-14 06:18 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2017-02-25 14:32 - 2016-12-14 06:14 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2017-02-25 14:32 - 2016-12-14 06:14 - 00089416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2017-02-25 14:32 - 2016-12-14 06:08 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-02-25 14:32 - 2016-12-14 06:06 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-02-25 14:32 - 2016-12-14 05:46 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2017-02-25 14:32 - 2016-12-14 05:45 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2017-02-25 14:32 - 2016-12-14 05:42 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-02-25 14:32 - 2016-12-14 05:41 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-02-25 14:32 - 2016-12-14 05:40 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-02-25 14:32 - 2016-12-14 05:40 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2017-02-25 14:32 - 2016-12-14 05:40 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-25 14:32 - 2016-12-14 05:39 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2017-02-25 14:32 - 2016-12-14 05:39 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2017-02-25 14:32 - 2016-12-14 05:38 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-02-25 14:32 - 2016-12-14 05:36 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-02-25 14:32 - 2016-12-14 05:35 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-02-25 14:32 - 2016-12-14 05:32 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2017-02-25 14:32 - 2016-12-14 05:32 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-02-25 14:32 - 2016-12-14 05:25 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2017-02-25 14:32 - 2016-12-14 05:23 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-02-25 14:32 - 2016-12-14 05:22 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-02-25 14:32 - 2016-12-14 05:22 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-02-25 14:32 - 2016-12-14 05:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-02-25 14:32 - 2016-12-09 11:34 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-02-25 14:32 - 2016-12-09 11:34 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-02-25 14:32 - 2016-12-09 11:33 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-02-25 14:32 - 2016-12-09 11:33 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-02-25 14:32 - 2016-12-09 11:30 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-02-25 14:32 - 2016-12-09 11:19 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-02-25 14:32 - 2016-12-09 11:14 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-02-25 14:32 - 2016-12-09 11:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-02-25 14:32 - 2016-12-09 11:10 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-02-25 14:32 - 2016-12-09 11:01 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-02-25 14:32 - 2016-12-09 10:52 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-02-25 14:32 - 2016-12-09 10:51 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2017-02-25 14:32 - 2016-12-09 10:45 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2017-02-25 14:32 - 2016-12-09 10:33 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-02-25 14:32 - 2016-12-09 10:28 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-02-25 14:32 - 2016-12-09 10:27 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-02-25 14:32 - 2016-12-09 10:27 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-02-25 14:32 - 2016-12-09 10:23 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-02-25 14:32 - 2016-12-09 10:22 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-02-25 14:32 - 2016-12-09 10:21 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-02-25 14:32 - 2016-12-09 10:20 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2017-02-25 14:32 - 2016-12-09 10:19 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2017-02-25 14:32 - 2016-12-09 10:19 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-02-25 14:32 - 2016-12-09 10:19 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2017-02-25 14:32 - 2016-12-09 10:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2017-02-25 14:32 - 2016-12-09 10:17 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-02-25 14:32 - 2016-11-11 11:15 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2017-02-25 14:32 - 2016-11-11 11:02 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-02-25 14:32 - 2016-11-11 11:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-02-25 14:32 - 2016-11-11 11:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-02-25 14:32 - 2016-11-11 10:56 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2017-02-25 14:32 - 2016-11-11 10:56 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
2017-02-25 14:32 - 2016-11-11 10:54 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-02-25 14:32 - 2016-11-11 10:31 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-02-25 14:32 - 2016-11-11 10:28 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
2017-02-25 14:32 - 2016-11-11 10:27 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2017-02-25 14:32 - 2016-11-11 10:26 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
2017-02-25 14:32 - 2016-11-11 10:25 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2017-02-25 14:32 - 2016-11-11 10:25 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2017-02-25 14:32 - 2016-11-11 10:24 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2017-02-25 14:32 - 2016-11-11 10:23 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-02-25 14:32 - 2016-11-11 10:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2017-02-25 14:32 - 2016-11-11 10:21 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2017-02-25 14:32 - 2016-11-11 10:20 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2017-02-25 14:32 - 2016-11-11 10:20 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-02-25 14:32 - 2016-11-11 10:20 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2017-02-25 14:32 - 2016-11-11 10:20 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-02-25 14:32 - 2016-11-11 10:20 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2017-02-25 14:32 - 2016-11-11 10:19 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-02-25 14:32 - 2016-11-11 10:19 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2017-02-25 14:32 - 2016-11-11 10:19 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-25 14:32 - 2016-11-11 10:17 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2017-02-25 14:32 - 2016-11-11 10:17 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2017-02-25 14:32 - 2016-11-11 10:16 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2017-02-25 14:32 - 2016-11-11 10:16 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2017-02-25 14:32 - 2016-11-11 10:15 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-02-25 14:32 - 2016-11-11 10:15 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2017-02-25 14:32 - 2016-11-11 10:14 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-02-25 14:32 - 2016-11-11 10:14 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-02-25 14:32 - 2016-11-11 10:13 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-02-25 14:32 - 2016-11-11 10:13 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
2017-02-25 14:32 - 2016-11-11 10:12 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
2017-02-25 14:32 - 2016-11-11 10:09 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-02-25 14:32 - 2016-11-11 10:08 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-02-25 14:32 - 2016-11-11 10:07 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-02-25 14:32 - 2016-11-11 10:07 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-02-25 14:32 - 2016-11-11 10:07 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-02-25 14:32 - 2016-11-11 10:07 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2017-02-25 14:32 - 2016-11-11 10:07 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-02-25 14:32 - 2016-11-11 10:06 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-02-25 14:32 - 2016-11-11 10:05 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-02-25 14:32 - 2016-11-11 10:05 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-02-25 14:32 - 2016-11-11 10:04 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2017-02-25 14:32 - 2016-11-11 10:03 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-02-25 14:32 - 2016-11-11 10:03 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2017-02-25 14:32 - 2016-11-11 10:02 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2017-02-25 14:32 - 2016-11-11 10:02 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-02-25 14:32 - 2016-11-11 10:02 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2017-02-25 14:32 - 2016-11-11 09:01 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2017-02-25 14:32 - 2016-11-11 08:59 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-02-25 14:32 - 2016-11-11 08:48 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2017-02-25 14:32 - 2016-11-11 08:47 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2017-02-25 14:32 - 2016-11-11 08:42 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-02-25 14:32 - 2016-11-11 08:42 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-02-25 14:32 - 2016-11-11 08:42 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2017-02-25 14:32 - 2016-11-11 08:42 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll
2017-02-25 14:32 - 2016-11-11 08:41 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
2017-02-25 14:32 - 2016-11-11 08:27 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2017-02-25 14:32 - 2016-11-11 08:26 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
2017-02-25 14:32 - 2016-11-11 08:24 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2017-02-25 14:32 - 2016-11-11 08:24 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2017-02-25 14:32 - 2016-11-11 08:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2017-02-25 14:32 - 2016-11-11 08:22 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-02-25 14:32 - 2016-11-11 08:19 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2017-02-25 14:32 - 2016-11-11 08:19 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-02-25 14:32 - 2016-11-11 08:19 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2017-02-25 14:32 - 2016-11-11 08:18 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2017-02-25 14:32 - 2016-11-11 08:18 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-02-25 14:32 - 2016-11-11 08:18 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2017-02-25 14:32 - 2016-11-11 08:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2017-02-25 14:32 - 2016-11-11 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2017-02-25 14:32 - 2016-11-11 08:15 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-02-25 14:32 - 2016-11-11 08:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
2017-02-25 14:32 - 2016-11-11 08:09 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2017-02-25 14:32 - 2016-11-11 08:08 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
2017-02-25 14:32 - 2016-11-11 08:06 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-02-25 14:32 - 2016-11-11 08:06 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
2017-02-25 14:32 - 2016-11-11 08:05 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-02-25 14:32 - 2016-11-11 08:04 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-02-25 14:32 - 2016-11-11 08:04 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-02-25 14:32 - 2016-11-11 08:03 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-02-25 14:24 - 2016-12-21 09:08 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-02-25 14:23 - 2016-12-21 09:08 - 00245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2017-02-25 14:23 - 2016-12-21 08:45 - 00153952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcmiplugin.dll
2017-02-25 13:55 - 2017-02-25 13:55 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-25 13:55 - 2016-12-29 14:10 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-02-25 13:55 - 2016-09-09 19:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-02-25 13:55 - 2016-09-09 19:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-02-25 13:55 - 2016-09-09 19:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-02-25 13:55 - 2016-09-09 19:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-02-25 13:40 - 2017-02-06 20:48 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-25 13:40 - 2017-02-06 20:48 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-25 13:38 - 2017-02-25 13:38 - 00000000 ____D C:\WINDOWS\Panther
2017-02-24 19:31 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-02-24 19:31 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-02-24 19:15 - 2017-02-24 19:15 - 00165671 _____ C:\Users\Lenovo\Downloads\latestwu.diagcab
2017-02-24 11:44 - 2017-02-24 11:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-02-24 11:44 - 2017-02-24 11:44 - 00000000 ____D C:\ProgramData\ESET
2017-02-24 11:44 - 2017-02-24 11:44 - 00000000 ____D C:\Program Files\ESET
2017-02-24 11:36 - 2017-02-24 11:43 - 106754176 _____ (ESET) C:\Users\Lenovo\Downloads\eav_nt64_sky.exe
2017-02-24 11:35 - 2017-02-24 11:35 - 03139200 _____ (ESET) C:\Users\Lenovo\Downloads\eset_nod32_antivirus_live_installer (1).exe
2017-02-24 11:34 - 2017-02-24 11:35 - 03139200 _____ (ESET) C:\Users\Lenovo\Downloads\eset_nod32_antivirus_live_installer.exe
2017-02-24 11:23 - 2017-02-24 11:23 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-02-24 11:23 - 2017-02-24 11:23 - 00001028 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2017-02-23 11:58 - 2017-02-23 11:58 - 00000000 ____D C:\Users\Lenovo\Desktop\samsung foto
2017-02-15 20:26 - 2017-02-15 20:26 - 00257864 _____ (Lenovo Group Limited) C:\WINDOWS\system32\iMDriverHelper.dll
2017-02-12 19:31 - 2017-02-12 19:31 - 00000000 ____D C:\Users\Lenovo\Desktop\Nový priečinok
2017-02-12 17:18 - 2017-02-12 17:18 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-03-05 21:30 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-05 21:28 - 2016-10-09 19:05 - 03229024 _____ C:\WINDOWS\system32\perfh01B.dat
2017-03-05 21:28 - 2016-10-09 19:05 - 00963008 _____ C:\WINDOWS\system32\perfc01B.dat
2017-03-05 21:28 - 2016-08-15 05:58 - 07836454 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-05 21:23 - 2016-08-15 06:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-05 21:23 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-05 21:23 - 2013-09-24 15:23 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-05 21:22 - 2016-08-15 05:54 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-05 00:17 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-03-04 23:51 - 2013-10-27 20:33 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-03-04 23:32 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-04 23:12 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-04 22:24 - 2013-10-27 20:36 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\TeamViewer
2017-03-04 21:48 - 2016-08-15 05:59 - 00000000 ____D C:\Users\Lenovo
2017-03-04 21:45 - 2013-09-24 15:39 - 00000000 ____D C:\Program Files\Lenovo
2017-03-04 21:45 - 2013-09-24 15:39 - 00000000 ____D C:\Program Files (x86)\Lenovo
2017-03-04 21:07 - 2016-10-08 10:41 - 00000000 ____D C:\Users\Lenovo\Documents\Soubory aplikace Outlook
2017-03-04 18:15 - 2013-12-30 17:16 - 00000000 ____D C:\Program Files (x86)\WebcamMax
2017-03-04 17:03 - 2013-09-24 16:10 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\ESET
2017-03-04 11:33 - 2009-07-14 04:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-03-03 22:26 - 2015-11-06 18:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-02 19:46 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-02 19:40 - 2016-08-20 16:48 - 00000000 ____D C:\Users\Lenovo\AppData\LocalLow\Temp
2017-03-02 19:38 - 2016-02-19 20:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-01 21:44 - 2016-08-13 18:44 - 00000000 ____D C:\Users\Lenovo\AppData\Local\osu!
2017-02-28 22:27 - 2014-03-21 19:01 - 00000000 ____D C:\Users\čo ja viem
2017-02-28 22:26 - 2015-03-27 22:30 - 00000000 ___RD C:\Users\Lenovo\Dropbox
2017-02-28 22:10 - 2013-12-26 20:39 - 00000000 ____D C:\Program Files (x86)\Steam
2017-02-27 20:57 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2017-02-27 14:13 - 2014-12-13 13:59 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\.minecraft
2017-02-27 14:09 - 2013-09-26 17:43 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\Skype
2017-02-27 13:24 - 2013-09-24 16:21 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Apps\2.0
2017-02-26 21:42 - 2013-10-25 12:41 - 00000000 ____D C:\Users\Lenovo\AppData\Local\ElevatedDiagnostics
2017-02-26 13:13 - 2015-10-04 10:29 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\TS3Client
2017-02-26 11:59 - 2013-09-24 15:39 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2017-02-25 17:35 - 2016-08-15 06:25 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-25 17:19 - 2016-08-15 05:53 - 00338640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-25 17:16 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-02-25 17:16 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-02-25 17:16 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-02-25 17:16 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-02-25 17:15 - 2016-07-16 23:05 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\setup
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-02-25 17:15 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-02-25 17:15 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-02-25 17:15 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-02-25 17:15 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing
2017-02-25 17:14 - 2016-07-16 12:47 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-02-25 16:48 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-25 13:59 - 2016-08-16 11:24 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-25 13:56 - 2016-08-16 11:23 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-25 13:55 - 2013-09-24 15:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-02-25 13:55 - 2013-09-24 15:21 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-25 13:05 - 2016-08-16 12:42 - 00000000 __SHD C:\Users\Lenovo\IntelGraphicsProfiles
2017-02-25 12:59 - 2016-08-15 19:13 - 00007606 _____ C:\Users\Lenovo\AppData\Local\resmon.resmoncfg
2017-02-24 17:56 - 2016-09-29 18:17 - 00000000 ____D C:\Users\Lenovo\AppData\Local\Discord
2017-02-24 17:55 - 2016-09-29 18:18 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
2017-02-24 17:54 - 2013-09-24 16:21 - 00000000 ____D C:\Program Files (x86)\Google
2017-02-24 17:53 - 2016-08-15 06:35 - 00000000 ___RD C:\Users\Lenovo\OneDrive
2017-02-24 11:44 - 2016-07-16 12:47 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-02-21 21:59 - 2016-01-27 15:19 - 00000000 ____D C:\Users\Lenovo\BrawlhallaReplays
2017-02-19 20:50 - 2015-10-23 20:07 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\vlc
2017-02-17 15:38 - 2014-07-26 13:08 - 00000000 ____D C:\ProgramData\CanonIJPLM
2017-02-12 17:18 - 2015-03-27 22:26 - 00000000 ____D C:\Users\Lenovo\AppData\Roaming\Dropbox
2017-02-04 11:02 - 2013-09-24 16:22 - 00002284 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

==================== Files in the root of some directories =======

2016-08-15 19:13 - 2017-02-25 12:59 - 0007606 _____ () C:\Users\Lenovo\AppData\Local\resmon.resmoncfg
2016-08-15 06:51 - 2016-08-15 06:51 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-03-04 17:50

==================== End of FRST.txt ============================

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 21:36

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-03-2017
Ran by Lenovo (05-03-2017 21:31:33)
Running from C:\Users\Lenovo\Desktop
Windows 10 Pro Version 1607 (X64) (2016-08-15 05:24:07)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-104870834-3866067964-3722874268-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-104870834-3866067964-3722874268-503 - Limited - Disabled)
Guest (S-1-5-21-104870834-3866067964-3722874268-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-104870834-3866067964-3722874268-1003 - Limited - Enabled)
Lenovo (S-1-5-21-104870834-3866067964-3722874268-1000 - Administrator - Enabled) => C:\Users\Lenovo

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: ESET NOD32 Antivirus 10.0.390.0 (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: ESET NOD32 Antivirus 10.0.390.0 (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Reader XI - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.1.171 - Adobe Systems, Inc.)
Aktualizácie NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Angry Birds Breakfast 1 (HKLM-x32\...\{85B535D9-F249-49CB-9D75-011F420A40D7}) (Version: 1.0.16 - Rovio Entertainment Ltd.)
Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.135 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.14.15 - Atheros Communications Inc.)
Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5 (HKLM-x32\...\{E031338C-839D-4EDD-9537-99B653C39D81}) (Version: 6.5.5.24 - Autodesk, Inc.)
Brawlhalla (HKLM-x32\...\Steam App 291550) (Version: - Blue Mammoth Games)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
Canon MP280 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series) (Version: - )
Canon MP280 series User Registration (HKLM-x32\...\Canon MP280 series User Registration) (Version: - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.16.50 - Conexant)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
CPUID HWMonitor 1.30 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CrystalDiskInfo 7.0.5 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.5 - Crystal Dew World)
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.5.1 - Dolby Laboratories Inc)
Dropbox (HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\Dropbox) (Version: 19.4.13 - Dropbox, Inc.)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 7.0.3.3 - Lenovo)
Energy Management (x32 Version: 7.0.3.3 - Lenovo) Hidden
ESET NOD32 Antivirus (HKLM\...\{2C4A3E47-2A55-4AE1-969C-67B3F9F836EF}) (Version: 10.0.390.0 - ESET, spol. s r.o.)
Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.2.5 - SCS Software)
Goat Simulator (HKLM-x32\...\Steam App 265930) (Version: - Coffee Stain Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Spoločnosť Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4358 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.12.204.1 - Lenovo EasyCamera)
Lenovo Service Bridge (HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\dda9ca0b023f4c56) (Version: 1.6.6.0 - Lenovo)
Lenovo System Interface Foundation (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.0.070.04 - Lenovo)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.07.0045 - Lenovo)
Mafia II (HKLM-x32\...\Steam App 50130) (Version: - 2K Czech)
Malwarebytes verzia 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Medal of Honor™ Warfighter (HKLM-x32\...\{13AD2A08-C3B8-49F2-B374-7C1D790626BC}) (Version: 1.0.0.0 - Electronic Arts)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Minecraft1.7.2 (HKLM-x32\...\Minecraft1.7.2) (Version: - )
Moj CEWE FOTOSVET (HKLM-x32\...\Moj CEWE FOTOSVET) (Version: 6.0.5 - CEWE Stiftung u Co. KGaA)
MouseServer version 1.5.2.0 (HKLM-x32\...\{E13018F5-FFC7-4729-9C1B-1A85807D03E6}_is1) (Version: 1.5.2.0 - Necta Co.)
Mozilla Firefox 47.0.2 (x86 sk) (HKLM-x32\...\Mozilla Firefox 47.0.2 (x86 sk)) (Version: 47.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.2.6148 - Mozilla)
NVIDIA Grafický ovládač 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.0.13.2135 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{845c2eda-ec26-4ef5-988a-787b716d99f1}) (Version: latest - ppy Pty Ltd)
Ovládací panel NVIDIA 376.54 (Version: 376.54 - NVIDIA Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PC Translator 2004 Komplet (HKLM-x32\...\PC Translator 2004 Komplet) (Version: - JANOSiK TEAM)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version: - )
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7601.39016 - Realtek Semiconductor Corp.)
Remote Mouse version 3.002 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 3.002 - Remote Mouse)
Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.24 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.24.104 - Skype Technologies S.A.)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer)
The Escapists (HKLM-x32\...\Steam App 298630) (Version: - Mouldy Toof Studios)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics)
Unturned (HKLM-x32\...\Steam App 304930) (Version: - Nelson Sexton)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
WebcamMax (HKLM-x32\...\WebcamMax) (Version: 7.8.0.6.MultiLanguage - )
Windows Driver Package - Lenovo (ACPIVPC) System (12/15/2011 7.1.0.1) (HKLM\...\99841829BE839365AA67B2AD0E50D371F59F8A1E) (Version: 12/15/2011 7.1.0.1 - Lenovo)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.101 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-104870834-3866067964-3722874268-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {074C27E6-84CD-4A03-8CFF-731910BB901B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe
Task: {0CC218E9-B055-4CEA-A84F-33F8FC4AB1F3} - System32\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {0D82C475-26D5-48CB-BC81-74331AB5AC54} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate.exe
Task: {1158D50F-EAE5-4B30-8B6F-D4B3C1642A2F} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-104870834-3866067964-3722874268-1000 => Rundll32.exe dfshim.dll,ShOpenVerbShortcut C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.appref-ms
Task: {1AEE9C40-F8F2-44E6-9A8D-F4D53FA9EA64} - System32\Tasks\{8511B30E-45B4-42F5-8625-170133E1B2FA} => Chrome.exe hxxp://ui.skype.com/ui/0/6.10.60.104/sk ... rogressBar
Task: {1B92AA72-2148-463A-B0B5-80311DC56687} - System32\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {1DAFF8A5-DD1E-4415-A3A1-CCA471995082} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe
Task: {1DB2C5F2-65E0-4336-AE68-28B5ECA4B16B} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-104870834-3866067964-3722874268-1000UA1d236e7101a6a00 => C:\Users\Lenovo\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {26FD4DAA-3F91-4A5F-936F-F3609D3D35C2} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {3678DA8A-97FE-4C58-B449-CA29FB744DFA} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe
Task: {371C7618-CE62-4474-82C0-DABDE372DB5F} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe
Task: {390BD305-3731-4170-A1A5-C0D4D64D1815} - System32\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {3BC8CD40-AEDD-4E41-9466-34C5887E7B5C} - System32\Tasks\{5CD6162E-F528-4719-9994-6AC116C1AA95} => pcalua.exe -a C:\Users\Lenovo\Downloads\LeagueofLegends_EUNE_Installer_06_17_13.exe -d C:\Users\Lenovo\Downloads
Task: {4025AEF6-CA60-4BC4-86AB-1E9C654F0526} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe
Task: {435808E4-FE36-4CE3-9DDD-959DA9BB5B50} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {4A8D2013-4199-4BCF-87EA-114DFC497AFB} - System32\Tasks\AdobeAAMUpdater-1.0-Lenovo-PC-Lenovo => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-05-26] (Adobe Systems Incorporated)
Task: {4ED9A09D-B720-47E6-9D61-93F16C2B42B2} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe
Task: {519980AB-C20D-4D35-A18B-21783C5CCD81} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec.exe
Task: {5CA1F475-6261-4F8D-A091-DCB5D3633A96} - System32\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5D3E8678-E2E2-4114-901C-2465581EE6E5} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ad46306838e6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5DB0AC33-0D75-4562-B59F-DCDEAE6386C6} - System32\Tasks\GoogleUpdateTaskMachineUA1d12f4ab86e528 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5EA446A2-1F9D-463C-8A08-151ED44F5A50} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe
Task: {623885FC-797F-4F55-9B11-AF5CA47BBE06} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe
Task: {6455A2CC-4932-4526-95B1-4D75581FAE65} - System32\Tasks\{6E983478-4F1B-4EC8-94F4-46F1A2A87288} => Chrome.exe hxxp://ui.skype.com/ui/0/7.26.64.101/sk ... rogressBar
Task: {777DD35B-66FB-4C70-86B7-F93F7063A606} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe
Task: {7956ABE7-A1BB-46BE-8D33-97A61EAB30BD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-08] (Piriform Ltd)
Task: {82E10AB1-68B2-4C6B-998C-A576C84D326F} - System32\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {88441398-22D4-44B6-BF94-957C3C41C942} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => Sc.exe START ImControllerService
Task: {8EA384E9-3538-4B3F-A272-B9BAA0623EEB} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe
Task: {8EF4F202-B1C2-4665-B561-1CF769EC12CA} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-104870834-3866067964-3722874268-1000Core1d236e7f7f2f40 => C:\Users\Lenovo\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {9642C3C0-EE3E-4526-B7B7-4A83AFE5B20E} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {9D5E7FD3-E340-4679-938E-A64B632D3CAA} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {A86EB1A6-C5E5-4934-8834-C78906DD198C} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe
Task: {B1016BF6-23CF-46F9-964A-86EA4412B6E7} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\3bb6c664-7e74-4d8e-96c9-8873648519c6 => powershell.exe -nologo -noninteractive "&amp; {New-Item -Path Registry::HKCU\Software\Lenovo\ImController\ScheduledTasks\3bb6c664-7e74-4d8e-96c9-8873648519c6 -type directory -force;$conter=Get-Date;$conter=$conter.ToUniversalTime();Set-ItemProperty -Path Registry::HKCU\Software\Lenovo\ImController\ScheduledTasks\3 (the data entry has 73 more characters).
Task: {B3FB6E62-04BF-4401-B285-C18D668FDA40} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe
Task: {B56C00FA-BE75-4F38-9EAD-5012BBE8E7C4} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2017-01-18] ()
Task: {B6E4C0FE-E7E6-43D8-840A-DE203ABEE515} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2017-01-18] ()
Task: {BCDB51B0-5617-45BA-99A6-EB70379E6C15} - System32\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {BF2D3C0A-F813-467C-941B-DA552C4D298F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-17] (Adobe Systems Incorporated)
Task: {CF756EE8-AFE4-400F-8066-5A78D79559DC} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe
Task: {D030F552-F00D-4B4B-84C0-09E434A075FC} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-01] (Lenovo)
Task: {D37F56A6-E4FF-4ADD-A92A-BDCE80BD7202} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {E45BC06C-4245-4974-9944-D525359618DF} - System32\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {E8099A9F-A127-4077-B977-FDA757BF6514} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {E9B035A5-3EDE-449A-8117-658BB02392C1} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe
Task: {ECA9AB01-717A-4325-BE3A-177659CF7EDA} - System32\Tasks\{3ED71B50-0BFE-4026-9BB6-2CD6ED626AE3} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {F2B7DAA5-DB36-4809-8473-18CADB27AD4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe
Task: {F8CE9F6A-7C7D-46CF-A7C6-13DA55104DBC} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe
Task: {FB716BE8-2A1E-4C7B-AA66-EACADF8FBA3A} - System32\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {FD9CE6D0-65C2-4A9C-B43D-6CD3295423A7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-104870834-3866067964-3722874268-1000Core1d236e7f7f2f40.job => C:\Users\Lenovo\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-104870834-3866067964-3722874268-1000UA1d236e7101a6a00.job => C:\Users\Lenovo\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Spúšťač aplikácií Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Web Applications\www.youtube.com\https_80\Moje odbery - YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxps://www.youtube.com/feed/subscriptions
ShortcutWithArgument: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Profile 1\Web Applications\www.facebook.com\https_80\Facebook.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --app=hxxps://www.facebook.com/
ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Spúšťač aplikácií Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome\Vzdialená plocha Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->

==================== Loaded Modules (Whitelisted) ==============

2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-02-25 14:34 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2013-11-05 14:23 - 2015-09-29 13:24 - 00075136 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe
2017-02-26 20:15 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-02-26 20:15 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2013-09-24 15:23 - 2016-12-29 14:16 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-02-25 14:34 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2017-03-04 17:13 - 2017-03-04 17:13 - 00154480 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2016-09-16 12:17 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-02-25 14:33 - 2016-12-21 08:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-02-25 14:32 - 2016-12-21 07:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-02-25 14:32 - 2016-12-21 07:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-02-25 14:32 - 2016-12-21 07:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-02-25 14:32 - 2016-12-21 07:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-02-25 14:32 - 2016-12-21 07:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2008-12-20 02:20 - 2013-09-24 15:39 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2012-02-21 12:06 - 2013-09-24 15:39 - 01490944 _____ () C:\Program Files (x86)\Lenovo\Energy Management\EMWpfUI.dll
2012-02-21 12:06 - 2013-09-24 15:39 - 00005120 _____ () C:\Program Files (x86)\Lenovo\Energy Management\sk-SK\EMWpfUI.resources.dll
2008-12-20 02:20 - 2013-09-24 15:39 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2017-03-04 21:40 - 2017-01-18 16:36 - 00023416 _____ () C:\Program Files (x86)\Lenovo\System Update\SUService.exe

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2017-03-04 16:57 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-104870834-3866067964-3722874268-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img13.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: CxAudMsg => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: IJPLMSVC => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: nvUpdatusService => 2
MSCONFIG\Services: RemoteMouseService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: SynTPEnhService => 2
MSCONFIG\Services: TeamViewer => 2
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: ZAtheros Bt&Wlan Coex Agent => 2
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "CanonMyPrinter"
HKLM\...\StartupApproved\Run32: => "CanonSolutionMenuEx"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Malwarebytes TrayApp"
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\...\StartupApproved\Run: => "CCleaner Monitoring"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{920FFD2E-7354-4FB9-94C2-0D41BBCA4E80}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Brawlhalla\Brawlhalla.exe
FirewallRules: [{2B35DE9F-8A20-4FFA-AC0A-EC20C976DF05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Brawlhalla\Brawlhalla.exe
FirewallRules: [{CB2399EB-BD52-4936-9DEA-0263A7376AE8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3A311A1B-6F68-4417-9367-31BB1A7B03D3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5386CA40-4923-4E94-9CCC-578202D678B3}] => (Allow) C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe
FirewallRules: [{37285DA6-4EE8-41D0-B551-9B59F44CC0BD}] => (Allow) C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe
FirewallRules: [{3A0C2AAA-C6A7-4F2E-9E45-C7A5CAA70CF8}] => (Allow) C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe
FirewallRules: [{7EDB59BD-E045-41D1-82F8-75398D976867}] => (Allow) C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe
FirewallRules: [{2C2AF1EB-59A7-4F95-9856-A59E37F0834A}] => (Allow) C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe
FirewallRules: [{56BD5C5A-300F-4754-9D8E-98D12E145F2A}] => (Allow) C:\Program Files\Adobe\Adobe Photoshop CC 2015\Photoshop.exe
FirewallRules: [{8249AD01-6824-42B5-9D66-53B0750BAF9E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{462A28BB-70EB-4FC9-B6E2-44E4EC053051}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{E1EBE0A4-248B-4B2E-9C3A-9F260113D087}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{591C9BA3-BF44-4DDB-A41C-31334FDFF9CD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8E3C125C-8A44-4FB4-9C08-1382531F4671}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{F762165D-D759-4806-8BC2-E0DD1411C4FB}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{72CFA848-CADA-4C6E-BD75-0D4545048DFC}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8A5D9821-1904-4004-A810-1EEDE3D47D79}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2E4EA487-9074-4068-9210-3DBF0C765F4E}] => (Allow) C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{D4D60CC0-1F94-4266-9AC1-EDCD822CE707}] => (Allow) C:\Users\Lenovo\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{948CF995-AB24-46E0-9BC5-22FAB79EAA84}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mafia II\pc\mafia2.exe
FirewallRules: [{34DECFE9-2A8D-4487-B5EC-3C78C038BD4B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mafia II\pc\mafia2.exe
FirewallRules: [{222B0BE4-B7F3-4FF6-BCAC-3F6F4D86C206}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{416AF4EB-C512-4F91-AF41-C6308D3774A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{B6D17652-B397-4686-B2F4-F4242694232C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Escapists\TheEscapists.exe
FirewallRules: [{9E1B0B8C-C6FB-4E32-9FE9-65F71B1FA030}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Escapists\TheEscapists.exe
FirewallRules: [{E3C158E6-54B9-494B-AB8A-6FA478DFAB53}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{1B0C2D3E-0E17-46F0-B932-244BC812415A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{3E052322-775A-4BB1-A2EC-BE31D4441D7A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{C973D432-38D1-4E46-9B5B-AC451991EAD8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{EC1CD446-27CD-4C31-BD60-E211F99792BC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{5277020A-5882-4817-BAD2-94B484B628FE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{C152C5C5-ED1F-4F4E-BF8E-AAE88264D9AD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\SaintsRowTheThird_DX11.exe
FirewallRules: [{F6707C3A-861E-4872-9E8A-77FDB99D26FA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\SaintsRowTheThird_DX11.exe
FirewallRules: [{0B8CAC1D-1899-4B12-A7C2-CD677000787A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\SaintsRowTheThird.exe
FirewallRules: [{14254C55-2C50-4C20-90D7-AB6044E42799}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\SaintsRowTheThird.exe
FirewallRules: [{052B6B99-2589-4AC3-AB04-8CFF01EF322C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\game_launcher.exe
FirewallRules: [{F80FECC8-B483-4EC3-9431-DBA5FC0068F1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Saints Row the Third\game_launcher.exe
FirewallRules: [{57C63704-8111-455A-BC9B-77A0D2D6E20C}] => (Allow) D:\hry\Medal of Honor Warfighter\MOHW.exe
FirewallRules: [{C48A6E8D-3027-4C9F-BF37-1D0314F20C3C}] => (Allow) D:\hry\Medal of Honor Warfighter\MOHW.exe
FirewallRules: [{DA03E566-BB90-4B1E-B361-57B4EB9CEBCA}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{9950B5CD-2F93-4BB1-8F7B-5E6EB69564F1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{1A19D3D1-BA24-40D5-808A-281C049F4F9A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{50088407-1AF5-4FE4-A278-2ABC644CBDF9}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{A457921C-C9DC-4FDA-A670-A6B9BCEF84FC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{0E9EAD35-795E-402A-B79B-ABEB9BC63FA5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8C4EE0F3-42C1-4E06-9F89-02459D60A222}] => (Allow) LPort=8090
FirewallRules: [{862C72EF-56C4-408E-9984-177EDEB6CAC8}] => (Allow) LPort=20443
FirewallRules: [{AED5DB03-B572-497E-B1C0-1BE0456E0D48}] => (Allow) LPort=33333
FirewallRules: [{CCD69843-B641-43C2-986A-F0467E9EA2AD}] => (Allow) LPort=6881
FirewallRules: [{29739E98-F1A2-4E5F-B8DC-6FA1EEAF9ABE}] => (Allow) LPort=27022
FirewallRules: [{2B280288-723D-4C35-B368-5D9C26489F86}] => (Allow) LPort=7850
FirewallRules: [{6870F79B-0013-4175-ACC0-A609A8F6E345}] => (Allow) LPort=3478
FirewallRules: [{DC93A9A5-2720-4731-9A61-F2DA78BF45AB}] => (Allow) LPort=20010
FirewallRules: [{6F91FF90-5018-454F-B1F7-DE09776388A8}] => (Allow) LPort=443
FirewallRules: [{1C972458-7D2E-4CA5-82BD-3A4A59F9AD5E}] => (Allow) LPort=80
FirewallRules: [{B56A6500-28B6-4896-ADAD-848F781030A4}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{2DB458D7-B0C6-4AF8-8AEC-AF56CFC73BEE}] => (Allow) LPort=59084
FirewallRules: [{728FAF05-F3A4-4742-887C-51BC1F2DCF2F}] => (Allow) LPort=59084
FirewallRules: [{1B876A55-F3C2-4F8C-8332-B956DC2CC495}] => (Allow) LPort=59084
FirewallRules: [{A26F0F22-8A35-4079-8BCB-2942470F721A}] => (Allow) LPort=59084
FirewallRules: [{029DCD6F-A918-4AF8-84F0-DBF5DFA1FFB6}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{5B6DE9E7-95B8-4E46-97E4-082B90C505F1}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{E3655403-B0F4-42EE-88B0-E0607681FE67}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{AB6D2AA4-28B4-4D4F-95BC-44CA0834B868}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{DB75375D-3BF2-4127-A885-5C178786F992}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{654E3C5F-53F9-4AC4-9CDD-736746BD480B}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [{9DD4BB95-8DB9-4963-B603-E3E930578B3F}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [TCP Query User{CE6C5A63-1CBF-4FAB-9393-0190BEB26039}C:\program files (x86)\remote mouse\remotemouse.exe] => (Allow) C:\program files (x86)\remote mouse\remotemouse.exe
FirewallRules: [UDP Query User{5EEF6ABE-E7AA-42F0-99E1-10DD18B49947}C:\program files (x86)\remote mouse\remotemouse.exe] => (Allow) C:\program files (x86)\remote mouse\remotemouse.exe
FirewallRules: [{18C0A68F-00D3-4969-A824-323EFA6AF026}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe
FirewallRules: [{3EA6CEE7-4139-4458-A74C-BDB3B37F94CE}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe
FirewallRules: [{611C2336-C6F9-4D6F-B4FE-A750E2244D1E}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe
FirewallRules: [{EC6CB4F3-381A-49D5-86E5-07521E331048}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe
FirewallRules: [{006382CA-E5D9-4B86-AC14-E48D18C479A6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{9C45D4DC-11A3-4971-9DD1-483FD1BAA9CD}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{A53E326B-442B-4A42-8B74-E3E7DF5036AE}C:\program files (x86)\java\jre1.8.0_121\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_121\bin\javaw.exe
FirewallRules: [UDP Query User{CA7B9ABE-03E3-4630-BCFE-08718C8F8490}C:\program files (x86)\java\jre1.8.0_121\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_121\bin\javaw.exe
FirewallRules: [{FAB7B7FD-1425-411A-B0F0-8D4A66D018DE}] => (Block) C:\program files (x86)\java\jre1.8.0_121\bin\javaw.exe
FirewallRules: [{88D31906-93D3-4854-87D5-18CDAB446C0A}] => (Block) C:\program files (x86)\java\jre1.8.0_121\bin\javaw.exe
FirewallRules: [{CC8F0A44-0900-4564-85AC-B0FD9134C690}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{AFBF5FAF-0978-4418-B1A3-B40931518E8A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{6371E2F1-FB43-4E30-9C8B-EA22B9CEF3B6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{DC761A35-2ABA-4326-956F-1BB7B08CFB23}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{41E63FB3-8029-4480-B283-A872E07E29A6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{FE2B630E-1EBF-4AA8-BA8A-970F7A271458}C:\program files (x86)\teamviewer\teamviewer.exe] => (Allow) C:\program files (x86)\teamviewer\teamviewer.exe
FirewallRules: [UDP Query User{7DDFC9B9-93F4-4373-B35E-94C32E1E9D66}C:\program files (x86)\teamviewer\teamviewer.exe] => (Allow) C:\program files (x86)\teamviewer\teamviewer.exe
FirewallRules: [{F3120F92-8102-42DA-A204-5F1CFA9C256A}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe
FirewallRules: [{180AE569-92CD-40D4-BCA1-CADCABD4EE60}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe

==================== Restore Points =========================

25-02-2017 13:49:36 Windows Update
27-02-2017 21:16:28 JRT Pre-Junkware Removal
04-03-2017 11:22:33 zoek.exe restore point

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/05/2017 09:32:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x2004
Čas spustenia chybujúcej aplikácie: 0x01d295ef8fa5da7f
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: f27786af-e985-4614-8601-c5bb32dae764
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:32:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1e84
Čas spustenia chybujúcej aplikácie: 0x01d295ef7dbb6e41
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 5955d561-5553-45dd-988f-7d8298c47e0c
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:31:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x226c
Čas spustenia chybujúcej aplikácie: 0x01d295ef6bdb38a6
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 7166e5a0-60ce-43df-a740-b84cd50ef4de
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:31:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1a8
Čas spustenia chybujúcej aplikácie: 0x01d295ef5a16102e
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 15322578-93e6-42e3-9c41-f33314104833
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:30:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1f00
Čas spustenia chybujúcej aplikácie: 0x01d295ef4846c690
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: a731da3c-18b2-4545-a716-469bf43a4766
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:30:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x12c8
Čas spustenia chybujúcej aplikácie: 0x01d295ef3633c733
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: ae58e726-8933-4d5c-b365-bf105717e43a
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:29:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x11ac
Čas spustenia chybujúcej aplikácie: 0x01d295ef245b1938
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 191886b5-a777-4e4b-9a3a-665ad18535b1
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:29:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1968
Čas spustenia chybujúcej aplikácie: 0x01d295ef1265c542
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 78c7301f-9865-493a-93f5-c4030a1fcd05
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:28:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x2300
Čas spustenia chybujúcej aplikácie: 0x01d295ef009afe8c
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 542b3f82-cee0-4f32-8a55-0cf8415c1d2b
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:

Error: (03/05/2017 09:28:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1b40
Čas spustenia chybujúcej aplikácie: 0x01d295eeef07dbd7
Cesta chybujúcej aplikácie: C:\WINDOWS\System32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: 016487f0-d74a-4b31-abb5-d4fd8cab4f4a
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:


System errors:
=============
Error: (03/05/2017 09:32:42 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Služba Windows License Manager Service bola ukončená s nasledujúcou chybou služby:
General access denied error

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7005) (User: )
Description: Volanie LoadUserProfile zlyhalo s nasledujúcou chybou:
The configuration registry database is corrupt.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba WinHTTP Web Proxy Auto-Discovery Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 16-krát.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Diagnostic Service Host sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 14-krát.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Network Store Interface Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 16-krát.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Služba zoznamu sietí sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 16-krát.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Windows Font Cache Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 8-krát.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba COM+ Event System sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 6-krát.

Error: (03/05/2017 09:32:38 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Služba Windows License Manager Service bola ukončená s nasledujúcou chybou služby:
General access denied error

Error: (03/05/2017 09:32:09 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Connected Devices Platform Service bola ukončená s nasledujúcou chybou:
Unspecified error


CodeIntegrity:
===================================
Date: 2017-03-04 21:04:51.297
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-02-26 13:48:41.680
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.629
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.599
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.526
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.506
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.487
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:40.341
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:40.024
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:43:32.250
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 56%
Total physical RAM: 3998.35 MB
Available physical RAM: 1722.75 MB
Total Virtual: 5726.35 MB
Available Virtual: 3415.03 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:237.81 GB) (Free:102.52 GB) NTFS
Drive d: (Nový zväzok) (Fixed) (Total:226.77 GB) (Free:185.33 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C3FFC3FF)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=237.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=226.8 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=1.1 GB) - (Type=12)

==================== End of Addition.txt ============================

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 21:38

Ak som správne pochopil CDI je HWMOnitor.
Tu je log:

CPUID HWMonitor Report
-------------------------------------------------------------------------

Binaries
-------------------------------------------------------------------------

HWMonitor version 1.3.0.0

Monitoring
-------------------------------------------------------------------------

Mainboard Model Product Name (0x00000482 - 0xFB9476A0)

LPCIO
-------------------------------------------------------------------------

Hardware Monitors
-------------------------------------------------------------------------

Hardware monitor ACPI
Temperature 0 44 degC (111 degF) [0xC64] (TZ00)

Hardware monitor Battery
Voltage 0 12.18 Volts [0x2F96] (Current Voltage)
Capacity 0 3888 mWh [0xF30] (Designed Capacity)
Capacity 1 3831 mWh [0xEF7] (Full Charge Capacity)
Capacity 2 3831 mWh [0xEF7] (Current Capacity)
Level 0 2 pc [0x62] (Wear Level)
Level 1 100 pc [0x64] (Charge Level)

Hardware monitor Intel I/O
Clock Speed 0 349.19 MHz [0x15D] (Graphics)


Processors
-------------------------------------------------------------------------

Number of processors 1
Number of threads 4

APICs
-------------------------------------------------------------------------

Processor 0
-- Core 0
-- Thread 0 0
-- Thread 1 1
-- Core 1
-- Thread 0 2
-- Thread 1 3

Timers
-------------------------------------------------------------------------

Perf timer 2.533 MHz
Sys timer 1.000 KHz


Processors Information
-------------------------------------------------------------------------

Processor 1 ID = 0
Number of cores 2 (max 2)
Number of threads 4 (max 4)
Name Intel Core i5 3230M
Codename Ivy Bridge
Specification Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Package (platform ID) Socket 988B rPGA (0x4)
CPUID 6.A.9
Extended CPUID 6.3A
Core Stepping E1/L1
Technology 22 nm
TDP Limit 35.0 Watts
Tjmax 105.0 °C
Core Speed 1197.2 MHz
Multiplier x Bus Speed 12.0 x 99.8 MHz
Stock frequency 2600 MHz
Instructions sets MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, EM64T, VT-x, AES, AVX
L1 Data cache 2 x 32 KBytes, 8-way set associative, 64-byte line size
L1 Instruction cache 2 x 32 KBytes, 8-way set associative, 64-byte line size
L2 cache 2 x 256 KBytes, 8-way set associative, 64-byte line size
L3 cache 3 MBytes, 12-way set associative, 64-byte line size
FID/VID Control yes


Turbo Mode supported, enabled
Max non-turbo ratio 26x
Max turbo ratio 32x
Max efficiency ratio 12x
Min Power 24 Watts
O/C bins none
Ratio 1 core 32x
Ratio 2 cores 30x
Ratio 3 cores 30x
Ratio 4 cores 30x
TSC 2594.0 MHz
APERF 2993.0 MHz
MPERF 2594.0 MHz

Temperature 0 49 degC (120 degF) (Core #0)
Temperature 1 52 degC (125 degF) (Core #1)
Temperature 2 52 degC (125 degF) (Package)
Voltage 0 1.05 Volts (VID)
Power 0 4.04 W (Package)
Power 1 2.00 W (IA Cores)
Power 2 0.04 W (GT)
Power 3 2.01 W (Uncore)
Clock Speed 0 1197.23 MHz (Core #0)
Clock Speed 1 1197.23 MHz (Core #1)


Thread dumps
-------------------------------------------------------------------------

CPU Thread 0
APIC ID 0
Topology Processor ID 0, Core ID 0, Thread ID 0
Type 01020105h
Max CPUID level 0000000Dh
Max CPUID ext. level 80000008h
Cache descriptor Level 1, D, 32 KB, 2 thread(s)
Cache descriptor Level 1, I, 32 KB, 2 thread(s)
Cache descriptor Level 2, U, 256 KB, 2 thread(s)
Cache descriptor Level 3, U, 3 MB, 16 thread(s)

CPUID
0x00000000 0x0000000D 0x756E6547 0x6C65746E 0x49656E69
0x00000001 0x000306A9 0x02100800 0x7FBAE3BF 0xBFEBFBFF
0x00000002 0x76035A01 0x00F0B2FF 0x00000000 0x00CA0000
0x00000003 0x00000000 0x00000000 0x00000000 0x00000000
0x00000004 0x1C004121 0x01C0003F 0x0000003F 0x00000000
0x00000004 0x1C004122 0x01C0003F 0x0000003F 0x00000000
0x00000004 0x1C004143 0x01C0003F 0x000001FF 0x00000000
0x00000004 0x1C03C163 0x02C0003F 0x00000FFF 0x00000006
0x00000005 0x00000040 0x00000040 0x00000003 0x00021120
0x00000006 0x00000077 0x00000002 0x00000009 0x00000000
0x00000007 0x00000000 0x00000281 0x00000000 0x00000000
0x00000008 0x00000000 0x00000000 0x00000000 0x00000000
0x00000009 0x00000000 0x00000000 0x00000000 0x00000000
0x0000000A 0x07300403 0x00000000 0x00000000 0x00000603
0x0000000B 0x00000001 0x00000002 0x00000100 0x00000002
0x0000000B 0x00000004 0x00000004 0x00000201 0x00000002
0x0000000C 0x00000000 0x00000000 0x00000000 0x00000000
0x0000000D 0x00000007 0x00000340 0x00000340 0x00000000
0x80000000 0x80000008 0x00000000 0x00000000 0x00000000
0x80000001 0x00000000 0x00000000 0x00000001 0x28100800
0x80000002 0x20202020 0x49202020 0x6C65746E 0x20295228
0x80000003 0x65726F43 0x294D5428 0x2D356920 0x30333233
0x80000004 0x5043204D 0x20402055 0x30362E32 0x007A4847
0x80000005 0x00000000 0x00000000 0x00000000 0x00000000
0x80000006 0x00000000 0x00000000 0x01006040 0x00000000
0x80000007 0x00000000 0x00000000 0x00000000 0x00000100
0x80000008 0x00003024 0x00000000 0x00000000 0x00000000

MSR 0x0000001B 0x00000000 0xFEE00900
MSR 0x0000003A 0x00000000 0x00000001
MSR 0x000001A0 0x00000000 0x00850089
MSR 0x000000CE 0x00080C10 0xE0011A00
MSR 0x00000017 0x00100000 0x00000000
MSR 0x00000035 0x00000000 0x00020004
MSR 0x000000C1 0x00000000 0x00000000
MSR 0x000000C2 0x00000000 0x00000000
MSR 0x000000C3 0x00000000 0x00000000
MSR 0x000000C4 0x00000000 0x00000000
MSR 0x00000186 0x00000000 0x00000000
MSR 0x00000187 0x00000000 0x00000000
MSR 0x000001AD 0x00000000 0x1E1E1E20
MSR 0x00000194 0x00000000 0x00110000
MSR 0x0000019A 0x00000000 0x00000008
MSR 0x000001A4 0x00000000 0x00000000
MSR 0x000001FC 0x00000000 0x0014005F
MSR 0x00000601 0x18141494 0x80000380
MSR 0x00000602 0x18141494 0x80000190
MSR 0x00000606 0x00000000 0x000A1003
MSR 0x00000610 0x8000815E 0x00DC8118
MSR 0x00000611 0x00000000 0x14FBB200
MSR 0x00000639 0x00000000 0x0DC1D85D
MSR 0x00000641 0x00000000 0x004BD341
MSR 0x00000614 0x00100000 0x00C00118
MSR 0x0000019C 0x00000000 0x88380000
MSR 0x000001A2 0x00000000 0x00691200
MSR 0x000001B1 0x00000000 0x88350000
MSR 0x00000198 0x00002177 0x00001E00
MSR 0x00000199 0x00000000 0x00002000


Storage
-------------------------------------------------------------------------

Drive 0
Device Path \\?\ide#diskst500lt012-9ws142_______________________0001lvm1#4&3359eddd&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Type Fixed
Name ST500LT0 12-9WS142
Capacity 465.8 GB
SMART Support Yes
Volume c:\, 237.8 GBytes (43.1 percent available)
Volume d:\, 226.8 GBytes (81.7 percent available)

USB Devices
-------------------------------------------------------------------------

USB Device USB Input Device, class=0x00, subclass=0x00, vendor=0x045E, product=0x0095
USB Device Generic USB Hub, class=0x09, subclass=0x00, vendor=0x8087, product=0x0024
USB Device Qualcomm Atheros AR3012 Bluetooth 4.0, class=0xE0, subclass=0x01, vendor=0x0CF3, product=0x3004
USB Device Generic USB Hub, class=0x09, subclass=0x00, vendor=0x8087, product=0x0024
USB Device USB Composite Device, class=0xEF, subclass=0x02, vendor=0x5986, product=0x0295

Graphic APIs
-------------------------------------------------------------------------

API Intel I/O

Display Adapters
-------------------------------------------------------------------------

Display adapter 0
Display name \\.\DISPLAY1
Name Intel(R) HD Graphics 4000
Board Manufacturer Lenovo
PCI device bus 0 (0x0), device 2 (0x2), function 0 (0x0)
Vendor ID 0x8086 (0x17AA)
Model ID 0x0166 (0x3901)
Performance Level 0
Core clock 349.2 MHz


Monitor 0
Model (Seiko Epson)
ID SEC4252
Serial
Manufacturing Date Week 0, Year 2010
Size 15.3 inches
Max Resolution 1366 x 768 @ 60 Hz
Horizontal Freq. Range 0-0 kHz
Vertical Freq. Range 0-0 Hz
Max Pixel Clock 0 MHz
Gamma Factor 2.2

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 21:43

Snímka.PNG
Snímka.PNG (10.72 KiB) Zobrazeno 10641 x

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 05 bře 2017 23:10

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
SearchScopes: HKU\S-1-5-21-104870834-3866067964-3722874268-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-104870834-3866067964-3722874268-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
DPF: HKLM {233C1507-6A77-46A4-9443-F871F945D258} hxxps://fpdownload.macromedia.com/pub/s ... tor/sw.cab
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
C:\WINDOWS\system32\InstallUtil.InstallLog
C:\Users\Lenovo\AppData\Local\PeerDistRepub
C:\ProgramData\DP45977C.lfl
Task: {0CC218E9-B055-4CEA-A84F-33F8FC4AB1F3} - System32\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {1B92AA72-2148-463A-B0B5-80311DC56687} - System32\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {390BD305-3731-4170-A1A5-C0D4D64D1815} - System32\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {435808E4-FE36-4CE3-9DDD-959DA9BB5B50} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {5CA1F475-6261-4F8D-A091-DCB5D3633A96} - System32\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5D3E8678-E2E2-4114-901C-2465581EE6E5} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ad46306838e6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5DB0AC33-0D75-4562-B59F-DCDEAE6386C6} - System32\Tasks\GoogleUpdateTaskMachineUA1d12f4ab86e528 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {82E10AB1-68B2-4C6B-998C-A576C84D326F} - System32\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {BCDB51B0-5617-45BA-99A6-EB70379E6C15} - System32\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {D37F56A6-E4FF-4ADD-A92A-BDCE80BD7202} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {E45BC06C-4245-4974-9944-D525359618DF} - System32\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {ECA9AB01-717A-4325-BE3A-177659CF7EDA} - System32\Tasks\{3ED71B50-0BFE-4026-9BB6-2CD6ED626AE3} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {FB716BE8-2A1E-4C7B-AA66-EACADF8FBA3A} - System32\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

Error: (03/05/2017 09:30:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x12c8
Čas spustenia chybujúcej aplikácie: 0x01d295ef3633c733
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\svchost.exe
Cesta chybujúceho modulu: c:\windows\system32\LicenseManager.dll
Identifikácia hlásenia: ae58e726-8933-4d5c-b365-bf105717e43a
Celé meno chybujúceho balíka:
Identifikácia chybujúcej aplikácie vzhľadom na balík:


c:\windows\system32\LicenseManager.dll podívej se , zda tam máš tento soubor.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 05 bře 2017 23:25

Fix result of Farbar Recovery Scan Tool (x64) Version: 05-03-2017
Ran by Lenovo (05-03-2017 23:20:55) Run:1
Running from C:\Users\Lenovo\Desktop
Loaded Profiles: Lenovo (Available Profiles: Lenovo)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
SearchScopes: HKU\S-1-5-21-104870834-3866067964-3722874268-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-104870834-3866067964-3722874268-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
DPF: HKLM {233C1507-6A77-46A4-9443-F871F945D258} hxxps://fpdownload.macromedia.com/pub/s ... tor/sw.cab
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
C:\WINDOWS\system32\InstallUtil.InstallLog
C:\Users\Lenovo\AppData\Local\PeerDistRepub
C:\ProgramData\DP45977C.lfl
Task: {0CC218E9-B055-4CEA-A84F-33F8FC4AB1F3} - System32\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {1B92AA72-2148-463A-B0B5-80311DC56687} - System32\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {390BD305-3731-4170-A1A5-C0D4D64D1815} - System32\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {435808E4-FE36-4CE3-9DDD-959DA9BB5B50} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {5CA1F475-6261-4F8D-A091-DCB5D3633A96} - System32\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5D3E8678-E2E2-4114-901C-2465581EE6E5} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ad46306838e6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {5DB0AC33-0D75-4562-B59F-DCDEAE6386C6} - System32\Tasks\GoogleUpdateTaskMachineUA1d12f4ab86e528 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {82E10AB1-68B2-4C6B-998C-A576C84D326F} - System32\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {BCDB51B0-5617-45BA-99A6-EB70379E6C15} - System32\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {D37F56A6-E4FF-4ADD-A92A-BDCE80BD7202} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {E45BC06C-4245-4974-9944-D525359618DF} - System32\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {ECA9AB01-717A-4325-BE3A-177659CF7EDA} - System32\Tasks\{3ED71B50-0BFE-4026-9BB6-2CD6ED626AE3} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {FB716BE8-2A1E-4C7B-AA66-EACADF8FBA3A} - System32\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-104870834-3866067964-3722874268-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{233C1507-6A77-46A4-9443-F871F945D258} => key removed successfully
HKCR\CLSID\{233C1507-6A77-46A4-9443-F871F945D258} => key not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => key removed successfully
HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully
idsvc => service removed successfully
HKLM\System\CurrentControlSet\Services\wpcsvc => key removed successfully
wpcsvc => service removed successfully
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => moved successfully
C:\WINDOWS\system32\InstallUtil.InstallLog => moved successfully
C:\Users\Lenovo\AppData\Local\PeerDistRepub => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0CC218E9-B055-4CEA-A84F-33F8FC4AB1F3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0CC218E9-B055-4CEA-A84F-33F8FC4AB1F3} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1B92AA72-2148-463A-B0B5-80311DC56687} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B92AA72-2148-463A-B0B5-80311DC56687} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d0f140a248c0c8 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{390BD305-3731-4170-A1A5-C0D4D64D1815} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{390BD305-3731-4170-A1A5-C0D4D64D1815} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1cf2db09538d00f => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{435808E4-FE36-4CE3-9DDD-959DA9BB5B50} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{435808E4-FE36-4CE3-9DDD-959DA9BB5B50} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5CA1F475-6261-4F8D-A091-DCB5D3633A96} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5CA1F475-6261-4F8D-A091-DCB5D3633A96} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1cfeeb9b92bf593 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D3E8678-E2E2-4114-901C-2465581EE6E5} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D3E8678-E2E2-4114-901C-2465581EE6E5} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d1ad46306838e6 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore1d1ad46306838e6 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5DB0AC33-0D75-4562-B59F-DCDEAE6386C6} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5DB0AC33-0D75-4562-B59F-DCDEAE6386C6} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d12f4ab86e528 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d12f4ab86e528 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{82E10AB1-68B2-4C6B-998C-A576C84D326F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82E10AB1-68B2-4C6B-998C-A576C84D326F} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d04087469f5f88 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BCDB51B0-5617-45BA-99A6-EB70379E6C15} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCDB51B0-5617-45BA-99A6-EB70379E6C15} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d09527dd9b57a8 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D37F56A6-E4FF-4ADD-A92A-BDCE80BD7202} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D37F56A6-E4FF-4ADD-A92A-BDCE80BD7202} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore1d15e9e719d415b => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E45BC06C-4245-4974-9944-D525359618DF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E45BC06C-4245-4974-9944-D525359618DF} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore1cef606923ec9fe => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ECA9AB01-717A-4325-BE3A-177659CF7EDA} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECA9AB01-717A-4325-BE3A-177659CF7EDA} => key removed successfully
C:\WINDOWS\System32\Tasks\{3ED71B50-0BFE-4026-9BB6-2CD6ED626AE3} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3ED71B50-0BFE-4026-9BB6-2CD6ED626AE3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FB716BE8-2A1E-4C7B-AA66-EACADF8FBA3A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB716BE8-2A1E-4C7B-AA66-EACADF8FBA3A} => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d0c079334786fc => key removed successfully
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => moved successfully
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => not found.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cef606923ec9fe.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d15e9e719d415b.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf2db09538d00f.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cfeeb9b92bf593.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d04087469f5f88.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d09527dd9b57a8.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0c079334786fc.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0e7c0f2d8c949.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0f140a248c0c8.job => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 88604942 B
Java, Flash, Steam htmlcache => 497178514 B
Windows/system/drivers => 9541066 B
Edge => 199 B
Chrome => 12446273 B
Firefox => 93924400 B
Opera => 116736 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 32913 B
NetworkService => 128 B
Lenovo => 64801119 B
UpdatusUser => 0 B

RecycleBin => 0 B
EmptyTemp: => 731.1 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 23:22:04 ====


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 4 hosti