Kontrola logů Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 10 zář 2016 13:23

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:21:32, on 10. 9. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)


Boot mode: Normal

Running processes:
C:\Fraps\fraps.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\Users\Neocron\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID= ... 567044E8B0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MK LOL] "C:\Program Files (x86)\MKJogo\MK IM\Bin\MKIM.exe" -auto
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [RemoTerm.exe] C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\RemoTerm.exe
O4 - HKCU\..\Run: [iFunBox] C:\i-Funbox DevTeam\iFunBox_x64.exe /tray
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: Vyhledat aktualizace.lnk = C:\Program Files (x86)\Common Files\PCTV Systems\WebUpdater\WebUpdater.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: COMODO Chromodo Update Service (ChromodoUpdater) - Comodo - C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7592 bytes


Jinak žádný problém jsem zatím nezaznamenal až na dlouhé spouštění notebooku , při načítání Windows mi naskočí černá plocha která trvá i několik minut , poté naskočí plocha

Reklama
Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logů

Příspěvekod jerabina » 11 zář 2016 01:23

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit Farbar Recovery Scan Tool (FRST)
32bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
64bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
a ulož jej na plochu. ,pak spusť FRST jako správce
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 11:10

Zde FRST část 1:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by Neocron (administrator) on LENOVO-PC (11-09-2016 11:00:25)
Running from C:\Users\Neocron\Desktop
Loaded Profiles: Neocron (Available Profiles: Neocron)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Comodo) C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Beepa P/L) C:\Fraps\fraps.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Beepa P/L) C:\Fraps\fraps64.dat
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.23941.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1610936 2016-07-10] (COMODO)
HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791848 2016-08-18] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3947704 2015-11-26] (Synaptics Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-08-19] (NVIDIA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-08-22] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\Run: [MK LOL] => C:\Program Files (x86)\MKJogo\MK IM\Bin\MKIM.exe [942584 2016-08-19] (MKGame)
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\Run: [RemoTerm.exe] => C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\RemoTerm.exe [241976 2013-09-20] (PCTV Systems S.à r.l.)
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\Run: [iFunBox] => C:\i-Funbox DevTeam\iFunBox_x64.exe [2783232 2016-09-01] (i-Funbox.com)
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\RunOnce: [Uninstall C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\MountPoints2: {e01d5031-3d1f-11e5-9bc3-2c337aeec048} - "F:\setup.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Vyhledat aktualizace.lnk [2016-08-19]
ShortcutTarget: Vyhledat aktualizace.lnk -> C:\Program Files (x86)\Common Files\PCTV Systems\WebUpdater\WebUpdater.exe (PCTV Systems)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{4e7ede96-485e-4ea9-b128-20bd264f7824}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{ef5af616-612a-41fb-adb0-cc3312ce21b2}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID= ... 567044E8B0
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKLM -> DefaultScope {6036D3F6-0EE2-44BA-8212-5401349500AF} URL =
SearchScopes: HKLM-x32 -> DefaultScope {6036D3F6-0EE2-44BA-8212-5401349500AF} URL =
SearchScopes: HKU\S-1-5-21-3291327581-932694293-2557528726-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3291327581-932694293-2557528726-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-16] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-16] (Oracle Corporation)

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32.dll [2016-01-16] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-16] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-19] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-19] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://cs-cz.facebook.com/","hxxp://badoo.com/startpage/"
CHR Profile: C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-10]
CHR Extension: (Dokumenty Google) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-10]
CHR Extension: (Disk Google) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-31]
CHR Extension: (YouTube) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-31]
CHR Extension: (Adblock na Youtube™) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-03-04]
CHR Extension: (Vyhledávání Google) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-31]
CHR Extension: (Tabulky Google) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-10]
CHR Extension: (Vzdálená plocha Chrome) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2016-06-29]
CHR Extension: (AdBlock) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-08-24]
CHR Extension: (Webcam Toy) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2015-12-03]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-01]
CHR Extension: (Gmail) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-31]
CHR Extension: (Chrome Media Router) - C:\Users\Neocron\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S4 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2015-03-27] (Broadcom Corporation.)
R2 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [2001592 2016-08-13] (Comodo)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-07-10] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-07-10] (COMODO)
S4 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
S4 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [374360 2016-08-18] (Intel Corporation)
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-28] (Intel(R) Corporation) [File not signed]
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-28] (Intel(R) Corporation)
S4 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S4 LenovoSetSvr; C:\Program Files (x86)\Lenovo\Lenovo Settings\LenovoSetSvr.exe [389680 2015-02-28] (Lenovo(beijing) Limited)
S4 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-02-28] (Lenovo(beijing) Limited)
S4 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-18] (Lenovo(beijing) Limited)
S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2016-08-21] ()
S4 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-26] (PointGrab LTD)
S4 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-26] (PointGrab LTD)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75136 2015-10-10] ()
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-07-26] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S4 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831712 2016-08-21] (Intel® Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 azvusb; C:\Windows\System32\drivers\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [173312 2015-03-27] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7592664 2014-12-05] (Broadcom Corporation)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [32224 2016-07-10] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [851864 2016-07-10] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [45600 2016-07-10] (COMODO)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-08-08] (Disc Soft Ltd)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [138568 2016-07-10] (COMODO)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
S3 mod7700; C:\Windows\system32\DRIVERS\mod7700.sys [1077840 2010-11-19] (DiBcom SA)
S3 MODRC; C:\Windows\System32\drivers\modrc.sys [24272 2010-11-19] (DiBcom S.A.)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvlti.inf_amd64_561c3173c020f30d\nvlddmkm.sys [14199360 2016-08-19] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [761600 2015-06-15] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-11-26] (Synaptics Incorporated)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-09-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-11 11:00 - 2016-09-11 11:02 - 00017163 _____ C:\Users\Neocron\Desktop\FRST.txt
2016-09-11 11:00 - 2016-09-11 11:00 - 00000000 ____D C:\FRST
2016-09-11 10:59 - 2016-09-11 11:00 - 02397696 _____ (Farbar) C:\Users\Neocron\Desktop\FRST64.exe
2016-09-11 10:59 - 2016-09-11 10:59 - 02397696 _____ (Farbar) C:\Users\Neocron\Downloads\FRST64.exe
2016-09-10 22:01 - 2016-09-10 22:01 - 00000000 ____D C:\Users\Neocron\Downloads\Rise of the Tomb Raider - CorePack
2016-09-10 22:00 - 2016-09-10 22:29 - 632843264 _____ () C:\Users\Neocron\Downloads\Rise_Of_TB_Instaler_6.3.exe
2016-09-10 21:57 - 2016-09-10 21:57 - 00012549 _____ C:\Users\Neocron\Downloads\[CzT]Rise_of_the_Tomb_Raider_2016_cestina_v6_3.torrent
2016-09-10 21:56 - 2016-09-10 21:56 - 00035657 _____ C:\Users\Neocron\Downloads\[CzT]Rise_of_the_Tomb_Raider_All_Updates_DLC_s_2016_ (1).torrent
2016-09-10 21:55 - 2016-09-10 22:16 - 00000000 ____D C:\Users\Neocron\Downloads\The Witcher 3 - Wild Hunt GOTY (2016)(CZ)
2016-09-10 21:55 - 2016-09-10 21:55 - 00170751 _____ C:\Users\Neocron\Downloads\[CzT]Zaklinac_3_Divoky_hon_The_Witcher_3_Wild_Hunt_Game_of_the_Year_Edition_2016_CZ_.torrent
2016-09-10 16:05 - 2016-09-10 16:05 - 00000000 ____D C:\Users\Neocron\AppData\Local\NetworkTiles
2016-09-10 13:38 - 2016-09-10 14:24 - 3602662808 _____ C:\Users\Neocron\Downloads\Teenage.Mutant.Ninja.Turtles.Out.of.the.Shadows.2016.720p.BluRay.DD5.1.x264-HiDt.CZ.mkv
2016-09-10 13:37 - 2016-09-10 14:51 - 2855434568 _____ C:\Users\Neocron\Downloads\X-Men.Apocalypse.2016.1080p.BluRay.DTS-HD.MA.7.1.x264-LEGi0N.CZ.mkv
2016-09-10 13:36 - 2016-09-10 13:36 - 00096051 _____ C:\Users\Neocron\Downloads\[CzT]X_Men_Apokalypsa_X_Men_Apocalypse_2016_CZ_EN_1080pHD_.torrent
2016-09-10 13:36 - 2016-09-10 13:36 - 00038190 _____ C:\Users\Neocron\Downloads\[CzT]Zelvy_Ninja_2_Teenage_Mutant_Ninja_Turtles_Out_of_the_Shadows_2016_CZ_EN_720pHD_.torrent
2016-09-10 13:21 - 2016-09-10 13:21 - 00388608 _____ (Trend Micro Inc.) C:\Users\Neocron\Downloads\HijackThis.exe
2016-09-10 13:21 - 2016-09-10 13:21 - 00388608 _____ (Trend Micro Inc.) C:\Users\Neocron\Desktop\HijackThis.exe
2016-09-10 12:52 - 2016-09-10 11:48 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2016-09-10 11:48 - 2016-09-10 12:38 - 00000000 ____D C:\zoek_backup
2016-09-10 11:47 - 2016-09-10 11:47 - 01309184 _____ C:\Users\Neocron\Downloads\zoek.exe
2016-09-10 11:47 - 2016-09-10 11:47 - 01309184 _____ C:\Users\Neocron\Desktop\zoek.exe
2016-09-10 11:03 - 2016-09-11 10:55 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\uTorrent
2016-09-10 11:03 - 2016-09-10 11:03 - 00001052 _____ C:\Users\Neocron\Desktop\µTorrent.lnk
2016-09-10 11:03 - 2016-09-10 11:03 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2016-09-10 11:02 - 2016-09-10 11:02 - 02168712 _____ (emc) C:\Users\Neocron\Downloads\uTorrent221.exe
2016-09-10 10:59 - 2016-09-10 10:59 - 00035657 _____ C:\Users\Neocron\Downloads\[CzT]Rise_of_the_Tomb_Raider_All_Updates_DLC_s_2016_.torrent
2016-09-09 19:02 - 2016-09-09 19:02 - 25199688 _____ C:\Users\Neocron\Desktop\RogueKillerX64.exe
2016-09-09 19:01 - 2016-09-09 19:02 - 25199688 _____ C:\Users\Neocron\Downloads\RogueKillerX64.exe
2016-09-06 16:48 - 2016-09-06 16:48 - 00000559 _____ C:\Users\Neocron\Desktop\JRT.txt
2016-09-06 16:38 - 2016-09-06 16:40 - 01610560 _____ (Malwarebytes) C:\Users\Neocron\Desktop\JRT.exe
2016-09-06 16:38 - 2016-09-06 16:38 - 01610560 _____ (Malwarebytes) C:\Users\Neocron\Downloads\JRT.exe
2016-09-05 17:32 - 2016-09-06 16:33 - 00000000 ____D C:\AdwCleaner
2016-09-05 17:11 - 2016-09-05 17:11 - 00448512 _____ (OldTimer Tools) C:\Users\Neocron\Downloads\TFC.exe
2016-09-05 16:34 - 2016-09-05 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hitman Absolution
2016-09-05 15:49 - 2016-09-05 15:57 - 00000000 ____D C:\Users\Neocron\Downloads\Futurama CZ Komplet (1. - 8. série + futufilmy)
2016-09-04 12:13 - 2016-09-04 12:13 - 00000000 ____D C:\Users\Neocron\AppData\Local\Black_Tree_Gaming
2016-09-04 12:12 - 2016-09-04 12:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2016-09-04 12:12 - 2016-09-04 12:12 - 00000000 ____D C:\Program Files\Nexus Mod Manager
2016-09-03 09:36 - 2016-09-03 09:37 - 00000000 ____D C:\Users\Neocron\Documents\NFS Most Wanted
2016-09-03 09:36 - 2016-09-03 09:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed Most Wanted Modded
2016-09-02 17:57 - 2016-09-06 18:27 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\NVIDIA
2016-09-02 16:57 - 2016-09-02 16:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by.xatab
2016-09-02 16:01 - 2016-09-04 00:31 - 00045428 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2016-09-02 15:57 - 2016-09-02 15:57 - 00000000 ___HD C:\VTRoot
2016-09-01 21:49 - 2016-09-01 21:53 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\iFunbox_UserCache
2016-09-01 21:49 - 2016-09-01 21:49 - 00000704 _____ C:\Users\Public\Desktop\iFunbox.lnk
2016-09-01 21:49 - 2016-09-01 21:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\i-Funbox DevTeam
2016-09-01 21:49 - 2016-09-01 21:49 - 00000000 ____D C:\i-Funbox DevTeam
2016-09-01 19:56 - 2016-09-01 19:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Repacky od tomi2k9
2016-09-01 19:23 - 2016-09-01 19:25 - 00000000 ____D C:\Mass Effect serie
2016-09-01 16:22 - 2016-09-01 16:49 - 00000000 ____D C:\Users\Neocron\Downloads\Fallout 4 by xatab
2016-09-01 16:10 - 2016-09-03 10:34 - 00000000 ____D C:\Users\Neocron\Downloads\Mass Effect - CZ Trilogie - t2k9
2016-09-01 15:53 - 2016-09-01 15:53 - 23682560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 22571008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 19418624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 08124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 06044672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 04612096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 04130944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 03893376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 02289664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-09-01 15:53 - 2016-09-01 15:53 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01430200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00965120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-09-01 15:53 - 2016-09-01 15:53 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-09-01 15:53 - 2016-09-01 15:53 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2016-09-01 15:53 - 2016-09-01 15:53 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL
2016-09-01 15:53 - 2016-09-01 15:53 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2016-09-01 15:53 - 2016-09-01 15:53 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-09-01 15:53 - 2016-09-01 15:53 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-09-01 15:53 - 2016-09-01 15:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-09-01 15:53 - 2016-09-01 15:53 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2016-09-01 15:53 - 2016-09-01 15:53 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-09-01 15:53 - 2016-09-01 15:53 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2016-09-01 15:53 - 2016-09-01 15:53 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL
2016-09-01 15:52 - 2016-09-01 15:53 - 19423232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 22218808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 20965240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 09128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 07814488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 07624192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 05722312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 03245056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 02846208 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02711040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02680832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02485760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02264064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02257248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 02143232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01935360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01906176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01875456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01377008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-09-01 15:52 - 2016-09-01 15:52 - 01316352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01279328 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01163696 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 01106944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01099608 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 01046976 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-09-01 15:52 - 2016-09-01 15:52 - 01014784 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01006080 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00987992 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00942424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2016-09-01 15:52 - 2016-09-01 15:52 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00885832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00852824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00846552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00807776 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00681312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 00658776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00590952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00204288 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00141824 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-09-01 15:52 - 2016-09-01 15:52 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-09-01 15:52 - 2016-09-01 15:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
2016-09-01 15:52 - 2016-09-01 15:52 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL
2016-09-01 15:52 - 2016-08-20 07:21 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-09-01 15:52 - 2016-08-20 07:16 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-09-01 15:52 - 2016-08-19 03:33 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-08-30 16:33 - 2016-09-01 16:14 - 00000000 ____D C:\Users\Neocron\Downloads\Mass Effect 3
2016-08-28 15:51 - 2016-08-28 15:51 - 03826240 _____ C:\Users\Neocron\Downloads\adwcleaner_6.010.exe
2016-08-28 15:51 - 2016-08-28 15:51 - 03826240 _____ C:\Users\Neocron\Desktop\adwcleaner_6.010.exe
2016-08-23 23:36 - 2016-08-23 23:36 - 113771200 _____ C:\Users\Neocron\Desktop\Butchers Bridge v1.0 (By Project Leischii, The Natoken Project, Mapskins Porters).wxy
2016-08-23 20:54 - 2016-08-23 20:54 - 17187328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 13080576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 05622600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-08-23 20:54 - 2016-08-23 20:54 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-08-23 20:54 - 2016-08-23 20:54 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00450400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-08-23 20:54 - 2016-08-23 20:54 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-08-23 20:54 - 2016-08-23 20:54 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-08-23 20:54 - 2016-08-23 20:54 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00224096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-08-23 20:54 - 2016-08-23 20:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-08-23 20:54 - 2016-08-23 20:54 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-08-23 20:54 - 2016-08-23 20:54 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-08-23 20:54 - 2016-08-23 20:54 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 13433856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 12345344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 12174336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-08-23 20:53 - 2016-08-23 20:53 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-08-23 20:53 - 2016-08-23 20:53 - 03116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 02422784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 02251432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-08-23 20:53 - 2016-08-23 20:53 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-08-23 20:53 - 2016-08-23 20:53 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01780736 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01694200 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01469120 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01066096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01062400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 01052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00955008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00587968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00584032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00509784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00381760 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00361096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00321280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00151224 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00077664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 11:10

FRST část 2 :

2016-08-23 20:53 - 2016-08-23 20:53 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-08-23 20:53 - 2016-08-23 20:53 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe
2016-08-23 20:53 - 2016-08-23 20:53 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-08-23 20:53 - 2016-08-23 20:53 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-08-23 20:53 - 2016-08-23 20:53 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2016-08-23 20:53 - 2016-08-23 20:53 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2016-08-22 22:38 - 2016-08-22 22:38 - 00001834 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-08-22 22:38 - 2016-08-22 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-08-22 22:37 - 2016-08-22 22:38 - 00000000 ____D C:\Program Files\iTunes
2016-08-22 22:37 - 2016-08-22 22:37 - 00000000 ____D C:\Program Files\iPod
2016-08-22 22:37 - 2016-08-22 22:37 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-08-22 22:22 - 2016-08-22 22:22 - 00000000 ____D C:\Users\Neocron\AppData\Local\Apple Computer
2016-08-22 22:07 - 2016-08-23 22:07 - 00000000 ____D C:\Users\Neocron\Downloads\MC Gey - RλP-LIFE
2016-08-21 23:21 - 2016-08-21 23:21 - 00000000 ____D C:\Users\Neocron\Downloads\Stargate universe CZ 2.série 20.epizod
2016-08-21 00:25 - 2016-08-21 00:25 - 00000000 ____D C:\Users\Neocron\Desktop\pokehack
2016-08-21 00:22 - 2016-08-21 00:22 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2016-08-21 00:22 - 2016-08-21 00:22 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Intel
2016-08-21 00:21 - 2016-08-21 00:21 - 00000000 ____D C:\ProgramData\Intel.sav
2016-08-21 00:21 - 2016-08-21 00:21 - 00000000 ____D C:\Program Files\Common Files\Intel
2016-08-21 00:21 - 2016-08-21 00:21 - 00000000 ____D C:\Program Files (x86)\Cisco
2016-08-20 02:10 - 2016-08-20 02:10 - 163215700 _____ C:\Users\Neocron\Desktop\Sharp Rift v1 (By Existor).wxy
2016-08-20 00:25 - 2016-08-20 00:34 - 00000000 ____D C:\Users\Neocron\Downloads\Stargate universe CZ 1.série 20.epizod
2016-08-19 15:33 - 2016-08-19 15:33 - 00000000 ____D C:\Users\Neocron\AppData\Local\NVIDIA
2016-08-19 15:27 - 2016-09-10 12:57 - 00000000 ____D C:\ProgramData\NVIDIA
2016-08-19 15:27 - 2016-08-19 15:27 - 00138808 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-08-19 15:26 - 2016-08-19 15:25 - 01365048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-08-19 15:26 - 2016-08-19 15:25 - 00148928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 06386048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 02468288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 00548920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-08-19 15:26 - 2016-08-09 18:06 - 07255045 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-08-19 15:16 - 2016-08-19 15:25 - 10728856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 09086344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 03901520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 03443152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 01023544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 00961080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 00945088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 00897592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 00644648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-08-19 15:16 - 2016-08-19 15:25 - 00345936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 40070200 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 35182648 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 34837952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 28236856 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 10273096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 08681720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 02914752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 02553912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 00803096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 00442816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 00413256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-08-19 15:16 - 2016-08-19 15:24 - 00393664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-08-19 15:16 - 2016-08-11 16:33 - 00040827 _____ C:\WINDOWS\system32\nvinfo.pb
2016-08-19 15:11 - 2016-08-19 15:11 - 00000000 ____D C:\Users\Neocron\AppData\Local\238010
2016-08-19 09:02 - 2016-08-19 09:02 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-08-19 08:58 - 2016-08-19 08:58 - 00000000 ____D C:\ProgramData\USOShared
2016-08-19 08:57 - 2016-08-19 15:23 - 00000000 ____D C:\Users\Neocron\AppData\Local\ConnectedDevicesPlatform
2016-08-19 08:57 - 2016-08-19 08:57 - 00000020 ___SH C:\Users\Neocron\ntuser.ini
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Šablony
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Poslední
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Okolní síť
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Dokumenty
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\Data aplikací
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-08-19 08:55 - 2016-08-19 08:55 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2016-08-19 08:53 - 2016-08-19 08:56 - 00000000 ___DC C:\WINDOWS\Panther
2016-08-19 08:52 - 2016-08-19 08:55 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-08-19 08:52 - 2016-08-19 08:55 - 00007623 _____ C:\WINDOWS\diagerr.xml
2016-08-19 08:47 - 2016-08-19 08:47 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2016-08-19 08:47 - 2016-08-19 08:47 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-08-19 08:45 - 2016-07-15 20:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-08-19 08:45 - 2016-07-15 20:28 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-08-19 08:45 - 2016-07-15 20:28 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-08-19 08:45 - 2016-07-15 20:26 - 00376320 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2016-08-19 08:45 - 2016-07-15 20:26 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-08-19 08:45 - 2016-07-15 20:25 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2016-08-19 08:45 - 2016-07-15 20:23 - 14388224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2016-08-19 08:45 - 2016-07-15 20:22 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2016-08-19 08:45 - 2016-07-15 20:22 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2016-08-19 08:45 - 2016-07-15 20:19 - 01323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-08-19 08:45 - 2016-07-15 20:16 - 05850624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-08-19 08:45 - 2016-07-15 20:16 - 04969472 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-08-19 08:45 - 2016-07-15 20:15 - 06582784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2016-08-19 08:45 - 2016-07-15 20:13 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-08-19 08:45 - 2016-07-15 20:13 - 01198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2016-08-19 08:45 - 2016-07-15 20:13 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-08-19 08:45 - 2016-07-15 20:12 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-08-19 08:45 - 2016-07-15 20:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2016-08-19 08:45 - 2016-07-15 20:11 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2016-08-19 08:45 - 2016-07-15 19:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2016-08-19 08:45 - 2016-07-15 19:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2016-08-19 08:45 - 2016-07-15 19:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll
2016-08-19 08:45 - 2016-07-15 19:42 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2016-08-19 08:45 - 2016-07-15 19:41 - 00355840 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2016-08-19 08:45 - 2016-07-15 19:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2016-08-19 08:45 - 2016-07-15 19:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2016-08-19 08:45 - 2016-07-15 19:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2016-08-19 08:45 - 2016-07-15 19:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2016-08-19 08:45 - 2016-07-15 19:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2016-08-19 08:45 - 2016-07-15 19:32 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2016-08-19 08:45 - 2016-07-15 19:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2016-08-19 08:45 - 2016-07-15 19:31 - 04977664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll
2016-08-19 08:45 - 2016-07-15 19:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2016-08-19 08:45 - 2016-07-15 19:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2016-08-19 08:45 - 2016-07-15 19:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2016-08-19 08:45 - 2016-07-15 19:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2016-08-19 08:45 - 2016-07-15 19:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2016-08-19 08:45 - 2016-07-15 19:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2016-08-19 08:39 - 2016-08-19 08:39 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-08-19 08:39 - 2016-08-19 07:55 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-08-19 08:36 - 2016-09-10 12:59 - 00003190 _____ C:\WINDOWS\System32\Tasks\FRAPS
2016-08-19 08:36 - 2016-09-10 12:57 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-08-19 08:36 - 2016-08-19 08:36 - 00003492 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-08-19 08:36 - 2016-08-19 08:36 - 00003344 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3F5A9915-9604-4F37-8E61-B7050319C451}
2016-08-19 08:36 - 2016-08-19 08:36 - 00003268 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-19 08:36 - 2016-08-19 08:36 - 00003254 _____ C:\WINDOWS\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d
2016-08-19 08:36 - 2016-08-19 08:36 - 00002938 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3291327581-932694293-2557528726-1001
2016-08-19 08:36 - 2016-08-19 08:36 - 00002876 _____ C:\WINDOWS\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon
2016-08-19 08:36 - 2016-08-19 08:36 - 00002362 _____ C:\WINDOWS\System32\Tasks\{D967501B-B337-459D-BA83-15C4F62A7152}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002318 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3291327581-932694293-2557528726-500
2016-08-19 08:36 - 2016-08-19 08:36 - 00002314 _____ C:\WINDOWS\System32\Tasks\DolbySelectorTask
2016-08-19 08:36 - 2016-08-19 08:36 - 00002312 _____ C:\WINDOWS\System32\Tasks\{D922782C-5A52-449D-B92A-A105A416F446}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002298 _____ C:\WINDOWS\System32\Tasks\{28BA422C-BD33-4382-9CDB-C0830C5130A6}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002254 _____ C:\WINDOWS\System32\Tasks\Synaptics TouchPad Enhancements
2016-08-19 08:36 - 2016-08-19 08:36 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2016-08-19 08:36 - 2016-08-19 08:36 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-08-19 08:36 - 2016-08-19 08:36 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO
2016-08-19 08:36 - 2016-08-19 08:36 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2016-08-19 08:36 - 2014-12-10 04:09 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2943985629-2717472603-367765836-500
2016-08-19 08:32 - 2016-08-19 08:32 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-08-19 08:32 - 2016-08-19 08:32 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-08-19 08:32 - 2016-08-19 08:32 - 00000000 ____D C:\Program Files\MSBuild
2016-08-19 08:32 - 2016-08-19 08:32 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-08-19 08:32 - 2016-08-19 08:13 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-08-19 08:32 - 2016-05-25 15:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-08-19 08:32 - 2016-05-25 15:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-08-19 08:32 - 2016-05-25 15:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-08-19 08:32 - 2016-05-25 12:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-08-19 08:32 - 2016-05-25 12:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-08-19 08:32 - 2016-05-25 12:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-08-19 08:20 - 2016-08-19 08:20 - 00000000 ____D C:\Users\Default\AppData\Local\LogMeIn Hamachi
2016-08-19 08:20 - 2016-08-19 08:20 - 00000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Hamachi
2016-08-19 08:19 - 2016-08-19 16:50 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-08-19 08:14 - 2016-08-19 08:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2016-08-19 08:12 - 2016-08-19 08:22 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-08-19 08:08 - 2016-09-05 17:14 - 00000000 ____D C:\Users\Neocron
2016-08-19 08:08 - 2016-08-19 15:35 - 01549328 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Šablony
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Soubory cookie
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Poslední
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Okolní tiskárny
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Okolní síť
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Nabídka Start
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Dokumenty
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Documents\Obrázky
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Documents\Hudba
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Documents\Filmy
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\Data aplikací
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-08-19 08:08 - 2016-08-19 08:08 - 00000000 _SHDL C:\Users\Neocron\AppData\Local\Data aplikací
2016-08-19 08:07 - 2016-08-19 08:07 - 01375290 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-08-19 08:02 - 2016-08-19 15:28 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-08-19 08:02 - 2016-08-19 15:27 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-08-19 08:02 - 2016-08-19 08:02 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-08-19 08:02 - 2016-08-19 08:02 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2016-08-19 08:02 - 2016-08-19 08:02 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2016-08-19 08:02 - 2016-08-19 08:02 - 00000000 ____D C:\Program Files\Realtek
2016-08-19 08:01 - 2016-09-05 15:36 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-19 08:01 - 2016-08-21 00:21 - 00000000 ____D C:\Program Files\Intel
2016-08-19 08:01 - 2016-08-19 08:01 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-08-19 08:01 - 2016-08-19 08:01 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2016-08-19 08:01 - 2016-08-19 08:01 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-08-19 08:01 - 2016-08-19 08:01 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2016-08-19 08:01 - 2016-05-27 15:50 - 00104584 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2016-08-19 08:01 - 2016-05-27 15:50 - 00100488 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2016-08-19 08:00 - 2016-08-19 08:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2016-08-19 08:00 - 2016-08-19 08:00 - 00000000 ____D C:\Program Files\Synaptics
2016-08-19 07:58 - 2016-07-16 13:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-08-19 07:55 - 2016-09-11 10:22 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-08-19 07:54 - 2016-09-01 19:14 - 00280936 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-18 22:15 - 2016-08-18 22:15 - 00000000 ____D C:\NVIDIA
2016-08-18 22:13 - 2016-08-18 22:21 - 00221558 _____ C:\WINDOWS\ntbtlog.txt
2016-08-18 22:13 - 2016-08-18 22:13 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-08-18 21:39 - 2016-08-18 21:39 - 00001635 _____ C:\Users\Neocron\Desktop\CCleanerPortable – zástupce.lnk
2016-08-18 21:37 - 2016-09-06 16:16 - 00000000 ____D C:\Users\Neocron\Desktop\Hry
2016-08-18 21:37 - 2016-08-18 21:37 - 00000000 ____D C:\Users\Neocron\AppData\Local\Apple
2016-08-17 23:24 - 2016-08-17 23:26 - 10530960 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-08-17 23:24 - 2016-08-17 23:26 - 08644456 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-08-17 23:24 - 2016-08-17 23:26 - 00694952 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-08-17 23:24 - 2016-08-17 23:26 - 00584712 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-08-17 23:24 - 2016-08-11 16:33 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-08-17 23:24 - 2016-08-11 16:33 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2016-08-16 22:32 - 2016-08-16 22:34 - 01922616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437254.dll
2016-08-16 22:32 - 2016-08-16 22:33 - 01585088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437254.dll
2016-08-13 17:01 - 2016-08-19 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\No Man's Sky [GOG.com]
2016-08-13 17:01 - 2016-08-13 17:02 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\HelloGames
2016-08-13 15:27 - 2016-08-13 15:27 - 00000000 ____D C:\Users\Neocron\AppData\Local\vsixinstaller
2016-08-13 15:01 - 2016-08-19 16:49 - 00000279 _____ C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koš.lnk
2016-08-13 14:18 - 2016-08-19 08:22 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-13 14:18 - 2016-08-19 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-08-13 14:18 - 2016-08-13 14:18 - 00000000 ____D C:\Program Files\WinRAR
2016-08-13 13:23 - 2016-08-13 13:23 - 00000000 ____D C:\Program Files (x86)\Comodo

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-11 10:58 - 2016-08-11 22:30 - 01474832 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2016-09-10 22:56 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-09-10 22:56 - 2015-08-18 18:12 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\vlc
2016-09-10 15:17 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-09-10 12:59 - 2015-12-24 17:04 - 00000000 ____D C:\Fraps
2016-09-10 12:55 - 2016-07-16 08:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI
2016-09-10 12:36 - 2013-08-22 17:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-09-10 11:18 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2016-09-10 11:14 - 2015-10-31 17:20 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-09-10 00:26 - 2015-11-01 03:47 - 00000000 ____D C:\Users\Neocron\AppData\Local\CrashDumps
2016-09-06 16:14 - 2015-10-31 01:15 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-09-05 16:35 - 2015-08-08 17:20 - 00000000 ____D C:\Users\Neocron\AppData\Local\SKIDROW
2016-09-05 16:02 - 2015-08-06 17:17 - 00000000 ____D C:\Games
2016-09-05 15:36 - 2015-12-29 10:37 - 00000027 _____ C:\ProgramData\lcsuc_prof.cfg
2016-09-05 15:36 - 2015-08-06 16:38 - 00000000 __SHD C:\Users\Neocron\IntelGraphicsProfiles
2016-09-03 12:20 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2016-09-03 11:34 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-09-02 18:05 - 2015-08-08 13:58 - 00000000 ____D C:\Users\Neocron\Documents\My Games
2016-09-02 14:14 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2016-09-01 19:57 - 2016-01-31 13:49 - 00000000 ____D C:\Users\Neocron\Documents\BioWare
2016-09-01 19:22 - 2015-08-07 08:31 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-09-01 19:11 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Provisioning
2016-08-30 18:08 - 2015-02-28 12:35 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2016-08-27 14:59 - 2015-08-08 11:22 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\DAEMON Tools Lite
2016-08-26 12:18 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-08-26 07:43 - 2016-07-16 13:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-08-26 07:43 - 2016-07-16 13:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-08-22 22:37 - 2015-09-19 15:30 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-08-21 00:21 - 2015-10-30 08:28 - 00000000 ____D C:\Users\Default.migrated
2016-08-21 00:21 - 2015-02-28 12:04 - 00000000 ____D C:\ProgramData\Intel
2016-08-21 00:21 - 2015-02-28 12:02 - 00000000 ____D C:\Program Files (x86)\Intel
2016-08-20 20:56 - 2015-06-17 17:04 - 06112072 _____ (Apple, Inc.) C:\WINDOWS\system32\usbaaplrc.dll
2016-08-20 20:56 - 2015-06-17 17:04 - 00054784 _____ (Apple, Inc.) C:\WINDOWS\system32\Drivers\usbaapl64.sys
2016-08-20 09:49 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\appcompat
2016-08-20 02:08 - 2016-03-30 17:18 - 00000000 ____D C:\Wooxy
2016-08-19 16:50 - 2015-09-19 15:31 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-08-19 16:50 - 2015-08-06 16:48 - 00002284 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-19 16:50 - 2015-02-28 12:34 - 00002007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk
2016-08-19 16:49 - 2016-08-11 22:44 - 00002221 _____ C:\Users\Public\Desktop\Internet (Chromodo).lnk
2016-08-19 16:49 - 2016-08-11 22:30 - 00001904 _____ C:\Users\Public\Desktop\COMODO Internet Security.lnk
2016-08-19 16:49 - 2016-05-19 11:55 - 00002170 _____ C:\Users\Public\Desktop\TVCenter.lnk
2016-08-19 16:49 - 2015-12-24 17:04 - 00000611 _____ C:\Users\Public\Desktop\Fraps.lnk
2016-08-19 16:49 - 2015-11-19 21:09 - 00001031 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2016-08-19 16:49 - 2015-10-31 01:14 - 00001183 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-08-19 16:49 - 2015-09-03 22:20 - 00000405 _____ C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programy a funkce.lnk
2016-08-19 16:49 - 2015-08-18 18:12 - 00001151 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-08-19 16:49 - 2015-08-08 11:22 - 00001869 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-08-19 16:49 - 2015-08-06 21:50 - 00002444 _____ C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-08-19 16:49 - 2015-08-06 16:48 - 00002272 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-08-19 16:49 - 2015-08-06 16:46 - 00001279 _____ C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-08-19 16:49 - 2015-02-28 12:48 - 00001995 _____ C:\Users\Public\Desktop\Microsoft Office 2013 Activation.lnk
2016-08-19 16:48 - 2016-03-05 20:02 - 00002398 _____ C:\Users\Neocron\Desktop\Spouštěč aplikací Chrome.lnk
2016-08-19 16:48 - 2015-08-30 03:57 - 00001266 _____ C:\Users\Neocron\Desktop\CrystalDiskInfo.lnk
2016-08-19 16:48 - 2015-08-06 17:58 - 00000436 _____ C:\Users\Neocron\Desktop\Tento počítač.lnk
2016-08-19 16:45 - 2015-10-30 20:35 - 00000000 ____D C:\WINDOWS\ShellNew
2016-08-19 16:09 - 2015-02-28 12:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-08-19 16:08 - 2015-02-28 12:19 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-08-19 16:04 - 2015-08-06 16:47 - 00000000 ____D C:\Users\Neocron\AppData\Local\Lenovo
2016-08-19 16:04 - 2015-02-28 12:31 - 00000000 ____D C:\ProgramData\Lenovo
2016-08-19 16:04 - 2015-02-28 12:11 - 00000000 ____D C:\Program Files\Lenovo
2016-08-19 16:00 - 2015-11-15 21:03 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\.minecraft
2016-08-19 15:35 - 2016-07-17 00:25 - 00460704 _____ C:\WINDOWS\system32\perfh005.dat
2016-08-19 15:35 - 2016-07-17 00:25 - 00099332 _____ C:\WINDOWS\system32\perfc005.dat
2016-08-19 15:28 - 2015-02-28 12:09 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-08-19 15:13 - 2016-03-13 20:20 - 00000000 ____D C:\Users\Neocron\AppData\Local\dxhr
2016-08-19 09:39 - 2015-08-06 16:38 - 00000000 ____D C:\Users\Neocron\AppData\Local\Packages
2016-08-19 09:04 - 2015-08-06 21:50 - 00000000 ___RD C:\Users\Neocron\OneDrive
2016-08-19 08:58 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\USOPrivate
2016-08-19 08:58 - 2015-08-06 21:45 - 00000000 ____D C:\Users\Neocron\AppData\Local\Comms
2016-08-19 08:55 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows NT
2016-08-19 08:53 - 2016-07-16 13:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-08-19 08:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-08-19 08:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Registration
2016-08-19 08:51 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\system32\winrm
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-08-19 08:45 - 2016-07-17 00:25 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-08-19 08:45 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-08-19 08:45 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\servicing
2016-08-19 08:36 - 2015-08-06 21:40 - 00023020 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-08-19 08:34 - 2016-07-16 13:47 - 00000000 __RHD C:\Users\Public\Libraries
2016-08-19 08:32 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-08-19 08:32 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-08-19 08:32 - 2016-07-16 13:43 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2016-08-19 08:32 - 2016-07-16 13:43 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2016-08-19 08:32 - 2016-07-16 13:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2016-08-19 08:32 - 2016-07-16 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2016-08-19 08:32 - 2016-07-16 13:43 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2016-08-19 08:22 - 2016-08-11 22:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-08-19 08:22 - 2016-08-10 16:29 - 00000000 ____D C:\WINDOWS\SysWOW64\1033
2016-08-19 08:22 - 2016-08-10 16:27 - 00000000 ____D C:\WINDOWS\system32\1033
2016-08-19 08:22 - 2016-07-28 23:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PP助手5.0
2016-08-19 08:22 - 2016-05-19 11:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCTV Systems
2016-08-19 08:22 - 2016-04-27 15:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlast + DLC Whistleblower
2016-08-19 08:22 - 2016-03-21 19:28 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2016-08-19 08:22 - 2016-03-14 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
2016-08-19 08:22 - 2016-03-13 20:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deus Ex Human Revolution - Directors Cut
2016-08-19 08:22 - 2016-03-05 20:39 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2016-08-19 08:22 - 2016-03-05 20:02 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-08-19 08:22 - 2016-01-23 21:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bioshock Infinite
2016-08-19 08:22 - 2016-01-12 20:59 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-08-19 08:22 - 2015-12-24 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2016-08-19 08:22 - 2015-11-16 22:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-08-19 08:22 - 2015-10-31 01:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-08-19 08:22 - 2015-09-09 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2016-08-19 08:22 - 2015-08-30 03:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2016-08-19 08:22 - 2015-08-18 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-08-19 08:22 - 2015-08-08 12:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Far Cry 4 - Gold Edition
2016-08-19 08:22 - 2015-08-08 11:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2016-08-19 08:22 - 2015-02-28 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2016-08-19 08:20 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\spool
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-08-19 08:16 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2016-08-19 08:16 - 2016-01-26 22:14 - 00000000 ____D C:\WINDOWS\SysWOW64\xlive
2016-08-19 08:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-08-19 08:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-08-19 08:14 - 2016-08-11 22:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
2016-08-19 08:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-08-19 08:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\InputMethod
2016-08-19 08:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Help
2016-08-19 08:14 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Cursors
2016-08-19 08:14 - 2016-03-30 17:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wooxy
2016-08-19 08:14 - 2015-11-28 20:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2016-08-19 08:14 - 2015-11-19 21:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2016-08-19 08:14 - 2015-10-16 19:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strogino CS Portal
2016-08-19 08:14 - 2015-10-11 16:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2016-08-19 08:14 - 2015-02-28 12:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-08-19 08:14 - 2015-02-28 12:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-08-19 08:13 - 2016-08-10 16:38 - 00000000 ____D C:\Program Files\IIS
2016-08-19 08:13 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-08-19 08:13 - 2014-11-21 14:18 - 00000000 ____D C:\Program Files\Embedded Lockdown Manager
2016-08-19 08:11 - 2015-09-10 19:57 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo
2016-08-19 08:11 - 2015-08-06 16:41 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-08-19 08:07 - 2016-07-16 08:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-08-19 08:04 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-08-19 08:04 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-08-19 06:25 - 2015-08-06 16:48 - 00000980 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-19 00:25 - 2015-08-06 16:47 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-18 19:00 - 2016-07-26 10:36 - 00000000 ____D C:\Users\Neocron\AppData\Local\Downloaded Installations
2016-08-18 16:46 - 2016-05-27 15:50 - 01027680 _____ C:\WINDOWS\system32\igfxSDK.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00966232 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00962656 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00622680 _____ (Intel Corporation) C:\WINDOWS\system32\IntelCpHDCPSvc.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00537184 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00467544 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00402520 _____ C:\WINDOWS\system32\igfxTray.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00374360 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00355424 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00302176 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00269400 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00237664 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00233056 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00232536 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
2016-08-18 16:46 - 2016-05-27 15:50 - 00175704 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-08-17 23:25 - 2015-08-06 16:38 - 00000000 ____D C:\Users\Neocron\AppData\Local\NVIDIA Corporation
2016-08-17 23:17 - 2015-11-16 15:31 - 01907016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435435.dll
2016-08-17 23:17 - 2015-11-16 15:31 - 01566352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435435.dll
2016-08-14 20:28 - 2016-03-25 18:56 - 00000000 ____D C:\lol skin
2016-08-13 16:58 - 2016-07-04 14:39 - 00000000 ____D C:\ProgramData\MAGIX
2016-08-13 16:58 - 2016-07-04 14:39 - 00000000 ____D C:\Program Files (x86)\MAGIX
2016-08-13 15:36 - 2016-08-10 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 14.0
2016-08-13 15:33 - 2016-08-10 16:26 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2016-08-13 15:32 - 2016-08-10 16:26 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2016-08-13 15:09 - 2016-08-10 16:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0
2016-08-13 15:01 - 2016-07-26 10:38 - 00000000 ____D C:\Program Files (x86)\Samsung
2016-08-13 14:19 - 2015-08-12 18:53 - 00000000 ____D C:\Users\Neocron\AppData\Roaming\WinRAR
2016-08-13 14:14 - 2016-08-10 22:58 - 00000000 ____D C:\Users\Neocron\Downloads\Independence Day Resurgence 2016 HD-TS x264 AC3-CPG
2016-08-13 14:05 - 2016-07-04 14:42 - 00000000 ____D C:\Users\Public\Documents\MAGIX

==================== Files in the root of some directories =======

2015-09-01 23:20 - 2015-12-07 00:36 - 0007598 _____ () C:\Users\Neocron\AppData\Local\resmon.resmoncfg
2016-08-19 08:02 - 2016-08-19 08:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-12-29 10:37 - 2016-09-05 15:36 - 0000027 _____ () C:\ProgramData\lcsuc_prof.cfg

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-09-09 14:49

==================== End of FRST.txt ============================

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 11:12

A zde Addition část 1 :

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016
Ran by Neocron (11-09-2016 11:04:31)
Running from C:\Users\Neocron\Desktop
Windows 10 Home Version 1607 (X64) (2016-08-19 06:56:42)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3291327581-932694293-2557528726-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3291327581-932694293-2557528726-503 - Limited - Disabled)
Guest (S-1-5-21-3291327581-932694293-2557528726-501 - Limited - Disabled)
Neocron (S-1-5-21-3291327581-932694293-2557528726-1001 - Administrator - Enabled) => C:\Users\Neocron

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: COMODO Antivirus (Enabled - Up to date) {D0CC7563-ABD2-DEBE-138E-FDD553335AF2}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Comodo Defense+ (Enabled - Up to date) {6BAD9487-8DE8-D130-293E-C6A728B4104F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall (Enabled) {E8F7F446-E1BD-DFE6-38D1-54E0ADE01D89}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Active Directory Authentication Library for SQL Server (Version: 13.0.1601.5 - Microsoft Corporation) Hidden
Active Directory Authentication Library for SQL Server (x86) (x32 Version: 13.0.1601.5 - Microsoft Corporation) Hidden
Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.3.183.90 - Adobe Systems Incorporated)
Ansel (Version: 372.54 - NVIDIA Corporation) Hidden
Aplikace Intel® PROSet/Wireless (HKLM-x32\...\{795ee3a0-97fa-489a-9543-7564ccc43be4}) (Version: 18.12.0 - Intel Corporation)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bioshock Infinite verze v1.1.25.5165 (HKLM-x32\...\Bioshock Infinite_is1) (Version: v1.1.25.5165 - (R.G.Danik1B9))
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
COMODO Internet Security Premium (HKLM\...\{EC925096-5689-4BE3-B675-D16D0394B4A0}) (Version: 8.4.0.5076 - COMODO Security Solutions Inc.)
CPUID HWMonitor 1.29 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CrystalDiskInfo 6.5.2 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.5.2 - Crystal Dew World)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.1.0.0074 - Disc Soft Ltd)
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Deus Ex Human Revolution - Directors Cut verze 2.0.0.0u1 (HKLM-x32\...\Deus Ex Human Revolution - Directors Cut_is1) (Version: 2.0.0.0u1 - Sqare Enix)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Fallout 4 v.1.5.157 (HKLM-x32\...\Fallout 4_is1) (Version: - )
Far Cry 4 - Gold Edition verze 1.9.0 (HKLM-x32\...\{16912222-481A-4D9D-B7F8-81BE1F98B0E5}_is1) (Version: 1.9.0 - Ubisoft)
Fraps (HKLM-x32\...\Fraps) (Version: - )
Garrys Mod version 14.07.10 (HKLM\...\{C8F834F5-46EA-4933-8AA9-F6CD7D29EED0}_is1) (Version: 14.07.10 - Strogino CS Portal)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
Hitman Absolution v1.0.446.0 (HKLM-x32\...\Hitman Absolution_is1) (Version: - )
Chromodo (HKLM-x32\...\Chromodo) (Version: 50.14.22.468 - Comodo)
iFunbox (v3.0.3109.1352) (HKLM-x32\...\iFunbox_is1) (Version: v3.0.3109.1352 - iFunbox DevTeam)
IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4331 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.2.1000 - Intel Corporation)
iTunes (HKLM\...\{955524E7-79EB-4CA9-BA4D-FD2DF587651B}) (Version: 12.4.3.1 - Apple Inc.)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10279 - Realtek Semiconductor Corp.)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11105 - Realtek Semiconductor Corp.)
Lenovo Motion Control (HKLM-x32\...\InstallShield_{A60E1DE0-2AD1-4BD3-BBCC-4FBB22FB6F85}) (Version: 2.5.1.0225 - PointGrab)
Lenovo Motion Control (x32 Version: 2.5.1.0225 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden
Lenovo Settings (HKLM-x32\...\InstallShield_{42F8AFC3-7944-46CC-9689-94FF9869D0A7}) (Version: 1.0.0.52 - Lenovo)
Lenovo Settings (x32 Version: 1.0.0.52 - Lenovo) Hidden
Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.1.0.61 - Lenovo)
Lenovo Updates (x32 Version: 1.1.0.61 - Lenovo) Hidden
Lenovo_Wireless_Driver (HKLM-x32\...\{5D642A72-8194-4A22-80DA-11FE610CCA8E}) (Version: 6.35.223.5 - Lenovo)
LenovoUtility (HKLM-x32\...\InstallShield_{6ADA7E88-8D16-4D0D-BC90-2B93AC5E56DA}) (Version: 3.0.0.4 - Lenovo)
LenovoUtility (x32 Version: 3.0.0.4 - Lenovo) Hidden
Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - )
Malwarebytes Anti-Malware verze 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mass Effect (HKLM-x32\...\Mass Effect_is1) (Version: - )
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (čeština) (HKLM-x32\...\{E249803A-BD5B-4FDC-A630-976C2971F5B4}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (čeština) (HKLM-x32\...\{25C7677B-0398-46A3-A0EE-7B393D20FA30}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4641.3004 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 Express LocalDB (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2016 LocalDB (HKLM\...\{E359515A-92E6-4FA3-A2C9-E1BA02D8DE6E}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server 2016 Management Objects (HKLM-x32\...\{0F1C8E2F-199A-4946-B3BF-0906DACFD032}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{20EA85AA-2A1D-4F11-B09F-4BA2BF3C8989}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{8BFDE775-C5B8-46DB-84EF-43FFC8A2E8AD}) (Version: 13.0.14500.10 - Microsoft Corporation)
Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{D091DE8C-EA0F-49AF-8DE3-BD6C79737C6E}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (14.0.60519.0) (HKLM-x32\...\{4E27B0EF-7BAB-432A-AF3D-3FC8F3F7353F}) (Version: 14.0.60519.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2016 (HKLM\...\{96EB5054-C775-4BEF-B7B9-AA96A295EDCD}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2016 (HKLM-x32\...\{84C23ECA-FE4D-494F-9247-3EBAD57E7F0C}) (Version: 13.0.1601.5 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation)
MK LOL (HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\MK LOL) (Version: - )
Need for Speed Most Wanted Modded verze 1.3 (HKLM-x32\...\{1DD6C8AA-3DF8-480D-BD74-B1108197A60A}_is1) (Version: 1.3 - Mlcik)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.61.23 - Black Tree Gaming)
No Man's Sky (HKLM-x32\...\1446213994_is1) (Version: 2.0.0.2 - GOG.com)
NVIDIA Ovladač 3D Vision 372.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 372.54 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 372.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.54 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Oddworld - New n Tasty (HKLM-x32\...\Oddworld - New n Tasty_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
Onekey Theater (HKLM-x32\...\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo)
Outlast + DLC Whistleblower verze 1.0 (HKLM-x32\...\Outlast + DLC Whistleblower_is1) (Version: 1.0 - Danik1B9)
Ovládací panel NVIDIA 372.54 (Version: 372.54 - NVIDIA Corporation) Hidden
Podpora aplikací Apple (32bitová) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)
Podpora aplikací Apple (64bitová) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.)
PP助手5.0 (HKLM-x32\...\PP助手5.0) (Version: 5.0.3.1154 - 广州爱禾网络技术有限公司)
Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
Prerequisites for SSDT (HKLM-x32\...\{B7E94916-7AE6-4F7F-A377-7A410A42BA19}) (Version: 13.0.1601.5 - Microsoft Corporation)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.21243 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.9.6 - Rockstar Games)
Roslyn Language Services - x86 (x32 Version: 14.0.25425 - Microsoft Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.5 - Synaptics Incorporated)
Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (x32 Version: 14.102.25521 - Microsoft) Hidden
Thief (HKLM-x32\...\Thief_is1) (Version: 4107.3 - Eidos)
TVCenter (HKLM\...\{B32267A7-4B02-4C03-A69C-61247B3A3A2C}) (Version: 6.4.9.1033 - PCTV Systems)
TypeScript Tools for Microsoft Visual Studio 2015 (x32 Version: 1.8.36.0 - Microsoft Corporation) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Windows Driver Package - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
Wooxy version 1.3 (HKLM-x32\...\{C183CD14-47D8-4F98-AF06-4744CB834C8E}_is1) (Version: 1.3 - Chewy)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3291327581-932694293-2557528726-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00D9FB78-DCE8-4853-9C73-BE7E9AF17108} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-09] (Microsoft Corporation)
Task: {0829C442-011F-4FD1-BC6B-079FC1D3D959} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {0CFDA15F-D358-4A30-830F-DD41A3E11963} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-10] (Lenovo)
Task: {311E41A9-357C-4454-A4C8-9CC089DCF5CA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-06] (Google Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe
Task: {3FD624F5-0C5A-488B-9DFB-1CA39481236F} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe
Task: {42C14FA6-12E7-4F9C-B69A-B5831D2DFE7F} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe
Task: {4CBC473A-6582-4845-9A1E-0ED3F0086D75} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {511172A1-E464-4155-A189-E41A694D1BB0} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-11-26] (Synaptics Incorporated)
Task: {605F225B-AAF1-4900-A788-61F58F39837D} - System32\Tasks\{28BA422C-BD33-4382-9CDB-C0830C5130A6} => pcalua.exe -a "C:\Games\League of Legends\lol.launcher.exe" -d "C:\Games\League of Legends\"
Task: {7738114F-9F41-4D4F-A4C0-FAD2723D4284} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-06] (Google Inc.)
Task: {85431F11-A76C-4A1D-B4E3-D0F1CC62481C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {862835A2-984A-4C0A-8746-24C60898CF2D} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-07-10] (COMODO)
Task: {9BC544CA-8138-4CA9-836A-16D149AABB5F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A0B094F7-C0FE-49F1-83D3-6A58DA7FEC47} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A36B983E-17BD-4504-A3CD-1E9AB8FEE942} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {A9E6F4BD-7A4F-4B5A-B0E5-AEED0A2A8A52} - System32\Tasks\{D967501B-B337-459D-BA83-15C4F62A7152} => pcalua.exe -a "C:\Users\Neocron\Desktop\World of Warcraft 1.12\WoW.exe" -d "C:\Users\Neocron\Desktop\World of Warcraft 1.12"
Task: {B953085F-8B3F-4EA4-BF7A-5BC08F780B5D} - System32\Tasks\{D922782C-5A52-449D-B92A-A105A416F446} => pcalua.exe -a "C:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=all
Task: {C78F800B-7415-42B9-827C-717873E31D23} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {CA606F7D-C96D-4667-B573-42DF603C98B1} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {CAA285FB-DE18-4388-B60E-73477FB4CFC3} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-07-10] (COMODO)
Task: {D0A69406-165F-4D13-B905-F5A615B9F31D} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-07-10] (COMODO)
Task: {E070DCE7-2447-416A-BF50-F9FF3937F0CD} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2016-07-10] (COMODO)
Task: {EA0C7CC4-81F4-47B9-B81A-18595796C50B} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: {EB4056E6-AA67-41B6-AF2B-6117BB9EE201} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2013-02-26] (Beepa P/L)
Task: {F622189C-E274-4067-A84B-3B9B17306EE2} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-07] (Intel Corporation)
Task: {FA543852-904C-41E0-AD55-6446BEE66A3F} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2016-07-10] (COMODO)
Task: {FD066D35-4D90-49EF-9A07-9F70A5681281} - \CCleanerSkipUAC -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Neocron\Desktop\Spouštěč aplikací Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Spouštěč aplikací Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Neocron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Vzdálená plocha Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp

==================== Loaded Modules (Whitelisted) ==============

2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-08-19 15:26 - 2016-08-11 14:27 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-10-10 19:50 - 2015-10-10 19:50 - 00075136 _____ () C:\WINDOWS\SysWoW64\PnkBstrA.exe
2016-07-16 13:42 - 2016-07-16 13:42 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-08-19 09:03 - 2016-08-19 09:03 - 00959168 _____ () C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00130048 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
2016-07-16 13:42 - 2016-07-16 13:42 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-07-16 13:43 - 2016-07-16 13:43 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-07-16 13:43 - 2016-07-16 13:43 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll
2016-07-16 13:43 - 2016-07-17 00:29 - 09761280 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 01401344 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-07-16 13:43 - 2016-07-17 00:29 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 02438144 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-09-01 15:52 - 2016-09-01 15:52 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-08-16 08:48 - 2016-08-16 08:49 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-08-16 08:48 - 2016-08-16 08:49 - 13475840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-06-03 15:18 - 2016-06-03 15:18 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2016-03-04 14:01 - 2016-03-04 14:02 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2015-06-24 22:57 - 2015-06-24 22:57 - 00133184 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2016-03-16 11:25 - 2016-03-16 11:25 - 00073912 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
2010-12-17 22:56 - 2010-12-17 22:56 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
2013-03-07 22:53 - 2013-03-07 22:53 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
2010-12-17 22:56 - 2010-12-17 22:56 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
2010-12-17 22:56 - 2010-12-17 22:56 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
2010-01-13 02:55 - 2010-01-13 02:55 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
2010-01-13 02:55 - 2010-01-13 02:55 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
2010-12-16 22:16 - 2010-12-16 22:16 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
2010-01-18 09:34 - 2010-01-18 09:34 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
2013-03-07 22:55 - 2013-03-07 22:55 - 00472576 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
2013-03-07 22:58 - 2013-03-07 22:58 - 00499488 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
2013-03-07 22:54 - 2013-03-07 22:54 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\WINDOWS\system32\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\acmigration.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\appraiser.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AppXApplicabilityBlob.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AppXDeploymentServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AudioSes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\audiosrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\AzureSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CastLaunch.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\cdd.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Chakra.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Chakradiag.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Chakrathunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ClipUp.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CloudBackupSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CloudExperienceHostUser.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\clusapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\combase.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CompatTelRunner.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ConsoleLogon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\container.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\CredProvDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\C_G18030.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\c_GSM7.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\C_IS2022.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\d3d12SDKLayers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dafpos.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\das.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dasHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\delegatorprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\deviceassociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DeviceCensus.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\difx64.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\domgmt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dosvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DPTopologyApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DPTopologyAppv2_0.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DscCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\DscCoreConfProv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dwmcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\dxmasf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\edgehtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\encapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\facecredentialprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\FrameServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fveapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\fveapibase.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\GamePanel.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\generaltel.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\GenValObj.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\GfxUIEx.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Gfxv2_0.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Gfxv4_0.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\hvax64.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\hvix64.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\hvloader.efi:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\hvloader.exe:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\ie4uinit.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\iedkcs32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ieframe.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\iernonce.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\iertutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\iesetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\igfxCUIService.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\igfxEM.exe:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\igfxext.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\igfxHK.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\igfxSDK.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\igfxTray.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\indexeddbserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\inetcpl.cpl:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\InstallAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\InstallAgentUserBroker.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\IntelCpHDCPSvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\IntelWiDiUMS64.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\kdhvcom.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KnobsCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\KnobsCsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\LicenseManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\LicenseManagerSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\LockAppHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\lsasrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MCRecvSrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfcore.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfpmp.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mfsvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mispace.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MSAJApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msctf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msdxm.ocx:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\msfeeds.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mshtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\mstsc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MusNotification.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\MusUpdateHandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\netiougc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NetworkMobileSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NFCProvisioningPlugin.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ntoskrnl.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvapi64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvdispco6435435.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvdispco6437254.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco6435435.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco6437254.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvEncMFTH264.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvEncodeAPI64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvfatbinaryLoader.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NvFBC64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NvIFR64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvoglv64.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvptxJitCompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\nvvsvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\offlinelsa.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\pidgenx.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provdatastore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provengine.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provhandlers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provisioningcsp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provops.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ProvPluginEng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\provtool.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\qmgr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\reseteng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ResetEngine.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\ResetEngine.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\rpcrt4.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\samlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\samsrv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\schannel.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_nt.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingSyncCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SettingSyncPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\shell32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\shutdownux.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\slc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\slcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\sppsvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\spwmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\StorageUsage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\storagewmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\storagewmi_passthru.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\StoreAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\StorSvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\SysResetErr.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\systemreset.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\tcpipcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\tsmf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\twinui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\updatepolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\uReFS.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\urlmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\usbaaplrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\usocore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\w32time.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wfdprov.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WiFiConfigSP.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wifiprofilessettinghandler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\win32kbase.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\win32kfull.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WinBioDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WinBioDataModelOOBE.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Audio.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Editing.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\windows.storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Logon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Search.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\winload.efi:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\winload.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\winmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\winresume.efi:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\winresume.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WinTypes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlanapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlanhlp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlanmsm.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlansec.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlansvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wlansvcpal.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wmp.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\wmploc.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WpAXHolder.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wpninprc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wsp_fs.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wsp_health.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\wuauclt.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wuaueng.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wups2.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wuuhext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\WWAHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wwanprotdim.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wwansvc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\XblAuthManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\aclui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AudioSes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\bcastdvr.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\BcastDVRHelper.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Chakra.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Chakradiag.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Chakrathunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ClipboardServer.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudBackupSettings.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\clusapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\combase.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\container.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\CredProvDataModel.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\C_G18030.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\c_GSM7.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\C_IS2022.DLL:$CmdTcID [64]

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 11:13

Addition čast 2 :

AlternateDataStreams: C:\WINDOWS\SysWOW64\D3D12.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\delegatorprovider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\deviceassociation.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\DscCoreConfProv.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\dwmcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\dxmasf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\edgehtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\encapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\FSClient.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\GamePanel.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\iedkcs32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ieframe.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\iernonce.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\iertutil.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\iesetup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\indexeddbserver.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\inetcpl.cpl:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\InstallAgent.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\LicenseManager.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\LockAppHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MCRecvSrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfksproxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfnetcore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfnetsrc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfpmp.exe:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfps.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsensorgroup.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsrcsnk.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mfsvr.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mispace.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\MSAJApi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msctf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msdxm.ocx:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\msfeeds.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mshtml.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\mstsc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\netiougc.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\ntdll.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvapi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvcompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvcuda.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvcuvid.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvEncMFTH264.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvEncodeAPI.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NvFBC.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NvIFR.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\NvIFROpenGL.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvoglv32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvopencl.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\nvStreaming.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\oemdspif.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\offlinelsa.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\offlinesam.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\pidgenx.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\rpcrt4.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\samlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\schannel.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncCore.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\shell32.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\slc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\slcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\smphost.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sppc.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\sppcext.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\spwmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\storagewmi.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\storagewmi_passthru.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\StoreAgent.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\tcpipcfg.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\tsmf.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\twinui.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\updatepolicy.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\uReFS.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\urlmon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wfdprov.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\win32kfull.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wincorlib.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\windows.storage.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\winmde.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WinTypes.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanapi.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wlanhlp.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmp.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wmploc.DLL:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_fs.dll:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\SysWOW64\wsp_health.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\SysWOW64\WWAHost.exe:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\bthport.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\BTHUSB.SYS:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\ClipSp.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\cng.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgkrnl.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgmms1.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\dxgmms2.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidclass.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidparse.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\hidusb.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\hvservice.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\ksecpkg.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mrxsmb20.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\ntfs.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\partmgr.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\pdc.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\rdbss.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\stornvme.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\tcpip.sys:$CmdTcID [130]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\usbaapl64.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wof.sys:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\xinputhid.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\Neocron\Desktop\adwcleaner_6.010.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Neocron\Desktop\adwcleaner_6.010.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Neocron\Desktop\Butchers Bridge v1.0 (By Project Leischii, The Natoken Project, Mapskins Porters).wxy:$CmdZnID [26]
AlternateDataStreams: C:\Users\Neocron\Desktop\Sharp Rift v1 (By Existor).wxy:$CmdZnID [26]
AlternateDataStreams: C:\Users\Neocron\Downloads\adwcleaner_6.010.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Neocron\Downloads\adwcleaner_6.010.exe:$CmdZnID [26]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Classes\regfile: regedit.exe "%1" <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2016-09-10 11:52 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Neocron\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\{7481f7cc-1072-4e4e-9ed4-5ccb08a80f01}.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: BcmBtRSupport => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: Disc Soft Lite Bus Service => 3
MSCONFIG\Services: EvtEng => 2
MSCONFIG\Services: igfxCUIService2.0.0.0 => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2
MSCONFIG\Services: Intel(R) Capability Licensing Service TCP IP Interface => 3
MSCONFIG\Services: Intel(R) ME Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: jhi_service => 2
MSCONFIG\Services: LenovoSetSvr => 2
MSCONFIG\Services: LenovoWiFiHotspotSvr => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: LUService => 2
MSCONFIG\Services: MyWiFiDHCPDNS => 3
MSCONFIG\Services: PGService => 2
MSCONFIG\Services: PG_Service_Launcher => 2
MSCONFIG\Services: RegSrvc => 2
MSCONFIG\Services: ZeroConfigService => 2
HKLM\...\StartupApproved\StartupFolder: => "Vyhledat aktualizace.lnk"
HKLM\...\StartupApproved\Run: => "Energy Manager"
HKLM\...\StartupApproved\Run: => "OnekeyStudio"
HKLM\...\StartupApproved\Run: => "PhoneCompanion"
HKLM\...\StartupApproved\Run: => "Lenovo Utility"
HKLM\...\StartupApproved\Run: => "NvBackend"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "LenovoUtility"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "EaseUS EPM tray"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "MK LOL"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "RemoTerm.exe"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\StartupApproved\Run: => "iFunBox"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{7F16D22E-576B-49A9-8934-02BC3093D48A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [UDP Query User{55174B74-3DB1-432B-8253-0417B5D7C593}C:\program files (x86)\pp助手5.0\adevicehelpermon.exe] => (Allow) C:\program files (x86)\pp助手5.0\adevicehelpermon.exe
FirewallRules: [TCP Query User{1A865BA2-C9B2-4093-93D4-3435D6AF8275}C:\program files (x86)\pp助手5.0\adevicehelpermon.exe] => (Allow) C:\program files (x86)\pp助手5.0\adevicehelpermon.exe
FirewallRules: [UDP Query User{C96E13E1-A393-4E83-AEE7-82F8C8EE73AD}C:\program files (x86)\pp助手5.0\pphelper5.exe] => (Allow) C:\program files (x86)\pp助手5.0\pphelper5.exe
FirewallRules: [TCP Query User{5637722D-ECF1-48D4-BDF9-B49D63B08143}C:\program files (x86)\pp助手5.0\pphelper5.exe] => (Allow) C:\program files (x86)\pp助手5.0\pphelper5.exe
FirewallRules: [{CCA2D622-CC09-4C14-B057-9A43D6CC61B0}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe
FirewallRules: [{A6DD2821-16E8-4D82-AA74-A6E63FE86BE6}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouseCore.exe
FirewallRules: [{07D96606-D06F-4B23-94B5-E825CBBE916C}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [{43EEBC4B-F5E8-4615-B695-4E446B2562F8}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [{A424DDF5-6C4C-48FF-A0AC-0171490F637A}] => (Allow) LPort=2869
FirewallRules: [{FD5400A7-5398-47D9-A278-12250BF6C491}] => (Allow) LPort=1900
FirewallRules: [{A6303874-3376-4512-AC7F-CE2E59D85DFF}] => (Allow) C:\Program Files (x86)\Common Files\PCTV Systems\StreamingServer\StrmServer.exe
FirewallRules: [{4AE274CE-DD3B-438B-B6DC-A95692116243}] => (Allow) C:\Program Files (x86)\Common Files\PCTV Systems\PVR\VideoControl.exe
FirewallRules: [{B3A85432-A46B-400A-9ADE-135E05A2DB6B}] => (Allow) C:\Program Files (x86)\PCTV Systems\TVCenter\TVCenter.exe
FirewallRules: [{346AEEC1-98D4-47CE-932F-28BE5F39D10D}] => (Block) C:\games\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [{E22247E8-87FC-46E0-905A-11C75114D595}] => (Block) C:\games\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{53206598-CC02-4E09-8DFB-856008AE1933}C:\games\outlast + dlc whistleblower\binaries\win64\olgame.exe] => (Allow) C:\games\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [TCP Query User{B123C1BC-D547-48CA-9494-B7684716B590}C:\games\outlast + dlc whistleblower\binaries\win64\olgame.exe] => (Allow) C:\games\outlast + dlc whistleblower\binaries\win64\olgame.exe
FirewallRules: [{4830A904-55DE-48ED-9782-DCB187D28DFA}] => (Allow) C:\Games\Steam\bin\steamwebhelper.exe
FirewallRules: [{5CBFDFC5-E5C7-4F6C-8C42-86E741368E3C}] => (Allow) C:\Games\Steam\bin\steamwebhelper.exe
FirewallRules: [{52AE0F46-F2D8-44FE-9D01-9A3A1CEC646A}] => (Allow) C:\Games\Steam\Steam.exe
FirewallRules: [{B9554C9E-4B51-48E7-A5B7-7F845B315CBA}] => (Allow) C:\Games\Steam\Steam.exe
FirewallRules: [UDP Query User{1445E19A-84A5-4FC2-8824-ECA333FE873D}C:\games\techland - steve hood\dying light\dying light\dyinglightgame.exe] => (Block) C:\games\techland - steve hood\dying light\dying light\dyinglightgame.exe
FirewallRules: [TCP Query User{EE4AF0D5-FEA6-4D62-8804-7E63841BC073}C:\games\techland - steve hood\dying light\dying light\dyinglightgame.exe] => (Block) C:\games\techland - steve hood\dying light\dying light\dyinglightgame.exe
FirewallRules: [{74F45912-3DE6-4F0D-8F26-67E3B86D57EC}] => (Block) C:\users\neocron\desktop\plague inc\plagueincevolved.exe
FirewallRules: [{0DE1C0EF-BF06-4C15-9CCB-C7A2E9C8C8A0}] => (Block) C:\users\neocron\desktop\plague inc\plagueincevolved.exe
FirewallRules: [UDP Query User{BF7F6E8C-F689-4B7B-9525-42E5DEA7E3FF}C:\users\neocron\desktop\plague inc\plagueincevolved.exe] => (Allow) C:\users\neocron\desktop\plague inc\plagueincevolved.exe
FirewallRules: [TCP Query User{A66A2506-226C-4B29-A0B2-C2A245A9121D}C:\users\neocron\desktop\plague inc\plagueincevolved.exe] => (Allow) C:\users\neocron\desktop\plague inc\plagueincevolved.exe
FirewallRules: [UDP Query User{E7D8109F-FE03-4BB9-B896-76DD883037BA}C:\games\r.g. mechanics\oddworld - new n tasty\nnt.exe] => (Block) C:\games\r.g. mechanics\oddworld - new n tasty\nnt.exe
FirewallRules: [TCP Query User{A115F186-8D89-488A-B662-9826B456241F}C:\games\r.g. mechanics\oddworld - new n tasty\nnt.exe] => (Block) C:\games\r.g. mechanics\oddworld - new n tasty\nnt.exe
FirewallRules: [{5012C686-A13F-4ED4-85DF-168EF9AC857C}] => (Allow) C:\Games\Rockstar Games\Grand Theft Auto V\GTA5.exe
FirewallRules: [{1A43A78E-5FF3-419B-81F4-CB87DC939FF7}] => (Allow) C:\Games\Rockstar Games\Grand Theft Auto V\GTA5.exe
FirewallRules: [{AFA22DD1-AE7C-4FE3-9D3A-DCA0E4C96182}] => (Allow) LPort=55100
FirewallRules: [TCP Query User{F5215F06-B0EE-49AC-A21F-DED1625FB93A}C:\games\far cry 4 - gold edition\bin\farcry4.exe] => (Block) C:\games\far cry 4 - gold edition\bin\farcry4.exe
FirewallRules: [UDP Query User{9FCE5913-E823-4564-B7B1-C7708AE59071}C:\games\far cry 4 - gold edition\bin\farcry4.exe] => (Block) C:\games\far cry 4 - gold edition\bin\farcry4.exe
FirewallRules: [TCP Query User{8CEF319D-2FD1-45CE-9EE2-8F21F488C3C7}C:\games\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\games\rockstar games\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{9714B05F-EEDC-4436-810D-96412B2FA1B0}C:\games\rockstar games\grand theft auto v\gta5.exe] => (Allow) C:\games\rockstar games\grand theft auto v\gta5.exe
FirewallRules: [{524312D1-9F82-4C3B-BB51-6C4D8028D623}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C8542CE9-A61E-4A50-A05E-CFE3FD64AA56}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7F22BCB2-20CA-4805-9993-81EF145E15B2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E68ADFB5-100D-48C5-B058-599A807B051F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{284C70A9-E4AA-49CB-AC71-167B3AECF69F}C:\wow cata\backgrounddownloader.exe] => (Allow) C:\wow cata\backgrounddownloader.exe
FirewallRules: [UDP Query User{DFE9BFB6-C936-4AB6-A278-349AEED36E46}C:\wow cata\backgrounddownloader.exe] => (Allow) C:\wow cata\backgrounddownloader.exe
FirewallRules: [{312458C8-5860-4C31-A260-1F7FBB7D914B}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{279C6E20-1FA4-4BD4-8D0D-528EB3563088}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{4446025A-6A5E-4B5F-A74E-5D75DE1BC7C2}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{537B3493-365F-434E-923D-BB40795E7958}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{5D8DB5B5-7392-4D58-9691-25F89E596393}C:\games\garrys mod\hl2.exe] => (Allow) C:\games\garrys mod\hl2.exe
FirewallRules: [UDP Query User{DDB08713-6D22-4897-8360-0D76FDA7C936}C:\games\garrys mod\hl2.exe] => (Allow) C:\games\garrys mod\hl2.exe
FirewallRules: [TCP Query User{5CE8BFF3-C1E3-4C1F-B616-02A9E1945580}C:\games\garrys mod\hl2.exe] => (Allow) C:\games\garrys mod\hl2.exe
FirewallRules: [UDP Query User{1DCE4059-9A87-4956-9B65-16964B41CC71}C:\games\garrys mod\hl2.exe] => (Allow) C:\games\garrys mod\hl2.exe
FirewallRules: [TCP Query User{13118D94-013F-424F-B8D2-261DBAA93F4A}C:\games\fallout 4\fallout4.exe] => (Block) C:\games\fallout 4\fallout4.exe
FirewallRules: [UDP Query User{654C294E-1E1E-414F-892A-5661E83F6736}C:\games\fallout 4\fallout4.exe] => (Block) C:\games\fallout 4\fallout4.exe
FirewallRules: [TCP Query User{F014C3F1-9A57-4A7E-809D-26326DAA2061}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [UDP Query User{B7473F07-13BE-4213-98D4-84BB01CEBB5C}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [{0C707A33-55DE-4F8B-B5AB-8DE69C92042A}] => (Block) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [{4D104239-7F2E-48F8-9034-33BA1B814683}] => (Block) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [{6B77C2E1-9AFC-42A1-9189-C54D177ECC93}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{73EB7B98-4ABD-4946-B9BF-BDD1C4339B5A}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{59AF1563-2B35-4A16-813B-2703F0990D25}C:\users\neocron\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\neocron\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{40FE255E-0387-4B30-9FDF-23801A8953EF}C:\users\neocron\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\neocron\appdata\roaming\utorrent\utorrent.exe

==================== Restore Points =========================

07-09-2016 18:18:52 Naplánovaný kontrolní bod
10-09-2016 11:49:38 zoek.exe restore point

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/10/2016 08:56:32 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Procedura Open pro službu BITS v knihovně DLL C:\Windows\System32\bitsperf.dll se nezdařila. Výkonnostní data pro tuto službu nebudou k dispozici. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.

Error: (09/10/2016 11:50:04 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (09/10/2016 11:39:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: wmiprvse.exe, verze: 10.0.14393.0, časové razítko: 0x57899ab2
Název chybujícího modulu: ntdll.dll, verze: 10.0.14393.103, časové razítko: 0x57b7e207
Kód výjimky: 0xc0000374
Posun chyby: 0x00000000000f73f3
ID chybujícího procesu: 0x13ac
Čas spuštění chybující aplikace: 0x01d20b471a722801
Cesta k chybující aplikaci: C:\WINDOWS\system32\wbem\wmiprvse.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: ac1a26ce-afab-4035-be19-59f2bfb6c8ca
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/10/2016 11:39:22 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (09/10/2016 11:39:21 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (09/10/2016 11:39:00 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (09/10/2016 11:39:00 AM) (Source: Microsoft Security Client) (EventID: 5000) (User: )
Description: Event-ID 5000

Error: (09/10/2016 12:26:09 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO-PC)
Description: Aplikaci Microsoft.XboxApp_8wekyb3d8bbwe!Microsoft.XboxApp se nepovedlo aktivovat, protože došlo k chybě: -2144927142. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (09/10/2016 12:25:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LoLPatcher.exe, verze: 0.51.0.219, časové razítko: 0x57c86db5
Název chybujícího modulu: LoLPatcher.exe, verze: 0.51.0.219, časové razítko: 0x57c86db5
Kód výjimky: 0xc0000005
Posun chyby: 0x0007d954
ID chybujícího procesu: 0x274
Čas spuštění chybující aplikace: 0x01d20ae8bd47419a
Cesta k chybující aplikaci: C:\Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.67\deploy\LoLPatcher.exe
Cesta k chybujícímu modulu: C:\Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.67\deploy\LoLPatcher.exe
ID zprávy: 75ef6708-dc97-4014-90f1-d65110993b2b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (09/09/2016 07:24:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: wmiprvse.exe, verze: 10.0.14393.0, časové razítko: 0x57899ab2
Název chybujícího modulu: msvcrt.dll, verze: 7.0.14393.0, časové razítko: 0x57899b47
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000005b1bd
ID chybujícího procesu: 0x22d0
Čas spuštění chybující aplikace: 0x01d20abedb47c4d3
Cesta k chybující aplikaci: C:\WINDOWS\system32\wbem\wmiprvse.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\msvcrt.dll
ID zprávy: 3f06f72b-2937-4c99-a7f6-a6ac77bb4ea8
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (09/10/2016 11:03:57 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/10/2016 10:58:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/10/2016 10:32:13 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 4003) (User: NT AUTHORITY)
Description: Služba Automatická konfigurace sítě WLAN zjistila při resetování nebo zotavení adaptéru omezené připojení.

Kód: 8 0x0 0x0

Error: (09/10/2016 10:32:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 4003) (User: NT AUTHORITY)
Description: Služba Automatická konfigurace sítě WLAN zjistila při resetování nebo zotavení adaptéru omezené připojení.

Kód: 2 0xdeaddeed 0xeeec

Error: (09/10/2016 10:32:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 4003) (User: NT AUTHORITY)
Description: Služba Automatická konfigurace sítě WLAN zjistila při resetování nebo zotavení adaptéru omezené připojení.

Kód: 1 0xc 0x4

Error: (09/10/2016 08:59:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/10/2016 03:19:15 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} se v daném časovém limitu neregistroval u služby DCOM.

Error: (09/10/2016 12:57:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
a APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (09/10/2016 12:57:25 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba WMPNetworkSvc závisí na službě WSearch, která neuspěla při spuštění v důsledku následující chyby:
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.

Error: (09/10/2016 12:36:15 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


CodeIntegrity:
===================================
Date: 2016-09-10 22:06:41.661
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-10 12:57:06.881
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-09-10 11:34:34.645
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-10 11:11:00.245
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-09-10 01:35:14.926
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-10 01:13:19.295
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-08 22:14:18.101
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-08 16:09:37.259
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-08 16:09:25.300
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-09-07 18:52:11.413
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\guard64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4210H CPU @ 2.90GHz
Percentage of memory in use: 24%
Total physical RAM: 8104.27 MB
Available physical RAM: 6114.52 MB
Total Virtual: 9384.27 MB
Available Virtual: 7069.12 MB

==================== Drives ================================

Drive c: (Windows10_OS) (Fixed) (Total:888.87 GB) (Free:253.65 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive l: (LENOVO) (Fixed) (Total:25 GB) (Free:20.18 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 4F6DA4E3)

Partition: GPT.

==================== End of Addition.txt ============================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logů

Příspěvekod jaro3 » 11 zář 2016 15:06

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\RunOnce: [Uninstall C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\MountPoints2: {e01d5031-3d1f-11e5-9bc3-2c337aeec048} - "F:\setup.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
SearchScopes: HKLM -> DefaultScope {6036D3F6-0EE2-44BA-8212-5401349500AF} URL =
SearchScopes: HKLM-x32 -> DefaultScope {6036D3F6-0EE2-44BA-8212-5401349500AF} URL =
SearchScopes: HKU\S-1-5-21-3291327581-932694293-2557528726-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3291327581-932694293-2557528726-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
C:\WINDOWS\system32\C_932.NLS
2016-08-19 08:36 - 2016-08-19 08:36 - 00003268 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-19 08:36 - 2016-08-19 08:36 - 00002362 _____ C:\WINDOWS\System32\Tasks\{D967501B-B337-459D-BA83-15C4F62A7152}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002312 _____ C:\WINDOWS\System32\Tasks\{D922782C-5A52-449D-B92A-A105A416F446}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002298 _____ C:\WINDOWS\System32\Tasks\{28BA422C-BD33-4382-9CDB-C0830C5130A6}
C:\WINDOWS\System32\Tasks\McAfee
C:\ProgramData\DP45977C.lfl
C:\ProgramData\lcsuc_prof.cfg
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-08-19 06:25 - 2015-08-06 16:48 - 00000980 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-19 00:25 - 2015-08-06 16:47 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
Task: {0829C442-011F-4FD1-BC6B-079FC1D3D959} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {311E41A9-357C-4454-A4C8-9CC089DCF5CA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-06] (Google Inc.)
Task: {7738114F-9F41-4D4F-A4C0-FAD2723D4284} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-06] (Google Inc.)
Task: {85431F11-A76C-4A1D-B4E3-D0F1CC62481C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9BC544CA-8138-4CA9-836A-16D149AABB5F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A0B094F7-C0FE-49F1-83D3-6A58DA7FEC47} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {C78F800B-7415-42B9-827C-717873E31D23} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {EA0C7CC4-81F4-47B9-B81A-18595796C50B} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: {FD066D35-4D90-49EF-9A07-9F70A5681281} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Classes\regfile: regedit.exe "%1" <===== ATTENTION

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\WINDOWS\system32\GfxValDisplayLog.bin

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 20:50

Fix result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016
Ran by Neocron (11-09-2016 20:45:47) Run:1
Running from C:\Users\Neocron\Desktop
Loaded Profiles: Neocron (Available Profiles: Neocron)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\RunOnce: [Uninstall C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\...\MountPoints2: {e01d5031-3d1f-11e5-9bc3-2c337aeec048} - "F:\setup.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
SearchScopes: HKLM -> DefaultScope {6036D3F6-0EE2-44BA-8212-5401349500AF} URL =
SearchScopes: HKLM-x32 -> DefaultScope {6036D3F6-0EE2-44BA-8212-5401349500AF} URL =
SearchScopes: HKU\S-1-5-21-3291327581-932694293-2557528726-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3291327581-932694293-2557528726-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
C:\WINDOWS\system32\C_932.NLS
2016-08-19 08:36 - 2016-08-19 08:36 - 00003268 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-08-19 08:36 - 2016-08-19 08:36 - 00002362 _____ C:\WINDOWS\System32\Tasks\{D967501B-B337-459D-BA83-15C4F62A7152}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002312 _____ C:\WINDOWS\System32\Tasks\{D922782C-5A52-449D-B92A-A105A416F446}
2016-08-19 08:36 - 2016-08-19 08:36 - 00002298 _____ C:\WINDOWS\System32\Tasks\{28BA422C-BD33-4382-9CDB-C0830C5130A6}
C:\WINDOWS\System32\Tasks\McAfee
C:\ProgramData\DP45977C.lfl
C:\ProgramData\lcsuc_prof.cfg
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-08-19 06:25 - 2015-08-06 16:48 - 00000980 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-19 00:25 - 2015-08-06 16:47 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
Task: {0829C442-011F-4FD1-BC6B-079FC1D3D959} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {311E41A9-357C-4454-A4C8-9CC089DCF5CA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-06] (Google Inc.)
Task: {7738114F-9F41-4D4F-A4C0-FAD2723D4284} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-06] (Google Inc.)
Task: {85431F11-A76C-4A1D-B4E3-D0F1CC62481C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9BC544CA-8138-4CA9-836A-16D149AABB5F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A0B094F7-C0FE-49F1-83D3-6A58DA7FEC47} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {C78F800B-7415-42B9-827C-717873E31D23} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {EA0C7CC4-81F4-47B9-B81A-18595796C50B} - \OFFICE2013ACT -> No File <==== ATTENTION
Task: {FD066D35-4D90-49EF-9A07-9F70A5681281} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Classes\regfile: regedit.exe "%1" <===== ATTENTION

EmptyTemp:
End
*****************

Processes closed successfully.
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Neocron\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64 => value removed successfully
"HKU\S-1-5-21-3291327581-932694293-2557528726-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e01d5031-3d1f-11e5-9bc3-2c337aeec048}" => key removed successfully
HKCR\CLSID\{e01d5031-3d1f-11e5-9bc3-2c337aeec048} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-3291327581-932694293-2557528726-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-3291327581-932694293-2557528726-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
C:\WINDOWS\system32\C_932.NLS => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\WINDOWS\System32\Tasks\{D967501B-B337-459D-BA83-15C4F62A7152} => moved successfully
C:\WINDOWS\System32\Tasks\{D922782C-5A52-449D-B92A-A105A416F446} => moved successfully
C:\WINDOWS\System32\Tasks\{28BA422C-BD33-4382-9CDB-C0830C5130A6} => moved successfully
C:\WINDOWS\System32\Tasks\McAfee => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully
C:\ProgramData\lcsuc_prof.cfg => moved successfully
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat => moved successfully
C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0829C442-011F-4FD1-BC6B-079FC1D3D959}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0829C442-011F-4FD1-BC6B-079FC1D3D959}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{311E41A9-357C-4454-A4C8-9CC089DCF5CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{311E41A9-357C-4454-A4C8-9CC089DCF5CA}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7738114F-9F41-4D4F-A4C0-FAD2723D4284}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7738114F-9F41-4D4F-A4C0-FAD2723D4284}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{85431F11-A76C-4A1D-B4E3-D0F1CC62481C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85431F11-A76C-4A1D-B4E3-D0F1CC62481C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BC544CA-8138-4CA9-836A-16D149AABB5F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BC544CA-8138-4CA9-836A-16D149AABB5F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A0B094F7-C0FE-49F1-83D3-6A58DA7FEC47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0B094F7-C0FE-49F1-83D3-6A58DA7FEC47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C78F800B-7415-42B9-827C-717873E31D23}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C78F800B-7415-42B9-827C-717873E31D23}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA0C7CC4-81F4-47B9-B81A-18595796C50B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA0C7CC4-81F4-47B9-B81A-18595796C50B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OFFICE2013ACT" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FD066D35-4D90-49EF-9A07-9F70A5681281}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FD066D35-4D90-49EF-9A07-9F70A5681281}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => not found.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => not found.
"HKU\S-1-5-21-3291327581-932694293-2557528726-1001\Software\Classes\regfile" => key removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 290904508 B
Java, Flash, Steam htmlcache => 353392350 B
Windows/system/drivers => 8802 B
Edge => 9216 B
Chrome => 723024713 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 20382 B
NetworkService => 0 B
Neocron => 22870495 B

RecycleBin => 49663730400 B
EmptyTemp: => 47.5 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:45:59 ====

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 21:07

Nevím zda stačí jen tohle :D všechno je OK tak mi přijde zbytečné dávat zbytek :)

SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
File name: GfxValDisplayLog.bin
Detection ratio: 0 / 55
Analysis date: 2016-09-11 19:03:40 UTC ( 0 minut ago )
7050 1259
Empty file! This file is 0 bytes in size, software running in your computer may have blocked the file that you intended to upload or you may have sent an empty file.

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logů

Příspěvekod jerabina » 11 zář 2016 21:33

V pořádku, co problémy? :-)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Cron
Level 1.5
Level 1.5
Příspěvky: 141
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Kontrola logů

Příspěvekod Cron » 11 zář 2016 22:41

Zatím jsem nezaznamenal žádné :)

edit: Myslím žádný z uvedených :-)

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Kontrola logů

Příspěvekod jerabina » 11 zář 2016 23:36

Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore) .
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci.

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem. Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy, je to vše a můžeš dát vyřešeno - zelenou "fajfku" ;)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 5 hostů