Prosím o kontrolu logu HJT Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod jaro3 » 03 říj 2018 23:04

No tak Combofix to nedovede smazat..

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate


Vyčisti systém CCleanerem

Stáhni si OTC

na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 08:48

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03.10.2018 01
Ran by Hačís (administrator) on HAČÍS-PC (04-10-2018 08:43:03)
Running from C:\Users\Hačís\Desktop
Loaded Profiles: Hačís (Available Profiles: Hačís & Děti)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Windows\System32\atiesrxx.exe
() C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18388936 2018-09-11] (Realtek Semiconductor)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
Startup: C:\Users\Hačís\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Poslat do aplikace OneNote.lnk [2018-04-22]
ShortcutTarget: Poslat do aplikace OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicyUsers\S-1-5-21-2123216125-335965321-1693192355-1003\User: Restriction - Chrome <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8E7F98CD-F1E6-436B-854F-273C4B574F9F}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{DB0A3BFC-3FE9-4523-83AC-91C68D0BC2E7}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-2123216125-335965321-1693192355-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2123216125-335965321-1693192355-1000 -> {2B82B6F4-6B2E-4DF7-84E1-E7690F824A84} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2018-09-27] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL [2018-10-03] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2018-09-11] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\URLREDIR.DLL [2018-10-03] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-10-03] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: rk8u8k6q.default-1538247061974
FF ProfilePath: C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974 [2018-10-04]
FF Homepage: Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974 -> about:home
FF NewTab: Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974 -> about:newtab
FF Extension: (Firefox Monitor) - C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\features\{cd8171c7-3005-4fd6-876c-9445ce7c46cc}\fxmonitor@mozilla.org.xpi [2018-09-29]
FF Extension: (Telemetry coverage) - C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\features\{cd8171c7-3005-4fd6-876c-9445ce7c46cc}\telemetry-coverage-bug1487578@mozilla.org.xpi [2018-09-29] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll [2018-09-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-09-11] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-09-25] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll [2018-09-11] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-09-11] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2018-09-11] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2013-08-20] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-10-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-10-01] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxps://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Profile: C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default [2018-10-04]
CHR Extension: (Prezentace) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-01]
CHR Extension: (Dokumenty) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-16]
CHR Extension: (Disk Google) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-11-16]
CHR Extension: (YouTube) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-11-16]
CHR Extension: (Adobe Acrobat) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-12-21]
CHR Extension: (Tabulky) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-11-17]
CHR Extension: (Chrome Media Router) - C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-20]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [305176 2017-11-16] ()
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9680472 2018-09-26] (Microsoft Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [7677008 2017-10-16] (INCA Internet Co., Ltd.)
R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Video Converter Ultimate\Transfer\DriverInstall.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11944 2017-11-16] (Advanced Micro Devices Inc.)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [21527576 2017-11-16] ()
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [493592 2017-11-16] ()
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [33872 2011-11-28] (AnvSoft Inc.)
S3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [33592 2015-05-24] (Dev47Apps)
S3 DroidCamVideo; C:\Windows\System32\DRIVERS\droidcamvideo.sys [229432 2015-05-24] (Dev47Apps)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2017-12-26] (DT Soft Ltd)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-11-16] (REALiX(tm))
R1 nfstat; C:\Windows\System32\drivers\nfstat.sys [134760 2018-09-20] (Riverbed Technology, Inc.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2018-02-01] (Apple, Inc.) [File not signed]
S3 wdm_usb; C:\Windows\System32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB)
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2018-10-02] (Zemana Ltd.)
R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2018-10-02] (Zemana Ltd.)
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x64.sys [X]
S3 dump_wmimmc; \??\C:\Program Files (x86)\Metin2\GameGuard\dump_wmimmc.sys [X]
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\drivers\Monitor_win7_x64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-10-04 08:43 - 2018-10-04 08:43 - 000014573 _____ C:\Users\Hačís\Desktop\FRST.txt
2018-10-04 08:42 - 2018-10-04 08:43 - 000000000 ____D C:\FRST
2018-10-04 08:41 - 2018-10-04 08:42 - 002414080 _____ (Farbar) C:\Users\Hačís\Desktop\FRST64.exe
2018-10-04 08:31 - 2018-10-04 08:37 - 000000000 ____D C:\Users\Hačís\Desktop\backups
2018-10-03 22:38 - 2018-10-03 22:38 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2018-10-03 22:36 - 2018-10-03 22:36 - 000002464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002434 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002416 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002411 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002367 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002332 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002328 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2018-10-03 22:36 - 2018-10-03 22:36 - 000002210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive pro firmy.lnk
2018-10-03 22:20 - 2018-10-03 22:20 - 000388608 _____ (Trend Micro Inc.) C:\Users\Hačís\Desktop\HijackThis.exe
2018-10-03 11:26 - 2018-10-03 11:26 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\Google
2018-10-03 08:40 - 2018-10-03 08:40 - 000000000 ____D C:\Users\Hačís\Documents\AVS4YOU
2018-10-02 21:49 - 2018-10-04 08:38 - 000000000 ____D C:\Qoobox
2018-10-02 21:49 - 2018-10-02 21:57 - 000000000 ____D C:\Windows\erdnt
2018-10-02 21:31 - 2018-10-04 08:43 - 000047683 _____ C:\Windows\ZAM.krnl.trace
2018-10-02 21:31 - 2018-10-04 08:43 - 000021953 _____ C:\Windows\ZAM_Guard.krnl.trace
2018-10-02 21:31 - 2018-10-02 21:31 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
2018-10-02 21:31 - 2018-10-02 21:31 - 000203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys
2018-10-02 21:31 - 2018-10-02 21:31 - 000001148 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2018-10-02 21:31 - 2018-10-02 21:31 - 000000000 ____D C:\Users\Hačís\AppData\Local\Zemana
2018-10-02 21:31 - 2018-10-02 21:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2018-10-02 21:31 - 2018-10-02 21:31 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-10-02 21:21 - 2014-02-13 23:59 - 000024064 _____ C:\Windows\zoek-delete.exe
2018-10-02 20:58 - 2018-10-02 21:17 - 000000000 ____D C:\zoek_backup
2018-10-02 20:31 - 2018-10-02 20:32 - 006625600 _____ (Zemana Ltd. ) C:\Users\Hačís\Desktop\Zemana.AntiMalware.Setup.exe
2018-10-02 20:31 - 2018-10-02 20:31 - 002038755 _____ C:\Users\Hačís\Desktop\zoek.exe
2018-10-02 19:40 - 2018-10-02 20:33 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-10-02 19:39 - 2018-10-02 20:01 - 000000000 ____D C:\ProgramData\RogueKiller
2018-10-02 18:06 - 2018-10-02 18:06 - 000002759 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2018-10-02 18:06 - 2018-10-02 18:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-10-02 18:06 - 2018-10-02 18:06 - 000000000 ____D C:\Program Files (x86)\Sophos
2018-10-01 22:46 - 2018-10-01 22:46 - 001790024 _____ (Malwarebytes) C:\Users\Hačís\Desktop\JRT.exe
2018-10-01 22:45 - 2018-10-01 22:45 - 027157048 _____ (Adlice Software) C:\Users\Hačís\Desktop\RogueKiller_portable64.exe
2018-10-01 20:57 - 2018-10-01 20:57 - 000002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-10-01 20:57 - 2018-10-01 20:57 - 000002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-10-01 20:55 - 2018-10-01 20:55 - 000003386 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-10-01 20:55 - 2018-10-01 20:55 - 000003258 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-09-30 18:19 - 2018-09-30 18:19 - 000000000 ____D C:\ProgramData\Sophos
2018-09-30 18:16 - 2018-09-30 18:16 - 195958672 _____ (Sophos Limited) C:\Users\Děti\Downloads\Sophos Virus Removal Tool.exe
2018-09-30 18:07 - 2018-09-30 18:07 - 000000000 ____D C:\Users\Děti\AppData\Roaming\Adobe
2018-09-30 17:56 - 2018-09-30 17:56 - 000000000 ____D C:\Users\Děti\AppData\Local\mbamtray
2018-09-30 17:45 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\hh3jieg1ucx
2018-09-30 17:38 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\3ce2ya4p240
2018-09-30 17:30 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\eygcxagbo4f
2018-09-30 17:29 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\00b4hxfzx5c
2018-09-30 17:07 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\lmrrdroejzg
2018-09-30 14:16 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\r3qw1xbhgw3
2018-09-30 14:07 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\130b0b4ocqy
2018-09-30 14:01 - 2018-09-30 14:01 - 000000000 ____D C:\ProgramData\WjIOjGvJCfODeXVB
2018-09-30 13:56 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\omaefet3eym
2018-09-30 13:56 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\gormp5x0evs
2018-09-30 13:27 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ovx0qblivpw
2018-09-30 13:16 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\dga0u5kmu5w
2018-09-30 13:11 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\aqmh13j20s2
2018-09-30 13:11 - 2018-09-30 13:14 - 000000000 ____D C:\Program Files\HJTWJO4U08
2018-09-30 13:06 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\x2imgkjw3lb
2018-09-30 12:55 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ygrox4kmpqc
2018-09-30 12:41 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\yzqlbva1lix
2018-09-30 12:26 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\3f4xgawjpai
2018-09-30 12:16 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\zpzdktybg4e
2018-09-30 12:06 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\4bhmymhmz3n
2018-09-30 11:56 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\nv4qwnmitzm
2018-09-30 11:55 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\1ueerqmk4fw
2018-09-30 11:41 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\0sx4xb2wkgg
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wbneen3cakm
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\uqklxuq3bpp
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\mpnvprj33jn
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\3eq5fibggzp
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\y2cdg30o154
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\xdbjew0ebnw
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\qfbolhfixhe
2018-09-30 11:11 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\kqtn35nyksr
2018-09-30 11:09 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vlrxvmgpbfm
2018-09-30 11:09 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\2hlvkweizah
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ia1jho0rtou
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\g2jgy3jy0cs
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\daxshilvflw
2018-09-30 11:07 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\iwyddph33j3
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\szq0myifpwv
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\slnv3c1pg4i
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\othmmklaufh
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\4up0t3gnrhx
2018-09-30 10:55 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\xnikdioprop
2018-09-30 10:17 - 2018-09-30 10:17 - 000000000 ____D C:\Users\Hačís\AppData\Local\mbam
2018-09-30 10:16 - 2018-09-30 10:16 - 000000000 ____D C:\Users\Hačís\AppData\Local\mbamtray
2018-09-30 10:15 - 2018-09-30 10:15 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-09-30 10:15 - 2018-09-30 10:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-09-30 10:15 - 2018-09-30 10:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-09-30 10:15 - 2018-09-30 10:15 - 000000000 ____D C:\Program Files\Malwarebytes
2018-09-30 10:15 - 2018-09-11 13:18 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-09-29 21:03 - 2018-10-02 17:27 - 000000000 ____D C:\AdwCleaner
2018-09-29 21:00 - 2018-09-29 21:01 - 080408496 _____ (Malwarebytes ) C:\Users\Hačís\Desktop\mb3-setup-consumer-3.6.1.2711-1.0.463-1.0.7063.exe
2018-09-29 21:00 - 2018-09-29 21:00 - 007567568 _____ (Malwarebytes) C:\Users\Hačís\Desktop\AdwCleaner.exe
2018-09-29 20:59 - 2018-09-29 20:59 - 000448512 _____ (OldTimer Tools) C:\Users\Hačís\Desktop\TFC.exe
2018-09-29 20:59 - 2018-09-29 20:59 - 000050688 _____ (Atribune.org) C:\Users\Hačís\Desktop\ATF-Cleaner.exe
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\pqjhlyaij4p
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\chdk4rn0p2g
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\g2hgrrek4tl
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ccxld2btr4f
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\aiqxdp2j2ye
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\04dd3opwinq
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\qubn023ut11
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\la2vlm5mouk
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\k4e0qdqdsxf
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\egkvyuirmvt
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\byoccsr5awv
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\1rmxxtuxnj4
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\xibjq0rh1na
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vw51xgv3143
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ch4vifxsxp0
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\0gxeyae45l1
2018-09-29 17:26 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\rfey3c0k32z
2018-09-29 17:26 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\etjzn1nrftw
2018-09-29 17:23 - 2018-09-29 17:25 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vlh3hsob5q0
2018-09-29 17:23 - 2018-09-29 17:25 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\0syghxusskg
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\tiod5uanl5r
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\tfnjc2nuxqe
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\14a5ops3r2f
2018-09-29 17:12 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\lijia2u2as3
2018-09-29 17:11 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wuyfuwi44yu
2018-09-29 17:11 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\osrhd1xyczz
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\smstnl4t1xt
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\okoapnjjegc
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\np5iak5homj
2018-09-29 16:57 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\rar3a24r3eo
2018-09-29 16:56 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\lprqgv2eica
2018-09-29 16:56 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\gnnzspdulls
2018-09-29 16:50 - 2018-09-29 16:50 - 000000000 ____D C:\Users\Hačís\Documents\MAGIX_MusicEditor
2018-09-29 16:50 - 2018-09-29 16:50 - 000000000 ____D C:\Users\Hačís\Documents\MAGIX downloads
2018-09-29 16:50 - 2018-09-29 16:50 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\MAGIX
2018-09-29 16:50 - 2018-09-29 16:50 - 000000000 ____D C:\Users\Hačís\AppData\Local\Xara
2018-09-29 16:50 - 2018-09-29 16:50 - 000000000 ____D C:\Program Files\Common Files\MAGIX Shared
2018-09-29 16:46 - 2018-09-30 11:15 - 000000000 ____D C:\ProgramData\MAGIX
2018-09-29 16:46 - 2018-09-30 11:01 - 000000000 ___RD C:\Users\Hačís\Documents\MAGIX
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\zywez53rmgy
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ldflgbpnfdu
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\22mxecvpjl5
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wow3hira2wg
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\f1a11uuevi4
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\aqdu3wnpf4z
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\4eqkwtq5byl
2018-09-29 16:39 - 2018-10-02 17:49 - 000000000 ____D C:\Program Files (x86)\Full
2018-09-29 16:39 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wj2bqs25opr
2018-09-29 16:38 - 2018-09-29 16:38 - 000001810 _____ C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config
2018-09-29 16:37 - 2018-09-29 16:37 - 000140800 _____ C:\Users\Hačís\AppData\Local\installer.dat
2018-09-29 16:35 - 2018-10-02 17:49 - 000000000 ____D C:\Windows\SysWOW64\wsfhyqup
2018-09-29 16:33 - 2018-09-29 16:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2018-09-29 16:33 - 2018-09-29 16:33 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2018-09-29 16:25 - 2018-09-29 16:25 - 000000000 ____D C:\ProgramData\AVS4YOU
2018-09-29 16:24 - 2018-09-29 16:24 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\AVS4YOU
2018-09-29 16:23 - 2018-09-29 16:23 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2018-09-29 16:22 - 2018-09-29 16:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2018-09-29 16:22 - 2018-09-29 16:23 - 000000000 ____D C:\Program Files (x86)\AVS4YOU
2018-09-29 16:22 - 2018-09-29 16:22 - 000001201 _____ C:\Users\Hačís\Desktop\AVS Video Editor.lnk
2018-09-29 16:22 - 2011-06-23 12:26 - 001700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2018-09-29 16:22 - 2011-06-23 12:25 - 000024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll
2018-09-29 16:10 - 2018-09-29 16:10 - 000003316 _____ C:\Windows\System32\Tasks\CorelUpdateHelperTaskCore
2018-09-29 16:10 - 2018-09-29 16:10 - 000000000 ____D C:\Program Files (x86)\Corel
2018-09-29 16:06 - 2018-09-29 16:10 - 000000000 ____D C:\Program Files\Corel
2018-09-29 15:39 - 2018-09-29 15:40 - 004058374 _____ C:\Users\Hačís\projekt x.sto
2018-09-29 15:39 - 2018-09-29 15:39 - 003187830 _____ C:\Users\Hačís\projekt x.~sto
2018-09-29 14:59 - 2018-09-29 14:59 - 000000377 _____ C:\Users\Hačís\pokoj01.sto
2018-09-29 14:40 - 2018-09-29 14:40 - 000000380 _____ C:\Users\Hačís\pokoj.sto
2018-09-29 09:50 - 2018-09-29 09:50 - 000001137 _____ C:\Users\Public\Desktop\PRO100.lnk
2018-09-29 09:37 - 2018-09-29 09:37 - 000000000 ____D C:\Program Files (x86)\Ecru
2018-09-29 09:35 - 2018-09-29 09:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PRO100
2018-09-29 09:35 - 2018-09-29 09:35 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\Ecru
2018-09-20 09:16 - 2018-09-20 09:16 - 000134760 _____ (Riverbed Technology, Inc.) C:\Windows\system32\Drivers\nfstat.sys
2018-09-19 10:09 - 2018-09-19 10:09 - 000223817 _____ C:\Users\Hačís\Desktop\NORMA Hustopeče - PKS 2019 - výchozí návrh.pdf
2018-09-19 10:09 - 2018-09-19 10:09 - 000000000 ____D C:\Users\Hačís\Documents\Vlastní šablony Office
2018-09-14 15:43 - 2018-09-14 15:43 - 000000000 ____D C:\Windows\Tasks\ImCleanDisabled
2018-09-14 15:33 - 2018-09-14 15:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SP Driver
2018-09-14 15:33 - 2018-09-14 15:33 - 000000000 ____D C:\Program Files\MediaTek
2018-09-14 15:33 - 2018-09-14 15:33 - 000000000 ____D C:\Program Files (x86)\ClockworkMod
2018-09-14 15:32 - 2018-09-14 15:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\AdbDriverInstaller
2018-09-13 19:54 - 2018-09-13 19:54 - 000000000 ____D C:\Users\Public\Documents\Steam
2018-09-13 19:54 - 2018-09-13 19:54 - 000000000 ____D C:\Users\Hačís\AppData\LocalLow\Empyrean
2018-09-13 14:22 - 2018-06-13 18:23 - 000140992 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-09-13 14:22 - 2018-06-13 18:18 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 002860032 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-09-13 14:22 - 2018-06-08 15:05 - 001602048 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 000783872 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 000612352 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 000470016 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 000443392 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-09-13 14:22 - 2018-06-08 15:05 - 000246272 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-09-13 14:20 - 2018-08-31 17:08 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2018-09-13 14:20 - 2018-08-31 17:08 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-09-13 14:20 - 2018-08-30 06:05 - 001190912 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2018-09-13 14:20 - 2018-08-30 05:49 - 001008128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2018-09-13 14:20 - 2018-08-28 07:50 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2018-09-13 14:20 - 2018-08-13 17:54 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-09-13 14:20 - 2018-08-13 17:54 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-09-13 14:20 - 2018-08-13 17:54 - 001888768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2018-09-13 14:20 - 2018-08-13 17:54 - 000056832 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2018-09-13 14:20 - 2018-08-13 17:54 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
2018-09-13 14:20 - 2018-08-13 17:54 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-09-13 14:20 - 2018-08-13 17:54 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2018-09-13 14:20 - 2018-08-13 17:53 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-09-13 14:20 - 2018-08-13 17:53 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2018-09-13 14:20 - 2018-08-13 17:41 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 000004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-09-13 14:20 - 2018-08-13 17:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2018-09-13 14:20 - 2018-08-12 22:32 - 000378464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-09-13 14:20 - 2018-08-12 22:31 - 001894496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-09-13 14:20 - 2018-08-12 22:31 - 000289376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-09-13 14:20 - 2018-08-12 22:28 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2018-09-13 14:20 - 2018-08-12 22:14 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2018-09-13 14:20 - 2018-08-10 17:59 - 005552816 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-09-13 14:20 - 2018-08-10 17:59 - 000154800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-09-13 14:20 - 2018-08-10 17:58 - 000385120 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-09-13 14:20 - 2018-08-10 17:58 - 000263776 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-09-13 14:20 - 2018-08-10 17:58 - 000096864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-09-13 14:20 - 2018-08-10 17:57 - 000708272 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-09-13 14:20 - 2018-08-10 17:57 - 000631624 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-09-13 14:20 - 2018-08-10 17:56 - 001664296 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-09-13 14:20 - 2018-08-10 17:55 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 001461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-09-13 14:20 - 2018-08-10 17:54 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 08:49

2018-09-13 14:20 - 2018-08-10 17:53 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:53 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:45 - 004054192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-09-13 14:20 - 2018-08-10 17:45 - 000309424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-09-13 14:20 - 2018-08-10 17:44 - 003961440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-09-13 14:20 - 2018-08-10 17:42 - 001315512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-09-13 14:20 - 2018-08-10 17:41 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:39 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-09-13 14:20 - 2018-08-10 17:39 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-09-13 14:20 - 2018-08-10 17:27 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-09-13 14:20 - 2018-08-10 17:22 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-09-13 14:20 - 2018-08-10 17:22 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-09-13 14:20 - 2018-08-10 17:22 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-09-13 14:20 - 2018-08-10 17:21 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-09-13 14:20 - 2018-08-10 17:20 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-09-13 14:20 - 2018-08-10 17:17 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-09-13 14:20 - 2018-08-10 17:17 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-09-13 14:20 - 2018-08-10 17:17 - 000129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-09-13 14:20 - 2018-08-10 17:15 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-09-13 14:20 - 2018-08-10 17:13 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-09-13 14:20 - 2018-08-10 17:13 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-09-13 14:20 - 2018-08-10 17:13 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-09-13 14:20 - 2018-08-10 17:13 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-09-13 14:20 - 2018-08-10 17:12 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-09-13 14:20 - 2018-08-10 17:12 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2018-09-13 14:20 - 2018-08-10 17:12 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2018-09-13 14:20 - 2018-08-10 17:12 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2018-09-13 14:20 - 2018-08-10 17:12 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2018-09-13 14:20 - 2018-08-10 17:12 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-09-13 14:20 - 2018-08-10 17:10 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-09-13 14:20 - 2018-08-10 17:10 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-09-13 14:20 - 2018-08-10 17:10 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-09-13 14:20 - 2018-08-10 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-09-13 14:20 - 2018-08-10 17:09 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-09-13 14:20 - 2018-08-10 17:09 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:09 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-09-13 14:20 - 2018-08-10 17:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-09-13 14:20 - 2018-08-03 17:55 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2018-09-13 14:20 - 2018-08-03 17:39 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2018-09-13 14:20 - 2018-07-29 17:55 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-09-13 14:20 - 2018-07-18 17:18 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2018-09-13 14:20 - 2018-07-07 17:24 - 003226112 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-09-13 14:20 - 2018-07-06 18:09 - 000947904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-09-13 14:20 - 2018-06-29 17:55 - 000695808 _____ (Microsoft Corporation) C:\Windows\system32\cscsvc.dll
2018-09-13 14:20 - 2018-06-29 17:55 - 000137728 _____ (Microsoft Corporation) C:\Windows\system32\CscMig.dll
2018-09-13 14:20 - 2018-06-29 17:55 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2018-09-13 14:20 - 2018-06-29 17:55 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2018-09-13 14:20 - 2018-06-29 17:40 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscdll.dll
2018-09-13 14:20 - 2018-06-29 17:14 - 000516096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\csc.sys
2018-09-13 14:20 - 2018-06-29 17:09 - 000034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscapi.dll
2018-09-13 14:20 - 2018-06-27 18:01 - 000114368 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-09-13 14:20 - 2018-06-27 17:55 - 003246592 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-09-13 14:20 - 2018-06-27 17:55 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-09-13 14:20 - 2018-06-27 17:55 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-09-13 14:20 - 2018-06-27 17:55 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-09-13 14:20 - 2018-06-27 17:54 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-09-13 14:20 - 2018-06-27 17:54 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-09-13 14:20 - 2018-06-27 17:43 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-09-13 14:20 - 2018-06-27 17:42 - 002366464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-09-13 14:20 - 2018-06-27 17:42 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2018-09-13 14:20 - 2018-06-27 17:42 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2018-09-13 14:20 - 2018-06-27 17:41 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-09-13 14:20 - 2018-06-27 17:21 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-09-13 14:20 - 2018-06-27 17:16 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2018-09-13 14:20 - 2018-06-27 15:20 - 000419648 _____ C:\Windows\SysWOW64\locale.nls
2018-09-13 14:20 - 2018-06-27 15:19 - 000419648 _____ C:\Windows\system32\locale.nls
2018-09-13 14:20 - 2018-06-21 05:33 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-09-13 14:20 - 2018-06-21 05:09 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-09-13 14:20 - 2018-06-08 18:21 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-09-13 14:20 - 2018-06-08 18:20 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-09-13 14:20 - 2018-06-08 18:20 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-09-13 14:20 - 2018-06-08 18:20 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-09-13 14:20 - 2018-06-08 18:19 - 000357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2018-09-13 14:20 - 2018-06-08 18:19 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2018-09-13 14:20 - 2018-06-08 18:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-09-13 14:20 - 2018-06-08 17:55 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-09-13 14:20 - 2018-06-08 17:55 - 000330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-09-13 14:20 - 2018-06-08 17:55 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-09-13 14:20 - 2018-06-08 17:54 - 000269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2018-09-13 14:20 - 2018-06-08 17:44 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2018-09-13 14:20 - 2018-06-08 17:29 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-09-13 14:20 - 2018-06-08 17:28 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2018-09-13 14:20 - 2018-05-30 15:05 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-09-13 14:20 - 2018-05-30 15:05 - 000467856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-09-13 14:20 - 2018-05-30 15:05 - 000459632 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2018-09-13 14:20 - 2018-05-15 06:16 - 001681088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-09-13 14:20 - 2018-05-15 05:44 - 004120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-09-13 14:20 - 2018-05-15 05:44 - 001159680 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2018-09-13 14:20 - 2018-05-15 05:44 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-09-13 14:20 - 2018-05-15 05:44 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2018-09-13 14:20 - 2018-05-15 05:24 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2018-09-13 14:20 - 2018-05-15 05:23 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2018-09-13 14:20 - 2018-05-15 05:13 - 003207168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-09-13 14:20 - 2018-05-15 05:13 - 000782848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2018-09-13 14:20 - 2018-05-15 05:13 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-09-13 14:20 - 2018-05-15 05:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2018-09-13 14:20 - 2018-05-15 05:01 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2018-09-13 14:20 - 2018-05-15 05:01 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2018-09-13 14:20 - 2018-05-12 04:07 - 000076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-09-13 14:20 - 2018-05-12 04:07 - 000033152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-09-13 14:20 - 2018-05-12 04:07 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-09-13 14:20 - 2018-05-11 23:19 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-09-13 14:20 - 2018-05-11 23:19 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-09-13 14:20 - 2018-05-11 02:40 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-09-13 14:20 - 2018-05-11 02:40 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-09-13 14:20 - 2018-05-02 17:32 - 000344064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2018-09-13 14:20 - 2018-05-02 17:32 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2018-09-13 14:20 - 2018-05-02 17:32 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2018-09-13 14:20 - 2018-05-02 17:32 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2018-09-13 14:20 - 2018-05-02 17:32 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2018-09-13 14:20 - 2018-05-02 17:32 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2018-09-13 14:20 - 2018-05-02 17:32 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2018-09-13 14:20 - 2018-04-26 15:05 - 000998912 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000918296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000065880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000063832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000021848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000020824 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000019288 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000018776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000017240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000017240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000015192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000013152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2018-09-13 14:20 - 2018-04-26 15:05 - 000011096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2018-09-13 14:20 - 2018-04-25 18:02 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2018-09-13 14:20 - 2018-04-25 17:18 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-09-12 17:03 - 2014-02-24 23:27 - 000000000 ____D C:\Users\Hačís\Downloads\Wise-Care-365-PRO-+-Serial-Key-(UploadniTo)
2018-09-11 19:39 - 2018-09-11 19:39 - 013687502 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2018-09-11 19:39 - 2018-09-11 19:39 - 006173640 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2018-09-11 19:39 - 2018-09-11 19:39 - 003677120 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2018-09-11 19:39 - 2018-09-11 19:39 - 003632464 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 003452120 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 003214672 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 002939728 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 001353280 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000692128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000541072 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000392840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000343672 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000327240 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000327232 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000230664 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000220352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000218232 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000192944 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000174904 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000122280 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000116504 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000093872 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2018-09-11 19:39 - 2018-09-11 19:39 - 000023656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2018-09-11 19:37 - 2018-09-11 19:37 - 001061200 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2018-09-11 19:37 - 2018-09-11 19:37 - 000124240 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2018-09-11 17:57 - 2018-10-02 17:27 - 000000000 ____D C:\Program Files (x86)\IObit
2018-09-11 16:54 - 2018-07-17 00:02 - 000563832 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-10-04 08:42 - 2018-08-28 14:43 - 000000000 ____D C:\Users\Hačís\AppData\Local\CrashDumps
2018-10-04 08:40 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2018-10-04 08:39 - 2017-11-19 04:20 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-10-04 08:39 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-10-04 03:13 - 2009-07-14 06:45 - 000019648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-10-04 03:13 - 2009-07-14 06:45 - 000019648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-10-03 22:38 - 2018-03-31 19:28 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-10-03 22:38 - 2009-07-14 05:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-10-03 22:36 - 2018-03-31 19:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office 2016
2018-10-03 22:35 - 2018-03-31 19:27 - 000000000 ____D C:\Program Files\Microsoft Office
2018-10-03 22:22 - 2009-07-14 17:18 - 000668542 _____ C:\Windows\system32\perfh005.dat
2018-10-03 22:22 - 2009-07-14 17:18 - 000141202 _____ C:\Windows\system32\perfc005.dat
2018-10-03 22:22 - 2009-07-14 07:13 - 001583226 _____ C:\Windows\system32\PerfStringBackup.INI
2018-10-03 22:15 - 2009-07-14 07:08 - 000032630 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-10-02 23:02 - 2009-07-14 04:34 - 000000215 _____ C:\Windows\system.ini
2018-10-02 21:32 - 2017-11-16 22:09 - 000000000 ____D C:\Users\Hačís
2018-10-02 21:28 - 2017-11-17 09:50 - 000000008 __RSH C:\Users\Hačís\ntuser.pol
2018-10-02 21:17 - 2009-07-14 05:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-10-02 17:49 - 2018-04-30 17:36 - 000000000 ____D C:\Program Files (x86)\FormatFactory
2018-10-02 17:27 - 2017-11-16 22:27 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\IObit
2018-10-02 17:27 - 2017-11-16 22:27 - 000000000 ____D C:\Users\Hačís\AppData\LocalLow\IObit
2018-10-02 17:27 - 2017-11-16 22:27 - 000000000 ____D C:\ProgramData\IObit
2018-10-01 20:56 - 2017-11-16 22:24 - 000000000 ____D C:\Program Files (x86)\Google
2018-10-01 08:41 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2018-09-30 18:19 - 2017-11-17 09:57 - 000063694 __RSH C:\Users\Děti\ntuser.pol
2018-09-30 18:19 - 2017-11-17 09:57 - 000000000 ____D C:\Users\Děti
2018-09-30 17:56 - 2017-11-19 20:05 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-09-30 17:43 - 2017-11-19 20:05 - 000000000 ____D C:\Users\Hačís\AppData\LocalLow\Mozilla
2018-09-30 13:17 - 2017-12-26 22:09 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\DAEMON Tools Pro
2018-09-29 20:03 - 2009-07-14 06:45 - 000671176 _____ C:\Windows\system32\FNTCACHE.DAT
2018-09-29 20:02 - 2017-11-20 23:12 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\uTorrent
2018-09-29 16:50 - 2017-11-16 22:24 - 000181472 _____ C:\Users\Hačís\AppData\Local\GDIPFONTCACHEV1.DAT
2018-09-29 16:23 - 2017-11-25 10:18 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\Wondershare
2018-09-29 16:23 - 2017-11-25 10:18 - 000000000 ____D C:\ProgramData\Wondershare
2018-09-29 16:21 - 2018-08-28 14:25 - 000000000 ____D C:\Users\Hačís\Documents\Corel VideoStudio Pro
2018-09-29 16:21 - 2018-08-24 10:08 - 000000000 ____D C:\ProgramData\Corel
2018-09-29 16:09 - 2017-11-25 23:27 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vlc
2018-09-29 09:15 - 2018-07-17 17:39 - 000000000 ____D C:\Users\Hačís\Desktop\Nová složka (3)
2018-09-27 19:52 - 2017-11-25 09:59 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\Anvsoft
2018-09-27 18:51 - 2018-03-19 10:41 - 000004128 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-09-20 20:22 - 2017-12-24 15:12 - 000000000 ____D C:\Users\Hačís\Desktop\hanča
2018-09-15 03:01 - 2017-11-18 20:44 - 001557940 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-09-14 16:31 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\rescache
2018-09-14 09:54 - 2017-11-20 05:02 - 000000000 ____D C:\Windows\system32\appraiser
2018-09-13 20:24 - 2017-11-19 04:02 - 000000000 ____D C:\Windows\system32\MRT
2018-09-13 20:19 - 2017-11-19 04:02 - 139184408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-09-12 17:06 - 2009-07-14 07:32 - 000000000 ____D C:\Windows\Downloaded Program Files
2018-09-12 15:24 - 2018-07-27 15:56 - 000000000 ____D C:\Program Files\StepMania 5
2018-09-12 15:23 - 2018-07-27 15:11 - 000000000 ____D C:\Program Files (x86)\PlayDance
2018-09-12 15:23 - 2009-07-14 07:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2018-09-11 19:44 - 2018-03-19 10:41 - 000000000 ____D C:\Program Files\CCleaner
2018-09-11 19:40 - 2017-11-16 22:36 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2018-09-11 19:37 - 2017-11-16 22:12 - 000120208 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2018-09-11 18:31 - 2017-11-16 23:10 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-09-11 18:31 - 2017-11-16 23:10 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-09-11 18:31 - 2017-11-16 23:10 - 000004540 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-09-11 18:31 - 2017-11-16 23:10 - 000004408 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-09-11 18:31 - 2017-11-16 23:10 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-09-11 18:31 - 2017-11-16 23:10 - 000000000 ____D C:\Windows\system32\Macromed
2018-09-11 17:31 - 2018-04-20 19:47 - 000004528 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier

==================== Files in the root of some directories =======

2018-09-29 16:38 - 2018-09-29 16:38 - 000001810 _____ () C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config
2018-03-13 16:16 - 2018-03-13 16:16 - 000195236 _____ () C:\Users\Hačís\AppData\Roaming\DMGR_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
2018-09-29 16:37 - 2018-09-29 16:37 - 000140800 _____ () C:\Users\Hačís\AppData\Local\installer.dat

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-09-25 03:19

==================== End of FRST.txt ============================

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 08:50

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03.10.2018 01
Ran by Hačís (04-10-2018 08:44:22)
Running from C:\Users\Hačís\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2017-11-16 20:08:42)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2123216125-335965321-1693192355-500 - Administrator - Disabled)
Děti (S-1-5-21-2123216125-335965321-1693192355-1003 - Limited - Enabled) => C:\Users\Děti
Guest (S-1-5-21-2123216125-335965321-1693192355-501 - Limited - Disabled)
Hačís (S-1-5-21-2123216125-335965321-1693192355-1000 - Administrator - Enabled) => C:\Users\Hačís
HomeGroupUser$ (S-1-5-21-2123216125-335965321-1693192355-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1.25534 - emc, uTorrent.CZ)
1.1i (HKLM-x32\...\{Temna vez - Sberatelska edice}_is1) (Version: - Spidla Data Processing, s.r.o.)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Adobe Flash Player 31 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated)
Adobe Photoshop CC 2018 (HKLM-x32\...\PHSP_19_0) (Version: 19.0 - Adobe Systems Incorporated)
Any Video Converter Ultimate 5.8.3 (HKLM-x32\...\Any Video Converter Ultimate_is1) (Version: - Any-Video-Converter.com)
AVS Video Editor 7.4.1 (HKLM-x32\...\AVS Video Editor_is1) (Version: 7.4.1.281 - Online Media Technologies Ltd.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/28/2014 11.0.0000.00000) (HKLM\...\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (12/06/2010 4.0.0000.00000) (HKLM\...\76F6B4A696B8C9A7ACFF01D4E1D6EF2D974C3E67) (Version: 12/06/2010 4.0.0000.00000 - Google, Inc.)
Balíček ovladače systému Windows - MediaTek Inc. (usbser) Ports (09/01/2011 2.0.1136.0) (HKLM\...\32DC281B7E359EA3D16ECC7D98609F6A592B981D) (Version: 09/01/2011 2.0.1136.0 - MediaTek Inc.)
Balíček ovladače systému Windows - MediaTek Inc. Net (07/14/2011 1.1129.00) (HKLM\...\8BC3CF920AF63C7AEF78B82D1C60D94704FB95CD) (Version: 07/14/2011 1.1129.00 - MediaTek Inc.)
Balíček ovladače systému Windows - Microsoft (WUDFRd) WPD (02/22/2006 5.2.5326.4762) (HKLM\...\B77DDB8A5697AAF5DA4E4859E53C301B877DD206) (Version: 02/22/2006 5.2.5326.4762 - Microsoft)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.46 - Piriform)
Corel Update Manager (HKLM\...\{6FA1F197-5EA9-4C48-BEA0-EC8F97AFE8F8}) (Version: 2.3.110 - Corel corporation) Hidden
Corel VideoStudio Ultimate X10 (HKLM-x32\...\_{F66B7119-9BE1-4982-A96D-4DB070A70B81}) (Version: X10.0.0.137 - Corel Corporation)
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.2.0.0348 - DT Soft Ltd)
Ďálova věž - Sběratelská edice (HKLM-x32\...\{Dablova vez - Sberatelska edice}_is1) (Version: - Spidla Data Processing, s.r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 69.0.3497.100 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - )
ICA (HKLM-x32\...\{F66B7119-9BE1-4982-A96D-4DB070A70B81}) (Version: 20.0.0.137 - Corel Corporation) Hidden
Laroxion_MT2 (HKLM-x32\...\{04C5FE2F-828B-4D7B-8D62-20FC73FAD96A}) (Version: 1.0.0 - Laroxion)
Malwarebytes verze 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
Master PDF Editor 3.6 (HKLM\...\Master PDF Editor 3_is1) (Version: 3.6.30 - Code Industry Ltd.)
MediaTek Driver Packages version 5.14.53.00 (HKLM\...\MediaTek Driver Packages_is1) (Version: 5.14.53.00 - MediaTek.Inc.)
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProplusRetail - cs-cz) (Version: 16.0.10827.20138 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850405-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2123216125-335965321-1693192355-1000\...\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft Project Professional 2016 - cs-cz (HKLM\...\ProjectProRetail - cs-cz) (Version: 16.0.10827.20138 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visio Professional 2016 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 16.0.10827.20138 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Mobile Upgrade S Gotu2v5.2.1 (HKLM-x32\...\{C9A7E6A6-110D-4DBC-A8E2-F634613B5A8C}_is1) (Version: - TCL Communication Technology Holdings Limited)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nero 2014 (HKLM-x32\...\{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}) (Version: 15.0.02200 - Nero AG)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.10827.20138 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.10827.20138 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.10827.20138 - Microsoft Corporation) Hidden
Prerequisite installer (HKLM-x32\...\{5909A89E-C97F-407C-AE2B-47BDED86BF5D}) (Version: 15.0.0005 - Nero AG) Hidden
PRO100 (HKLM-x32\...\{B3DBB43D-9451-45D0-B5A9-6413C98D091B}) (Version: 1.0.0 - Ecru)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.88.617.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8382 - Realtek Semiconductor Corp.)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.6.1 - Sophos Limited)
SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
The Sims 4 (HKLM-x32\...\The Sims 4_is1) (Version: - )
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0 - Ghisler Software GmbH)
Universal Adb Driver (HKLM-x32\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
VLC media player 2.1.0 (HKLM\...\VLC media player) (Version: 2.1.0 - VideoLAN)
VSUltimate64 (HKLM\...\{339A24A4-4B91-4D75-BEE8-1381F3BEFB19}) (Version: 20.0.0.137 - Corel Corporation) Hidden
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
ZD Soft Screen Recorder (HKLM-x32\...\{D893898C-2FFB-41F9-ADA5-80A3C1FC8F86}) (Version: 9.1.0 - ZD Soft)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2123216125-335965321-1693192355-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Hačís\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-10-02] ()
ContextMenuHandlers1: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2012-10-23] (DT Soft Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2012-10-23] (DT Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2018-10-02] ()
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2012-06-09] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {21DF32B1-D244-409F-BF7A-3A5B8108468A} - System32\Tasks\{D424AF5A-2B27-4D65-A4CA-36E16FE1A104} => C:\Windows\system32\pcalua.exe -a G:\Setup.exe -d G:\
Task: {45EC9A87-8318-4239-B78C-D469B80D99E3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-10-03] (Microsoft Corporation)
Task: {61CF483A-076D-4ADF-ADD8-D18C483C88EC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-10-03] (Microsoft Corporation)
Task: {62984315-D7D3-45FB-B71C-3E3141B50A32} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {6AAC4411-A9A9-4D0A-9C7D-9298B35978E5} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-09-26] (Microsoft Corporation)
Task: {74E6630B-79D9-4F86-B012-61A92D3BD75B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-11] (Piriform Ltd)
Task: {781BD534-7892-43AC-8FE7-DC9FC4C91928} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-10-01] (Google Inc.)
Task: {78367A45-9B89-401B-887A-4FE660FE5ECE} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-10-03] (Microsoft Corporation)
Task: {84691A71-DBF3-48E7-90C2-6D4668A13234} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_pepper.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {93A90B8C-957D-44B5-A7CF-EA0BD2AB32D4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {98C03107-D161-4BC1-80E8-6C9F733C98C5} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2013-08-20] (Nero AG)
Task: {A5D29F68-68D8-4FD0-9E88-7F547BBEB2CB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [2018-10-03] (Microsoft Corporation)
Task: {A9FDEC8C-91B0-45EA-B7A3-9CF3F23A7A93} - System32\Tasks\{48A39D7E-87E1-4527-BA24-ACC2819B7CB0} => C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\
Task: {AB05C395-67A3-4D81-A28A-840B633DF0D5} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-11] (Piriform Ltd)
Task: {B7650D90-709D-4140-98BF-A756284E7E65} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-10-01] (Google Inc.)
Task: {C0468901-8AC4-431F-907C-D9D3369596B4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-11] (Adobe Systems Incorporated)
Task: {D774648B-EC37-4285-928B-2361CFC6EF61} - System32\Tasks\CorelUpdateHelperTaskCore => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2016-11-08] (Corel Corporation)
Task: {DBB1DAE7-77A1-4323-BE61-A62B53A6D544} - System32\Tasks\{90C1D99C-5530-44D5-988A-7CBB64098E2A} => C:\Windows\system32\pcalua.exe -a G:\autorun.exe -d G:\
Task: {EDD2C30C-DFBF-4EEB-9F60-309A907DF3B0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-09-26] (Microsoft Corporation)
Task: {F986DF5D-47D1-40EC-BF38-927BF497E91B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-10-03] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-11-16 22:29 - 2017-11-16 22:29 - 000305176 _____ () C:\Windows\system32\atiesrxx.exe
2017-11-16 22:29 - 2017-11-16 22:29 - 000704536 _____ () C:\Windows\system32\atieclxx.exe
2018-03-31 19:39 - 2018-03-31 19:39 - 000959168 _____ () C:\Users\Hačís\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2018-10-02 21:31 - 2018-10-02 21:31 - 000155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2017-12-26 22:10 - 2017-12-26 22:08 - 000002560 _____ () C:\Program Files (x86)\DAEMON Tools Pro\MSIMG32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2018-10-02 23:02 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2123216125-335965321-1693192355-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hačís\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A441E673-4287-402F-B6A5-F96979CB2F18}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{50886020-C279-4FD8-80C5-E514BF72A3B4}] => (Allow) C:\Users\Hačís\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{805A41AB-6924-4861-95D1-8EDCA8AA6670}] => (Allow) C:\Users\Hačís\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{80F0A9CE-233C-4B01-BA75-B6B22E88B3D9}] => (Allow) C:\Program Files (x86)\Alawarhry.cz\Darkness and Flame Missing Memories Collectors Edition\DarknessAndFlame_MissingMemories_CE.exe
FirewallRules: [{3053F541-3193-432C-84D8-0A27A38E82AB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{22C40509-611E-4BC2-B501-3E76F35300DA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{1AAD8570-7DBC-477F-AC3B-3150944C3D1B}C:\program files (x86)\outlast + dlc whistleblower\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{2F7B75E2-602B-4658-BA9B-5E24273D67F0}C:\program files (x86)\outlast + dlc whistleblower\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [{4A510109-BD72-4918-8BB2-3EFCF511700D}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{AA8B7F1F-E011-499F-B293-D89727DA0F3E}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{63B82ED6-C0CD-4428-AA57-D329A8513A68}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe
FirewallRules: [{C52970D0-8E8F-4CA0-A126-1BCBB645D03E}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe
FirewallRules: [{E46D0335-8A23-4439-94E6-627425F97EAC}] => (Allow) C:\Program Files (x86)\Alawarhry.cz\The Legacy Prisoner Collectors Edition\TheLegacy_Prisoner_CE.exe
FirewallRules: [{4CF3E485-356F-4E86-984F-2511FA1951DF}] => (Allow) C:\Program Files (x86)\FormatFactory\FormatFactory.exe
FirewallRules: [{34F8FC84-B1CA-47AD-B22F-4B48E8AFFCC2}] => (Allow) C:\Program Files (x86)\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe
FirewallRules: [{0B154809-6D01-45B6-96FA-B1404B1C0A24}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0467B517-B7B0-4FE1-96E0-98CC8601C7BB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BBD8E79F-4061-45F3-8870-CC4C89462A38}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BAA9CF40-5FB1-4F06-BFCD-7893219503AF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C14BE2F7-B0FA-4637-B70D-404563A2FF98}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{42C6E946-6FFD-486F-A018-B5202268E4B7}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{53730CF2-6D21-4B7A-A4EA-A163F00467E4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{826661CD-FB51-4FFA-A58A-8A423CFBAD75}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{B2FA6AE7-9B14-472F-AC8A-3336EB6C5FD9}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{FBE6998C-AEBC-463E-83CE-30F979031B7D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

01-10-2018 03:00:29 Windows Update
01-10-2018 08:58:49 Windows Update
02-10-2018 03:00:29 Windows Update
02-10-2018 17:33:27 JRT Pre-Junkware Removal
02-10-2018 17:55:37 Removed Sophos Virus Removal Tool.
02-10-2018 18:05:32 Removed Sophos Virus Removal Tool.
02-10-2018 18:06:31 Installed Sophos Virus Removal Tool.
02-10-2018 21:00:15 zoek.exe restore point
02-10-2018 21:46:33 Zemana AntiMalware 2.10.2018 21:46:30
02-10-2018 23:40:48 Windows Update
03-10-2018 18:00:03 Windows Update
04-10-2018 03:00:33 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/04/2018 08:42:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: malwarebytes_assistant.exe, verze: 3.1.0.1614, časové razítko: 0x5b9bcc2c
Název chybujícího modulu: malwarebytes_assistant.exe, verze: 3.1.0.1614, časové razítko: 0x5b9bcc2c
Kód výjimky: 0xc0000005
Posun chyby: 0x0000bad2
ID chybujícího procesu: 0x1b98
Čas spuštění chybující aplikace: 0x01d45bad6cabb194
Cesta k chybující aplikaci: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
Cesta k chybujícímu modulu: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
ID zprávy: adae8880-c7a0-11e8-a2b6-fcaa1488776d

Error: (10/03/2018 08:13:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: malwarebytes_assistant.exe, verze: 3.1.0.1614, časové razítko: 0x5b9bcc2c
Název chybujícího modulu: malwarebytes_assistant.exe, verze: 3.1.0.1614, časové razítko: 0x5b9bcc2c
Kód výjimky: 0xc0000005
Posun chyby: 0x0000bad2
ID chybujícího procesu: 0x1164
Čas spuštění chybující aplikace: 0x01d45ae02f566499
Cesta k chybující aplikaci: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
Cesta k chybujícímu modulu: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
ID zprávy: 6ee3c571-c6d3-11e8-a4af-fcaa1488776d

Error: (10/02/2018 07:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15600

Error: (10/02/2018 07:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15600

Error: (10/02/2018 07:20:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/02/2018 05:54:30 PM) (Source: MsiInstaller) (EventID: 11606) (User: Hačís-PC)
Description: Product: Sophos Virus Removal Tool -- Error 1606.Could not access network location data.

Error: (10/02/2018 05:54:30 PM) (Source: MsiInstaller) (EventID: 11606) (User: Hačís-PC)
Description: Product: Sophos Virus Removal Tool -- Error 1606.Could not access network location data.

Error: (10/02/2018 05:53:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program mbam.exe verze 3.1.0.1614 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: e90

Čas spuštění: 01d45a67dac64de7

Čas ukončení: 47929

Cesta k aplikaci: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe

ID hlášení: 3e506f8a-c65b-11e8-adfb-fcaa1488776d


System errors:
=============
Error: (10/04/2018 03:03:17 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80070643): Internet Explorer 11 pro Windows 7 pro platformu x64.

Error: (10/03/2018 06:01:41 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80070643): Internet Explorer 11 pro Windows 7 pro platformu x64.

Error: (10/02/2018 11:41:54 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80070643): Internet Explorer 11 pro Windows 7 pro platformu x64.

Error: (10/02/2018 11:02:54 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (10/02/2018 11:02:29 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (10/02/2018 11:01:13 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\HAS~1\AppData\Local\Temp\catchme.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (10/02/2018 11:01:13 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\HAS~1\AppData\Local\Temp\catchme.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (10/02/2018 11:01:13 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\HAS~1\AppData\Local\Temp\catchme.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.


CodeIntegrity:
===================================

Date: 2018-10-02 23:02:29.299
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:02:29.237
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:01:13.327
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\HAS~1\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:01:13.265
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\HAS~1\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:01:13.187
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\HAS~1\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:01:13.093
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\HAS~1\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:01:13.015
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\HAS~1\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-02 23:01:12.953
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\HAS~1\AppData\Local\Temp\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: AMD A6-6400K APU with Radeon(tm) HD Graphics
Percentage of memory in use: 53%
Total physical RAM: 3256.28 MB
Available physical RAM: 1503.92 MB
Total Virtual: 6510.7 MB
Available Virtual: 4890.69 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:482.19 GB) (Free:203.23 GB) NTFS
Drive e: (Foto a video) (Fixed) (Total:292.97 GB) (Free:258.24 GB) NTFS
Drive f: (Všehochut) (Fixed) (Total:156.25 GB) (Free:25.48 GB) NTFS
Drive g: (House Flipper) (CDROM) (Total:1.95 GB) (Free:0 GB) UDF

\\?\Volume{847e9bb3-cb08-11e7-8b97-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 8FF8398E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=482.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=156.3 GB) - (Type=0F Extended)
Partition 4: (Not Active) - (Size=293 GB) - (Type=07 NTFS)

==================== End of Addition.txt ===========================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod jaro3 » 04 říj 2018 19:49

Odinstaluj:
IObit\Advanced SystemCare

C:\Users\Hačís\projekt x.sto
C:\Users\Hačís\projekt x.~sto
C:\Users\Hačís\pokoj01.sto
C:\Users\Hačís\pokoj.sto
znáš ty soubory?

C:\Program Files (x86)\Ecru
C:\Program Files (x86)\Full
znáš ty programy?


Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
GroupPolicyUsers\S-1-5-21-2123216125-335965321-1693192355-1003\User: Restriction - Chrome <==== ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-2123216125-335965321-1693192355-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2123216125-335965321-1693192355-1000 -> {2B82B6F4-6B2E-4DF7-84E1-E7690F824A84} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x64.sys [X]
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\drivers\Monitor_win7_x64.sys [X]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-09-30 17:45 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\hh3jieg1ucx
2018-09-30 17:38 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\3ce2ya4p240
2018-09-30 17:30 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\eygcxagbo4f
2018-09-30 17:29 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\00b4hxfzx5c
2018-09-30 17:07 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\lmrrdroejzg
2018-09-30 14:16 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\r3qw1xbhgw3
2018-09-30 14:07 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\130b0b4ocqy
2018-09-30 14:01 - 2018-09-30 14:01 - 000000000 ____D C:\ProgramData\WjIOjGvJCfODeXVB
2018-09-30 13:56 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\omaefet3eym
2018-09-30 13:56 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\gormp5x0evs
2018-09-30 13:27 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ovx0qblivpw
2018-09-30 13:16 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\dga0u5kmu5w
2018-09-30 13:11 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\aqmh13j20s2
2018-09-30 13:11 - 2018-09-30 13:14 - 000000000 ____D C:\Program Files\HJTWJO4U08
2018-09-30 13:06 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\x2imgkjw3lb
2018-09-30 12:55 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ygrox4kmpqc
2018-09-30 12:41 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\yzqlbva1lix
2018-09-30 12:26 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\3f4xgawjpai
2018-09-30 12:16 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\zpzdktybg4e
2018-09-30 12:06 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\4bhmymhmz3n
2018-09-30 11:56 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\nv4qwnmitzm
2018-09-30 11:55 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\1ueerqmk4fw
2018-09-30 11:41 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\0sx4xb2wkgg
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wbneen3cakm
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\uqklxuq3bpp
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\mpnvprj33jn
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\3eq5fibggzp
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\y2cdg30o154
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\xdbjew0ebnw
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\qfbolhfixhe
2018-09-30 11:11 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\kqtn35nyksr
2018-09-30 11:09 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vlrxvmgpbfm
2018-09-30 11:09 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\2hlvkweizah
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ia1jho0rtou
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\g2jgy3jy0cs
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\daxshilvflw
2018-09-30 11:07 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\iwyddph33j3
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\szq0myifpwv
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\slnv3c1pg4i
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\othmmklaufh
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\4up0t3gnrhx
2018-09-30 10:55 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\xnikdioprop
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\pqjhlyaij4p
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\chdk4rn0p2g
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\g2hgrrek4tl
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ccxld2btr4f
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\aiqxdp2j2ye
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\04dd3opwinq
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\qubn023ut11
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\la2vlm5mouk
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\k4e0qdqdsxf
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\egkvyuirmvt
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\byoccsr5awv
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\1rmxxtuxnj4
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\xibjq0rh1na
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vw51xgv3143
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ch4vifxsxp0
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\0gxeyae45l1
2018-09-29 17:26 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\rfey3c0k32z
2018-09-29 17:26 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\etjzn1nrftw
2018-09-29 17:23 - 2018-09-29 17:25 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\vlh3hsob5q0
2018-09-29 17:23 - 2018-09-29 17:25 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\0syghxusskg
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\tiod5uanl5r
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\tfnjc2nuxqe
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\14a5ops3r2f
2018-09-29 17:12 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\lijia2u2as3
2018-09-29 17:11 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wuyfuwi44yu
2018-09-29 17:11 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\osrhd1xyczz
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\smstnl4t1xt
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\okoapnjjegc
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\np5iak5homj
2018-09-29 16:57 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\rar3a24r3eo
2018-09-29 16:56 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\lprqgv2eica
2018-09-29 16:56 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\gnnzspdulls
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\zywez53rmgy
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\ldflgbpnfdu
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\22mxecvpjl5
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wow3hira2wg
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\f1a11uuevi4
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\aqdu3wnpf4z
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\4eqkwtq5byl
2018-09-29 16:39 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Hačís\AppData\Roaming\wj2bqs25opr
2018-09-29 16:38 - 2018-09-29 16:38 - 000001810 _____ C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config
2018-09-29 16:37 - 2018-09-29 16:37 - 000140800 _____ C:\Users\Hačís\AppData\Local\installer.dat
2018-09-29 16:35 - 2018-10-02 17:49 - 000000000 ____D C:\Windows\SysWOW64\wsfhyqup
C:\Windows\Tasks\ImCleanDisabled
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {781BD534-7892-43AC-8FE7-DC9FC4C91928} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-10-01] (Google Inc.)
Task: {B7650D90-709D-4140-98BF-A756284E7E65} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-10-01] (Google Inc.)

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na https://www.virustotal.com/#/home/uploadVirustotal
C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config
C:\Users\Hačís\AppData\Roaming\DMGR_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
C:\Users\Hačís\AppData\Local\installer.dat

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 22:30

Dobrý večer

IObit\Advanced SystemCare nemám nainstalovaný.
prosím tak soubory znám ale programy neznám.

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 22:31

Fix result of Farbar Recovery Scan Tool (x64) Version: 03.10.2018 01
Ran by Hačís (04-10-2018 22:05:14) Run:1
Running from C:\Users\Hačís\Desktop
Loaded Profiles: Hačís (Available Profiles: Hačís & Děti)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
GroupPolicyUsers\S-1-5-21-2123216125-335965321-1693192355-1003\User: Restriction - Chrome <==== ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-2123216125-335965321-1693192355-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2123216125-335965321-1693192355-1000 -> {2B82B6F4-6B2E-4DF7-84E1-E7690F824A84} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x64.sys [X]
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\drivers\Monitor_win7_x64.sys [X]
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-09-30 17:45 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\hh3jieg1ucx
2018-09-30 17:38 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\3ce2ya4p240
2018-09-30 17:30 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\eygcxagbo4f
2018-09-30 17:29 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\00b4hxfzx5c
2018-09-30 17:07 - 2018-10-02 17:31 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\lmrrdroejzg
2018-09-30 14:16 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\r3qw1xbhgw3
2018-09-30 14:07 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\130b0b4ocqy
2018-09-30 14:01 - 2018-09-30 14:01 - 000000000 ____D C:\ProgramData\WjIOjGvJCfODeXVB
2018-09-30 13:56 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\omaefet3eym
2018-09-30 13:56 - 2018-09-30 18:34 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\gormp5x0evs
2018-09-30 13:27 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\ovx0qblivpw
2018-09-30 13:16 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\dga0u5kmu5w
2018-09-30 13:11 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\aqmh13j20s2
2018-09-30 13:11 - 2018-09-30 13:14 - 000000000 ____D C:\Program Files\HJTWJO4U08
2018-09-30 13:06 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\x2imgkjw3lb
2018-09-30 12:55 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\ygrox4kmpqc
2018-09-30 12:41 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\yzqlbva1lix
2018-09-30 12:26 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\3f4xgawjpai
2018-09-30 12:16 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\zpzdktybg4e
2018-09-30 12:06 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\4bhmymhmz3n
2018-09-30 11:56 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\nv4qwnmitzm
2018-09-30 11:55 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\1ueerqmk4fw
2018-09-30 11:41 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\0sx4xb2wkgg
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\wbneen3cakm
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\uqklxuq3bpp
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\mpnvprj33jn
2018-09-30 11:19 - 2018-09-30 18:33 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\3eq5fibggzp
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\y2cdg30o154
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\xdbjew0ebnw
2018-09-30 11:14 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\qfbolhfixhe
2018-09-30 11:11 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\kqtn35nyksr
2018-09-30 11:09 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\vlrxvmgpbfm
2018-09-30 11:09 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\2hlvkweizah
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\ia1jho0rtou
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\g2jgy3jy0cs
2018-09-30 11:08 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\daxshilvflw
2018-09-30 11:07 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\iwyddph33j3
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\szq0myifpwv
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\slnv3c1pg4i
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\othmmklaufh
2018-09-30 10:56 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\4up0t3gnrhx
2018-09-30 10:55 - 2018-09-30 18:32 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\xnikdioprop
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\pqjhlyaij4p
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\chdk4rn0p2g
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\g2hgrrek4tl
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\ccxld2btr4f
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\aiqxdp2j2ye
2018-09-29 17:40 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\04dd3opwinq
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\qubn023ut11
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\la2vlm5mouk
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\k4e0qdqdsxf
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\egkvyuirmvt
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\byoccsr5awv
2018-09-29 17:34 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\1rmxxtuxnj4
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\xibjq0rh1na
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\vw51xgv3143
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\ch4vifxsxp0
2018-09-29 17:29 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\0gxeyae45l1
2018-09-29 17:26 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\rfey3c0k32z
2018-09-29 17:26 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\etjzn1nrftw
2018-09-29 17:23 - 2018-09-29 17:25 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\vlh3hsob5q0
2018-09-29 17:23 - 2018-09-29 17:25 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\0syghxusskg
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\tiod5uanl5r
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\tfnjc2nuxqe
2018-09-29 17:17 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\14a5ops3r2f
2018-09-29 17:12 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\lijia2u2as3
2018-09-29 17:11 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\wuyfuwi44yu
2018-09-29 17:11 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\osrhd1xyczz
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\smstnl4t1xt
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\okoapnjjegc
2018-09-29 17:04 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\np5iak5homj
2018-09-29 16:57 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\rar3a24r3eo
2018-09-29 16:56 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\lprqgv2eica
2018-09-29 16:56 - 2018-09-30 10:49 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\gnnzspdulls
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\zywez53rmgy
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\ldflgbpnfdu
2018-09-29 16:41 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\22mxecvpjl5
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\wow3hira2wg
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\f1a11uuevi4
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\aqdu3wnpf4z
2018-09-29 16:40 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\4eqkwtq5byl
2018-09-29 16:39 - 2018-09-30 10:48 - 000000000 ____D C:\Users\Ha��s\AppData\Roaming\wj2bqs25opr
2018-09-29 16:38 - 2018-09-29 16:38 - 000001810 _____ C:\Users\Ha��s\AppData\Roaming\25IKJ9G.exe.config
2018-09-29 16:37 - 2018-09-29 16:37 - 000140800 _____ C:\Users\Ha��s\AppData\Local\installer.dat
2018-09-29 16:35 - 2018-10-02 17:49 - 000000000 ____D C:\Windows\SysWOW64\wsfhyqup
C:\Windows\Tasks\ImCleanDisabled
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {781BD534-7892-43AC-8FE7-DC9FC4C91928} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-10-01] (Google Inc.)
Task: {B7650D90-709D-4140-98BF-A756284E7E65} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-10-01] (Google Inc.)

EmptyTemp:
End
*****************

Processes closed successfully.
"HKU\S-1-5-21-2123216125-335965321-1693192355-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks" => removed successfully
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-2123216125-335965321-1693192355-1003\User => moved successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => removed successfully
HKLM\Software\Classes\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => not found
HKU\S-1-5-21-2123216125-335965321-1693192355-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2B82B6F4-6B2E-4DF7-84E1-E7690F824A84} => removed successfully
HKLM\Software\Classes\CLSID\{2B82B6F4-6B2E-4DF7-84E1-E7690F824A84} => not found
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz143 => removed successfully
cpuz143 => service removed successfully
HKLM\System\CurrentControlSet\Services\iobit_monitor_server => removed successfully
iobit_monitor_server => service removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"C:\Users\Ha��s\AppData\Roaming\hh3jieg1ucx" => not found
"C:\Users\Ha��s\AppData\Roaming\3ce2ya4p240" => not found
"C:\Users\Ha��s\AppData\Roaming\eygcxagbo4f" => not found
"C:\Users\Ha��s\AppData\Roaming\00b4hxfzx5c" => not found
"C:\Users\Ha��s\AppData\Roaming\lmrrdroejzg" => not found
"C:\Users\Ha��s\AppData\Roaming\r3qw1xbhgw3" => not found
"C:\Users\Ha��s\AppData\Roaming\130b0b4ocqy" => not found
C:\ProgramData\WjIOjGvJCfODeXVB => moved successfully
"C:\Users\Ha��s\AppData\Roaming\omaefet3eym" => not found
"C:\Users\Ha��s\AppData\Roaming\gormp5x0evs" => not found
"C:\Users\Ha��s\AppData\Roaming\ovx0qblivpw" => not found
"C:\Users\Ha��s\AppData\Roaming\dga0u5kmu5w" => not found
"C:\Users\Ha��s\AppData\Roaming\aqmh13j20s2" => not found
C:\Program Files\HJTWJO4U08 => moved successfully
"C:\Users\Ha��s\AppData\Roaming\x2imgkjw3lb" => not found
"C:\Users\Ha��s\AppData\Roaming\ygrox4kmpqc" => not found
"C:\Users\Ha��s\AppData\Roaming\yzqlbva1lix" => not found
"C:\Users\Ha��s\AppData\Roaming\3f4xgawjpai" => not found
"C:\Users\Ha��s\AppData\Roaming\zpzdktybg4e" => not found
"C:\Users\Ha��s\AppData\Roaming\4bhmymhmz3n" => not found
"C:\Users\Ha��s\AppData\Roaming\nv4qwnmitzm" => not found
"C:\Users\Ha��s\AppData\Roaming\1ueerqmk4fw" => not found
"C:\Users\Ha��s\AppData\Roaming\0sx4xb2wkgg" => not found
"C:\Users\Ha��s\AppData\Roaming\wbneen3cakm" => not found
"C:\Users\Ha��s\AppData\Roaming\uqklxuq3bpp" => not found
"C:\Users\Ha��s\AppData\Roaming\mpnvprj33jn" => not found
"C:\Users\Ha��s\AppData\Roaming\3eq5fibggzp" => not found
"C:\Users\Ha��s\AppData\Roaming\y2cdg30o154" => not found
"C:\Users\Ha��s\AppData\Roaming\xdbjew0ebnw" => not found
"C:\Users\Ha��s\AppData\Roaming\qfbolhfixhe" => not found
"C:\Users\Ha��s\AppData\Roaming\kqtn35nyksr" => not found
"C:\Users\Ha��s\AppData\Roaming\vlrxvmgpbfm" => not found
"C:\Users\Ha��s\AppData\Roaming\2hlvkweizah" => not found
"C:\Users\Ha��s\AppData\Roaming\ia1jho0rtou" => not found
"C:\Users\Ha��s\AppData\Roaming\g2jgy3jy0cs" => not found
"C:\Users\Ha��s\AppData\Roaming\daxshilvflw" => not found
"C:\Users\Ha��s\AppData\Roaming\iwyddph33j3" => not found
"C:\Users\Ha��s\AppData\Roaming\szq0myifpwv" => not found
"C:\Users\Ha��s\AppData\Roaming\slnv3c1pg4i" => not found
"C:\Users\Ha��s\AppData\Roaming\othmmklaufh" => not found
"C:\Users\Ha��s\AppData\Roaming\4up0t3gnrhx" => not found
"C:\Users\Ha��s\AppData\Roaming\xnikdioprop" => not found
"C:\Users\Ha��s\AppData\Roaming\pqjhlyaij4p" => not found
"C:\Users\Ha��s\AppData\Roaming\chdk4rn0p2g" => not found
"C:\Users\Ha��s\AppData\Roaming\g2hgrrek4tl" => not found
"C:\Users\Ha��s\AppData\Roaming\ccxld2btr4f" => not found
"C:\Users\Ha��s\AppData\Roaming\aiqxdp2j2ye" => not found
"C:\Users\Ha��s\AppData\Roaming\04dd3opwinq" => not found
"C:\Users\Ha��s\AppData\Roaming\qubn023ut11" => not found
"C:\Users\Ha��s\AppData\Roaming\la2vlm5mouk" => not found
"C:\Users\Ha��s\AppData\Roaming\k4e0qdqdsxf" => not found
"C:\Users\Ha��s\AppData\Roaming\egkvyuirmvt" => not found
"C:\Users\Ha��s\AppData\Roaming\byoccsr5awv" => not found
"C:\Users\Ha��s\AppData\Roaming\1rmxxtuxnj4" => not found
"C:\Users\Ha��s\AppData\Roaming\xibjq0rh1na" => not found
"C:\Users\Ha��s\AppData\Roaming\vw51xgv3143" => not found
"C:\Users\Ha��s\AppData\Roaming\ch4vifxsxp0" => not found
"C:\Users\Ha��s\AppData\Roaming\0gxeyae45l1" => not found
"C:\Users\Ha��s\AppData\Roaming\rfey3c0k32z" => not found
"C:\Users\Ha��s\AppData\Roaming\etjzn1nrftw" => not found
"C:\Users\Ha��s\AppData\Roaming\vlh3hsob5q0" => not found
"C:\Users\Ha��s\AppData\Roaming\0syghxusskg" => not found
"C:\Users\Ha��s\AppData\Roaming\tiod5uanl5r" => not found
"C:\Users\Ha��s\AppData\Roaming\tfnjc2nuxqe" => not found
"C:\Users\Ha��s\AppData\Roaming\14a5ops3r2f" => not found
"C:\Users\Ha��s\AppData\Roaming\lijia2u2as3" => not found
"C:\Users\Ha��s\AppData\Roaming\wuyfuwi44yu" => not found
"C:\Users\Ha��s\AppData\Roaming\osrhd1xyczz" => not found
"C:\Users\Ha��s\AppData\Roaming\smstnl4t1xt" => not found
"C:\Users\Ha��s\AppData\Roaming\okoapnjjegc" => not found
"C:\Users\Ha��s\AppData\Roaming\np5iak5homj" => not found
"C:\Users\Ha��s\AppData\Roaming\rar3a24r3eo" => not found
"C:\Users\Ha��s\AppData\Roaming\lprqgv2eica" => not found
"C:\Users\Ha��s\AppData\Roaming\gnnzspdulls" => not found
"C:\Users\Ha��s\AppData\Roaming\zywez53rmgy" => not found
"C:\Users\Ha��s\AppData\Roaming\ldflgbpnfdu" => not found
"C:\Users\Ha��s\AppData\Roaming\22mxecvpjl5" => not found
"C:\Users\Ha��s\AppData\Roaming\wow3hira2wg" => not found
"C:\Users\Ha��s\AppData\Roaming\f1a11uuevi4" => not found
"C:\Users\Ha��s\AppData\Roaming\aqdu3wnpf4z" => not found
"C:\Users\Ha��s\AppData\Roaming\4eqkwtq5byl" => not found
"C:\Users\Ha��s\AppData\Roaming\wj2bqs25opr" => not found
"C:\Users\Ha��s\AppData\Roaming\25IKJ9G.exe.config" => not found
"C:\Users\Ha��s\AppData\Local\installer.dat" => not found
C:\Windows\SysWOW64\wsfhyqup => moved successfully
C:\Windows\Tasks\ImCleanDisabled => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{781BD534-7892-43AC-8FE7-DC9FC4C91928}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{781BD534-7892-43AC-8FE7-DC9FC4C91928}" => removed successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7650D90-709D-4140-98BF-A756284E7E65}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7650D90-709D-4140-98BF-A756284E7E65}" => removed successfully
"C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8331375 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 2747735 B
Edge => 0 B
Chrome => 418832675 B
Firefox => 458752 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 33058 B
Public => 0 B
ProgramData => 0 B
systemprofile => 93304737 B
systemprofile32 => 36142 B
LocalService => 66228 B
NetworkService => 66228 B
Hačís => 756705 B
Děti => 347892 B

RecycleBin => 0 B
EmptyTemp: => 508.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 22:05:28 ====


Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod jaro3 » 04 říj 2018 22:41

"C:\Users\Ha��s\AppData\Roaming\omaefet3eym -- koukni se , zada tam máš tento soubor/složku

C:\Users\Hačís\AppData\Local\installer.dat smažeme..

soubor onetwo.exe.config jsem nechtěl testovat , ale:
C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config

dodej na VT,


+
Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt

Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 23:09

C:\Users\Ha��s\AppData\Roaming\omaefet3eym toto je složka v pc
C:\Users\Hačís\AppData\Local\installer.dat smazáno

http://r.virscan.org/language/en/report ... 8dc8c1b499

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 23:10

OTL logfile created on: 4.10.2018 22:50:51 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Hačís\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,18 Gb Total Physical Memory | 2,22 Gb Available Physical Memory | 69,75% Memory free
6,36 Gb Paging File | 5,12 Gb Available in Paging File | 80,59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 482,19 Gb Total Space | 203,91 Gb Free Space | 42,29% Space Free | Partition Type: NTFS
Drive E: | 292,97 Gb Total Space | 258,24 Gb Free Space | 88,15% Space Free | Partition Type: NTFS
Drive F: | 156,25 Gb Total Space | 25,48 Gb Free Space | 16,31% Space Free | Partition Type: NTFS
Drive G: | 1,95 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

Computer Name: HAČÍS-PC | User Name: Hačís | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Hačís\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\DAEMON Tools Pro\MSIMG32.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (MBAMService) -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe ()
SRV:64bit: - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (ZAMSvc) -- C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (NAUpdate) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ZAM) -- C:\Windows\SysNative\drivers\zam64.sys (Zemana Ltd.)
DRV:64bit: - (ZAM_Guard) -- C:\Windows\SysNative\drivers\zamguard64.sys (Zemana Ltd.)
DRV:64bit: - (nfstat) -- C:\Windows\SysNative\drivers\nfstat.sys (Riverbed Technology, Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (amdxhc) -- C:\Windows\SysNative\drivers\amdxhc.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices)
DRV:64bit: - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices)
DRV:64bit: - (amdide64) -- C:\Windows\SysNative\drivers\amdide64.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys ()
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys ()
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (wdm_usb) -- C:\Windows\SysNative\drivers\usb2ser.sys (MBB)
DRV:64bit: - (RMCAST) -- C:\Windows\SysNative\drivers\rmcast.sys (Microsoft Corporation)
DRV:64bit: - (DroidCamVideo) -- C:\Windows\SysNative\drivers\droidcamvideo.sys (Dev47Apps)
DRV:64bit: - (DroidCam) -- C:\Windows\SysNative\drivers\droidcam.sys (Dev47Apps)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (anvsnddrv) -- C:\Windows\SysNative\drivers\anvsnddrv.sys (AnvSoft Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (HWiNFO32) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS (REALiX(tm))
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,IE11UpgradePageShownTime = C0 FA 6D B8 B7 59 D4 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 06 D8 B3 35 04 57 D4 01 [binary data]
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.countryCode: "CZ"
FF - prefs.js..browser.search.region: "CZ"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_108.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_108.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2017.11.19 20:05:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hačís\AppData\Roaming\Mozilla\Extensions
[2017.11.19 20:05:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hačís\AppData\Roaming\Mozilla\SystemExtensionsDev
[2018.09.29 20:51:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\extensions
[2018.04.20 19:55:24 | 000,006,212 | ---- | M] () (No name found) -- C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\liomqgv9.default-1524246403824\features\{96c82469-da76-43dc-bd94-f0241424b33f}\tls13-rollout-bug1442042@mozilla.org.xpi
[2018.09.29 20:59:41 | 000,015,090 | ---- | M] () (No name found) -- C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\features\{cd8171c7-3005-4fd6-876c-9445ce7c46cc}\fxmonitor@mozilla.org.xpi
[2018.09.29 20:59:41 | 000,006,835 | ---- | M] () (No name found) -- C:\Users\Hačís\AppData\Roaming\Mozilla\Firefox\Profiles\rk8u8k6q.default-1538247061974\features\{cd8171c7-3005-4fd6-876c-9445ce7c46cc}\telemetry-coverage-bug1487578@mozilla.org.xpi

========== Chrome ==========

CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\Hačís\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6918.723.0.0_0\

O1 HOSTS File: ([2018.10.02 23:02:51 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\URLREDIR.DLL (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [ZAM] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Hačís\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Poslat do aplikace OneNote.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Internet)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8E7F98CD-F1E6-436B-854F-273C4B574F9F}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB0A3BFC-3FE9-4523-83AC-91C68D0BC2E7}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-minsb-roaming.16 {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf.16 {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\osf-roaming.16 {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2018.05.17 08:46:26 | 000,000,064 | R--- | M] () - G:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2018.10.04 22:48:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Hačís\Desktop\OTL.exe
[2018.10.04 08:42:58 | 000,000,000 | ---D | C] -- C:\FRST
[2018.10.04 08:41:45 | 002,414,080 | ---- | C] (Farbar) -- C:\Users\Hačís\Desktop\FRST64.exe
[2018.10.04 08:31:56 | 000,000,000 | ---D | C] -- C:\Users\Hačís\Desktop\backups
[2018.10.03 22:38:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2018.10.03 22:20:26 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Hačís\Desktop\HijackThis.exe
[2018.10.03 11:26:48 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\Google
[2018.10.03 08:40:07 | 000,000,000 | ---D | C] -- C:\Users\Hačís\Documents\AVS4YOU
[2018.10.02 23:04:57 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2018.10.02 21:49:50 | 000,000,000 | ---D | C] -- C:\Qoobox
[2018.10.02 21:49:36 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2018.10.02 21:31:33 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zam64.sys
[2018.10.02 21:31:32 | 000,203,680 | ---- | C] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zamguard64.sys
[2018.10.02 21:31:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
[2018.10.02 21:31:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zemana AntiMalware
[2018.10.02 21:31:09 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Local\Zemana
[2018.10.02 21:21:57 | 000,000,000 | ---D | C] -- C:\Windows\Temp
[2018.10.02 21:21:57 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Local\Temp
[2018.10.02 20:58:07 | 000,000,000 | ---D | C] -- C:\zoek_backup
[2018.10.02 20:31:53 | 006,625,600 | ---- | C] (Zemana Ltd. ) -- C:\Users\Hačís\Desktop\Zemana.AntiMalware.Setup.exe
[2018.10.02 19:39:49 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2018.10.02 18:06:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2018.10.02 18:06:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
[2018.10.01 22:46:42 | 001,790,024 | ---- | C] (Malwarebytes) -- C:\Users\Hačís\Desktop\JRT.exe
[2018.10.01 22:45:11 | 027,157,048 | ---- | C] (Adlice Software) -- C:\Users\Hačís\Desktop\RogueKiller_portable64.exe
[2018.09.30 18:19:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2018.09.30 17:45:24 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\hh3jieg1ucx
[2018.09.30 17:38:56 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\3ce2ya4p240
[2018.09.30 17:30:12 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\eygcxagbo4f
[2018.09.30 17:29:45 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\00b4hxfzx5c
[2018.09.30 17:07:13 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\lmrrdroejzg
[2018.09.30 14:16:36 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\r3qw1xbhgw3
[2018.09.30 14:07:18 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\130b0b4ocqy
[2018.09.30 13:56:58 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\omaefet3eym
[2018.09.30 13:56:54 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\gormp5x0evs
[2018.09.30 13:27:02 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\ovx0qblivpw
[2018.09.30 13:16:05 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\dga0u5kmu5w
[2018.09.30 13:11:34 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\aqmh13j20s2
[2018.09.30 13:06:55 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\x2imgkjw3lb
[2018.09.30 12:55:58 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\ygrox4kmpqc
[2018.09.30 12:41:51 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\yzqlbva1lix
[2018.09.30 12:26:15 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\3f4xgawjpai
[2018.09.30 12:16:06 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\zpzdktybg4e
[2018.09.30 12:06:49 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\4bhmymhmz3n
[2018.09.30 11:56:43 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\nv4qwnmitzm
[2018.09.30 11:55:49 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\1ueerqmk4fw
[2018.09.30 11:41:10 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\0sx4xb2wkgg
[2018.09.30 11:19:28 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\uqklxuq3bpp
[2018.09.30 11:19:21 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\wbneen3cakm
[2018.09.30 11:19:21 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\3eq5fibggzp
[2018.09.30 11:19:20 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\mpnvprj33jn
[2018.09.30 11:14:51 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\y2cdg30o154
[2018.09.30 11:14:48 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\xdbjew0ebnw
[2018.09.30 11:14:47 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\qfbolhfixhe
[2018.09.30 11:11:23 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\kqtn35nyksr
[2018.09.30 11:09:04 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\vlrxvmgpbfm
[2018.09.30 11:09:03 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\2hlvkweizah
[2018.09.30 11:08:57 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\ia1jho0rtou
[2018.09.30 11:08:57 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\g2jgy3jy0cs
[2018.09.30 11:08:57 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\daxshilvflw
[2018.09.30 11:07:04 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\iwyddph33j3
[2018.09.30 10:56:22 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\othmmklaufh
[2018.09.30 10:56:17 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\szq0myifpwv
[2018.09.30 10:56:13 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\slnv3c1pg4i
[2018.09.30 10:56:01 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\4up0t3gnrhx
[2018.09.30 10:55:40 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\xnikdioprop
[2018.09.30 10:17:06 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Local\mbam
[2018.09.30 10:16:30 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Local\mbamtray
[2018.09.30 10:15:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2018.09.30 10:15:52 | 000,152,688 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbae64.sys
[2018.09.30 10:15:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2018.09.30 10:15:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2018.09.29 21:03:34 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2018.09.29 21:00:55 | 007,567,568 | ---- | C] (Malwarebytes) -- C:\Users\Hačís\Desktop\AdwCleaner.exe
[2018.09.29 21:00:03 | 080,408,496 | ---- | C] (Malwarebytes ) -- C:\Users\Hačís\Desktop\mb3-setup-consumer-3.6.1.2711-1.0.463-1.0.7063.exe
[2018.09.29 20:59:51 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\Hačís\Desktop\TFC.exe
[2018.09.29 20:59:32 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\Hačís\Desktop\ATF-Cleaner.exe
[2018.09.29 17:40:55 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\pqjhlyaij4p
[2018.09.29 17:40:55 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\aiqxdp2j2ye
[2018.09.29 17:40:55 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\04dd3opwinq
[2018.09.29 17:40:54 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\g2hgrrek4tl
[2018.09.29 17:40:17 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\chdk4rn0p2g
[2018.09.29 17:40:16 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\ccxld2btr4f
[2018.09.29 17:34:09 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\1rmxxtuxnj4
[2018.09.29 17:34:07 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\la2vlm5mouk
[2018.09.29 17:34:05 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\qubn023ut11
[2018.09.29 17:34:05 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\k4e0qdqdsxf
[2018.09.29 17:34:05 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\egkvyuirmvt
[2018.09.29 17:34:05 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\byoccsr5awv
[2018.09.29 17:29:48 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\0gxeyae45l1
[2018.09.29 17:29:47 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\xibjq0rh1na
[2018.09.29 17:29:47 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\vw51xgv3143
[2018.09.29 17:29:47 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\ch4vifxsxp0
[2018.09.29 17:26:39 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\rfey3c0k32z
[2018.09.29 17:26:39 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\etjzn1nrftw
[2018.09.29 17:23:23 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\0syghxusskg
[2018.09.29 17:23:22 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\vlh3hsob5q0
[2018.09.29 17:17:39 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\tfnjc2nuxqe
[2018.09.29 17:17:24 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\tiod5uanl5r
[2018.09.29 17:17:24 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\14a5ops3r2f
[2018.09.29 17:12:14 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\lijia2u2as3
[2018.09.29 17:11:15 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\wuyfuwi44yu
[2018.09.29 17:11:15 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\osrhd1xyczz
[2018.09.29 17:04:54 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\smstnl4t1xt
[2018.09.29 17:04:50 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\okoapnjjegc
[2018.09.29 17:04:49 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\np5iak5homj
[2018.09.29 16:57:17 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\rar3a24r3eo
[2018.09.29 16:56:58 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\lprqgv2eica
[2018.09.29 16:56:58 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\gnnzspdulls
[2018.09.29 16:50:47 | 000,000,000 | ---D | C] -- C:\Users\Hačís\Documents\MAGIX_MusicEditor
[2018.09.29 16:50:44 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Local\Xara
[2018.09.29 16:50:41 | 000,000,000 | ---D | C] -- C:\Users\Hačís\Documents\MAGIX downloads
[2018.09.29 16:50:38 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\MAGIX
[2018.09.29 16:50:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MAGIX Shared
[2018.09.29 16:50:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MAGIX Shared
[2018.09.29 16:46:22 | 000,000,000 | R--D | C] -- C:\Users\Hačís\Documents\MAGIX
[2018.09.29 16:46:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MAGIX Services
[2018.09.29 16:46:19 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX
[2018.09.29 16:41:49 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\ldflgbpnfdu
[2018.09.29 16:41:48 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\zywez53rmgy
[2018.09.29 16:41:47 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\22mxecvpjl5
[2018.09.29 16:40:26 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\f1a11uuevi4
[2018.09.29 16:40:20 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\4eqkwtq5byl
[2018.09.29 16:40:12 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\aqdu3wnpf4z
[2018.09.29 16:40:04 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\wow3hira2wg
[2018.09.29 16:39:41 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\wj2bqs25opr
[2018.09.29 16:39:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Full
[2018.09.29 16:33:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2018.09.29 16:33:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2018.09.29 16:25:00 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2018.09.29 16:24:56 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\AVS4YOU
[2018.09.29 16:23:45 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2018.09.29 16:22:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
[2018.09.29 16:22:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVSMedia
[2018.09.29 16:22:17 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GdiPlus.dll
[2018.09.29 16:22:17 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3a.dll
[2018.09.29 16:22:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU
[2018.09.29 16:10:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Protexis
[2018.09.29 16:10:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Corel
[2018.09.29 16:06:44 | 000,000,000 | ---D | C] -- C:\Program Files\Corel
[2018.09.29 09:37:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ecru
[2018.09.29 09:35:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PRO100
[2018.09.29 09:35:12 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\Ecru
[2018.09.20 09:16:20 | 000,134,760 | ---- | C] (Riverbed Technology, Inc.) -- C:\Windows\SysNative\drivers\nfstat.sys
[2018.09.19 10:09:06 | 000,000,000 | ---D | C] -- C:\Users\Hačís\Documents\Vlastní šablony Office
[2018.09.14 15:33:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SP Driver
[2018.09.14 15:33:33 | 000,000,000 | ---D | C] -- C:\Program Files\MediaTek
[2018.09.14 15:33:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ClockworkMod
[2018.09.14 15:32:04 | 000,000,000 | ---D | C] -- C:\Users\Hačís\AppData\Roaming\AdbDriverInstaller
[2018.09.13 19:54:19 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Steam
[2018.09.13 14:22:09 | 002,860,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aitstatic.exe
[2018.09.13 14:22:08 | 001,602,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appraiser.dll
[2018.09.13 14:22:08 | 000,783,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2018.09.13 14:22:08 | 000,680,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2018.09.13 14:22:08 | 000,612,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devinv.dll
[2018.09.13 14:22:08 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\centel.dll
[2018.09.13 14:22:08 | 000,443,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\invagent.dll
[2018.09.13 14:22:08 | 000,301,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\acmigration.dll
[2018.09.13 14:22:08 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepic.dll
[2018.09.13 14:22:08 | 000,140,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CompatTelRunner.exe
[2018.09.13 14:20:29 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2018.09.13 14:20:29 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msihnd.dll
[2018.09.13 14:20:29 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2018.09.13 14:20:29 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2018.09.13 14:20:29 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2018.09.13 14:20:29 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2018.09.13 14:20:29 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msimsg.dll
[2018.09.13 14:20:29 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2018.09.13 14:20:29 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2018.09.13 14:20:29 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2018.09.13 14:20:29 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2018.09.13 14:20:29 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2018.09.13 14:20:29 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2018.09.13 14:20:29 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll

standacich
Level 3
Level 3
Příspěvky: 514
Registrován: říjen 12
Bydliště: Hustopeče
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu HJT

Příspěvekod standacich » 04 říj 2018 23:10

[2018.09.13 14:20:29 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2018.09.13 14:20:29 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2018.09.13 14:20:29 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2018.09.13 14:20:29 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2018.09.13 14:20:28 | 004,054,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2018.09.13 14:20:28 | 000,880,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2018.09.13 14:20:28 | 000,782,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webservices.dll
[2018.09.13 14:20:28 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2018.09.13 14:20:28 | 000,342,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2018.09.13 14:20:28 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2018.09.13 14:20:28 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msihnd.dll
[2018.09.13 14:20:28 | 000,309,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2018.09.13 14:20:28 | 000,289,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2018.09.13 14:20:28 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll
[2018.09.13 14:20:28 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2018.09.13 14:20:28 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\INETRES.dll
[2018.09.13 14:20:28 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2018.09.13 14:20:28 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptbase.dll
[2018.09.13 14:20:28 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
[2018.09.13 14:20:28 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscdll.dll
[2018.09.13 14:20:28 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2018.09.13 14:20:28 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2018.09.13 14:20:28 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msimsg.dll
[2018.09.13 14:20:28 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wfapigp.dll
[2018.09.13 14:20:28 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
[2018.09.13 14:20:28 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2018.09.13 14:20:28 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2018.09.13 14:20:27 | 001,806,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2018.09.13 14:20:27 | 001,499,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2018.09.13 14:20:27 | 000,385,120 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2018.09.13 14:20:27 | 000,378,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2018.09.13 14:20:27 | 000,312,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2018.09.13 14:20:27 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2018.09.13 14:20:27 | 000,129,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\videoprt.sys
[2018.09.13 14:20:27 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcrypt.dll
[2018.09.13 14:20:27 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2018.09.13 14:20:27 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2018.09.13 14:20:27 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2018.09.13 14:20:27 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscapi.dll
[2018.09.13 14:20:27 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2018.09.13 14:20:27 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2018.09.13 14:20:27 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comcat.dll
[2018.09.13 14:20:26 | 003,961,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2018.09.13 14:20:26 | 001,664,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2018.09.13 14:20:26 | 001,461,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2018.09.13 14:20:26 | 001,211,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2018.09.13 14:20:26 | 000,749,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FirewallAPI.dll
[2018.09.13 14:20:26 | 000,263,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2018.09.13 14:20:26 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2018.09.13 14:20:26 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll
[2018.09.13 14:20:26 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2018.09.13 14:20:26 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hlink.dll
[2018.09.13 14:20:26 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
[2018.09.13 14:20:26 | 000,033,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys
[2018.09.13 14:20:25 | 003,207,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2018.09.13 14:20:25 | 001,867,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2018.09.13 14:20:25 | 001,159,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webservices.dll
[2018.09.13 14:20:25 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2018.09.13 14:20:25 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2018.09.13 14:20:25 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2018.09.13 14:20:24 | 005,552,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2018.09.13 14:20:24 | 003,246,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2018.09.13 14:20:24 | 001,942,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2018.09.13 14:20:24 | 000,114,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\consent.exe
[2018.09.13 14:20:23 | 004,120,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2018.09.13 14:20:23 | 002,066,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2018.09.13 14:20:23 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2018.09.13 14:20:22 | 000,708,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2018.09.13 14:20:22 | 000,634,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2018.09.13 14:20:22 | 000,631,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2018.09.13 14:20:22 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll
[2018.09.13 14:20:22 | 000,459,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2018.09.13 14:20:22 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2018.09.13 14:20:22 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2018.09.13 14:20:22 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2018.09.13 14:20:22 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2018.09.13 14:20:22 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf3216.dll
[2018.09.13 14:20:22 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2018.09.13 14:20:22 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf3216.dll
[2018.09.13 14:20:22 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2018.09.13 14:20:21 | 001,311,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjet40.dll
[2018.09.13 14:20:21 | 001,190,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2018.09.13 14:20:21 | 000,998,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ucrtbase.dll
[2018.09.13 14:20:21 | 000,918,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ucrtbase.dll
[2018.09.13 14:20:21 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2018.09.13 14:20:21 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2018.09.13 14:20:21 | 000,405,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2018.09.13 14:20:21 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\zipfldr.dll
[2018.09.13 14:20:21 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2018.09.13 14:20:21 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2018.09.13 14:20:21 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2018.09.13 14:20:21 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2018.09.13 14:20:21 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2018.09.13 14:20:21 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CscMig.dll
[2018.09.13 14:20:21 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icfupgd.dll
[2018.09.13 14:20:21 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2018.09.13 14:20:21 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2018.09.13 14:20:21 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2018.09.13 14:20:21 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2018.09.13 14:20:21 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wfapigp.dll
[2018.09.13 14:20:21 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2018.09.13 14:20:21 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msimg32.dll
[2018.09.13 14:20:21 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2018.09.13 14:20:21 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comcat.dll
[2018.09.13 14:20:20 | 000,340,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msexcl40.dll
[2018.09.13 14:20:20 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
[2018.09.13 14:20:20 | 000,065,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-private-l1-1-0.dll
[2018.09.13 14:20:20 | 000,063,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-private-l1-1-0.dll
[2018.09.13 14:20:20 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2018.09.13 14:20:20 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2018.09.13 14:20:20 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe
[2018.09.13 14:20:20 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnscacheugc.exe
[2018.09.13 14:20:20 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleres.dll
[2018.09.13 14:20:20 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleres.dll
[2018.09.13 14:20:20 | 000,021,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-math-l1-1-0.dll
[2018.09.13 14:20:20 | 000,020,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-math-l1-1-0.dll
[2018.09.13 14:20:20 | 000,019,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-multibyte-l1-1-0.dll
[2018.09.13 14:20:20 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2018.09.13 14:20:20 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2018.09.13 14:20:20 | 000,018,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
[2018.09.13 14:20:20 | 000,017,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-string-l1-1-0.dll
[2018.09.13 14:20:20 | 000,017,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-stdio-l1-1-0.dll
[2018.09.13 14:20:20 | 000,017,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-string-l1-1-0.dll
[2018.09.13 14:20:20 | 000,017,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
[2018.09.13 14:20:20 | 000,016,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-runtime-l1-1-0.dll
[2018.09.13 14:20:20 | 000,015,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
[2018.09.13 14:20:20 | 000,015,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-convert-l1-1-0.dll
[2018.09.13 14:20:20 | 000,015,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
[2018.09.13 14:20:20 | 000,014,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-time-l1-1-0.dll
[2018.09.13 14:20:20 | 000,014,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-2-0.dll
[2018.09.13 14:20:20 | 000,013,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-time-l1-1-0.dll
[2018.09.13 14:20:20 | 000,013,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-filesystem-l1-1-0.dll
[2018.09.13 14:20:20 | 000,013,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-2-0.dll
[2018.09.13 14:20:20 | 000,013,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-conio-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-process-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-utility-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-process-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-locale-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-heap-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-crt-environment-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-2-0.dll
[2018.09.13 14:20:20 | 000,012,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-1.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l2-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-timezone-l1-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-2-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-1.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l2-1-0.dll
[2018.09.13 14:20:20 | 000,011,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-2-0.dll
[2018.09.13 14:20:20 | 000,011,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l2-1-0.dll
[2018.09.13 14:20:20 | 000,011,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-timezone-l1-1-0.dll
[2018.09.13 14:20:20 | 000,011,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l2-1-0.dll
[2018.09.13 14:20:20 | 000,011,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-2-0.dll
[2018.09.13 14:20:20 | 000,007,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbd.sys
[2018.09.13 14:20:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml6r.dll
[2018.09.13 14:20:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml6r.dll
[2018.09.13 14:20:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2018.09.13 14:20:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2018.09.13 14:20:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2018.09.13 14:20:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
[2018.09.11 19:39:36 | 003,632,464 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RltkAPO64.dll
[2018.09.11 19:39:36 | 003,452,120 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
[2018.09.11 19:39:36 | 003,214,672 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
[2018.09.11 19:39:36 | 002,939,728 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInstII64.dll
[2018.09.11 19:39:36 | 001,353,280 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
[2018.09.11 19:39:36 | 000,692,128 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtDataProc64.dll
[2018.09.11 19:39:36 | 000,541,072 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2018.09.11 19:39:36 | 000,392,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2018.09.11 19:39:36 | 000,343,672 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
[2018.09.11 19:39:36 | 000,327,240 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2018.09.11 19:39:36 | 000,327,232 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2018.09.11 19:39:36 | 000,230,664 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2018.09.11 19:39:36 | 000,220,352 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2018.09.11 19:39:36 | 000,218,232 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2018.09.11 19:39:36 | 000,192,944 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
[2018.09.11 19:39:36 | 000,174,904 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2018.09.11 19:39:36 | 000,116,504 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2018.09.11 19:39:36 | 000,093,872 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2018.09.11 19:39:36 | 000,023,656 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCoLDR64.dll
[2018.09.11 19:39:35 | 000,122,280 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
[2018.09.11 19:39:30 | 003,677,120 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
[2018.09.11 19:37:13 | 001,061,200 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2018.09.11 19:37:13 | 000,124,240 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\SysNative\RtNicProp64.dll
[2018.09.11 17:57:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[3 C:\Users\Hačís\Documents\*.tmp files -> C:\Users\Hačís\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2018.10.04 22:52:38 | 000,060,027 | ---- | M] () -- C:\Windows\ZAM.krnl.trace
[2018.10.04 22:52:38 | 000,035,257 | ---- | M] () -- C:\Windows\ZAM_Guard.krnl.trace
[2018.10.04 22:48:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Hačís\Desktop\OTL.exe
[2018.10.04 22:14:24 | 000,019,648 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2018.10.04 22:14:24 | 000,019,648 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2018.10.04 22:06:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2018.10.04 22:06:14 | 2560,839,680 | -HS- | M] () -- C:\hiberfil.sys
[2018.10.04 22:05:50 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\spu_storage.bin
[2018.10.04 08:45:04 | 001,583,226 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2018.10.04 08:45:04 | 000,668,542 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2018.10.04 08:45:04 | 000,653,930 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2018.10.04 08:45:04 | 000,141,202 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2018.10.04 08:45:04 | 000,121,802 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2018.10.04 08:42:27 | 002,414,080 | ---- | M] (Farbar) -- C:\Users\Hačís\Desktop\FRST64.exe
[2018.10.03 22:20:32 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Hačís\Desktop\HijackThis.exe
[2018.10.02 23:02:51 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2018.10.02 21:31:33 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zam64.sys
[2018.10.02 21:31:32 | 000,203,680 | ---- | M] (Zemana Ltd.) -- C:\Windows\SysNative\drivers\zamguard64.sys
[2018.10.02 21:31:29 | 000,001,148 | ---- | M] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
[2018.10.02 21:28:21 | 000,000,008 | RHS- | M] () -- C:\Users\Hačís\ntuser.pol
[2018.10.02 20:33:40 | 000,028,272 | ---- | M] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2018.10.02 20:32:19 | 006,625,600 | ---- | M] (Zemana Ltd. ) -- C:\Users\Hačís\Desktop\Zemana.AntiMalware.Setup.exe
[2018.10.02 20:31:39 | 002,038,755 | ---- | M] () -- C:\Users\Hačís\Desktop\zoek.exe
[2018.10.02 18:06:56 | 000,002,759 | ---- | M] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2018.10.01 22:46:54 | 001,790,024 | ---- | M] (Malwarebytes) -- C:\Users\Hačís\Desktop\JRT.exe
[2018.10.01 22:45:29 | 027,157,048 | ---- | M] (Adlice Software) -- C:\Users\Hačís\Desktop\RogueKiller_portable64.exe
[2018.10.01 20:57:11 | 000,002,255 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2018.09.30 10:15:55 | 000,001,867 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2018.09.29 21:01:14 | 080,408,496 | ---- | M] (Malwarebytes ) -- C:\Users\Hačís\Desktop\mb3-setup-consumer-3.6.1.2711-1.0.463-1.0.7063.exe
[2018.09.29 21:00:58 | 007,567,568 | ---- | M] (Malwarebytes) -- C:\Users\Hačís\Desktop\AdwCleaner.exe
[2018.09.29 20:59:54 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\Hačís\Desktop\TFC.exe
[2018.09.29 20:59:47 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\Hačís\Desktop\ATF-Cleaner.exe
[2018.09.29 20:03:47 | 000,671,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2018.09.29 16:38:54 | 000,001,810 | ---- | M] () -- C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config
[2018.09.29 16:22:52 | 000,001,201 | ---- | M] () -- C:\Users\Hačís\Desktop\AVS Video Editor.lnk
[2018.09.29 15:40:11 | 004,058,374 | ---- | M] () -- C:\Users\Hačís\projekt x.sto
[2018.09.29 15:39:58 | 003,187,830 | ---- | M] () -- C:\Users\Hačís\projekt x.~sto
[2018.09.29 14:59:04 | 000,000,377 | ---- | M] () -- C:\Users\Hačís\pokoj01.sto
[2018.09.29 14:40:18 | 000,000,380 | ---- | M] () -- C:\Users\Hačís\pokoj.sto
[2018.09.29 09:50:38 | 000,001,137 | ---- | M] () -- C:\Users\Public\Desktop\PRO100.lnk
[2018.09.20 09:16:20 | 000,134,760 | ---- | M] (Riverbed Technology, Inc.) -- C:\Windows\SysNative\drivers\nfstat.sys
[2018.09.19 10:09:34 | 000,223,817 | ---- | M] () -- C:\Users\Hačís\Desktop\NORMA Hustopeče - PKS 2019 - výchozí návrh.pdf
[2018.09.15 03:01:41 | 001,557,940 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2018.09.11 19:39:36 | 003,632,464 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RltkAPO64.dll
[2018.09.11 19:39:36 | 003,452,120 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
[2018.09.11 19:39:36 | 003,214,672 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
[2018.09.11 19:39:36 | 002,939,728 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInstII64.dll
[2018.09.11 19:39:36 | 001,353,280 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTCOM64.dll
[2018.09.11 19:39:36 | 000,692,128 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtDataProc64.dll
[2018.09.11 19:39:36 | 000,541,072 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2018.09.11 19:39:36 | 000,392,840 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2018.09.11 19:39:36 | 000,343,672 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
[2018.09.11 19:39:36 | 000,327,240 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2018.09.11 19:39:36 | 000,327,232 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2018.09.11 19:39:36 | 000,230,664 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2018.09.11 19:39:36 | 000,220,352 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2018.09.11 19:39:36 | 000,218,232 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2018.09.11 19:39:36 | 000,192,944 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
[2018.09.11 19:39:36 | 000,174,904 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2018.09.11 19:39:36 | 000,116,504 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2018.09.11 19:39:36 | 000,093,872 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2018.09.11 19:39:36 | 000,023,656 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCoLDR64.dll
[2018.09.11 19:39:35 | 000,122,280 | ---- | M] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
[2018.09.11 19:39:30 | 013,687,502 | ---- | M] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2018.09.11 19:39:30 | 003,677,120 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
[2018.09.11 19:37:13 | 001,061,200 | ---- | M] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2018.09.11 19:37:13 | 000,124,240 | ---- | M] (Realtek Semiconductor Corporation) -- C:\Windows\SysNative\RtNicProp64.dll
[2018.09.11 19:37:13 | 000,120,208 | ---- | M] (Realtek Semiconductor Corporation) -- C:\Windows\SysNative\RTNUninst64.dll
[2018.09.11 18:31:07 | 000,842,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2018.09.11 18:31:07 | 000,175,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2018.09.11 13:18:22 | 000,152,688 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbae64.sys
[3 C:\Users\Hačís\Documents\*.tmp files -> C:\Users\Hačís\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2018.10.03 22:36:22 | 000,002,464 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk
[2018.10.03 22:36:22 | 000,002,440 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
[2018.10.03 22:36:22 | 000,002,434 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
[2018.10.03 22:36:22 | 000,002,416 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk
[2018.10.03 22:36:22 | 000,002,411 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
[2018.10.03 22:36:22 | 000,002,406 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
[2018.10.03 22:36:22 | 000,002,399 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy 2016.lnk
[2018.10.03 22:36:22 | 000,002,367 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
[2018.10.03 22:36:22 | 000,002,332 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
[2018.10.03 22:36:22 | 000,002,328 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
[2018.10.03 22:36:22 | 000,002,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive pro firmy.lnk
[2018.10.02 21:31:38 | 000,059,911 | ---- | C] () -- C:\Windows\ZAM.krnl.trace
[2018.10.02 21:31:38 | 000,035,135 | ---- | C] () -- C:\Windows\ZAM_Guard.krnl.trace
[2018.10.02 21:31:29 | 000,001,148 | ---- | C] () -- C:\Users\Public\Desktop\Zemana AntiMalware.lnk
[2018.10.02 21:21:58 | 000,024,064 | ---- | C] () -- C:\Windows\zoek-delete.exe
[2018.10.02 20:31:28 | 002,038,755 | ---- | C] () -- C:\Users\Hačís\Desktop\zoek.exe
[2018.10.02 19:40:21 | 000,028,272 | ---- | C] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2018.10.02 18:06:56 | 000,002,759 | ---- | C] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2018.10.01 20:57:11 | 000,002,296 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2018.10.01 20:57:11 | 000,002,255 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2018.09.30 10:15:55 | 000,001,867 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2018.09.29 16:38:54 | 000,001,810 | ---- | C] () -- C:\Users\Hačís\AppData\Roaming\25IKJ9G.exe.config
[2018.09.29 16:22:52 | 000,001,201 | ---- | C] () -- C:\Users\Hačís\Desktop\AVS Video Editor.lnk
[2018.09.29 15:39:58 | 004,058,374 | ---- | C] () -- C:\Users\Hačís\projekt x.sto
[2018.09.29 15:39:58 | 003,187,830 | ---- | C] () -- C:\Users\Hačís\projekt x.~sto
[2018.09.29 14:59:04 | 000,000,377 | ---- | C] () -- C:\Users\Hačís\pokoj01.sto
[2018.09.29 14:40:18 | 000,000,380 | ---- | C] () -- C:\Users\Hačís\pokoj.sto
[2018.09.29 09:50:38 | 000,001,137 | ---- | C] () -- C:\Users\Public\Desktop\PRO100.lnk
[2018.09.19 10:09:33 | 000,223,817 | ---- | C] () -- C:\Users\Hačís\Desktop\NORMA Hustopeče - PKS 2019 - výchozí návrh.pdf
[2018.09.11 19:39:30 | 013,687,502 | ---- | C] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2017.11.18 21:35:03 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2017.11.18 20:44:41 | 001,557,940 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2017.11.18 18:26:54 | 000,518,144 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2017.11.17 09:50:25 | 000,000,008 | RHS- | C] () -- C:\Users\Hačís\ntuser.pol
[2017.11.16 22:30:01 | 000,151,576 | ---- | C] () -- C:\Windows\SysWow64\hsa-thunk.dll
[2017.11.16 22:29:55 | 000,209,936 | ---- | C] () -- C:\Windows\SysWow64\amdgfxinfo32.dll
[2017.11.16 22:29:55 | 000,198,168 | ---- | C] () -- C:\Windows\SysWow64\atieah32.exe
[2017.11.16 22:29:54 | 001,004,064 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2017.11.16 22:29:54 | 000,807,456 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2017.11.16 22:29:54 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2017.11.16 22:29:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat

========== ZeroAccess Check ==========

[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2018.08.13 17:54:39 | 014,183,936 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2018.08.13 17:40:58 | 012,880,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2018.10.02 17:31:26 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\00b4hxfzx5c
[2018.09.30 10:49:50 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\04dd3opwinq
[2018.09.30 10:49:33 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\0gxeyae45l1
[2018.09.30 18:33:09 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\0sx4xb2wkgg
[2018.09.29 17:25:45 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\0syghxusskg
[2018.09.30 18:34:27 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\130b0b4ocqy
[2018.09.30 10:49:30 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\14a5ops3r2f
[2018.09.30 10:49:43 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\1rmxxtuxnj4
[2018.09.30 18:33:15 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\1ueerqmk4fw
[2018.09.30 10:48:49 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\22mxecvpjl5
[2018.09.30 18:32:39 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\2hlvkweizah
[2018.10.02 17:31:30 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\3ce2ya4p240
[2018.09.30 18:33:05 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\3eq5fibggzp
[2018.09.30 18:33:31 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\3f4xgawjpai
[2018.09.30 18:33:23 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\4bhmymhmz3n
[2018.09.30 10:48:43 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\4eqkwtq5byl
[2018.09.30 18:32:19 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\4up0t3gnrhx
[2018.09.14 15:32:04 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\AdbDriverInstaller
[2018.09.30 10:49:47 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\aiqxdp2j2ye
[2018.09.27 19:52:42 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Anvsoft
[2018.09.30 10:48:53 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\aqdu3wnpf4z
[2018.09.30 18:33:49 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\aqmh13j20s2
[2018.09.02 15:58:14 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\avidemux
[2018.03.20 21:57:20 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Brave Giant
[2018.09.30 10:49:42 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\byoccsr5awv
[2018.09.30 10:49:46 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\ccxld2btr4f
[2018.09.30 10:49:36 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\ch4vifxsxp0
[2018.09.30 10:49:46 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\chdk4rn0p2g
[2018.09.30 13:17:28 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\DAEMON Tools Pro
[2018.09.30 18:32:42 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\daxshilvflw
[2018.09.30 18:33:52 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\dga0u5kmu5w
[2018.04.08 17:29:29 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\DominiGames
[2018.09.29 09:35:12 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Ecru
[2018.09.30 10:49:41 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\egkvyuirmvt
[2018.09.30 10:49:35 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\etjzn1nrftw
[2018.10.02 17:31:28 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\eygcxagbo4f
[2018.09.30 10:48:56 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\f1a11uuevi4
[2018.04.28 10:17:54 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Five-BN Games
[2018.09.30 10:49:48 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\g2hgrrek4tl
[2018.09.30 18:32:37 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\g2jgy3jy0cs
[2018.03.15 17:59:51 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\GHISLER
[2018.09.30 10:49:14 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\gnnzspdulls
[2018.09.30 18:34:12 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\gormp5x0evs
[2018.10.02 17:31:31 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\hh3jieg1ucx
[2018.09.30 18:32:36 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\ia1jho0rtou
[2018.10.02 17:27:58 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\IObit
[2018.03.19 16:58:35 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\IteraLabs
[2018.09.30 18:32:29 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\iwyddph33j3
[2018.09.30 10:49:43 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\k4e0qdqdsxf
[2018.09.30 18:32:45 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\kqtn35nyksr
[2018.09.30 10:49:42 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\la2vlm5mouk
[2018.01.03 10:30:25 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Laroxion
[2018.09.30 10:48:45 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\ldflgbpnfdu
[2018.09.30 10:49:26 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\lijia2u2as3
[2018.10.02 17:31:24 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\lmrrdroejzg
[2018.09.30 10:49:11 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\lprqgv2eica
[2018.09.29 16:50:38 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\MAGIX
[2018.09.30 18:33:01 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\mpnvprj33jn
[2018.09.30 10:49:18 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\np5iak5homj
[2018.09.30 18:33:22 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\nv4qwnmitzm
[2018.09.30 10:49:19 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\okoapnjjegc
[2018.09.30 18:34:23 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\omaefet3eym
[2017.12.26 19:14:30 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Opera Software
[2018.09.30 10:49:25 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\osrhd1xyczz
[2018.09.30 18:32:25 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\othmmklaufh
[2018.09.30 18:33:58 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\ovx0qblivpw
[2018.09.30 10:49:49 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\pqjhlyaij4p
[2018.09.30 18:32:47 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\qfbolhfixhe
[2018.09.30 10:49:44 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\qubn023ut11
[2018.09.30 18:34:37 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\r3qw1xbhgw3
[2018.09.30 10:49:13 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\rar3a24r3eo
[2018.09.30 10:49:33 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\rfey3c0k32z
[2018.03.31 16:11:45 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Seznam.cz
[2018.09.30 18:32:22 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\slnv3c1pg4i
[2018.09.30 10:49:21 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\smstnl4t1xt
[2018.07.02 21:06:16 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\SPORE
[2018.07.27 15:56:58 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\StepMania 5
[2018.09.30 18:32:23 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\szq0myifpwv
[2018.09.30 10:49:29 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\tfnjc2nuxqe
[2018.09.30 10:49:31 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\tiod5uanl5r
[2018.09.30 18:33:07 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\uqklxuq3bpp
[2018.09.29 20:02:02 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\uTorrent
[2018.09.29 17:25:44 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\vlh3hsob5q0
[2018.09.30 18:32:38 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\vlrxvmgpbfm
[2018.09.30 10:49:37 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\vw51xgv3143
[2018.09.30 18:33:03 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\wbneen3cakm
[2018.09.30 10:48:40 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\wj2bqs25opr
[2018.09.29 16:23:26 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\Wondershare
[2018.09.30 10:48:42 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\wow3hira2wg
[2018.09.30 10:49:25 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\wuyfuwi44yu
[2018.09.30 18:33:45 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\x2imgkjw3lb
[2018.09.30 18:32:50 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\xdbjew0ebnw
[2018.09.30 10:49:34 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\xibjq0rh1na
[2018.09.30 18:32:12 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\xnikdioprop
[2018.09.30 18:32:53 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\y2cdg30o154
[2018.09.30 18:33:43 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\ygrox4kmpqc
[2018.09.30 18:33:38 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\yzqlbva1lix
[2018.09.30 18:33:29 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\zpzdktybg4e
[2018.09.30 10:48:51 | 000,000,000 | ---D | M] -- C:\Users\Hačís\AppData\Roaming\zywez53rmgy

========== Purity Check ==========



< End of report >


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Seznam[Bot] a 2 hosti